Advertisement
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
Macs are easy to hack: researcher

By Robert Vamosi, CNET News.com
August 14, 2007
URL: http://www.zdnet.com.au/news/security/soa/Macs-are-easy-to-hack-researcher/0,130061744,339281143,00.htm


"Macs are as easy to hack as they are to use", according to researcher Charles Miller.

Miller and his colleagues at Independent Security Evaluators discovered the first known vulnerability within the Apple iPhone.

During his presentation, "Hacking Leopard: Tools and techniques for attacking the newest Mac OS X, at the recent Black Hat Briefings, Miller said that for some reason the Mac OS has over 50-plus suid root programs.

Suid stands for "set user ID" and is used to temporarily elevate privileges to perform a specific task such as running executables.

Given the root access provided by these tools, they provide at least one vector for attack.

Another vector is Safari, which when opened, also opens several applications including: Address Book, Finder, iChat, Script Editor, iTunes, Dictionary, Help Viewer, iCal, Keynote, Mail, iPhoto, QuickTime Player, Sherlock, Terminal, BOMArchiveHelper, Preview and DiskImageMounter.

A flaw in any one of these could be easily exploited over the Web. That's because Apple's operating system doesn't randomise the location of the stack, the heap, the binary image or the dynamic libraries, meaning an attacker would know where in memory these applications are loaded on almost every machine running Mac OS X.

Open source is yet another vector for new attacks on Apple Macs.

Miller said that on July 31 Apple did update its version of Samba -- but for the first time in two and half years, and the latest version still fell short of the current open-source version.

Miller said his formula for finding a zero-day flaw on a Mac is this: "Find an open-source package that they use that's out of date--there's, like I said, plenty of those."

He then suggested reading through the change log for the current version of any of the above open-source software to find a useable bug that's been fixed in the newer version but still vulnerable to Mac OS X users.

Miller said by doing this, "you won't have to worry about static analysis or fuzzing or any of that stuff".

Several attempts to contact Apple for comment on this story went unanswered.


Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved.
ZDNET is a registered service mark of CBS Interactive. ZDNET Logo is a service mark of CBS Interactive.