ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Hacker cracks Apple downloads

Matt Loney ZDNet.co.uk

Published: 08 Jul 2002 16:27 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple Mac users could be unwittingly downloading and updating their systems with rogue code, according to the BugTraq security mailing list.

The exploit takes advantage of Apple's software updating mechanism in OS X, called SoftwareUpdate, which checks weekly for new updates from Apple. According to hacker Russell Harding, who claims to have discovered the exploit, the Mac OS X SoftwareUpdate feature downloads these updates over the HTTP protocol with no authentication, and installs them as root on the system.

It is a trivial matter, according to Harding, to use any one of several well-known techniques to trick a user into installing a malicious program posing as an update from Apple. Such techniques include DNS spoofing and DNS Cache Poisoning.

No patch is understood to be available -- a fact that will be compounded by the availability on the Internet of full instructions, together with the necessary applications.

When SoftwareUpdate runs, it connects via HTTP to an Apple.com page and sends a simple request for an xml document, which returns a list of software and current versions for OS X to check, according to Harding. After the check, OS X sends a list of its currently installed software to another page on Apple.com. If new software is available, the SoftwareUpdatesServer responds with the location of the software, size, and a brief description. If not, the server sends a blank page with the comment "No Updates".

"As you can see, with no authentication, it is trivial to impersonate the Apple servers," wrote Harding on his Web site. He provides two programs that he says have been customised for carrying out this attack. One program listens for DNS queries for updates, and when it receives them replies with spoofed packets re-routing them to the attacker's computer.

The second program, which is downloaded onto the victim's Mac masquerading as a security update, in fact contains a "back-doored" copy of the Secure Shell Server Daemon, sshd. "This version of sshd includes all the functions of the stock sshd," wrote Harding, "except the following: You can log in to any account on the system with the secret password 'URhacked!'. After logging in through this method, no logging of the connection is employed. In fact, you do not show up in the list of current users!"

Apple did not immediately respond to requests for comment.

Automatic updates of software -- particularly operating system software -- is a growing trend. Several Linux companies offer this feature for their distributions of the open-source operating system, and Microsoft recently launched a similar service called Microsoft Software Update Services.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
44 out of 84 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Operations Engineer - Server2003/SAN/NetBackups/WINS/DNS/LDAP/London

Operations Engineer / Media/ Server2003/ SAN/ NetBackups/ WINS/ DNS/ LDAP/ London/ 60k My client is a market leading global Media Organisation ...

Junior Level Systems Admin(desktop,server,AD,DNS,DBA) BANKING

DNS, DHCP, TCP/IP & Database administration for Sybase, Oracle or MS SQL Servers. A market leading developer of trading & risk management systems ...

2nd/3rd Line Support

AD, Exchange 2000/2003, System and operations management, (SMS, MOM, etc), Citrix, SQL, MS Clustering, SAN storage, TCP/IP, DNS, VPN; and Cisco ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains