Safari Automatic Script Execution Vulnerability Announced
If you use Safari as your principal Web browser, as we do, we recommend that you immediately go to the General panel of Safari's preferences and uncheck "Open 'safe' files after downloading." It is possible for someone to sent a malicious script enclosed in a zipped file that will automatically decode, open and run when downloaded. That script could easily cause damage like deleting files but if you don't believe it, go to this Secunia.com Web page and try the demonstration. No malicious script that takes advantage of this vulnerability is known to exist in the wild but it could be just a matter of time. Apple will probably patch Safari shortly but it is still not safe to automatically decode and open files. It's also not safe to manually decode and open compressed files from just any source. [Bill Fox]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?