Should Apple's Safari for Windows be Blamed for "Blended Threat" Described in Microsoft Security Advisory 953818?

Microsoft used some vague wording in the advisory: "Suggested Actions" are "Restrict use of Safari as a web browser ...".

It sounds as if it's a flaw rooted in Safari. But, what exactly is the role Safari playing in this "blended threat"? Answer is, Safari for Windows puts downloads to Desktop by default without a dialog box(such as the "File Download" dialog box in IE). Well, this is in fact a quite reasonable and convenient feature - downloading and saving requested file to user's Desktop by default. This feature itself does not constitute a mistake. What really makes the "blended threat" is some problem in loading program library files(DLL) by Windows Internet Explorer(and probably others), technical details is here.

trackback


この記事にトラックバックする(FC2ブログユーザー)

Natural Appetite Suppressant

In this niche you mostly find a lot of junkie webpages but this one is really good in my opinion. I like the way the info is laid out and how easy it is to get to and read. Good job on the site and keep it up.

comment

管理者にだけメッセージを送る

So why a patch then for Safari?

This is not a windows issue. Any browser downloading files (and I don't mean into the cache of the browser) without consent is inherently insecure, no matter what the Mac fanboys say.
That's why Safari is prompting now by default, which should be the default (only possible actually) setting.
What if "C:WindowsSystem32" or "%USERPROFILE%Start MenuProgramsStartup" is coincidentally your default download directory? Or "/home/user/.config/autostart" (if there would be safari for Linux ;-) ) ?

safari cache

please help me to change the cache directory of windows safari.

hi

thank you very much
regards
Profile

Author:LIUDIEYU
Welcome to FC2

Links
New Post
New Comment
New Trackback
Monthly Archive
Category
Search
RSS Feed