Safari User-Assisted Applescript Exec Attack

Discussion in 'News Aggregator' started by Packet Storm, 24 Oct 2015.

  1. Packet Storm

    Packet Storm Guest

    In versions of Mac OS X before 10.11.1, the applescript:// URL scheme is provided, which opens the provided script in the Applescript Editor. Pressing cmd-R in the Editor executes the code without any additional confirmation from the user. By getting the user to press cmd-R in Safari, and by hooking the cmd-key keypress event, a user can be tricked into running arbitrary Applescript code. Gatekeeper should be disabled from Security and Privacy in order to avoid the unidentified Developer prompt.

    Continue reading...
     

Share This Page

Loading...