<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Social Threat &#124; Who said social meant secure? &#187; Safari</title>
	<atom:link href="http://socialthreat.com/tag/safari/feed/" rel="self" type="application/rss+xml" />
	<link>http://socialthreat.com</link>
	<description>Who said social meant secure?</description>
	<lastBuildDate>Sat, 18 Jun 2011 03:07:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Safari User? Turn Off Autofill. NOW.</title>
		<link>http://socialthreat.com/2010/07/25/turn-off-autofill-now/</link>
		<comments>http://socialthreat.com/2010/07/25/turn-off-autofill-now/#comments</comments>
		<pubDate>Sun, 25 Jul 2010 22:05:52 +0000</pubDate>
		<dc:creator>Davezilla</dc:creator>
				<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Safari]]></category>

		<guid isPermaLink="false">http://socialthreat.com/?p=583</guid>
		<description><![CDATA[
			
				
			
		
According to the brilliant Jeremiah Grossman, a severe vulnerability exists in Safari 4x and 5x allowing a malicious Web site to invade via the Autofill feature. More frightening, this vulnerability exists even if you haven&#8217;t filled out anything on the page.

TIP: Safari users are recommended to turn off Autofill immediately until Apple posts a patch 


No related posts.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F07%2F25%2Fturn-off-autofill-now%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F07%2F25%2Fturn-off-autofill-now%2F&amp;style=normal&amp;service=bit.ly&amp;hashtags=exploit,Safari" height="61" width="50" /><br />
			</a>
		</div>
<p>According to the brilliant <a href="http://jeremiahgrossman.blogspot.com/">Jeremiah Grossman</a>, a severe vulnerability exists in Safari 4x and 5x <a href="http://jeremiahgrossman.blogspot.com/2010/07/i-know-who-your-name-where-you-work-and.html">allowing a malicious Web site to invade via the Autofill feature</a>. More frightening, <em>this vulnerability exists even if you haven&#8217;t filled out anything on the page</em>.</p>
<p><a href="http://socialthreat.com/wp-content/uploads/2010/07/Safari-Autofill.jpg"><img src="http://socialthreat.com/wp-content/uploads/2010/07/Safari-Autofill-500x137.jpg" alt="Safari Autofill" title="Safari Autofill" width="500" height="137" class="size-large wp-image-585" /></a></p>
<blockquote class="tip"><p><strong>TIP:</strong> Safari users are recommended to turn off Autofill immediately until Apple posts a patch or update to Safari. To turn off Autofill:</p>
<ol>
<li>Safari Menu > Preferences > Autofill</li>
<li>Uncheck all Autofill options</li>
<li>Close Preferences</li>
</ol>
</blockquote>
<blockquote class="update"><p><strong>UPDATE:</strong> Looks like a variant idea was posted by <a href="http://weblog.patrice.ch/2009/04/09/safari-autofill-birthday.html">Patrice Neff</a> back in 2009. Still hasn&#8217;t been fixed! Also, Jeremiah suspects this may be a Webkit issue, which means Chrome, Konqueror and a few <a href="http://en.wikipedia.org/wiki/List_of_web_browsers#WebKit-based_browsers">other browsers</a> such as OmniWeb, iCab and possibly even the Android mobile browser will be affected.</p></blockquote>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://socialthreat.com/2010/07/25/turn-off-autofill-now/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

