Advertisement
Promo

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Apple fixes downloads vulnerability

Matthew Broersma ZDNet.co.uk

Published: 16 Jul 2002 10:23 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple has released a patch for a glaring security hole in its software update system, which made it a trivial matter to install a back door into any Mac running OS X, according to security experts.

On Friday the company released an upgrade to its Software Update for Mac OS X that introduces an authentication process for the automatic download system. Last week, hacker Russell Harding, who claimed to have discovered the exploit, made available two programs that he said had been customised to carry out an attack via Software Update.

Apple's download is available to systems running Mac OS X 10.1 or later, via the Software Update system itself or Apple's Web site. The secure Web page includes optional instructions for verifying that the package is authentic -- which some hackers said they preferred, given the nature of the security glitch.

"Packages presented via the Software Update mechanism are now cryptographically signed, and the new Software Update client 1.4.6 checks for a valid signature before installing new packages," Apple said on the site. "Downloaded packages which do not contain a valid signature are deleted from the system."

According to Harding, versions 1.4.5 and earlier of Software Update downloads updates over the HTTP protocol with no authentication, and installs them as root on the system.

It is a simple matter, according to Harding, to use any one of several well-known techniques to trick a user into installing a malicious program posing as an update from Apple. Such techniques include DNS spoofing and DNS Cache Poisoning.

When a previous version of Software Update runs, it connects via HTTP to an Apple.com page and sends a simple request for an XML document, which returns a list of software and current versions for OS X to check, according to Harding. After the check, OS X sends a list of its currently installed software to another page on Apple.com. If new software is available, the Software Updates Server responds with the location of the software, size, and a brief description. If not, the server sends a blank page with the comment "No Updates".

Harding made available two programs that he said were been customised for carrying out this attack. One program listens for DNS queries for updates, and when it receives them replies with spoofed packets re-routing them to the attacker's computer.

The second program, which is downloaded onto the victim's Mac masquerading as a security update, in fact contains a "back-doored" copy of the Secure Shell Server Daemon, sshd. "This version of sshd includes all the functions of the stock sshd," wrote Harding, "except the following: You can log in to any account on the system with the secret password 'URhacked!'. After logging in through this method, no logging of the connection is employed. In fact, you do not show up in the list of current users!"

Automatic updates of software -- particularly operating system software -- is a growing trend. Several Linux companies offer this feature for their distributions of the open-source operating system, and Microsoft recently launched a similar service called Microsoft Software Update Services.

Matt Loney contributed to this report.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
68 out of 106 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Video icon

Video

Microsoft Windows 7 Special Report Special Report

How Microsoft can make Windows 7 a success

How Microsoft can make Windows 7 a success

Comment Many businesses have given Vista a wide berth; Microsoft must focus on five areas to make sure Windows 7 doesn't suffer the same fate, argues TechRepublic's Jason Hiner

More Special Reports

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters