safari loophole

A very serious security flaw in Apple's Safari

Researchers from they discovered a serious security flaw in some versions of Safari web of Apple. THE can be exploited by hackers to gain access to user passwords.

safari loophole

Experts say the flaw - found in OSX 10.8.5, Safari 6.0.5 (8536.30.1) and OSX 10.7.5, Safari 6.0.5 (7536.30.1) - is due to the "Open all windows from the Last Time ”or“ Reopen All Windows from Last Session ”.

This feature allows users to restore previous tabs in the browser before it closes. The security snapshot automatically connects malicious use to every website that the legitimate owner of the computer has logged in.
This feature shows that Safari stores all this information it needs somewhere. So the researchers discovered a hidden folder containing all the sensitive stuff . Unfortunately, Apple didn't take care to encrypt them.

This file, named LastSession.plist, displays all computer credentials in plain text.
So an attacker with physical access to the computer can get all of your information.
On the other hand, it is not at all difficult to develop a malicious program that will steal LastSession.plist.

Kaspersky says there is no indication that there is such a malware, however, experts believe it is only a matter of time until it appears.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).