Comments on: Exploit released for Mac OS X flaw
Exploit appears to have been crafted before Apple patched the flaw last week.
Exploit appears to have been crafted before Apple patched the flaw last week.
January 2, 2010 11:43 AM PST
January 2, 2010 9:41 AM PST
January 2, 2010 6:00 AM PST
Add headlines from CNET News to your homepage or feedreader.
More feeds available in our RSS feed index.
Related quotes
deal. You give a hacker physical access to a box running nearly
ANY OS, and he'll get in eventually. Thus the reason physical
security of a box is important as well.
osX disk to change the password, console access is a bit harder but
additional safety measures are always needed for critical operations
with untrusted logins.
It's not a big deal only because it's got a patch available to fix it which is likely to be installed on any system connecting to the net regularly.
This kind of exploit is also often used in conjunction with a remote code exploit to do actual damage. Typical use of a computer (whether it be OS-X, Windows, Linux or whatever) should always be performed ONLY as a user with limited priviledges with the root/administrator account only being used to install software and make certain configuration changes. This greatly limits the ability of any malicious code from remote exploits from actually doing any damage. However if you combine a remote exploit with a priviledge elevation exploit, a malicious hacker can then get around standard good computing practises.
Long story short, priviledge elevation flaws are probably the second most serious type of flaws after remote exploits. Good on Apple for fixing this one, but this should serve as a warning that *NO* OS is free from security flaws.
the system? That's like saying an emailer in your local post office is
able to bypass your spam filters.
There are some hacks reported in this story, but none appear to be
in the software...
the system? That's like saying an emailer in your local post office is
able to bypass your spam filters."
No, it's not the same (your analogy doesn't even make sense,) and yes, a local exploit from a trusted user from a remote location is serious.
Can you quantify this statement? Put some context in it? Even the article you linked to doesn't quantify the statement.
Let me just say that in my opinion, if you think that OSX is "secure", you are sadly mistaken. No OS is secure. There will always be vulnerabilities in their code. I also don't think of OS X as the "most secure" Operating System. It's hard to compare because of the amount of users that Windows has compared to OS X. For now, it's probably the safest Operating System to use because it's not widely exploited. But, the more users OS X gains, the more hackers and exploiters that will be looking at OS X.
semantics, it is also wrong. A "flaw" is anything that does not
work as intended. It does not need to cause any type of lock up,
shut down, or hiccup. If My OS occasionally types the "a" key
whenever I try to open Photoshop, that is a flaw. If it displays the
colour red instead of yellow, that is a flaw.
And of course companies that make OSes are responsible for
damage control. Especially when the foundational mind set that
underlies the product allows for this exploitation in the first
place. They made the product. It's use makes one vulnerable to
damage, in ways not intended by the user, and not a foreseeable
outcome of its use. This is the definition of product liability.
EVERYONE (even us Mac-users) to take security seriously. Hardly
anyone I know that uses a Mac has any additional security
protection on their computers. Most of them recoils at the thought
of it.
Anyhow, there was a flaw. Apple fixed it. But, it did exist. That's
proof enough to get secure.
The last thing we need are masses of Mac users poking around in system preferences changing settings in the hope of making things more secure.
It remains important that vulnerabilities be found and patched regardless of settings but it is also helpful to be aware of the nature of these exploits. Leaving unneeded services turned off is your first level of defense. Second, always have a least two user profiles, one with administrator privileges and one without. Make the non admin user your usual login. With OS X that is not a problem (it is how my Mac configured) and just login with admin privileges if you are installing software. Finally there is physical security. Don't hand your iBook over to a bald guy with a goatee wearing a black turtleneck at Starbucks. More could be said but that should usually be sufficient.
protection on their computers."
And I bet that most people you know do NOT have their machine
set up for remote access, with multiple accounts set up for people
they do not trust to use the machine. As such, this "vulnerability"
does not affect them, and they are perfectly safe in their current
computer practices.
Think of it this way... Would you have unprotected sex with a hooker? Didn't think so. Don't leave your computer unprotected either.
Some of the other vulns mentioned in the security update sound far more serious to me, like the buffer overflow in JPEG2000 decoding.
The only interesting thing about this vuln is that the code to prevent it has been present in the kernel for a long time, but had been disabled (#if 0) for unknown reasons.
account is disabled? I mean, will the attacker still be able to gain
root privileges? I ask this becasue, that's how most Mac desktops
and notebooks are configured by default.
Unix, Mac, OS2, Novell, VMS, etc. can all be cracked if you can access the console. And of course the only requirement to crack most Windows computers is that it is turned on.
things. For clarification please read the comment by Duin - the
creator of the expoit - in the talkback.
involved, I don't see why anyone would take anything you had to
say with any degree of seriousness.
user to already have an account on a machine is not a big deal. Is
that all you have? HAHAHAHAHAHAHA
'Doze box in '95 and it made Vista crash in 2007" schtick" these
Gates sycophants suck up to!
:)
Give me a break
Every OS is susceptable to attacks and as the popularity of Macs increase you will see more things like this. Nothing is perfect. Use what you like but get off your high horses and I'll get of my soap box.
No one said Macs were invulnerable, that'd be stupid, nothings perfect.
article, maybe someone would care about your soapbox.
But that's life!
If recent studies are to be beleived the internet has a user population of 84% Windows and 3.7% OSX. (see other Cnet article on Apple growth slowing.) That means people looking for attention, or looking to defraud, or just out to cause chaos, are going to focus on the largest possible impact.. the 84%. It's not wonder you hear about security vulnerabilities every week in windows, it's the target! It's also been around in it's current kernel incarnation for nearly 5 years.
But as OSX popularity grows those who wish to do damage will pay more and more attention to it. The recent slew of "We're immune to that because we're better than everyone else" commercials has probably caused a significant increase in the number of people looking for exploits.
Why? It's like telling a jewel theif, "I bet you can't steal this jewel!" They'll try, and they'll succeed.
My personal advice to Apple users, get use to hearing about vulnerabilites, torjans and exploits, and stop beleiveing the propaganda about how immune you are, and start practicing "safe computing"
First step, fix the one flaw in every operating system... the user.
Nothing could be further than the truth. OSX uses Launchd, so it's impossible for a program to spread on OSX systems.
http://en.wikipedia.org/wiki/Launchd
There have been ZERO exploits to OSX so far, and at this point in the game it's probably too late for any serious outbreak to ever occur. Launchd among 70 other differences, make OSX the most secure operating in massive use today.
Marketshare doesn't really matter, OSX is just as exposed to the network as Windows machines, the best minds in the business have tried and tried to crack OSX. It can't be done, the proof is in the facts. No Viruses or Spyware, or Trojans have affected OSX. Only a few issue with some bundled apps, but none have touched OSX.
Apple does all the Virus, Spyware, etc protection inside the OS, while Microsoft doesn't understand programming enough to do it internally, so they rely on 3rd parties, making the their OS far less secure than it should be.
If you want a trouble free, virus free, rock solid, fast OS, with a much better software library than Windows, Apple's Macs are by far the best computing device you can purchase.
Have a good day.
-
Nothing could be further than the truth. OSX uses Launchd, so it's impossible for a program to spread on OSX systems.
http://en.wikipedia.org/wiki/Launchd
There have been ZERO exploits to OSX so far, and at this point in the game it's probably too late for any serious outbreak to ever occur. Launchd among 70 other differences, make OSX the most secure operating in massive use today.
Marketshare doesn't really matter, OSX is just as exposed to the network as Windows machines, the best minds in the business have tried and tried to crack OSX. It can't be done, the proof is in the facts. No Viruses or Spyware, or Trojans have affected OSX. Only a few issue with some bundled apps, but none have touched OSX.
Apple does all the Virus, Spyware, etc protection inside the OS, while Microsoft doesn't understand programming enough to do it internally, so they rely on 3rd parties, making the their OS far less secure than it should be.
If you want a trouble free, virus free, rock solid, fast OS, with a much better software library than Windows, Apple's Macs are by far the best computing device you can purchase.
Have a good day.
-
http://www.microsoft.com/technet/security/advisory/926043.mspx
/P
person writing malware for fun, profit or attention, I would
definitely try to write a mac virus, et al for the simple reason that it
would be NEWS!. Writing windows malware is nothing particularly
special, but you get your name in lights (at Cnet anyway) if you
successfully booger up a bunch of macs.... but we should practice
safe computing... to keep from transfering infections to our
windows brethren....
--- by the way im not bothering because I've learned how shady
these stories have become, and how false they are. It seems
when it comes to Apple, there truly is a bias to regurgitate old
stories as new, and manufacture false information ---
is this the same contest winner who claimed to hack a mac in 30
seconds, but had to have local, or user privelages to do so?
IF THIS IS TRUE, SHAME, SHAME AND CONTINUED SHAME ON
CNET!
a pretty significant issue right? Also, considering how pathetic most
people make their passwords brute forcing a limited roll account
and then bootstrapping it with a root kit is a problem.
need to be an advantage.
I suppose folk like you walk to work on their hands just for the
sake of it!!!
need to be an advantage.
I suppose folk like you walk to work on their hands just for the
sake of it!!!
- THE DIFFERENCE
- by crumvoc October 17, 2006 4:09 PM PDT
- THE DIFFERENCE IS THAT WINDOWS VIRUSES' MALWARE AND THE
- Like this Reply to this comment
-
-
- THE CAPS LOCK
- by lesfilip October 17, 2006 6:53 PM PDT
- Welcome to the Mac platform. I'm surprised you have not noticed
- Like this
-
- crumvoc, here's a great Mac feature for you.
- by rcrusoe November 15, 2006 11:12 AM PST
- Open System Preferences
- Like this
-
(108 Comments)LIKE ACTUALLY DO DAMAGE, SCREW UP COMPUTERS, WASTE TIME,
WASTE MONEY, AND RUIN THE COMPUTING FUN... SO FAR, MAC
MALWARE IS JUST A CURIOSITY AND SOMETHING FOR WINDOWS
FOLKS TO FEEL GOOD ABOUT.... WHICH IS WHY I SWITCHED TO
MAC A YEAR AGO... AND LIFE (AND COMPUTING) IS GOOD....
that little "caps lock" button on the left of your keyboard. Use it.
Have a nice day!
Click on Keyboard & Mouse
Click Modifer Keys
Select No Action to the right of Caps Lock
You Caps Lock key is now disabled, and everyone on the Internet is
happy. ;)