Advertisement
Promo

Security threats Toolkit

Researcher: 'Macs as easy to hack as to use'

Robert Vamosi CNET News

Published: 14 Aug 2007 11:44 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

"Macs are as easy to hack as they are to use", according to researcher Charles Miller.

Miller and his colleagues at Independent Security Evaluators discovered the first known vulnerability within the Apple iPhone.

During his presentation, "Hacking Leopard: Tools and techniques for attacking the newest Mac OS X", at the recent Black Hat conference, Miller said that, for some reason, the Mac OS has over 50-plus suid root programs.

Suid stands for "set user ID" and is used to temporarily elevate privileges to perform a specific task, such as running executables.

Given the root access provided by these tools, they provide at least one vector for attack.

Another vector is Safari, which, when opened, also opens several applications, including: Address Book, Finder, iChat, Script Editor, iTunes, Dictionary, Help Viewer, iCal, Keynote, Mail, iPhoto, QuickTime Player, Sherlock, Terminal, BOMArchiveHelper, Preview and DiskImageMounter.

A flaw in any one of these could be easily exploited over the web. That's because Apple's operating system doesn't randomise the location of the stack, the heap, the binary image or the dynamic libraries, meaning an attacker would know where in memory these applications are loaded on almost every machine running Mac OS X.

Read this

Feature
Feature: Locating the real threats to corporate security

With organised criminals seizing the opportunities of cybercrime, how accurate is the established belief that company insiders are the biggest threat to IT security?

Read more +

Open source is yet another vector for new attacks on Apple Macs.

Miller said that, on 31 July, Apple did update its version of Samba — but that was for the first time in two and half years, and the latest version still fell short of the current open-source version.

Miller said his formula for finding a zero-day flaw on a Mac is this: "Find an open-source package that they use that's out of date — there's, like I said, plenty of those."

He then suggested reading through the change log for the current version of any of the above open-source software to find a useable bug that's been fixed in the newer version but which is still vulnerable to Mac OS X users.

Miller said, by doing this, "you won't have to worry about static analysis or fuzzing or any of that stuff".

Several attempts to contact Apple for comment on this story went unanswered.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
12 out of 41 people found this useful


Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters