<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hawk Wings &#187; exploit</title>
	<atom:link href="http://www.hawkwings.net/tag/exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hawkwings.net</link>
	<description>Tips and add-ons to make Apple Mail / Mail.app even better</description>
	<lastBuildDate>Tue, 26 Jul 2011 07:44:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Security Bug back for Leopard Mail</title>
		<link>http://www.hawkwings.net/2007/11/21/security-bug-back-for-leopard-mail/</link>
		<comments>http://www.hawkwings.net/2007/11/21/security-bug-back-for-leopard-mail/#comments</comments>
		<pubDate>Tue, 20 Nov 2007 21:53:54 +0000</pubDate>
		<dc:creator>Tim Gaden</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Apple Mail Bugs]]></category>
		<category><![CDATA[Apple Mail]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[leopard mail]]></category>
		<category><![CDATA[mail.app]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[shell script]]></category>
		<category><![CDATA[Tiger Mail]]></category>

		<guid isPermaLink="false">http://www.hawkwings.net/2007/11/21/security-bug-back-for-leopard-mail/</guid>
		<description><![CDATA[The shell script security exploit exposed and then fixed in Tiger Mail has been reintroduced into Leopard Mail. The loophole allows a sender to disguise an executable file (say, a shell script) as an image or some other harmless file. When clicked on, the executable file runs. Don&#8217;t remember? See the Hawk Wings post at [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.hawkwings.net/wp-content/uploads/2007/11/hopper_100px.jpg" alt="Hopper 100px"  align="right" border="0" hspace="10" vspace="0" height="104" width="98"/>The shell script security exploit exposed and then fixed in Tiger Mail has been reintroduced into Leopard Mail.</p>
<p>The loophole allows a sender to disguise an executable file (say, a shell script) as an image or some other harmless file.  When clicked on, the executable file runs. Don&#8217;t remember?  See <a href="http://www.hawkwings.net/2006/02/22/security-flaw-with-scripts-in-mailapp/" title="Hawk Wings  &raquo; Blog Archive   &raquo; Security flaw with scripts in Mail.app">the Hawk Wings post</a> <img src="http://www.hawkwings.net/images/extlink.jpg"/> at the time (Feb, 2006).</p>
<p>Now, it&#8217;s back. You can test for yourself. The Heise Security web site offers to send you a test email.  Give them an email address and after a confirmation, the email arrives:</p>
<div align=center><img src="http://www.hawkwings.net/wp-content/uploads/2007/11/heissesecurityemail.jpg" alt="Heissesecurityemail" height="358" width="450"/></div>
<p>CLick on the &#8220;jpg&#8221; to open it, and it runs a shell script, listing your current directory and exiting harmelessly:</p>
<div align=center><img src="http://www.hawkwings.net/wp-content/uploads/2007/11/shellscript.jpg" alt="Shellscript" height="164" width="434"/></div>
<p>Last time, the news prompted <a href="http://www.hawkwings.net/2006/02/23/mac-attack-snack-pack/" title="Hawk Wings  &raquo; Blog Archive   &raquo; Mac Attack Snack Pack">a range of responses</a>, some of them rather hysterical.  One writer <a href="http://www.hawkwings.net/2006/02/25/mailapp-too-dangerous-to-use/" title="Hawk Wings  &raquo; Blog Archive   &raquo; Mail.app too dangerous to use?">even claimed</a> that it made Mail.app too dangerous to use.</p>
<p>I am happy to follow John Gruber&#8217;s lead (again). <a href="http://daringfireball.net/2006/02/safari%20shell_script_exploit">As he said</a> <img src="http://www.hawkwings.net/images/extlink.jpg"/> last time:</p>
<blockquote><p>â€œIt boils down to this: you canâ€™t safely double-click files from untrusted sources, and you never could.  This is no different today on Mac OS X 10.4 than it was a decade ago on Mac OS 8 and 9.â€</p></blockquote>
<p>Puzzling that it&#8217;s back, yes.  But dangerous? No more than usual. </p>
<p><strong>UPDATE:</strong> &#8220;FatYank&#8221; provides a quick fix in the comments for those who are really worried about this:</p>
<blockquote><p>The workaround for this is to rename Terminal. When you rename Terminal and double click on the JPG, you get a message stating that Preview cannot open the file.</p></blockquote>
<p>Or, as Rob points out, you could use Quickview to view attachments first, in which these &#8220;fake&#8221; file show up as empty.  </p>
<p>Thanks!</p>
<p>[Via <a href="http://www.theregister.co.uk/2007/11/20/leopard_reintroduces_security_vuln/" title="Leopard security bug puts Mail users at risk | The Register">The Register</a> <img src="http://www.hawkwings.net/images/extlink.jpg"/>]<tags>mail.app, apple mail, leopard mail, security, shell script, bug, apple, tiger mail, exploit</tags><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.hawkwings.net/2006/02/22/security-flaw-with-scripts-in-mailapp/" rel="bookmark" title="22 February 2006, 11:51 am">Security flaw with scripts in Mail.app</a></li>
<li><a href="http://www.hawkwings.net/2005/10/18/rcmail-remotely-control-your-mac-by-email/" rel="bookmark" title="18 October 2005, 10:45 pm">RCMail: Remotely control your Mac by email</a></li>
<li><a href="http://www.hawkwings.net/2008/06/09/fix-for-leopard-mails-broken-new-mail-alert/" rel="bookmark" title="9 June 2008, 12:25 am">Fix for Leopard Mail&#8217;s broken new mail alert</a></li>
<li><a href="http://www.hawkwings.net/2007/03/03/scripts-to-automate-the-mailapp-envelope-speed-trick/" rel="bookmark" title="3 March 2007, 11:35 pm">Scripts to automate the Mail.app Envelope speed trick</a></li>
<li><a href="http://www.hawkwings.net/2006/05/04/remotely-control-your-mac-via-applescript/" rel="bookmark" title="4 May 2006, 7:40 am">Remotely control your Mac via AppleScript</a></li>
</ul>
<p><!-- Similar Posts took 6.647 ms --></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hawkwings.net/2007/11/21/security-bug-back-for-leopard-mail/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
	</channel>
</rss>

