Rob,Why put this on the web rather than inform Apple directly? or am I missing something. I will be very interested to hear Shay's comments
Mac

I'm sure Apple already knows about it as it's already done the rounds of Macintouch etc.

Yes, it's a security hole :) Also relatively easily exploitable, sadly. It does require the user to launch a URL to start the problem happening (not that it's hard to do, you could just mail the URL to the WAMUG list, for example :)

Until Apple fixes it I've installed MisFox and changed the helper for the 'help' URL type to something other than the 'help' application.

<http://www.clauss-net.de/misfox/misfox.html>

This may of course affect the functioning of Apple's Help application, so if you're a big user of it you might need to do something else.

As always, good backups are cheap insurance. (Something I was reminding myself of as I watched the exploit run and open the Terminal window :)

Have fun,
Shay
--
=========================== Shay  Telfer ================================
 Perth, Western Australia   Technomancer  Join Team Sungroper in the
 Opinions for hire              [POQ]     2005 World Solar Challenge
 [EMAIL PROTECTED]         fnord     <http://sungroper.asn.au/>