MacDailyNews - Where Mac news comes first

 MacDailyNews Poll

Deal of the Day

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

Macworld UK

TUAW

MacRumors

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Sat, Nov 21, 2009 - 06:46 PM EST  —  AAPL: 199.92 (-0.59, -0.29%)  |  NASDAQ: 2146.04 (-10.78, -0.5%)

Security firm warns of new Internet Explorer flaw, advises ‘use a different browser’
Thursday, July 01, 2004 - 09:42 AM EST

"Internet security research group Secunia issued a warning Wednesday about a security vulnerability it says it has discovered within Microsoft's Internet Explorer Web browser. The flaw, which Secunia has ranked as 'moderately critical,' is found within Internet Explorer versions 5.01, 5.5, and 6, Secunia says in an advisory," George V. Hulme reports for InformationWeek.

"Internet Explorer doesn't block malicious Web sites from inserting 'arbitrary content' in an arbitrary frame in a browser window, the Danish security firm says. Secunia says the malicious content will appear as if it originated from a trusted site, which is an attack commonly known as spoofing," Hulme reports.

"Secunia says it has verified the flaw in 'a fully patched Internet Explorer 6 running on Microsoft Windows XP' and that other versions of Internet Explorer could also be affected by this vulnerability. Secunia's only advice is that Internet Explorer users not visit untrusted Web sites or select a different browser," Hulme reports.

Full article here.

MacDailyNews Take: If you're a Mac user still slogging along with Microsoft's Internet Explorer (and our stats tell us there are still some of you out there), are you crazy? Please get with the program. It's called Safari, it's from Apple, and you can download it for free.

Requirements for Safari 1.2:
- Mac OS X 10.3 or later
- Any Macintosh computer

-Requirements for Safari 1.0:
- Mac OS X 10.2 or later
- Any Macintosh computer

More information and download link for Safari here.

MacDailyNews Note: You can use the Safari Debug Menu* to set Safari's User Agent to one of many different browser choices if you need to access sites that are "blocking" Safari. Set your User Agent to "Windows MSIE 6.0" and you'll be amazed at how many of these misguided sites will work with Safari.

*To turn on Safari's Debug Menu, Quit Safari, launch Terminal and type:
defaults write com.apple.Safari IncludeDebugMenu 1
Launch Safari and the Debug Menu will be active.

To turn off Safari's Debug Menu, Quit Safari, launch Terminal and type:
defaults write com.apple.Safari IncludeDebugMenu 0
Launch Safari and the Debug Menu will be inactive.

Bookmark and Share

Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: = registered.
Unregistered users: Feedback from multiple usernames are subject to deletion. Off-topic and posts from suspected astroturfers will be removed.

Jul 01, 04 - 09:56 am Comment from: five-o

Wait a minute MS says I need to use MSIE. Many sites use sniffers that will block you if you use a different browser.

What is the average user to do....


All I want to do is check my hotmail....


?

Jul 01, 04 - 09:57 am Comment from: Less is More

> and our stats tell us there are still some of you out there

Lies, damn lies, and masquerading browsers. Anyone really using Explorer deserves what they get -- microchit.

Jul 01, 04 - 09:58 am Comment from: ray

Sniffers only usually target Safari because they think its an out-dated version of netscape. Download Mozilla Firefox as a second browser.

Jul 01, 04 - 09:59 am Comment from: Less is More

I dumped my hotmail account when I found out who was behind it so long ago I can't even remember what year was it.

Jul 01, 04 - 10:06 am Comment from: shadowself

So...
Since Microsoft has stopped development of ALL non-Windows browsers (not just Mac browsers) is Microsoft going to issue patches for all versions or just the Windows versions?

Jul 01, 04 - 10:06 am Comment from: Firefox

Firefox works great for all us none OSxers (plenty out here waiting for the next generation g5 computers and imacs...)

Jul 01, 04 - 10:08 am Comment from: rick

My bank asks me to use MSIE 6.0 or Netscape 7.1 and indicates that Safari is not supported. What else can I do other than use Netscape 7.1? Not even the debug menu change to UserAgent to Netscape 7.0, because it does not work.

This is, I think, because my bank is using some technology to develop the security site that only supports MSIE (from micros*it) and even with Netscape it does not work well.

Jul 01, 04 - 10:15 am Comment from: Dugie

E*Trade Bank supports Safari AND it's free AND pays interest on all accounts.

Jul 01, 04 - 10:18 am Comment from: One guy from Finland

rick
change your bank. I did.
our airplane company accepts only msie so I changed airplane company.
it is that easy. in this world if company does idiotic things you say no to them. it is that easy. You have to let them know that you are not happy with their service and they can keep it.

Jul 01, 04 - 10:21 am Comment from: consumer

time for the US Consumer Product Safety Commission to issue a recall of all PC's running Microsoft System Software until this is fixed. If any other device had this many defects, they would not be allowed to sell the product in the US .

Jul 01, 04 - 10:22 am Comment from: Dave H

rick, this is someting that I come across all the time. I use Safari primarily, but have Mozilla 1.7 installed as a secondary. I asked the webmasters of one website why Netscape 7.1 and above was allowed when Mozilla 1.4 and above wasn't, when they are the same program. The answer was that they were looking into it, but three months later Mozilla is still being blocked. Stupid Microsoft brainwashed NetAdmins are to blame.

Jul 01, 04 - 10:33 am Comment from: giofoto

Some one here posted using a browser that was supposedly faster than Safari....I wanna say it was a Japanese developed browser....anyone rememeber what it was?

Jul 01, 04 - 10:37 am Comment from: Nobody

I am impressed. A security vulnerability this big, coupled with verifiable successful attacks against the IE-Windows users using websites is ranked as "moderately critical". Riiiight... I trust Secunia very much, especially after their report about OS X's supposedly bad security problems.

Jul 01, 04 - 10:43 am Comment from: Paul

Firefox is streets ahead of Safari. I don't know whether it's a common problem or something unique to my machine, but Safari doesn't render apple.com properly on my box! Keep meaning to get around to a Safari reset and use that again, but I'd really miss find-as-you-type and some of the other cool things.

Jul 01, 04 - 10:48 am Comment from: G Spank

Firefox Rocks.

Jul 01, 04 - 10:48 am Comment from: Jaime

I use Safari as my default browser and have installed Firefox to handle any sites that don't like Safari. This has proven to be both an effective and safe combination for me. I deleted MSIE from my hard drive several months ago because I have no need for it. It's a shame Windows users don't have the option to do that, but that's what they get for using Windows...

Jul 01, 04 - 10:56 am Comment from: Rob

Hmm, so this Windows IE issue is "moderately critical" according to Secunia, yet far more trivial issues with OS X are deemed highly critical by them?!? These guys are a piece of work...

Jul 01, 04 - 11:06 am Comment from: bd

Glofoto, I think the browser you are looking for is..... SHIIRA. I use it all the time. GREAT!

Jul 01, 04 - 11:09 am Comment from: max

"MacDailyNews Note: You can use the Safari Debug Menu* to set Safari's User Agent to one of many different browser choices if you need to access sites that are "blocking" Safari. Set your User Agent to "Windows MSIE 6.0" and you'll be amazed at how many of these misguided sites will work with Safari.

*Quit Safari, launch Terminal and type:
defaults write com.apple.Safari IncludeDebugMenu 1
Launch Safari and you'll have the Debug Menu active.

If you wish to turn it off, quit Safari, launch Terminal and type:
defaults write com.apple.Safari IncludeDebugMenu 0
Launch Safari and the Debug Menu will be inactive."


Come on MDN the whole purpose of using the mac is ease-of-use. Your solution is a pain-in-the-ass. When Safari doesn't work...people default to IE. Maybe it's time for some education about alternatives.

Jul 01, 04 - 11:13 am Comment from: Viridian

giofoto,

I think you may be referring to Shiira, a Japanese browser built for OS X (source code is available). Current version is 0.9.2.2, so it's not quite there yet, but it has a great deal of promise. Speedwise, it seems about on par with Safari to me, although I haven't used it extensively enough to judge. One nice feature is that when you start it up, it automatically uses your existing Safari bookmarks. It's not as polished as Safari in my opinion, but it's still young, and the developers deserve a great deal of credit for their achievement thus far. On the browser front, OS X really has an embarassment of riches. "Shiira" is the Japanese word for "dolphin" by the way, the fish (dorado, mahi-mahi), not the mammal.

Jul 01, 04 - 11:16 am Comment from: Nobody

"This is, I think, because my bank is using some technology to develop the security site that only supports MSIE (from micros*it) and even with Netscape it does not work well." - rick

Let me get this right. You trust a bank that "is using some technology to develop the security site that only supports MSIE"? Don't you know that 'security' doesn't belong in the same sentence with 'Windows' and 'IE'? Run to your bank and plainly state to your bank why you are closing your account.

Jul 01, 04 - 11:22 am Comment from: Luther

max,

Quit Safari, In Terminal type:
defaults write com.apple.Safari IncludeDebugMenu 1

This is too hard for you?
Oh well, run Safari Enhancer then - it does the same thing:
http://www.lordofthecows.com/safari_enhancer.php

Some Mac users are "Terminalphobic."

Jul 01, 04 - 11:22 am Comment from: gc

Firefox is very good, but Camino is the aquafied implimentation. Mmmmm, lickable....

Jul 01, 04 - 11:30 am Comment from: Viridian

Sorry, hit "Submit" instead of "Preview". I was just going to add that the default theme is Aqua, not Brushed Metal, for all those who don't like the "metallic-ky goodness" of Safari grin [apologies to As The Apple Turns]

On a personal note, I would love to see a full-featured Cocoa browser with the revolutionary history feature of Trailblazer.

Jul 01, 04 - 11:30 am Comment from: max

Luther,

The problem is when you update your system or safari and forget how you enabled the debug menu when it's gone. That pisses one off. I'll check out safari enhancer again but that seemed to cause me problems with some secure sites before.

Jul 01, 04 - 11:36 am Comment from: Viridian

max,
Let me get this straight, a simple solution is "a pain in the ass", so you default to a browser that is a proven security risk? Copy/Pasting one line is a pain in the ass?

Jul 01, 04 - 11:42 am Comment from: Viridian

max,
Just read your explanation to Luther; I wasn't trying to insult you, I was just baffled. If you can't remember the Terminal command to enable the debug menu offhand (neither can I) just do what I did, save the useful commands as text clippings and keep them in a folder.

Jul 01, 04 - 11:46 am Comment from: janne

You can always use a browser that is able to identify as MSIE if needed. With OmniWeb 5 you can set the identification to be site specific.

Jul 01, 04 - 12:01 pm Comment from: Russell

Pardon me for checking:

Wasn't there a post a few days ago about Secunia saying that Macs and PCs are equally unsafe concerning security flaws, and immediately MDN responded with "Secunia who?" and seemed to portray that we can't trust them.

Now we all praise this article for its "accuracy."

I don't doubt that IE is unsafe, but seriously, let's at least be fair-minded. smile

Jul 01, 04 - 12:11 pm Comment from: Viridian

Russell,

Well said, I had the exact same thought, but I guess the difference here is we don't have to trust Secunia to tell us that IE is insecure; a blind man with wooden glasses could have determined that. grin

Jul 01, 04 - 12:55 pm Comment from: Less is More

Internet Exploder sucks Secunia's holes.

Jul 01, 04 - 01:34 pm Comment from: Safari Guide


The only bad thing about setting Safari's user agent to identify itself as MSIE is that in the long run, it provides even less incentive for a site to support alternative browsers like Safari. They simply look at their web logs and say, "See? Only 0.1% of the people visiting our site are using Safari!"

It's better to keep using Safari and pushing the site to support Safari, even if the site works fine if Safari identifies itself as IE. It's like Google recently revealed that almost 4% of their users are using Safari and it's stuff like that that encourages other websites to take Safari seriously.

Jul 01, 04 - 01:54 pm Comment from: Jon E Wunnut

How do you get Safari to work under OS 9?

Jul 01, 04 - 02:26 pm Comment from: Jon E Wunnut

So let me get this straight: Secunia says Mac OS has security issues and they are stupid. Secunia says Microsoft has security issues and they are right on. Sounds like the hypocrisy factor to me.

Jul 01, 04 - 02:31 pm Comment from: mike

terminal-phobic...

I got a mac to get away from anything that looks like DOS, thanks.

Jul 01, 04 - 03:33 pm Comment from: treadlightly

This must be different than the multiple browser vulnerability that Secunia lists on their site with a moderately critical rating, since the multiple browser affects Safari among many others. Firefox 0.9 isn't vulnerable on that one though smile

Jul 01, 04 - 03:34 pm Comment from: treadlightly

Sorry, here's the link: http://secunia.com/advisories/11978/

Jul 01, 04 - 03:38 pm Comment from: no MS for me

Secunia was criticized because it did not accurately report the security "problems" with MacOSX, even exaggerating and misreprsenting the statistics in a poor effort to skew the results and slander OSX's reputation. If you're still under the delusion that MacOSX is anywhere near as insecure as MS Windows, then you better get some treatment for that mental illness.

Firebird and Mozilla are good alternatives to Safari. Just don't use that virus-ware from MS, unless you want to get infected with something.
As for banking sites, Safari works just find with Bank of America (at least here in the western US). Any bank (or site for that matter) that requires a user to use MSIE should be held liable for any stolen personal information and cleanup/repair/restoration costs.

Jul 01, 04 - 06:25 pm Comment from: Less is More

Good point 'no MS for me'

Banks intolerant of anything but Internet Exploder should get sued for any monetary losses suffered by users of that browser -- but why wait. Let's sue them now for extremely poor taste and the risks of having to keep that crap on our HDs!

Jul 01, 04 - 06:36 pm Comment from: neomonkey

All I want to do is check my hotmail...

for spam? Why don't you get macmail.com or excite.com free email? Macmail can even be used as POP3, and excite is going to 120MB/10MB per message in September. G-Mail is putting the pressure on...

I use iCab for OS 9.1, very fast, very nice, even does tabs. Still have to use IE for Washington Mutual site, though.

Jul 02, 04 - 01:54 am Comment from: Less is More

iCab rocks on 9!

Reader feedback page 1 of 1 pages:

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my info   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below: