|
|
| Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate. |
|
|||||||
| TouchArcade.com - iPhone Game Reviews and News |
![]() |
|
|
Thread Tools | Search this Thread |
|
|
#1 | |
|
macrumors regular
Join Date: Aug 2003
Location: Germany
|
Serious flaws discovered in Leopard's firewall
You wouldn't even believe Microsoft to be so stupid to expose open services (and even NetBIOS!!) to the internet when the firewall is setup to block ALL traffic. No kidding, Leopard does. Though, there is no proof of concept exploit, yet, that's a totally unneccessary design flaw, even a freshman CS student wouldn't be allowed to turn in.
From the article (German heise magazine): Quote:
|
|
|
|
|
|
|
#2 | |
|
macrumors 68040
Join Date: Jun 2004
Location: Chicago, IL
|
Quote:
|
|
|
|
|
|
|
#3 | |
|
macrumors Demi-God
Join Date: Mar 2006
Location: Las Vegas, Earth
|
The sky is falling...
Quote:
__________________
www.usheroes.us You don't have a soul. You are a soul. You have a body. C. S. Lewis |
|
|
|
|
|
|
#4 |
|
macrumors 65816
Join Date: Sep 2006
|
I wonder what degree of hardware firewall you would need to compensate.
Would a standard router with NAT work? Or, would you actually need a router with a specific firewall to compensate?
__________________
Mac Pro 2.66 GHz Quad, 14 GB RAM, two 22-inch LCD widescreens, 3.6 terabytes hard drive space. 2 SuperDrives. Mac OS X 10.5.x. Vista Ultimate. Fusion |
|
|
|
|
|
#5 | |
|
macrumors 601
Join Date: Sep 2006
|
Quote:
|
|
|
|
|
| flopticalcube |
| View Public Profile |
| Find More Posts by flopticalcube |
|
|
#6 | |
|
macrumors 65816
Join Date: Sep 2006
|
Quote:
It's a BEFSX41 Labeled as a Broadband Firewall Router. I've previously configured it, and it seems to have passed the online scanners. So, hopefully it will close the door that Apple is opening.
__________________
Mac Pro 2.66 GHz Quad, 14 GB RAM, two 22-inch LCD widescreens, 3.6 terabytes hard drive space. 2 SuperDrives. Mac OS X 10.5.x. Vista Ultimate. Fusion |
|
|
|
|
|
|
#7 | |
|
macrumors 601
Join Date: Sep 2006
|
Quote:
|
|
|
|
|
| flopticalcube |
| View Public Profile |
| Find More Posts by flopticalcube |
|
|
#8 |
|
macrumors 65816
Join Date: Sep 2006
|
__________________
Mac Pro 2.66 GHz Quad, 14 GB RAM, two 22-inch LCD widescreens, 3.6 terabytes hard drive space. 2 SuperDrives. Mac OS X 10.5.x. Vista Ultimate. Fusion |
|
|
|
|
|
#9 |
|
macrumors 603
Join Date: May 2002
|
Anybody turn on the advanced settings, use stealth, then look at the logs awhile latter.
![]() Edit: I miss the dead SPI enabled router.
__________________
May you be plagued by images of Richard Simmons flouncing through you brain, and squat thrusting his way though all waking thoughts.
|
|
|
|
|
|
#10 | |
|
macrumors 65816
Join Date: Sep 2006
|
Quote:
SPI, I seem to recall something about that when I was researching my router / firewall purchase. Seems it was a feature of the Linksys Router if I remember correctly. But, then I could just be mixing things up at the moment.
__________________
Mac Pro 2.66 GHz Quad, 14 GB RAM, two 22-inch LCD widescreens, 3.6 terabytes hard drive space. 2 SuperDrives. Mac OS X 10.5.x. Vista Ultimate. Fusion |
|
|
|
|
|
|
#11 |
|
macrumors 65816
Join Date: Apr 2006
|
__________________
Black MacBook | Core Duo 2 GHz | 2 GB Ram | 320 GB HDD | OS X Snow Leopard 10.6 - iPod Touch | 16 GB
Camino OpenSolaris |
|
|
|
|
|
#12 |
|
macrumors 65816
Join Date: Sep 2006
|
I believe I did do that. I spent hours comparing the settings with descriptions of what they did on the Internet. Hopefully I got everything.
__________________
Mac Pro 2.66 GHz Quad, 14 GB RAM, two 22-inch LCD widescreens, 3.6 terabytes hard drive space. 2 SuperDrives. Mac OS X 10.5.x. Vista Ultimate. Fusion |
|
|
|
|
|
#13 |
|
macrumors 68040
Join Date: Dec 2003
|
Are they saying the OS X firewall has always been terrible, or that 10.5 is a brand new firewall under the hood and it replaces a very good firewall that was in 10.4?
|
|
|
|
|
|
#14 |
|
macrumors 65816
Join Date: Sep 2006
|
It sounds to me like they are saying that 10.5 is worse. But, I could be wrong.
__________________
Mac Pro 2.66 GHz Quad, 14 GB RAM, two 22-inch LCD widescreens, 3.6 terabytes hard drive space. 2 SuperDrives. Mac OS X 10.5.x. Vista Ultimate. Fusion |
|
|
|
|
|
#15 |
|
macrumors 6502
Join Date: Feb 2007
Location: New York, NY
|
Well this is somewhat disappointing.
__________________
http://www.deliciousmacs.com |
|
|
|
|
|
#16 |
|
macrumors member
Join Date: Sep 2006
|
Has anyone else tested this? I'm not so quick to jump on this one yet. Why has it taken this long to figure this out?
Edited: I did a port scan on my local network with the firewall on block all and stealth and it would not pick up anything until the very second I allowed all incoming connections. Am I missing something here??? Last edited by weaverra : Oct 30, 2007 at 01:17 AM. |
|
|
|
|
|
#17 | |
|
macrumors 65816
Join Date: Sep 2006
|
Just double-checked, and I did have that disabled already. So, hopefully I'm protected.
I just updated my firmware to the latest revision (on the router / firewall). I was one revision behind there. And, I just went back through my settings, and all looks good there. So, hopefully Leopard won't open the door on me. Yes. If this is true, then Leopard will definitely be a let-down there. Quote:
Did you do this in the new Leopard (10.5)? Or, were you in Tiger (10.4.x)?
__________________
Mac Pro 2.66 GHz Quad, 14 GB RAM, two 22-inch LCD widescreens, 3.6 terabytes hard drive space. 2 SuperDrives. Mac OS X 10.5.x. Vista Ultimate. Fusion Last edited by devilot : Oct 30, 2007 at 01:39 AM. Reason: Merged THREE posts; PLEASE use "Edit" and/or "Multi-Quote" |
|
|
|
|
|
|
#18 | |
|
macrumors 603
Join Date: May 2002
|
Quote:
I looked and have Bonjour and the time server open.
__________________
May you be plagued by images of Richard Simmons flouncing through you brain, and squat thrusting his way though all waking thoughts.
|
|
|
|
|
|
|
#19 | |
|
macrumors 65816
Join Date: Sep 2006
|
Quote:
Hesitant to read between the lines... What is your belief based on your observations?
__________________
Mac Pro 2.66 GHz Quad, 14 GB RAM, two 22-inch LCD widescreens, 3.6 terabytes hard drive space. 2 SuperDrives. Mac OS X 10.5.x. Vista Ultimate. Fusion |
|
|
|
|
|
|
#20 | |
|
macrumors member
Join Date: Sep 2006
|
Quote:
00:19 is when I allowed all incoming connections Oct 30 00:16:56 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49202 uid = 0 proto=6 Oct 30 00:16:56 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49203 uid = 0 proto=6 Oct 30 00:16:56 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49204 uid = 0 proto=6 Oct 30 00:16:57 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49202 uid = 0 proto=6 Oct 30 00:16:57 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49204 uid = 0 proto=6 Oct 30 00:16:57 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49203 uid = 0 proto=6 Oct 30 00:16:58 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49202 uid = 0 proto=6 Oct 30 00:16:58 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49204 uid = 0 proto=6 Oct 30 00:16:58 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49203 uid = 0 proto=6 Oct 30 00:16:59 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49202 uid = 0 proto=6 Oct 30 00:16:59 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49204 uid = 0 proto=6 Oct 30 00:16:59 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49203 uid = 0 proto=6 Oct 30 00:17:00 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49202 uid = 0 proto=6 Oct 30 00:17:00 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49204 uid = 0 proto=6 Oct 30 00:17:00 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49203 uid = 0 proto=6 Oct 30 00:17:01 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49202 uid = 0 proto=6 Oct 30 00:17:01 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49204 uid = 0 proto=6 Oct 30 00:17:01 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49203 uid = 0 proto=6 Oct 30 00:17:03 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49202 uid = 0 proto=6 Oct 30 00:17:03 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49204 uid = 0 proto=6 Oct 30 00:17:03 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49203 uid = 0 proto=6 Oct 30 00:17:07 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49202 uid = 0 proto=6 Oct 30 00:17:07 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49204 uid = 0 proto=6 Oct 30 00:17:07 bobby-weavers-macbook-pro-15 Firewall[40]: Deny smbd connecting from 192.168.x.xxx:49203 uid = 0 proto=6 Oct 30 00:19:06 bobby-weavers-macbook-pro-15 Firewall[40]: Allow cupsd listening from :::631 uid = 0 proto=6 Oct 30 00:19:06 bobby-weavers-macbook-pro-15 Firewall[40]: Allow cupsd listening from 0.0.0.0:631 uid = 0 proto=6 Oct 30 00:21:18 bobby-weavers-macbook-pro-15 Firewall[40]: Stealth Mode connection attempt to UDP 192.168.x.xxx:49429 from 66.82.x.x:xx |
|
|
|
|
|
|
#21 |
|
macrumors Demi-God
Join Date: Apr 2005
Location: On top of the Storm Peaks waiting for the Time-Lost Proto Drake
|
This guy/site doesn't understand the Leopard firewall..
|
|
|
|
|
|
#22 | |
|
macrumors 603
Join Date: May 2002
|
Quote:
Almost sounded like they stayed there til you restarted. Which is basically how all Apple firewalls are typically punched in the contests, getting at them through stuff the user runs.
__________________
May you be plagued by images of Richard Simmons flouncing through you brain, and squat thrusting his way though all waking thoughts.
|
|
|
|
|
|
|
#23 |
|
macrumors 6502a
Join Date: Feb 2006
Location: Berlin, Germany
|
This is entirely possible. However, I honestly think that the apple firewall is not an easily usable and confidence inspiring product. And it is turned 'OFF' by default!
![]() I do not know the English version of the UI, but in the German version Apple tells you that 'normally the OS is choosing for which programms it allows incoming connection', that is not something I want my firewall to do. So if you have in-depth knowledge of the workings of the Mac OS X firewall, maybe you like to share it with us.
__________________
Anecdotal evidence is an oxymoron! |
|
|
|
| Detektiv-Pinky |
| View Public Profile |
| Find More Posts by Detektiv-Pinky |
|
|
#24 |
|
macrumors regular
Join Date: May 2007
Location: /dev/null
|
This is nonsense.
To begin with, there's no such thing as a "hardware firewall". A better (and commonly used) designation is "appliance". A firewall appliance is a dedicated box, running an OS (in many cases a tweaked Linux or *BSD, though there are of course many other possibilities, like IOS on Cisco firewalls), on top of which the actual firewall software sits. Now, assuming you call a "hardware firewall" any kind of dedicated firewall appliance, well, obviously, since your wireless router does wireless routing, it's not a dedicated firewall, is it? ![]() That said, whether you have a dedicated firewall box or not, it's the quality of the firewall software that has to be taken into account. It's always a very bad idea to make a product insecure by default. Microsoft has been bashed repeatedly for that, and so should Apple! ![]() However, I'm not yet ready to believe that their firewall is as flawed as the article says. I'll have a look in a couple days! |
|
|
|
|
|
#25 |
|
macrumors 6502
Join Date: Sep 2006
Location: UK
|
Thanks for the info. I'll be keeping my eye out for a software update to combat this problem.
|
|
|
|
| joelovesapple |
| View Public Profile |
| Find More Posts by joelovesapple |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|