Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Mac Hole Has Users, Hackers Abuzz (Mac security prob)

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
PfcHammer Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 12:15 PM
Original message
Mac Hole Has Users, Hackers Abuzz (Mac security prob)
Mac Hole Has Users, Hackers Abuzz
By Leander Kahney

Story location: http://www.wired.com/news/mac/0,2125,63528,00.html

02:00 AM May. 20, 2004 PT

Malicious script kiddies are reportedly rushing to exploit the first serious security hole discovered in Apple Computer's Mac OS X.

First discovered in February by a German Web designer, but not reported publicly until Tuesday, a vulnerability in OS X opens systems to potential hijackings when users simply visit a website.

Because of the way OS X handles certain protocols, a machine can be commanded through a Web link to run applications, scripts or Unix commands.

Though no victims have stepped forward yet, nefarious uses of the exploit are potentially unlimited. Experts warn machines could easily be hijacked to erase hard drives, spread viruses and spam, and report bank account numbers and passwords.

<snip>

Printer Friendly | Permalink |  | Top
Servo300 Donating Member (653 posts) Send PM | Profile | Ignore Thu May-20-04 12:17 PM
Response to Original message
1. I thought Windows was the only one that had security holes..
Printer Friendly | Permalink |  | Top
 
Just Me Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 12:18 PM
Response to Reply #1
3. "World War Three will be a guerilla information war,...
,...with no division between military and civilian participation." --Marshall McLuhan.

What can I say,...this quote is pervasive.
Printer Friendly | Permalink |  | Top
 
progressiveBadger Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 12:25 PM
Response to Reply #1
5. Every OS has security holes
It just so happens that 90% of computers run Windows so there is a lot more attention paid to it, by both virus writers and the press.
Printer Friendly | Permalink |  | Top
 
cheezus Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 12:18 PM
Response to Original message
2. stupid flaw on apple's part. but easy to fix
just make help: launch a program like textedit or chess instead of the help viewer. There's a few third party utils to let you do this. I used MoreInternet
Printer Friendly | Permalink |  | Top
 
Emillereid Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 12:26 PM
Response to Reply #2
6. Where did you get the utility? Can you give more info
about what to do? Has Apple sent out a fix yet?
Printer Friendly | Permalink |  | Top
 
cheezus Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 12:30 PM
Response to Reply #6
9. check out macnn.com
they're featuring a new utility that does what I just said, except you don't have to figure it out for yourself
Printer Friendly | Permalink |  | Top
 
Voltaire99 Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 04:29 PM
Response to Reply #6
14. Apple has had since February to act, and hasn't...
...which is one reason why there are fears the vulnerability is deeper than merely the Help API.
Printer Friendly | Permalink |  | Top
 
onehandle Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 12:25 PM
Response to Original message
4. If I posted everytime Windows had security flaws/major viruses...
Wasting time in Latest Breaking News would be my full time job.
Printer Friendly | Permalink |  | Top
 
progressiveBadger Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 12:26 PM
Response to Reply #4
7. If macs ever became truly popular
Edited on Thu May-20-04 12:27 PM by nosferatu
there will be as many security holes found it in as Linux, which, on average, fixes about five holes a week.
Printer Friendly | Permalink |  | Top
 
lil-petunia Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 12:29 PM
Response to Reply #7
8. fixing holes?
Is that why condi refers to shrub as her hubby?
Printer Friendly | Permalink |  | Top
 
tekriter Donating Member (734 posts) Send PM | Profile | Ignore Thu May-20-04 01:15 PM
Response to Reply #7
11. Actually, the main reason that Macs have so few security holes
is that OS X, by default, does not allow the installation of other software without entering a password. The usual virus/trojan method of an attachment to an email just doesn't work on a Mac.

This new exploit takes advantage of the structure of a URL, and bypasses the installer password block.

Printer Friendly | Permalink |  | Top
 
progressiveBadger Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 07:15 PM
Response to Reply #11
15. That only helps against virus/trojans
All I am saying is that if/when macs become a bigger target, there will be similar issues as there are with Windows right now. I'm not a mac hater, I like them equally. In fact, I'm waiting for a new TiBook right now. :)
Printer Friendly | Permalink |  | Top
 
bemildred Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 12:57 PM
Response to Original message
10. "Secure Web Server" is an oxymoron.
If you want security in a web server you need to do the work,
it doesn't come in a can.
Printer Friendly | Permalink |  | Top
 
RedEarth Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 01:30 PM
Response to Original message
12. Get Windows
Then you will really have problems......critical updates weekly.
Printer Friendly | Permalink |  | Top
 
Mithras61 Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 01:34 PM
Response to Reply #12
13. It must be your configuration...
I'm running Red Hat 9, Red Hat EL 2.1 U3, Red Hat EL3 U1, Fedora 1, Windows XP (home & pro), Windows 2000 (multiple versions) and Windows 2003 Server.

Guess which one I see most of the "security updates" for...

I'll give you a hint... Microsoft doesn't appear in the name of the product...
Printer Friendly | Permalink |  | Top
 
progressiveBadger Donating Member (1000+ posts) Send PM | Profile | Ignore Thu May-20-04 07:17 PM
Response to Reply #13
16. Hmmm... Server Admin?
Or someone with a lot of computers and/or hard drive space at home? :)
I find that my time is equally spent updating our linux servers as it is our windows servers. That says a lot seeing as how we have WAY more M$ products.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri May 03rd 2024, 10:01 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC