Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, June 23, 2008

Pray for Apple to release a security fix soon

According to SecureMac there are several (read > 0) trojan horses in the wild that leverage the root escalation problem.

Please Apple provide a security fix to the masses - at least use my ultra simple fix to open at least the root prompt. (Then at least some users will notice that there is something wrong).

Sources:
OSX.Trojan.PokerStealer
AppleScript.THT Trojan Horse

Saturday, June 21, 2008

Annoying Root Exploit on Mac OSX via Apple Remote Desktop

Lets remeber for one second, why a Mac is so much better than a PC:

It’s gorgeous. Inside and out.
Since the software on every Mac is created by the same company that makes the Mac itself, you get a completely integrated computer that’s as secure, stable, and powerful as it is elegant and easy to use.
Apple: Why Mac


It's so damn secure - that it ships with a root exploit. (Excuse me, maybe it's just that user friendly, that it won't ask for the root password).

Anyway, here's how to fix it (one line!):

chmod u-s /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent


Sources:
Mac OS X Root Escalation Through AppleScript
ARDAgent root privilege escalation
Root-Exploit für Mac OS X

Remember:
Security is like sex. Once you're penetrated you're ****ed.