Developer demos ‘exploit’ in Mac OS X Tiger’s Dashboard

“One developer claims to have found a security hole in Apple’s new Tiger operating system. According to his website, Apple’s highly touted Dashboard technology, found in the new version of Mac OS X 10.4, has a security vulnerability that could cause malicious third-party sites to auto-install a Widget, a small program designed to display Internet content on the desktop,” MacNN reports.

“If you’re running Safari on OS X Tiger and go to this website, a ‘slightly evil’ Dashboard widget will be automatically downloaded and installed and can’t be removed without manually removing the file from the Library folder and rebooting the computer.”

MacNN reports, “The author says it is a demonstration “how easy it is to exploit Dashboard for nefarious purposes. A subsequent discussion by the author outlines other ‘more evil’ exploits of the security hole.”

Full article, with the link to the demo widget site, here.

Slashdot has a discussion regarding this here.

Apple’s developer pages regarding Dashboard Security note that if a Widget attempts to access your file system, Java applets, and other sensitive parts of your system, and the Widget is located outside of /Library/Widgets/, a dialog is presented to users upon the Widget”s first load. The dialog asks the user whether or not they want to use the widget. If the request is approved, the widget is loaded and granted access to the resources that it requested.

The issue, of course, is that a nefarious Widget could promise you something wonderful, entice you to allow it to load, and then do something unexpected. Apple’s Dashboard Security page is here.

The Widget developer, stephan.com, concludes, “Apple has done a pretty good job of it – the only real change I would consider is re-thinking the logic behind autoinstall, and for heaven’s sake, please provide a way to remove widgets, ideally from outside the Dashboard.”

54 Comments

  1. Yea….heard about this. Goes to show…the more you add to an OS…the more doors you open to attack. This is really a non-issue though. At least I hope. I’m sure this will be fixed/taken care of soon. That’s what is nice about the Mac crowd…always looking out for their buddies.

  2. The solution to the problem is to disable the “Open “safe” files after downloading” option in Safari’s preferences.

    The widget at that site will just download as a zip file to the location you specified in Safari’s preferences.

  3. Also…

    If you have Little Snitch, it will ask you if you want to allow net access to any app (including widgets)… this will help stop malicious widgets from accessing the internet.

  4. Why would a Widget be allowed to access things on a users’ computer (aside from writing a pref file)?

    Isn’t the purcpose of the widget to only get contents from the Internet?

    I hope Apple fixes this promptly (which I believe they will).

  5. Hopefully Apple will make some changes and reduce the possibility of this becoming a problem. Not auto installing into the Widgets directory would be a start. Especially since if its autoinstalled it doesn’t ask for permissions..oops.

    Also an uninstaller would be nice. But in the meantime do a search for Widget Manager on Versiontracker and you will find a nice pref pane that can disable and uninstall widgets from the system preferences.

    MW: problem

  6. This is very bad…

    an auto install of an application/program with a malware, virus or spyware payload.

    This is what is going to happen go to a site an onload() function will install the widget with the payload. A hidden (1px transparent) widget will be installed and it will delete/destroy your data.

    Soon Apple will have more viruses (not just less) then Microsoft Windows…

    ©

  7. Yeah, that auto-install thing has GOT to go. It’s just plain stupid. This also points something interesting out. It confirms that the Mac is secure because it’s secure, not just because of market share. The second there’s a hole, people will exploit it.

  8. I also protected my widgets folder. This forces the widget to install on the desktop. I think I will do this to client machines on a regular basis.

  9. More blah blah blah from Sputnik. As everyone who has installed software on OS X knows, one has to authenticate and give explicit permission for an application to alter system files. The fact that if the “Open safe files after downloading” option is checked in Safari doesn’t mean anything much, all that happens is that the widget is installed in the widget directory, it doesn’t run automatically. One still actually has to RUN a malicious widget from Dashboard for it to do something. This is more of a problem with the user installing untrusted software, in my opinion.

  10. Putznik,

    This is nothing. People in the real IT World see what’s really going on and in ever-increasing numbers, they are switching to OS X… which has NO VIRUSES or other malware associated with it. Meanwhile, you and Bill Gates and Monkey Boy will writhe and scream in pain each time the AAPL market-share stats are released.

    Poor Putznik… out there floating in his tin can. Planet Earth is blue, and there’s nothing you can doooooooo….

  11. To all you “this is nothing” people —

    Malware is *sneaky*, that’s kind of the point. The fact that you have to OK the install is only one level of protection. Nobody who’s not a network administrator (and even some of them) is as paranoid as they ought to be. If I go to a site that says “Here’s a widget that shows the price of tea in China,” and it says “click OK to install,” I’m gonna install it cuz I want it.

    Once it’s in, if it has system-level access to my drive, it could install StartupItems, delete files, and all sorts of awful things while it’s happily telling me how much Tea costs.

    They gotta close that, and FAST. PC people are switching right now, thanks to the Mini. The idea that Tiger is shipping on all the new systems, with all its bugs, is bad enough; if there’s a Windows-style security flaw in one of the “cool new features”, that could put a stop to the changing tide.

    MDN Magic Word: “came”. They came, they saw that it wasn’t so great after all, they went back to Windows.

  12. Ivanna Noe: “So what’s the absolute WORST thing that could happen with some malware written this way?”

    I love the attitude of most people on this – if malware is on a mac, so what? But if it´s on windows, window´s sucks.
    If someone sticks something in your mac computer its okay.
    Sheeesh!!!
    ——

    And why couldn´t you install a legit widget (the weather), but that widget is transmitting things of interest from your computer to another website – like email addresses, passwords, etc, etc, etc.???
    How would you know?

  13. If it is true (???) that you must approve the install of any widget, and they CANNOT autoinstall, this is only a minor annoyance. What exactly should Apple do, NOT permit installs of widgets that you want to have? Seriously, and that wasn’t sarcasm–it was aimed at those more knowledgeable than I am. What is the alternative?

  14. Anyone notice how the weather widget is not very accurate? Can you change the place it gets updated from?.. ’cause “Accuweather.com” ain’t very accurate,and yes its on the proper city, minneapolis, mn.

  15. Helen o’ Troy,

    Although you were not addressing my question, I see how my post could be construed as being a “so what” attitude, so I’ll rephrase:

    Anyone know if a widget could actually do harm to data and/or system? I would assume (perhaps incorrectly) that the widgets won’t have access to write to those data files, or to access system files. What about installing other software? Perhaps they don’t have that access.

    I could be wrong. Obviously they can access my Address Book, so they could transmit that data. Seems they could access other things as well.

    Now, I also thought that there was something in the Dashboard where it doesn’t activate until you go to the actual Dashboard. If you saw a widget that should not be there, you should be able to get rid of it, right? While not ideal, at least it’s better than having some hidden program running that you cannot see.

    I do agree that Apple needs to do something about this ASAP. Seems that the solution should be fairly simple for them, and perhaps we’ll see a fix before the week is out.

  16. OK, guys, let’s keep it civil. Tiger is brand new. Dashboard and Widgets are brand new. It’s disappointing that Apple hasn’t noticed this vulnerability, and especially as no-automatic-installation has been such a strong part of OSX security. I’ll bet all the “I’m waiting for the problems to be fixed” late adopters are ROFLing right now. Hopefully 10.4.1 will address this; until then it’s safe-computing mode: every strange file is potentially a menace, don’t download from anyone you don’t know…

  17. What helen said is true, the usual tunnel vision of the devotees is apparent in this case.

    At any rate, windows still leads a zillion to one as far as malware goes.

  18. One more thing about accuweather.com. They and TWC are trying to get a bill passed in Congress that will prevent the National Weather Service from providing weather information other than emergency information. They are calling it unfair competition since the NWS is providing their info for free.

  19. I’m sure Apple will address this quickly, but it seems to me that you’d be safe as long as you only downloaded widgets from Apple’s website in the meantime.

  20. How about just downloading Apple approved widgets, it seems that the Apple library would be the first place to go and see if a particular widget is available. Got to keep it skeptical people

  21. “This is nothing. People in the real IT World see what’s really going on and in ever-increasing numbers, they are switching to OS X… which has NO VIRUSES or other malware associated with it. Meanwhile, you and Bill Gates and Monkey Boy will writhe and scream in pain each time the AAPL market-share stats are released.”

    How’s life over the rainbow in the land of make believe Mac Yak? People in the “real IT world” prefer Linux over OSX for a Windows-alternative OS, as market share stats show. Tiger has a string of vulnerability issues (not just what was mentioned in this article) that needs to be addressed before you try to convince anyone to switch for that very same reason.

  22. Rather annoying of course, but then again Tiger’s only been out for few weeks….there’s always going to be a few necessary security fixes. In comparison, how many people are actually using still using OSX 10.3.0 instead of one of the later updates?

  23. this is quite interesting, i might have to play around with it. the first thing that springs to mind is a transparent widget that when run would just erase the entire HD.

    thats quite scary

  24. don’t see what the massive fuss is about

    i’ve never had autorun “safe” downloads on
    i’ve never installed a widget straight into my widget folder, i’ve always run them from the desktop first, this will run the widget but not install it
    and since i use a regular user account and keep a seperate admin account it will require a password before installing it on the hard drive anyway

  25. to paraphrase mattyg, a windows operator regarding malware, etc. on windows computers:

    “don’t see what the massive fuss is about
    I got my anti-virus and malware software that keeps my system clean.”

    C´mon people – the average person knows zip about their computer (Apple or Windowz)- and knowing or wanting to monitor admin and user accounts, weeding things out of the /Lib folder, etc., etc, etc tech-talk mumbo jumbo.

    Apple is supposed to be easy, no maintenance, no worries OS, remember???

    You guys are all sounding like Windows owners:
    No problems with malware or viruses if I get it, I just weed it out, gee, so what?

    Dashboard widgets seem like the perfect Trojan Horse tool to tap into anyones computer.

  26. Is there anyway to open up a widget and see all the code and crap that it has in it to get it to work, so one could see if it´s sending data from my computer to another or doing some other mischievous thing that I don´t know about????

  27. helen

    fair point but doesn’t the below document not cover a lot of security issues?

    http://developer.apple.com/documentation/AppleApplications/Conceptual/Dashboard_Tutorial/Security/

    anyway the way i have my sytem setup does prevent a lot flaws effecting me, this being one of them, but this problem should be fixed, just like the first problem that was found with safari auto opening things

    p.s. good guess on the windows owner bit, it’s true i use one for games ocassionally and switched to mac about a year ago *hangs head in shame for the past* ” width=”19″ height=”19″ alt=”wink” style=”border:0;” />

  28. But what stops a widget that I okay to be on my computer from snooping around at what is inside and forwarding to some place???
    Soon there will be zillions of weather, stock, whatever widgets out there – which is the good one which is the bad one that is malware in disguise???
    All that document discusses you reference is:
    “The dialog asks them whether or not they want to use your widget. If the request is approved, your widget is loaded and granted access to the resources that it requested. The request is not repeated on subsequent loads if approved. If the request is denied, your widget is not allowed to load. If your widget is loaded again, the request is made to the user again.”

    Once its loaded, its too late.
    And from the story above:
    “If you’re running Safari on OS X Tiger and go to this website, a ‘slightly evil’ Dashboard widget will be automatically downloaded and installed and can’t be removed without manually removing the file from the Library folder and rebooting the computer.”

    How is the average person supposed to know this? Go to the Library? My parents can barely figure out how to send email and you think they are going to go rooting around their computer????

    Soon there will be calls for loading the OSX with or without dashboard installed….

  29. Come on everyone, do some research before blasting off at the mouth.

    1. Technically, any program or web page could transmit/receive personal data. Preferably, you should research each developer/company and decide whether to install a program, even the programs you buy in the store. It’s called being responsible for your purchases and yourself.

    2. Widgets are not compiled. They are HTML, CSS, and JavaScript, hence human readable. Just bring up the contextual menu for the widget in the Finder using Control-click with the mouse, or the secondary mouse button (if using a mouse with more than one button), or the Action button in the Finder toolbar and select “Show contents”. Then open each file to figure out if it will do what the developer claims. You can’t do this with compiled programs and hence widgets can be safer since they’re “open source” if people take the time to get them confirmed by someone knowledgeable.

    3. Once inside a widget, any piece of a widget can be opened by double-clicking. It will open in your default browser. Safari will render the HTML and attempt to run it as a web page (this may or may not work depending on the widget), so consider opening the HTML in a text editor such as TextEdit as a safer option. However, Safari only shows the code for CSS files or JavaScript files, i.e. it doesn’t execute CSS or JavaScript files by themselves.

    4. As mentioned several times already: widgets have to be dragged from the Widget bar and dropped onto the Dashboard before they will be activated. Otherwise, even though widgets are installed they never do anything by themselves. You have to do something more to make them work.

    Essentially, even with auto-install (which I don’t support), a person still has to cock the gun, aim the gun at one’s foot, and then shoot oneself in the foot. And yes, almost everyone one of us will do something like that on the spur of the moment at sometime in our lives, ignoring all of the warning signs.

    But this innate curiosity we have can also help protect us if we also use it to ask questions: Who made this widget? Are they trustworthy? Should I ask someone else whether this widget is safe? Should I wait until other people more gullible than me test it out first?

    Those are similar questions to ask when purchasing any software, reading any email, purchasing any product (TVs, cars, toothpaste, etc.), and even reading any information in the media (trustworthy?, references?, sources?, other opinions?).

    As individuals we have to take responsibility to look out for ourselves. Who goes to the produce section in a grocery store and just grabs some vegetables without considering whether the food is overly ripe or rotten? Even if you don’t check, you still have to properly prepare the food before eating it. If you choose to bypass any of those steps or refuse to ask yourself any of those questions, you may find many people aren’t going to be very sympathetic to your predicament. You loaded, cocked, aimed, and shot yourself in the foot.

    As a side note, restart really shouldn’t be necessary after removing a widget. Has anybody tried simply to logout and login again? Or has everyone forgotten the advantages of having user accounts? That should be much quicker than rebooting if you’re having widget troubles. ” width=”19″ height=”19″ alt=”grin” style=”border:0;” />

    MW: straight, as in “Go straight to the source”, as in the source code.

  30. How about this: if Apple took responsibility for confirming the safety of (and offering approval of) all widgets by listing valid ones on their website (like they do for Quicktime movie trailers). Then while there would be other widgets out there, only downloading the Apple-approved widgets would protect you from nefarious mal-widgets (m’idgets?).

  31. To Thom Peters II
    Thanks for being rational. The windoze trolls on here are gleeful at a piece of malware. Woohoo! So, for them, all machines must be crap as I can easily write a program that erases a hard drive and get a user to run it. Using their logic, there is no safe OS. I wonder what they do when they’re not pestering this site – have their diapers changed?

  32. Does Tiger still ask for admin passwords when installing stuff? (Havn’t tried it yet). Maybe apple should introduce a system where it asks for your password when you’re download stuff too. Could be a pain in the a$$ though.

  33. for the love-if you’re so worried….just uncheck “open ‘safe’ files after downloading” in safari prefs…is it seriously that hard…….

  34. The problem here is in TIGER’S, auto-download, auto-install and auto-run features – In its default state, Safari is set to open “safe” files after downloading – TIGER takes that a step further by automatically putting that WIDGET file in the appropriate directory in your user account – this is clearly NOT a good idea – anyone could make a widget that is malicious in intent that is AUTOMATICALLY installed on your system under TIGER. The way Dashboard has been designed is to blame – almost as if Apple couldn’t conceive of malicious intent … I expect 10.4.1 to be held up until Apple get a handle on this. I can’t believe they let this through.

    Magic word: “average” – how I’m feeling right now.

  35. So summarize:

    1. Current setup is not as secure as it could be; turn off Safari auto open. Protect your widget folder so all widget downloads don’t get installed there automatically.

    2. The concept of being able to do something “evil” is theoretically possible but not very practical with step one done and some other suggested modus operandi as described by Thom Peters II.

    3. Our trolls and the yellow dog journalist are in a feeding frenzy over this thing: the proverbial ant being made into a big ass hill.

    4. Winblow$ is still shit and Mac OS X Tiger still ROCKS!

    Cheers!

    ” width=”19″ height=”19″ alt=”cool smirk” style=”border:0;” />

  36. 5. Macmania lives in a gilded, rose-colored world where Macs can do no wrong, but in 2 years when the next MacOS comes out he will be telling us he can hardly wait for it to come out because Tiger has some “serious issues”…just like he said about OS 9 and the first OSx versions…
    6.MacMania has never owned a PC in his life, plays games on one when he is visiting friends…

  37. All it takes is one malware or virus or something to be introduced/injected by the Dashboard system into a Mac computer and the press and windows flamers will be all over this.

  38. Start quote …………

    freebee – Here is a good article expounding on exactly the point you make – the Mac Community has ZERO tolerance for security holes – we keep our neighborhood nice – and THAT is a very big reason why OS X is so much more secure.

    http://daringfireball.net/2004/06/broken_windows

    ………….. End quote

    Unfortunately, Jack, that is just not true. Have you not seen the hoo-hah at MacIntouch over AppleScript “applications”? Did you not follow it up at SecurityFocus?

    You all thought the applications you were buying were written in a proper programming langauge, such as objective C – and written carefully and with regard for your interests.

    Uh, uh. The Mac platform is plagued with half-assed stuff written in AppleScript that frequently damages people’s hard disks and – worse – sends their admin passwords in the clear (thus exposing their passwords to Trojans). Here’s a detailed write-up:

    <http://rixstep.com/1/20050501,03.html&gt;

    Worse, this has been known about for some time. Did this so-called “Mac Community” tolerate this?

    Yes, it did.

    The bottom line:

    OS X is Unix-based. Unix is secure. There are over 100 000 viruses for Windows; there are none (repeat none) for Linux or OS X. But even Unix is not immune to malfeasant attacks of various sorts – all it requires is a little “social engineering”. And it does not help matters when Apple open holes in the OS.

    Apple is quite capable of f*cking up Unix. This does not bode well for the future. Dashboard was never needed in the first place. It’s there because it “looks good” and for no other or better reason. It is flash not function. What business would want this absurdity. Apple has lost sight of what is important.

  39. Damian, thanks for pointing that out about those passwords exploits.
    I think we all like to know when something isn’t as secure as it seems to be. Just like Dashboard.

    I think you may be jumping the gun a little bit with saying, “What business would want this absurdity. Apple has lost sight of what is important.”

    For one, not everyone who uses OS X is a business user. Therefore Dashboard can be/is very appealing to many people. Personally, I like it. It’s a little bit added to the OS.

    I don’t think they’ve lost sight of what is important. Apple has made numerous other improvements to the OS. Mail is better, Safari is better, the speed has increased. Spotlight, for me, is awesome and extremely useful.

    Apple, as with other security issues directly releated to its OS, will deal with this issue accordingly. Security fixes for exploits in Apple’s OS have always come out rather quickly (which cannot be said for Microsoft fixes).

    This Dashboard issue is in fact an exploit, but should we panic just yet? No. However, we should always be on our toes with exploits within the OS. Nothing is indestructible, and we can’t forget that.

  40. damian

    so buisinesses won’t want their employees QUICKLY finding;

    the calculator
    ce que signifie cette phrase means in english
    what time it is in the Chinese branch

    and more for example? i sure as hell would

    as for applescript applications, frankly its the old case of great power comes great responsabilty on by user and company, yes applescript is dangerous but it’s very handy and anyone who’d consider using it would have to use the same common sense that you’d apply to any app from the net like is this from a reputable source?

    frankly i would like an option to make my computer refuse to run apple script that hasn’t been compiled by the mac/admin

  41. Matt: “so buisinesses won’t want their employees QUICKLY finding the calculator”

    Sorry, mate, buisnessess (sic) won’t want this crap on their machines.

    What do you mean “QUICKLY”? Have you got the caps lock stuck or what? Down Under we laugh at that.

    Businesses *won’t* buy Apple. They’ll say: look it’s worse than MS for security.

    You want a calculator, Matt. Look in the /Applications folder. Not far to seek. And this baby ain’t written in JavaScript.

    Have you got Spotlight?

    Try this:

    Command + Space > calc > Down arrow > Enter

    That didn’t kill you, did it, Matt?

    Grow up, mate.

    Windows stinks, but don’t – for God’s sake – be a Mac Fanboy. If Apple get it wrong, holler. And holler till they get it right – or move to Linux, if they won’t.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.