mobile version
MethodShop.com LLC

rssnews,
reviews and
how to's

methodshop
 
facebook
itunes
flickr
myspace
amazon
apple
technorati
twitter
  home | gadgets | games | music | video | picts | reviews | tutorials | about SocialTwist Tell-a-Friend
  corner



iTunes



methodshop MAILING LIST
Email:

4/04/2006

Safari's Kryptonite - An Image File



mac_better_than_you.png

I am not a developer. Nor am I a security guru. And quite frankly I don't know my way around Unix, WebKit or Core Image. But I do know when there is an issue involving the aforementioned areas that needs to be addressed.

This.....whatever this is, needs to be addressed by Apple. And quickly.

The lowdown; apparently drunkenbatman, of drunkenblog.com fame, has brought to light a flaw/vulnerability/hole/giant boo-boo in the way apps based on WebKit and WebCore handle certain images. It crashes them. Completely, unapologetically, and without prejudice, smacks them down like a red headed stepchild.

Drunkenbatman does a better job than I ever could of expounding on why discoveries like this one hint at an OS that may not be quite as secure as we all like to believe. So rather than stumble around attempting to provide my own explanation of what this is all about, I will paraphrase his post on the subject below (please keep in mind the image referenced in the following bullet points is not included in this post, for reasons that will become apparent to you soon enough);

  • the image below crashes anything webkit-based in a very hardcore way. Actually, it crashes anything using ImageIO in a hardcore way, which includes the Finder and Preview.app and apps based on Webkit and WebCore...
  • It's remarkably similar to the Safari Image of Doomâ„¢ from awhile ago, although this time ImageIO seems to be choking during an EXIF routine, so I won't rehash what I said there. However, a few thoughts...
  • This particular image (and ones like it) are already floating around on the web. It wasn't "created" to show off a flaw.
  • While it's hard not to notice that an image is once again taking out Safari (and it isn't as though the Finder needs much of an excuse to trip over itself) and there is inconvenience there, it should be thought of as a security issue first and foremost.
  • Applications out there which aren't hitting the crashiness have all basically rolled their own support instead of using what Apple provides. You are able to open the image with Photoshop, and Graphic Convertor, and of course things like Camino and Firefox will view this page just fine. If a developer can't trust Apple's included solution to be robust, there's little point in throwing it in aside from bullet points.
  • Don't underestimate the above, nor how widespread the problem is throughout OS X. As an example, I have yet to encounter a developer needing to use SOAP services in a serious way on OS X that hasn't given up on what Apple's provided to the point where they just write their own stack.
  • I haven't met anyone within Apple that's been around awhile who wouldn't admit over beers that they'd be mighty nervous dropping OS X as it currently stands into the orgy Windows swims in, so I'm always amused at what shows up around the web, and less amused by the pundits feeding it to them.
  • I haven't dropped a lot of time into this since I came across it, but did ask around and was told it'd been reported as bug #4485821 in Apple's system. No clue as to the status/resolution.

DrunkenBatman's post has already elicited a wide range of responses from his readers, many of which I assume are just upset that DB saw fit to actually include the aforementioned "Image of Death" directly in his post, crashing countless instances of Safari, NetNewsWire and the like (count me among the afflcited, as my NetNewsWire promptly crapped the bed as soon as I clicked the link to his post).

From drunkenbatman;

"I'm aware many people who have the site in their feeds will be trying to access it via something based on WebKit/WebCore. Safari may have crashed, and you lost all your open tabs. You may have had your RSS reader up, and opened up some links in tabs, and down it all went. Read whatever you will into the fact that while these things did occur to me, I'm attaching it inline instead of linking to it separately anyways."

I will not include the image in question, as I rather not tempt the regular readers I do have to delete StationA from their list of RSS feeds as retribution for my transgressions. But if you just have to see the bug in action click (Let me be clear; Safari WILL crash if you click the following links, there, consider yourselves warned) here or here.

It may be naive of me, but despite the unsettling ease with which a graphic can bring to its knees some of the very core applications in OS X, namely the Finder, Preview, and Safari, I am still unconcerned about the overall implications of such a flaw. Don't get me wrong, I understand just how significant a discovery this is. And how in the right, or wrong hands depending on how you look at it, coding bugs such as this one can be manipulated in ways that could conceivably result in security breaches Mac users have, to date, felt invulnerable to. But I am not worried. Maybe it's because it has been a long day, I'm beat, and I am finding it hard to muster up enough concern to be afraid of flesh, or OS, eating images on the web. Maybe it is because I have become one of those unreasonably smug Apple users I hear so much about on pro-Microsoft websites (no seriously, there are some). Perhaps it is because I rubbed the bald head of my pure ivory Steve Jobs statue three times this morning for good luck. I really can't say.

What I do know is that Apple has assigned this vulnerability a bug number, and that # is 4485821. Which means the people who need to know about it, do. We're in good hands. In fact I have no doubt that his Steveness deprived some engineer well deserved quality time with the family to address this unfortunate occurrence as quickly as possible, and is more than likely doing so as I write this post. That Steve, what a guy!

Maybe when I wake up in the morning I will feel differently about how secure OS X is. Maybe. But honestly, I don't see that happening.

- AH


[Via StationA.net]











Post a Comment




 
 











Links to this post:

Create a Link




Home






rssRSS Subscribe rssEmail Subscribe

methodshop on Facebook
Features
Extreme Pumpkin Carving [pics]
imageAt one point, the art of pumpkin carving went extreme... these are the photos..

imagearrowVirtual Pumpkin Carving [game]
Like carving Halloween pumpkins into jack-o'-lanterns but don't want to get your hands all dirty with goopy pumpkin innards? This virtual pumpkin carving game won't only keep your hands clean, but it's fun too.

arrowHow to Copy Music Off Your iPod or iPhone
mac miniHas a virus or hard drive crash wiped out your entire music collection on your computer? No problem. Here's how to copy music off your iPod or iPhone and back onto your computer.

arrowThe Biggest Bugs on Earth
bugsBugs tend to freak us out. Mosquitoes, spiders, wasps, centipedes... you name it. If it crawls, bites or buzzes anywhere near our faces, then we squirm, swat and run. But what's worse than a little bug crawling on or biting you? How about a really, really big one? Here are some of the biggest bugs on Earth. Enjoy!.

boxeearrowHack Your Apple TV with Boxee
Boxee is a free open source cross-platform media center and entertainment hub that can play movies, TV shows, music and photos, as well as streaming content from websites like Hulu, Netflix, CBS, Comedy Central, Last.fm, and flickr. All you need to hack your Apple TV so it can use Boxee is a USB stick. If you own an Apple TV, then you need Boxee. Install Boxee and set your Apple TV free.

imagearrowHow to Auto Follow People on Twitter
There's a way to auto follow your followers on Twitter. This auto follow Twitter trick can be pretty useful if you find yourself managing a Twitter account for a public figure, company or celebrity.

arrowRip DVD's for Your iPod or iPhone
handbrakeNeed something to watch on your iPod or iPhone? Here's a tutorial that explains how to use a program called Handbrake to rip DVD's into iPod compatible MPEG-4 video files.

yetiarrowYeti Sports
Like to smack penguins with baseball bats? Should your Yeti catch the penguin at the right moment and angle, you might just hit one out of the park, or arctic continent.

ipodarrowRejected iPod Engravings
When purchasing a new iPod from the Apple store, you can choose to have a custom message laser engraved on the back. These were the rejects.
 

Archives

Hot Links

Kiss Kiss - Chris Brown
If Alex Chilton were today a beautiful young woman, he'd sound like this...

Gadget Lounge
Do you like Gadgets? Come hang out in our lounge.

Blog Reader Survey
Do you read blogs? Tell them about it.


Add your link here









[ home ]
[ games ]
[ music ]
[ video ] RSSXML
digg blogpulse Technology Blogs - Blog Top Sites google mobile spain china france japan
cc View blog authority This page is powered by Blogger. Isn't yours?

Contact Us | About MethodShop.com | Search
MethodShop.com LLC ®1996-2009. All rights reserved.

methodshop.com
prev top