{"id":20447,"date":"2010-07-23T06:52:37","date_gmt":"2010-07-23T04:52:37","guid":{"rendered":"http:\/\/www.pasteris.it\/blog\/?p=20447"},"modified":"2010-07-23T06:52:37","modified_gmt":"2010-07-23T04:52:37","slug":"un-periodaccio-per-apple-ora-si-scopre-che-safari-e-bacato","status":"publish","type":"post","link":"https:\/\/www.pasteris.it\/blog\/2010\/07\/23\/un-periodaccio-per-apple-ora-si-scopre-che-safari-e-bacato\/","title":{"rendered":"Un periodaccio per Apple: ora si scopre che Safari \u00e8 bacato"},"content":{"rendered":"<p><a href=\"http:\/\/jeremiahgrossman.blogspot.com\/2010\/07\/i-know-who-your-name-where-you-work-and.html\">via Jeremiah Grossman<\/a><\/p>\n<blockquote><p>Right at the moment a Safari user visits a website, even if they\u2019ve  never been there before or entered any personal information, a malicious  website can uncover their first name, last name, work place, city,  state, and email address. Safari v4 &amp; v5, with a <a href=\"http:\/\/www.netmarketshare.com\/browser-market-share.aspx?qprid=2\">combined  market browser share of 4%<\/a> (~83 million users), has a feature  (Preferences &gt; AutoFill &gt; AutoFill web forms) enabled by default.  Essentially we are hacking auto-complete functionality.<\/p>\n<p><a href=\"http:\/\/1.bp.blogspot.com\/_JdybrokZBAk\/TEUpf7TexxI\/AAAAAAAABwU\/oP9jGxcIz5A\/s1600\/prefs.png\" onblur=\"try {parent.deselectBloggerImageGracefully();} catch(e) {}\"><img decoding=\"async\" id=\"BLOGGER_PHOTO_ID_5495844548747642642\" src=\"http:\/\/1.bp.blogspot.com\/_JdybrokZBAk\/TEUpf7TexxI\/AAAAAAAABwU\/oP9jGxcIz5A\/s400\/prefs.png\" border=\"0\" alt=\"\" \/><\/a><br \/>\nThis  feature AutoFill\u2019s HTML form text fields that have specific attribute  names such as name, company, city, state, country, email, etc.<\/p>\n<p>&#8230;<\/p>\n<p>I figured Apple might appreciate a  vulnerability disclosure prior to public discussion, which I did on June  17, 2010 complete with technical detail. A gleeful auto-response came  shortly after, to which I replied asking if Apple was already aware of  the issue. I received no response after that, human or robot. I have no  idea when or if Apple plans to fix the issue, or even if they are aware,  but thankfully Safari users only need to disable AutoFill web forms to  protect themselves.<\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>via Jeremiah Grossman Right at the moment a Safari user visits a website, even if they\u2019ve never been there before or entered any personal information, a malicious website can uncover their first name, last name, work place, city, state, and email address. Safari v4 &amp; v5, with a combined market browser share of 4% (~83 &#8230; <a title=\"Un periodaccio per Apple: ora si scopre che Safari \u00e8 bacato\" class=\"read-more\" href=\"https:\/\/www.pasteris.it\/blog\/2010\/07\/23\/un-periodaccio-per-apple-ora-si-scopre-che-safari-e-bacato\/\" aria-label=\"Per saperne di pi\u00f9 su Un periodaccio per Apple: ora si scopre che Safari \u00e8 bacato\">Leggi tutto<\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[56,1414,716],"class_list":["post-20447","post","type-post","status-publish","format-standard","hentry","category-computer","tag-apple","tag-browser-sicurezza","tag-safari"],"_links":{"self":[{"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/posts\/20447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/comments?post=20447"}],"version-history":[{"count":1,"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/posts\/20447\/revisions"}],"predecessor-version":[{"id":20448,"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/posts\/20447\/revisions\/20448"}],"wp:attachment":[{"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/media?parent=20447"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/categories?post=20447"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/tags?post=20447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}