Register FAQ/Rules Forum Spy Search Today's Posts Mark Forums Read

Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate.

 
Go Back   Mac Forums > Archive > Archives of Old Posts > MacRumors News Discussion (archive)
TouchArcade.com - iPhone Game Reviews and News

 
 
Thread Tools Search this Thread Display Modes
Old Jun 29, 2006, 04:10 PM   #1
MacRumors
macrumors bot
 
Join Date: Apr 2001
OS X Attack Code Released, and iTunes AAC Security Vulnerability Patched

http://www.macrumors.com/images/macrumorsthreadlogo.gif

According to News.com, security researcher Kevin Finisterre at Digital Munition has released "attack code" to the public that can locally exploit the launchd daemon.

Quote:
"Attackers may exploit this issue to execute arbitrary code with elevated privileges," Symantec said in a security alert to customers that was updated on Thursday.
The code affects Mac OS 10.4.0 - 10.4.6 (excluding the recently released 10.4.7 and 10.3.x). The same researcher also created a proof-of-concept Bluetooth exploiting worm earlier this year. According to News.com, his actions are in part to show that Apple software is not unbreakable.

Also mentioned in the article is that iTunes 6.0.5 is quietly patching an AAC parsing flaw.

Quote:
Parsing a maliciously-crafted AAC file could cause iTunes to terminate or potentially execute arbitrary code. iTunes 6.0.5 addresses this issue by improving the validation checks used when loading AAC files.

Digg this story

Last edited by Doctor Q : Jun 29, 2006 at 05:24 PM.
MacRumors is offline  
Old Jun 29, 2006, 04:12 PM   #2
dizastor
macrumors 6502a
 
dizastor's Avatar
 
Join Date: Dec 2001
Location: Los Angeles
another proof of concept. This isn't cool. Eventually someone will release one of these things in a less than sanitary manner.
__________________
ejc on Twitter
dizastor is offline  
Old Jun 29, 2006, 04:13 PM   #3
iGary
macrumors Demi-God
 
iGary's Avatar
 
Join Date: May 2004
Location: La Villa Strangiato
How about in English?
__________________
Mac Pro Octophallus 2.8 | 13" UMBP 2.26
iGary is offline  
Old Jun 29, 2006, 04:16 PM   #4
KEL9000
macrumors member
 
Join Date: May 2003
Quote:
Originally Posted by greenmonsterman
another proof of concept. This isn't cool. Eventually someone will release one of these things in a less than sanitary manner.

at least they released it after it had been fixed by apple.
KEL9000 is offline  
Old Jun 29, 2006, 04:18 PM   #5
Peace
macrumors Demi-God
 
Peace's Avatar
 
Join Date: Apr 2005
Location: On top of the Storm Peaks waiting for the Time-Lost Proto Drake
More bad publicity for Apple..Shows me that Apple is becoming a threat to the PeeCee world and because of this is coming under increasing PR attacks.
Peace is offline  
Old Jun 29, 2006, 04:19 PM   #6
michaeldmartin
macrumors regular
 
Join Date: Jun 2006
Location: Testicles. That is all.
Send a message via AIM to michaeldmartin
They have released a virus in a less-than-sanitary manner: Skype. (Leaked Beta) It was an accident, from a bug.. If you want to think of it as a virus, that is.
michaeldmartin is offline  
Old Jun 29, 2006, 04:21 PM   #7
joshysquashy
macrumors 6502a
 
Join Date: May 2005
Location: UK
Yet another example of why you should always download updates as soon as they are released - they often fix issues, and often highlight previous flaws which some people then take advantage of.
joshysquashy is offline  
Old Jun 29, 2006, 04:21 PM   #8
caveman_uk
Guest
 
caveman_uk's Avatar
 
Join Date: Feb 2003
Location: Hitchin, Herts, UK
Quote:
Originally Posted by Macrumors
[ According to News.com, his actions are in part to show that Apple software is not unbreakable.
So it's not just willy waving then? Oh good.

Seriously, Apple has one day to get people patched and this 'security researcher' releases exploit code on the web. Well thank you. At least it's only a local exploit.
caveman_uk is offline  
Old Jun 29, 2006, 04:22 PM   #9
rowanhall
macrumors member
 
Join Date: Dec 2004
Location: Belfast, Northern Ireland
Quote:
Originally Posted by greenmonsterman
another proof of concept. This isn't cool. Eventually someone will release one of these things in a less than sanitary manner.
exactally what i was thinking bro! i like living in my wee bubble...
__________________
20" iMac G5 1.8GHz (revA), 2gb RAM, 160Gb HDD, Superdrive, Bluetooth, Airport Extreme, 10.5.5
daily MacRumours lurker since March '04
rowanhall is offline  
Old Jun 29, 2006, 04:25 PM   #10
RichP
macrumors 68000
 
RichP's Avatar
 
Join Date: Jun 2003
Location: Motor City
http://rtechnic.com/images/quantumleap.jpg


As stated indirectly by mlr, still better than Windows. Unfortuneatly, Apple's high profile is going to make it more of a target, even if the marketshare is as low as it is.
__________________
"My ultimate vocation in life is to be an irritant" – Elvis Costello
RichP is offline  
Old Jun 29, 2006, 04:25 PM   #11
zap2
macrumors 601
 
zap2's Avatar
 
Join Date: Mar 2005
Location: NJ
well since 10.4.7 stops it, no real worrys
__________________
"We can't all be heroes because somebody has to sit on the curb and clap as they go by." Will Rogers
zap2 is offline  
Old Jun 29, 2006, 04:29 PM   #12
michaelrjohnson
macrumors 68020
 
michaelrjohnson's Avatar
 
Join Date: Aug 2000
Location: 54140
Send a message via AIM to michaelrjohnson
Gosh... a single proof of concept of a local exploit...

This really isn't that big of a deal. Moral of the story: run Software Update regularly. Apple has done really well in patching their own holes, and responding to these types of "exploits".

That being said, nobody (even Apple) claimed that Macs are somehow immune to security exploits, attacks, and viruses. Nobody should be surprised that these types of things exist, and will someday have a greater impact on your workflow.
__________________

michaelrjohnson is offline  
Old Jun 29, 2006, 04:30 PM   #13
MacsRgr8
macrumors 601
 
MacsRgr8's Avatar
 
Join Date: Sep 2002
Location: The Netherlands
Quote:
Originally Posted by zap2
well since 10.4.7 stops it, no real worrys
Yep.. the're too late IMHO.
__________________
Drag and Drop for Windows users:
DRAG your peecee off your desk, and DROP it in the trash.
MacsRgr8 is offline  
Old Jun 29, 2006, 04:30 PM   #14
Doctor Q
macrumors god
 
Doctor Q's Avatar
 
Join Date: Sep 2002
Location: Los Angeles, Row Q Seat 1
Quote:
Originally Posted by KEL9000
at least they released it after it had been fixed by apple.
Mac OS X 10.4.7 may fix it for Mac OS X 10.4, but Mac OS X 10.3 and earlier may have the same vulnerability. I generally feel safer with the latest O.S. release, even though new flaws will invariably be discovered, because at least the widely known flaws are fixed.
__________________
Oh do pay attention 007. In the wrong hands, this Dual 2.93GHz Quad-Core Nehalem Mac Pro could be very dangerous.
Doctor Q is offline  
Old Jun 29, 2006, 04:31 PM   #15
longofest
Demi-God (Editor)
 
longofest's Avatar
 
Join Date: Jul 2003
Location: Falls Church, VA
Send a message via AIM to longofest
Quote:
Originally Posted by Doctor Q
Mac OS X 10.4.7 may fix it for Mac OS X 10.4, but Mac OS X 10.3 and earlier may have the same vulnerability. I generally feel safer with the latest O.S. release, even though new flaws will invariably be discovered, because at least the widely known flaws are fixed.
10.3 is not affected by the launchd vulnerability.
longofest is offline  
Old Jun 29, 2006, 04:32 PM   #16
Jetson
macrumors 6502
 
Join Date: Oct 2003
I liked that worm crawling out of the apple graphic
Jetson is offline  
Old Jun 29, 2006, 04:32 PM   #17
Mac Pwnz You
macrumors newbie
 
Join Date: Jun 2006
Who really cares? No software is "un-breakable" and nobody ever said that Apple software was. It is still, better, more user-friendly, and more secure than Windows.
Mac Pwnz You is offline  
Old Jun 29, 2006, 04:33 PM   #18
Texas04
macrumors 6502a
 
Texas04's Avatar
 
Join Date: Jul 2005
Location: Texas
Send a message via AIM to Texas04
I have to agree with the Water analogy posted above...

My mac alows me to be safer, not immune, and work better than I could ever do with Windows... And Apple does a good job of securing its software, and making sure that everything runs fine "out of the box".

"I'd rather drink water from my local restaraunt, than one in Mexico"


P.S. I'm Mexican to.... And i still love my heritiage and home country!!!
__________________
My Computers-
MacBook Pro 2.0 GHZ~ 1.25 GB Ram
MacBook 1.86 GHZ 2GB Ram
30GB iPod Won from NASA (its engraved)
Texas04's Website!
Texas04 is offline  
Old Jun 29, 2006, 04:35 PM   #19
longofest
Demi-God (Editor)
 
longofest's Avatar
 
Join Date: Jul 2003
Location: Falls Church, VA
Send a message via AIM to longofest
Quote:
Originally Posted by Jetson
I liked that worm crawling out of the apple graphic
It's actually a really old graphic we have on the system. We've shunned some of the older ones for the more classic "news" and "rumor" graphics (aka the newspaper and question mark), but I thought I'd bring out the worm for this one
longofest is offline  
Old Jun 29, 2006, 04:36 PM   #20
Cubert
macrumors member
 
Join Date: Apr 2005
Obviously, Apple is on top of things. Their latest releases patch the issue.
Cubert is offline  
Old Jun 29, 2006, 04:37 PM   #21
iJaz
macrumors 6502a
 
iJaz's Avatar
 
Join Date: Dec 2004
"Mac's not invulnerable"
__________________
Home: PM G5 2.3 GHz 4.5 GB RAM, 20" ACD, 1G 512 MB and 2G 1GB Shuffle, 4 GB nano RED, 80 GB iPod, iPhone 3G S⃣ 32 GB Black. Work: MacBook C2D 2.0 GHz 4GB RAM
iJaz is offline  
Old Jun 29, 2006, 04:46 PM   #22
tveric
macrumors 6502
 
Join Date: Jun 2003
Quote:
Originally Posted by iJaz
"Mac's not invulnerable"
We really need a Slashdot-like moderating system.... -1 Troll!
tveric is offline  
Old Jun 29, 2006, 04:54 PM   #23
yellow
Demi-God (Moderator)
 
yellow's Avatar
 
Join Date: Oct 2003
Location: I love you, food.
Quote:
Originally Posted by Macrumors
According to News.com, his actions are in part to show that Apple software is not unbreakable.
Damnit, who keeps saying that it is? Well, cut it out!!
__________________
Chameleon's Consignment Loft
yellow is offline  
Old Jun 29, 2006, 04:55 PM   #24
Onizuka
macrumors 68040
 
Onizuka's Avatar
 
Join Date: Apr 2005
Location: Why are you wearing that stupid man suit?
*yawn*

So, really, who gives a damn? I don't want proof-of-concept. I want proof that it works in the wild. Come on now. Someone do something here. Quit making all of these claims. It's like foreplay without the ending. Ya know? WTF?
__________________
On Diebold: "i went to get cash last night and ended up voting republican. wonder how much that's gonna cost me." -Zimv20
Onizuka is offline  
Old Jun 29, 2006, 04:56 PM   #25
dejo
macrumors Demi-God
 
dejo's Avatar
 
Join Date: Sep 2004
Location: On the roadside
Wait. According to the "security through obscurity" people, nobody is writing exploits for Mac OS X because of its low marketshare. How can this be?
dejo is offline  

 

Mac Forums > Archive > Archives of Old Posts > MacRumors News Discussion (archive)

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 04:36 PM.

Mac News | Mac Rumors | iPhone Game Reviews | iPhone Apps

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright 2002-2009, MacRumors.com, LLC