Infesting you with Virus News
 

News

Contributed by: Lauren Gerber
Date: August 14, 2009
Lauren Gerber
1
Vote
0

Don't let the Safari 4 Top Sites Phish Bombs Get You!

 

Which web browser are you currently using? If you had to randomly select any five people from any shopping center worldwide, and ask them which browser they are using, it is highly possible that the answer will not be the same for each person. This is because there are many advantages and disadvantages to each browser available, as well as the factor that it is dependent upon personal preferences. Have you ever tried using Apple Safari? And if you did, how did you find it? Some people really enjoy using Apple Safari and use it as their browser of choice. Unfortunately a vulnerability has hit Apple Safari that relates to Safari's top website promotion feature.Apple_Safari.png

Let me get into more detail about this vulnerability, in order for you to gain a better understanding. Let it be known that Safari 4 has come up with a Top Sites feature that provides it's users with a small view of their favorite web sites in a quick glance. It is one of it's more popular features that enables users to land on their chosen websites quickly and easily. The platforms which are affected include Windows Vista and Windows XP. Some of the files of Windows XP include: acspecfc.dll, apmbatt.sys, comrepl.exe as well as compstui.dll.

The fundamental problem with this vulnerability is that manipulated websites are able to put certain arbitrary sites into your Top Sites view, this is achieved through automated actions. This will give malicious attackers the ability to perform phishing attacks. If online attackers manage to successfully exploit this vulnerability it will lead to the high risk of other types of online attacks.

The platforms which are affected:
Mac OS X v10.4.11
Mac OS X v10.5.7
Mac OS X Server v10.5.7
Windows XP
Windows Vista

Table 1. The affected platforms.

You may, at this point, be curious as to which versions of Apple Safari are vulnerable. The particular versions of Apple Safari that are vulnerable are versions prior to version 4.0.3. No I am not psychic, but I am sure you are now wondering what the solution to this vulnerability is. Firstly this vulnerability can be dealt with by preventing all automated visits to websites from affecting the Top Sites List. It is vital that only websites that are manually put into the URL address bar, be considered to be put into the Top Sites view.

There also updates which were made available in a decent time period from when this vulnerability was discovered. So the next part of the solution to this vulnerability is for all users to upgrade to the latest version, which is version 4.0.3 of the Apple Safari browser. If you are wondering where to find the updates, you do not need to wonder anymore for I will tell you. The Apple security updates are available to the general public from the Software update mechanism on the Apple web site. Alternatively you can apply the Apple Security updates for manual download from the Apple support/downloads section of the Apple web page. If you take the necessary steps, it will not be necessary for an online attacker to target you, because the problem will hopefully be gone.

User Comments

laura September 10, 2009
I second Albie. I hate everything about Top Sites; it's the only reason I quit using Safari. Do you (or anyone) know how to remove it?

Laura
Albie August 23, 2009
Lauren
Do you know how to completely disable the unecessarily intrusive, security-flawed top sites? I want to remove it COMPLETLEY.
Hope you can help me - and from my recent surfing, a lot of other folks besides!
Albie
Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

March 14, 2010
Every PC I have worked out that was infected with SE 2010 also was infected by the TDSS Rootkit. Just... more..
March 14, 2010
How do i remove the worm:win32/koobface? more..
March 14, 2010
after removeing trojan hiloti n i get an eror loading run dll efoyevalan.dll on start up more..
more comments..
rss
Home > Computer Security > Don't let the Safari 4 Top Sites Phish Bombs Get You!