ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Researcher: 'Macs as easy to hack as to use'

Robert Vamosi CNET News.com

Published: 14 Aug 2007 11:44 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

"Macs are as easy to hack as they are to use", according to researcher Charles Miller.

Miller and his colleagues at Independent Security Evaluators discovered the first known vulnerability within the Apple iPhone.

During his presentation, "Hacking Leopard: Tools and techniques for attacking the newest Mac OS X", at the recent Black Hat conference, Miller said that, for some reason, the Mac OS has over 50-plus suid root programs.

Suid stands for "set user ID" and is used to temporarily elevate privileges to perform a specific task, such as running executables.

Given the root access provided by these tools, they provide at least one vector for attack.

Another vector is Safari, which, when opened, also opens several applications, including: Address Book, Finder, iChat, Script Editor, iTunes, Dictionary, Help Viewer, iCal, Keynote, Mail, iPhoto, QuickTime Player, Sherlock, Terminal, BOMArchiveHelper, Preview and DiskImageMounter.

A flaw in any one of these could be easily exploited over the web. That's because Apple's operating system doesn't randomise the location of the stack, the heap, the binary image or the dynamic libraries, meaning an attacker would know where in memory these applications are loaded on almost every machine running Mac OS X.

Read this

Feature
Feature: Locating the real threats to corporate security

With organised criminals seizing the opportunities of cybercrime, how accurate is the established belief that company insiders are the biggest threat to IT security?

Read more +

Open source is yet another vector for new attacks on Apple Macs.

Miller said that, on 31 July, Apple did update its version of Samba — but that was for the first time in two and half years, and the latest version still fell short of the current open-source version.

Miller said his formula for finding a zero-day flaw on a Mac is this: "Find an open-source package that they use that's out of date — there's, like I said, plenty of those."

He then suggested reading through the change log for the current version of any of the above open-source software to find a useable bug that's been fixed in the newer version but which is still vulnerable to Mac OS X users.

Miller said, by doing this, "you won't have to worry about static analysis or fuzzing or any of that stuff".

Several attempts to contact Apple for comment on this story went unanswered.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
12 out of 39 people found this useful


Company/Topic Alerts

Create a new alert from the list below:








Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

5 comments