Peter D’Orsi

Art Technology News Games

Extremely critical Mac OS X zero-day exploit released



The cause for this problem is that OS X will automatically launch shell scripts (even inside a ZIP file) when it’s missing certain syntax at the beginning of the script.

Heise online recommends this temporary workaround:
The best immediate recourse against such an attack is to deactivate the option “Open ’safe’ files after downloading” in the “General” section of Safari’s preferences. Alternative web browsers such as Camino or Firefox do not support the automatic execution of files. These browsers can be prompted to automatically download a file by using the refresh command in the HTML source code of a web page. However, the file will not be executed. Since the Finder selects the icon for a file based on its extension, users are advised to verify that the OS is using the proper file type. This can be done through the information window or in column view.




Categorized as Software

Comments are closed.