Google Answers Logo
View Question
 
Q: Safari vulnerability test from Secunia broke my Terminal.app ( No Answer,   0 Comments )
Question  
Subject: Safari vulnerability test from Secunia broke my Terminal.app
Category: Computers > Operating Systems
Asked by: portersi-ga
List Price: $20.00
Posted: 28 Apr 2006 09:10 PDT
Expires: 27 May 2006 17:42 PDT
Question ID: 723701
A couple months ago there was a major security problem in Apple's
Safari browser, where it would automatically decompress a gzip file
and somehow fool the system into executing a shell script. Secunia
posted a proof-of-concept here:

http://secunia.com/mac_os_x_command_execution_vulnerability_test/

Which I clicked on and sure enough, Terminal.app executed the
calculator application.

The problem is, now my Terminal.app is broken. When ever I try to open
a console window, it says:

Last login: Thu Apr 20 23:26:38 on console
/Users/porter/Desktop/Secunia.mov; exit
Welcome to Darwin!
mini:~ porter$ /Users/porter/Desktop/Secunia.mov; exit
-bash: /Users/porter/Desktop/Secunia.mov: No such file or directory
logout
[Process completed]

The same result occurs even if the secunia.mov file is present, it
executes it then immediately exits.

Right now my workaround was to download another terminal app (iTerm)
which works fine. But I'd really like to get Terminal.app working
again. I e-mailed secunia but never heard back from them.

Some clues:
* When I login as a different user, there is no longer a problem. So
it's specific to this one user account.
* None of the hidden files in my home directory contain the unwanted script
* The same thing happens even if I launch Terminal.app from the
command line (in this case by using iTerm) such as "open
Terminal.app".
* Spotlight returns no reference to "secunia.mov". That string must be
somewhere on the hard drive, but maybe it's in a non-Spotlight indexed
folder.
Answer  
There is no answer at this time.

Comments  
There are no comments at this time.

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy