There is a zero day threat to all Safari users both in Windows and Mac, where a remote attacker can hide the actual URL address of the web page in the browser location bar. Let’s see how this works …
Since URL and web page spoofing is very common to phishing, I created this sample email with crafted URL on it.
I clicked the link and here’s what I got in Safari 3.1 for Windows.
A security flaw was found in Safari, when you input a URL containing a special characters followed by “@” which indicates the actual hostname. The special characters was crafted long enough to hide the URL of the page.
As most of Safari users experience the spinning wheel of death, it is evident that there are multiple vulnerabilities that lies within this application.
Is there available security patch/fix ? None, at the moment. So, please refrain from clicking or browsing untrusted websites.
Juan Pablo Lopez Yacubian has recently discovered this vulnerability.

Some people, some time ago reported this bug to Apple ( read this: http://marcoramilli.blogspot.com/2008/02/discovering-potential-vulnerabilities.html )
But they said: “thank you man” … and nothing more….
Comment by Marco Ramilli — October 7, 2008 @ 9:45 am |
Thanks Marco, i’ll add your blog to my reader.
I’m afraid they don’t care … as it seems this vulnerability has been around for awhile now.
Comment by Methusela Cebrian Ferrer — October 8, 2008 @ 12:01 pm |
Hi
Webmaster I would like to exchange links with you
email: abuse@softlayer.com
postmaster@softlayer.com
Comment by duandaHenly — March 5, 2009 @ 11:42 am |
Ok, ill reply offline.
Comment by Methusela Cebrian Ferrer — March 6, 2009 @ 6:44 am |