Possible Safari 4.0.3 issue

I just downloaded safari 4.0.3. Everything seemed fine, until I went to check my yahoo mail. There were three e-mail, one from Apple, barnesand noble and Toysrus. When I opened the apple nothing strange happened. Yet, when I opened the barnesandnoble e-mail the downloads box popped up with an entry showing Desktop 1-1. Well I clicked show in finder and when you click it, it just shows an empty textedit page. I immediately sent it to the trash bin and secured emptied the trash. I know clicking on it was pretty stupid, but back to the e-mails when I clicked back on the barnesandnoble e-mail a Desktop 2-1 popped up. The same thing for the toysrus e-mail, a Desktop 3-1 and 4-1 popped up. When you look in Finder under there are empty folders with the same titles Desktop 1-1, 2-1, 3-1, 4-1.

What the heck is going on? Is this some bug with Safari or was there some sort of malicious content hidden in those e-mails?

<Edited by Host>

MacBook, Mac OS X (10.4.11)

Posted on Aug 11, 2009 11:36 PM

Reply
98 replies

Aug 12, 2009 12:01 AM in response to reaper058

Kept clicking inbox until I got an ad for sleepy's mattresses when a Desktop 5-1 popped up in the download box.

Is it possible that these or cookies that haven't been saved right or something? Or am I just hoping, because I did clear out a cookie entry from ad.click the day before? Whatever is going on I'm a bit paranoid to do anything with my macbook. I sent a bug report to Apple.

Any help/advice would be most appreciated.

Message was edited by: reaper058

Aug 12, 2009 8:18 AM in response to reaper058

Tried replicating this today, but haven't been able to. Haven't encountered that same ad or any other ads so far that leads to that same weird incident.

I've already dumped all the folders and such into the trash bin and secure emptied my trash. What I would like to know though if there is anything to worry about all this? Was this some sort of malicious content or was this just a glitch in cookie saving or even something else?

I'm really worried about this since I'm not tech savy and haven't been able to find anything similar to this on the forum. Again would really appreciate any help.

Aug 13, 2009 2:57 PM in response to reaper058

You may have acquired a Trojan and/or tracker cookie.

SecureMac has introduced a free Trojan Detection Tool for Mac OS X. It's available here:

http://macscan.securemac.com/

The DNSChanger Removal Tool detects and removes spyware targeting Mac OS X and allows users to check to see if the trojan has been installed on their computer; if it has, the software helps to identify and remove the offending file. After a system reboot, the users' DNS records will be repaired.

(Note that a 30 day trial version of MacScan can be downloaded free of charge from:

http://macscan.securemac.com/buy/

and this can perform a complete scan of your entire hard disk. After 30 days free trial the cost is $29.99. The full version permits you to scan selected files and folders only, as well as the entire hard disk. It will detect (and delete if you ask it to) all 'tracker cookies' that switch you to web sites you did not want to go to.)

Aug 13, 2009 3:02 PM in response to mcpheed

@mcpheed: You should start your own topic with the specific details of your problem. It's very difficult for anyone to try to deal with multiple topics in the same thread.

Since I've tested the web site you linked to and got no such behavior, I would have to surmise that your issue is the result of JavaScript. If you disable JavaScript in Preferences>Advanced or install click2flash 1.5b4, you shouldn't have that problem.

Aug 13, 2009 6:01 PM in response to reaper058

Problem:
The mysterious Desktop-1,2,3 files appear in my home directory. It happens on both PPC macs.

Setup Safari my tests:

Safari: Empty Cache, Clear History, Remove all cookies (you may not want to delete your cookies)
Quit Safari
rm ~/Library/Preferences/com.apple.Safari.plist

Start Safari
Uncheck "Block Pop-Up Windows"

Preferences:
Uncheck Open "safe" files after downloading (General tab)
Uncheck "Enable Java" (Security tab)

Enter URL
http://deals.venturebeat.com/2009/08/13/pacific-biosciences-takes-68m-as-genome- sequencing-becomes-more-competitive/

Wait about 30+ seconds for files to appear

Check home directory for new directories

Results:

Apple Safari Download Window, I see three entries:
Desktop-1-1
Cannot move file

Desktop-2-1
Cannot move file

Desktop-3-1
Cannot move file

In my home directory, I see these files
-rwx------ 1 mobius mobius 0 Aug 13 17:44 Desktop-1-1
drwxr-xr-x 2 mobius mobius 68 Aug 13 17:44 Desktop-1
-rwx------ 1 mobius mobius 0 Aug 13 17:44 Desktop-2-1
drwxr-xr-x 2 mobius mobius 68 Aug 13 17:44 Desktop-2
-rwx------ 1 mobius mobius 0 Aug 13 17:44 Desktop-3-1
drwxr-xr-x 2 mobius mobius 68 Aug 13 17:44 Desktop-3

NOTE: The directories are empty.

Summary:
I can reproduce the same files and action with two different macs.
When I uncheck "Enable Javascript", I do NOT see errors. The web page is missing portions.
Using Firefox and Opera and opening the error console I see a tons of errors. I know not Javascript.

In many years of using Safari, I've never experienced this odd behavior. I'm guessing this should never happen. Me thinks there is a bug in 4.03

I have faith in Apple. I do, I do....

Computers:
ibook g4/933 Tiger 10.4.11 / Safari 4.03
Powermac g4/733 Tiger 10.4.11 / Safari 4.03

Aug 13, 2009 8:02 PM in response to Golden Shoes

Thank you.

Hmmm, that's interesting. This was my first visit to this particular web site. I'd never experienced any web site writing files to my home directory. Must be poorly written javascript?

I found files and directories. Simplistic question:
Could a malicious web site allow a hacker to fill up my home directory?

I shall sleep better knowing that my ibook remains oblivious to darker forces.

Cheers

Aug 14, 2009 1:47 PM in response to reaper058

Beginning on 8/11, subsequent to the Safari 4.0.3 update, the downloads box popped up showing a download as I visited my RoadRunner Web Mail login page, https://webmail.roadrunner.com. This happened around 11:30 PM. Two new entries showed up on the Macintosh HD in the Users folder. They were, Destop-1, a folder and Desktop-1-1, a document containing 0 bytes. I closed the RoadRunner Web Mail login page and reopened it and then two more entries appeared on the Macintosh HD in Users folder, Desktop-2 and Desktop-2-1-1. After that no more entries appeared when I closed and reopened the RoadRunner Web Mail login page. I deleted the files. Again on 8/12 and 8/13 the same downloads happened as I visited the RoadRunner Web Mail login page after 11:20 PM. They did not happen before then, so whatever is happening is time dependent. Both times I used Get Info and Grab to print the file information before deleting the files. Spotlight listed the info for the downloaded folder, Desktop-1, as: Where from: https://ads.traffiq.com/AdServer/Impressions/tcount.... The whole listing is very long. These downloads have also occurred on my wife's IMac after visiting the RoadRunner Web Mail login page later than 11:20 PM. I notified Roadrunner technical support about the occurrences -- they think the downloads are an issue with Safari 4.0.3 and asked me to check with Apple.

Aug 15, 2009 1:39 PM in response to damonnorcross

I am not sure, but it seems like several are having the same issue. My gut (and that is all) says that something has changed in the Safari update with Java compatibility. I searched out this topic because I was concerned it was some new type of malware when it happened to me, but I am less concerned about that now. I would just keep reporting the problem and hopefully it will be dealt with soon.

I deal with malware on a daily basis fixing Windows machines and this had me concerned for a minute because it had similar characteristics, and even more so when it crashed my Safari. But it didn't try to install anything, just download a file (over and over). It may be a attempt at a drive-by install for windows malware, but I can't say for sure since the file is 0K. I purposely take my Mac to sites that have given a Windows bug, and my Mac will show the attempted download which has given me clues several times of what bug the Windows machine has since Mac always warns you before downloading a executable file. That did NOT happen on the USA Today news site, just downloaded a file called Desktop-1-1 and so on.

The only fix I would know of it install an older version of Safari and see if that fixes it, but I would go back as soon as I could, because the last update closed several holes.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Possible Safari 4.0.3 issue

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.