Advertisement
Promo

Security threats Toolkit

Researcher: 'Macs as easy to hack as to use'

Robert Vamosi CNET News

Published: 14 Aug 2007 11:44 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

"Macs are as easy to hack as they are to use", according to researcher Charles Miller.

Miller and his colleagues at Independent Security Evaluators discovered the first known vulnerability within the Apple iPhone.

During his presentation, "Hacking Leopard: Tools and techniques for attacking the newest Mac OS X", at the recent Black Hat conference, Miller said that, for some reason, the Mac OS has over 50-plus suid root programs.

Suid stands for "set user ID" and is used to temporarily elevate privileges to perform a specific task, such as running executables.

Given the root access provided by these tools, they provide at least one vector for attack.

Another vector is Safari, which, when opened, also opens several applications, including: Address Book, Finder, iChat, Script Editor, iTunes, Dictionary, Help Viewer, iCal, Keynote, Mail, iPhoto, QuickTime Player, Sherlock, Terminal, BOMArchiveHelper, Preview and DiskImageMounter.

A flaw in any one of these could be easily exploited over the web. That's because Apple's operating system doesn't randomise the location of the stack, the heap, the binary image or the dynamic libraries, meaning an attacker would know where in memory these applications are loaded on almost every machine running Mac OS X.

Read this

Feature
Feature: Locating the real threats to corporate security

With organised criminals seizing the opportunities of cybercrime, how accurate is the established belief that company insiders are the biggest threat to IT security?

Read more +

Open source is yet another vector for new attacks on Apple Macs.

Miller said that, on 31 July, Apple did update its version of Samba — but that was for the first time in two and half years, and the latest version still fell short of the current open-source version.

Miller said his formula for finding a zero-day flaw on a Mac is this: "Find an open-source package that they use that's out of date — there's, like I said, plenty of those."

He then suggested reading through the change log for the current version of any of the above open-source software to find a useable bug that's been fixed in the newer version but which is still vulnerable to Mac OS X users.

Miller said, by doing this, "you won't have to worry about static analysis or fuzzing or any of that stuff".

Several attempts to contact Apple for comment on this story went unanswered.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
12 out of 41 people found this useful


Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Watchdog reveals illegal sale of phone...

The Information Commissioner's Office is preparing a prosecution file against a mobile operator's employees who allegedly sold on thousands of customers' details to a competitor. The... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters