Safe Terminal
Your rating: Now say why...

(2) 4.875

Minimizes Terminal utility script executions (for recent security issue).   Free
Add to my Watch List
Email me when discounted
Safe Terminal fixes a security weakness with Mac OS X Terminal utility, when it execute shell scripts without the user confirmation.

If Safari "Open safe files after download" is enabled, its possible to create malicious shell scripts that will be executed by the Terminal automatically after you download them. It is also possible to create malicious shell scripts that look like a document or a folder, that will be executed by Terminal on double click without warning.

After Safe Terminal is installed, the Terminal utility will show an alert before executing
What's New
Version 0.3:
  • Show an alert before executing a shell script.
  • test.command display also a text message.
  • Improved documentation.
Requirements
PPC, Mac OS X 10.3 and later.



MacUpdate - Safe Terminal



    Be the first to recommend a similar software title.
Safe Terminal User Discussion (Write a Review)
ver. 0.x:
(2)
Your rating: Now say why...
Overall:
(2)

sort: smiles | time
burypromote

+1

Hendrik Hero Hamlet Wouters reviewed on 26 Feb 2006
Ignoring all the delicacies of Safari (I use Camino) this app works perfectly to block terminal scripts in disguise.

How to disguise a terminal script as a Word file:
1). create script.command
2). rename to yourfilename.doc
3). 'get info' in finder, make it always open with terminal

this will get you a file that looks like a .doc, has the name of a .doc, and executes without warning when double-clicked.

Ezxept if this app is installed of course.
[Version 0.3]

2 Replies

burypromote

+1
Hendrik Hero Hamlet Wouters replied on 26 Feb 2006
Oh, and relying on Terminal.app for your app is a really really bad practice*, that can easily be avoided. (Even with AppleScript)

*I hev been guilty of this myself, though. Sometimes we programmers can be extremely lazy :-D
burypromote
Nir Soffer replied on 26 Feb 2006
This version (0.3) should not break software that rely on the terminal, it will only make be more annoying to use when you have to confirm the execution of the script.
There are currently no troubleshooting comments. If you are experiencing a problem with this app, please post a comment.


+1

thomas4532 rated on 10 Mar 2012

[Version 0.3]


Downloads:2,839
Version Downloads:2,357
Type:Utilities : Security
License:Free
Date:26 Feb 2006
Platform:PPC 32 / OS X
Price:Free0.00
Overall (Version 0.x):
Features:
Ease of Use:
Value:
Stability:
Displaying 1-1 of 1
Displaying 1-1 of 1
-
-
-
Please login or create a new
MacUpdate Member account
to use this feature
Watch Lists are available to
MacUpdate Desktop Members
Upgrade Now
Install with MacUpdate Desktop.
Save time moving files & cleaning
up space wasting archives.
Safe Terminal fixes a security weakness with Mac OS X Terminal utility, when it execute shell scripts without the user confirmation.

If Safari "Open safe files after download" is enabled, its possible to create malicious shell scripts that will be executed by the Terminal automatically after you download them. It is also possible to create malicious shell scripts that look like a document or a folder, that will be executed by Terminal on double click without warning.

After Safe Terminal is installed, the Terminal utility will show an alert before executing a shell script, allowing the user to confirm or cancel. The usage of the Terminal to type and run commands is not effected in any way.


- -