ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Mac malware door creaks open

Jo Best silicon.com

Published: 09 May 2005 17:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Dashboard, one of the much-publicised features of Apple's latest OS, Tiger, could be ripe for exploitation by porn scammers.

Apple has been encouraging developers to create new widgets for Tiger's Dashboard — a semi-transparent layer of everyday, often-used applications such as a calculator or currency converter that appears over the user's desktop — but within days of its public release, one developer claims to have already found a way to turn widgets into potential malware.

Developer Stephan, who has posted the widgets to his blog, has created two mini-apps which he describes as "slightly evil". One widget, he says, will automatically install itself on users' desktops when his 'Zaptastic' Web site is visited using Apple's Safari browser.

This, according to Stephan, is a golden opportunity for porn scammers, enabling them to auto-install widgets which can hijack browsers.

According to Stephan's blog: "I happen to like [auto-install] I think it's a great thing. But, as I have demonstrated here, it has the side effect of setting up a situation where a user can be given an application without their knowledge.

"That's not such a big deal; by default, widgets can't do much damage, and they can't run unless you drop them into your dashboard. The funny thing is that once that widget is there, according to Apple, you CANNOT remove it."

Widgets cannot be removed directly from the toolbar, but they can however be deleted from the Library folder.

"The average user, who can't find their Library folder with two mice and a spotlight, is stuck. It would take all of 30 seconds for me to pick out a nice porn image, make it the icon of a widget, drop it in your dashboard and you're stuck with it. It doesn't even need any Javascript," Stephan added.

Stephan has also created the zaptastic_evil widget, which redirects the user's browser to a Web site every time the widget Dashboard is launched — and drops the user out of Dashboard, preventing the widget from being closed.

A fellow blogger, going by the name of Aaron, has created a series of widgets that closely resemble Apple's own set of widgets and can be used to displace the genuine ones. One of these fake widgets can run with full system access without the user's express permission.

Apple declined to comment for this story.

Despite the potential for mayhem, Mac users can simply kill the widgets by deleting them from their Library folder, and using Activity Monitor to kill any instance of the widget already running.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
63 out of 163 people found this useful



Company/Topic Alerts

Create a new alert from the list below:





Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Transys comment speculation

I've been pondering why it's so difficult to get any official comment out of any of the organisations involved when it comes to what is happening with Transys. Transys is the consortium... More

Post a comment

Wallet Phones Are Coming:Visa Should J...

Wallet Phones Are Coming:Visa Should Jump On Board Author: Eric Everson, Founder MyMobiSafe.com I have touched on the subject of wallet phones (a mobile handset capable of eliminating... More

Post a comment

Mobile Networks Threatened - DEFCON Ha...

Mobile Networks Threatened - DEFCON Hackers Could Help Author: Eric Everson, Founder MyMobiSafe.com If you are worth your weight in code, you know that the “hot spot” this month... More

Post a comment