TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Remote Mac Exploitation via Custom URL Schemes

70 pointsby mefover 6 years ago

6 comments

netgustoover 6 years ago
To sum it up:<p>* MacOS automatically registers an application as the default handler for any custom URL schemes it declares, as soon as the app is downloaded (this happens automatically when the app hits the hard drive)<p>* Such custom URL schemes linked to malicious app may be opened via javascript automatically on a webpage, leading to the app execution by the system<p>* The system asks for permission to launch the app the first time. The name of the app as displayed in the permission box is app-controlled, so it can spoof its identity or use a cute name with emojis to make it less suspicious (as per the article)
评论 #17886208 未加载
tinus_hnover 6 years ago
This is a serious issue in Mac OS X but I don’t see how it ties in with the ‘use Google Chrome if you want to be secure’ spiel. Don’t open untrusted archives if you want to be secure would be better, if impractical, advice.
评论 #17897226 未加载
dep_bover 6 years ago
Great research, it&#x27;s important that macOS security gets some attention as people are lulled too much into a false sense of security nowadays. Also check out the tools on his site. They&#x27;re great. Always running BlockBlock, this helps a lot.
z3t4over 6 years ago
somewhat related i got a wierd bug on my web page that some links open a new tab and navigates to a seemingly random page from the browser history. but there doesnt seem to be anywhere to report the bug and it has existed for over a year.
评论 #17886375 未加载
auslanderover 6 years ago
&gt; And if you&#x27;re a Mac user concerned about security, use Google Chrome<p>and surrender your privacy to Google, have no functioning private browsing etc. makes me to rethink about objective-see tools.
whywhywhywhyover 6 years ago
&gt; If the Mac user is using Safari, the achieve will be automatically unzipped, as Apple thinks it&#x27;s wise to automatically open &quot;safe&quot; files. This fact is paramount<p>This hasn&#x27;t been true for a long time, the automatically open &#x27;safe&#x27; files option has been turned off by default for years now.<p>Though the option should be removed all together really.
评论 #17884423 未加载
评论 #17884724 未加载
评论 #17884678 未加载
评论 #17884265 未加载