what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

safariXSS.txt

safariXSS.txt
Posted Feb 6, 2005
Authored by Jonathan Rockway | Site uic.edu

Apple's Safari web browser ignores the Content-type: sent by the web server. As a result, plain text is rendered as HTML. This is obviously undesirable; a text file could contain HTML and carry out a cross site scripting attack. Version 1.2.4 v125.12 found vulnerable.

tags | advisory, web, xss
systems | apple
SHA-256 | 10a5c6ef669523ad42fb93782a22e3c443ad92a6b20d36b351021365eba4dc92

safariXSS.txt

Change Mirror Download
Input Validation Vulnerability in Apple Safari version 1.2.4 v125.12

Apple's Safari web browser ignores the Content-type: sent by the web
server. As a result, plain text is rendered as HTML. This is
obviously undesirable; a text file could contain HTML and carry out an
XSS attack.

For an example of this in action, visit:

http://tigger.uic.edu/htbin/perlwrap/jrockw2/safari_test.pl

This will only work if you are on the UIC campus, if you have a login
at UIC, UIUC, or UIS you can visit:

https://tigger.uic.edu/htbin/perlwrap-auth/jrockw2/safari_test.pl

Anyway, for the 99.99% of you not affiliated with the University of
Illinois, this script simply prints:
--
Content-type: text/plain

<HTML><BODY><FONT color="red">Your browser contains a security problem
if this text is red.</FONT></BODY></HTML>
--

sans the --'s, obviously.

In Safari, the text is red. In Firefox 1.0, the text is rendered
appropriately; i.e. the user sees the tag soup.

The security problem is that servers serving HTML may be taking
measures to prevent XSS attacks; i.e. they convert < to <. These
servers, when serving plain text, may not do this (because it is
unnecessary and undesirable). Safari opens up a hole where a malicious
user could inject HTML into a plain text output and perform an XSS
attack that would not work otherwise (with a proper browser).

The latest version of this advisory is viewable at
http://tigger.uic.edu/~jrockw2/safari_20050204.txt

Note that it won't render properly in Safari :-)

Regards,
--
Jonathan Rockway <jrockway@computer.org>
Student - University of Illinois at Chicago
http://www.uic.edu/~jrockw2/

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    0 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close