On Mar 1, 2006, at 8:34 PM, Bill Fox wrote: > Apple's Security Update 2006-001 issued today fixes this problem. I'm afraid it only partially fixes it. Launch Services will still start Terminal.app and run a bash shell script without a shebang line and path to the interpreter in the first line of the script without asking or without warning. Our demo exploit with a hidden trojan still works perfectly, post- update. -- Chris ------------------------- PGP Key: http://astcomm.net/~chris/PGP_Public_Key/ ------------------------- -------------- next part -------------- An HTML attachment was scrubbed... URL: http://listserver.themacintoshguy.com/pipermail/titanium/attachments/20060301/86279938/attachment.html