Slashdot Mirror


Software Update Vulnerability

redmoss writes "I just saw this exploit for Software Update on Bugtraq. Quoting the discoverer Russell Harding: 'Mac OS X includes a software updating mechanism 'Software Update.' Software Update, when configured by default, checks weekly for new updates from Apple. HTTP is used with absolutely no authentication. Using well-known techniques, such as DNS Spoofing, or DNS Cache Poisoning, it is trivial to trick a user into installing a malicious program posing as an update from Apple.' Looks like people using Software Update need to be careful, as there is currently no workaround." Well, one workaround for this particular exploit is to not share a LAN with someone who would do that sort of thing.

92 comments

  1. It's not a bug, it's a feature! by tristan-b · · Score: 3, Interesting

    Software Update is convinent, but it only allows you to update Apple software (and the occasional IE bug fix). This bug could just as easily be exploited to allow for a Mac computer lab to auto-update third party software, reducing the hassle of network-wide installs, and potentialy making the lab more secure by fixing bugs in other softare. Apple should provide this option, IMHO.

    1. Re:It's not a bug, it's a feature! by medcalf · · Score: 3, Interesting

      It would be nice if SU did provide a feature so that third parties could register their software with SU, and it could then be kept up to date transparently. Of course, this would only be a feature if the user got to pick the non-Apple software to be updated. Having a method where some client I install sets up SU to automatically keep spyware updated, and not telling me about it, would be most unpleasant.

      --
      -- Two men say they're Jesus. One of them must be wrong. - Dire Straits
    2. Re:It's not a bug, it's a feature! by tps12 · · Score: 2, Interesting

      I agree, this could be invaluable to sys admins.

      Rather than going through the agony of installing sshd on each and every client computer, and then writing a bash script to scp updated files as necessary, just have each client poll a central http server (hidden from the Internet by a firewall, of course) for bug updates. Then you just need one person at each workstation to click "okay" and install the thing.

      Just because the Mac is now Unix-based, doesn't mean we should give up the ease of use and convenience that made the Mac great in the first place.

      --

      Karma: Good (despite my invention of the Karma: sig)
    3. Re:It's not a bug, it's a feature! by foobar104 · · Score: 3, Informative

      Rather than going through the agony of installing sshd on each and every client computer....

      Not to be pedantic, but each and every client computer already has sshd on it. It's a part of OS X.

    4. Re:It's not a bug, it's a feature! by Gogo+Dodo · · Score: 2

      If you're in a lab environment, Macintosh Manager and NetBoot should be able to help with the software distribution problem.

    5. Re:It's not a bug, it's a feature! by AllInOne · · Score: 3, Informative

      VersionTracker Pro provides essentially this feature already...

      I haven't used it since it went out of free beta but it is a pretty neat tool for folks who are truly addicted to having the latest version of any software.

    6. Re:It's not a bug, it's a feature! by Anonymous Coward · · Score: 0

      Well, software installed via fink already has this ability. Setup a cronjob to "apt-get update; apt-get dist-upgrade" and you're good to go.

      Just because the Mac is now Unix-based, doesn't mean we should give up the ease of use and convenience that made the Mac great in the first place.

      Um, the mac hasn't ever had ease of use like that built in, except for system updates from apple. Other "hard to use" unixes like *BSD and Debian GNU/Linux, however, have had this built in for years (and not just for vendor software either!).

      Oh yeah, and how the fuck is it hard to "install" sshd? It's already installed, just click "Allow Remote Login" in the sharing pane inside system prefs to enable it.

    7. Re:It's not a bug, it's a feature! by good+soldier+svejk · · Score: 1

      I would use rsync inside ssh to automatically sync to a referance machine.

      --
      It is cowardly, and a betrayal of whatever it means to be a Jew, to act as a white man

      -James Baldwin
    8. Re:It's not a bug, it's a feature! by foobar104 · · Score: 2

      I would use rsync inside ssh to automatically sync to a referance machine.

      How do you plan to install software or preload libraries using rsync?

  2. Wouldn't work on me, or most net-savvy Mac users. by Alex+Thorpe · · Score: 2, Interesting

    The Mac news sites are very thorough, and I always read about new updates before I see them on Software Update. Also, I don't install everything listed. I've marked as inactive several foreign language updates, and some AirPort updates, as I only speak English and don't have an AirPort card.

    --
    "Common Sense Ain't" -Unknown
  3. True Of All Updaters by dthable · · Score: 2, Informative

    This is true of all those Automatic Update tools, including Red Carpet and Windows Update. They all use DNS to find the software on the Net and then install the modules without too much fuss. The only real work around is to know what you're installing. Download from what you believe to be the correct source, always look for a public verification key and then install it.

    1. Re:True Of All Updaters by Anonymous Coward · · Score: 3, Informative

      what are you talking about? red carpet verifies the gpg signatures on rpms before installing them. i suspect windows update does something similar.

    2. Re:True Of All Updaters by phyxeld · · Score: 3, Interesting
      The only real work around is to know what you're installing. Download from what you believe to be the correct source, always look for a public verification key and then install it.

      1. I believe swscan.apple.com to be the correct source. The point is, that could be made to resolve to a different, hostile, IP address.

      2. A public verification key? From apple? See, thats the problem. They don't do that currently. When they start to, they'll probably build it into the software update system, like they should have in the first place.

      An interesting sidenote: I've been sniffing some SU traffic after reading all this, and noticed some interesting HTTP headers:
      Accept-Ranges: bytes
      Date: Mon, 08 Jul 2002 07:01:41 GMT
      Content-Length: 7286
      Content-Type: text/plain
      Server: Netscape-Enterprise/3.6 SP3
      Etag: "ea810-1c76-3d20f5eb"
      Last-modified: Tue, 02 Jul 2002 00:38:03 GMT
      Via: 1.1 netcache04 (NetCache NetApp/5.2R1D8)
      Looks like Apple doesn't practice what they preach in terms of server software. :)
      And wtf is that NetApp cache bullshit? Does everyone see that, or am I being transparently proxied somewhere?! OK, just checked some other stuff, the NetApp cache header is only present on my SoftwareUpdate connections. Something on apple's end? Does everybody see this?

      (fwiw i'm using the incredibly simple tcpflow to watch my tcp traffic. ethereal is cooler, and lets me see non-tcp traffic too, but the current mac (fink) version has a very high suck factor. Sometimes ICMP packets don't show up, streams can almost never be reconstructed entirely, etc etc. Moving capture files off the mac over to a linux or bsd box for analysis is the only way I can seem to use ethereal for much of anything.)
      --
      __
      Choose mnemonic identifiers. If you can't remember what mnemonic means, you've got a problem. - Larry Wall
    3. Re:True Of All Updaters by ensignyu · · Score: 1

      It would make sense that Apple is using a (reverse-)proxy. Considering the ammount of traffic, a proxy server would speed things up.

    4. Re:True Of All Updaters by TheAJofOZ · · Score: 2
      what are you talking about? red carpet verifies the gpg signatures on rpms before installing them. i suspect windows update does something similar.

      erm, except the gpg signature comes from the same person supplying the malicious file..... oops.

    5. Re:True Of All Updaters by Hes+Nikke · · Score: 1

      you probably are being transpaently proxied. a few years ago apple made a deal with Akamai to proxy all there content, thats why an apple download will max my DSL, my ISP has there own set of akamai servers :D

      --
      Don't call me back. Give me a call back. Bye. So yeah. But bye our, well, but alright we are on a shirt this chill.
    6. Re:True Of All Updaters by pudge · · Score: 1

      Um, but the key used to sign the signature is known by the updater, which has the public key locally, and so the signature file would need to be used with a different key, which the client program would recognize as different. The whole point of PGP/GPG is that the key of the signer is known and trusted. If you could hack the client to recognize a different key, then that would be a problem. Otherwise, the only way would be to crack the GPG key ... oops.

    7. Re:True Of All Updaters by piznut · · Score: 0

      You are incorrect.

      This is not true of Windows Update. Windows Update uses a signed activex control to download and install software updates. While the security of this solution could potentially have holes poked in it (including user stupidity allowing a non signed control to run)...it is no less secure than many other update methods and is most certainly far more secure than what apple current implements.

    8. Re:True Of All Updaters by Anonymous Coward · · Score: 0

      my ISP has there own set of akamai servers :D

      So does my ISP. Infact, hey, thats cause it's the same ISP!

      ( /me checks whois and sees where you live... )

      A certain electric bike company in your town has an unencrypted wireless network with open smb shares! Ooh la la!

  4. Right... by Clue4All · · Score: 2, Insightful

    Well, one workaround for this particular exploit is to not share a LAN with someone who would do that sort of thing.

    You mean like the thousands of users on my cable network that I share a DNS server with? I'm not sure I trust them too much, but I can't really do much about that.

    --

    Is your browser retarded?
    1. Re:Right... by Strog · · Score: 1

      I'm just glad I can trust all these students here at the college.

      I often ask myself why I want to work at a college when the students are so good at hosing systems. I'm glad I don't deal with them more often than I do.

      Most of the students who are supposed to know about this kind of stuff don't (there are exceptions) and the ones who shouldn't know it do.

      I need to figure out who is upstream a little better.

  5. Re:Wouldn't work on me, or most net-savvy Mac user by tristan-b · · Score: 3, Interesting

    Or would it? All you'd have to do is wait for a legitimate update to be released and mask your software as that update (same filename/size/desc). The end user would have no idea they weren't updating to OS 10.1.6, but rather installing a trojan. Software Update is a trusted source for most users.

  6. Not Sharing a LAN? by Jeremiah+Cornelius · · Score: 3, Funny
    I guess Pudge's "Not sharing a LAN with someone who'd do that was meant to be enclosed in tags!
    <sarcasm>
    Well, one workaround for this particular exploit is to not share a LAN with someone who would do that sort of thing.
    </sarcasm>

    These exploit techniques could be used by a good blackhat to affect everyone on, let's say Rogers Cable, in a specific geographic region. Face, it: since this became a one-protocol world with fat pipes, we all trust upstream.

    Are you big enough for your home DNS to point only at root?

    --
    "Flyin' in just a sweet place,
    Never been known to fail..."
    1. Re:Not Sharing a LAN? by mkldev · · Score: 1

      Are you big enough for your home DNS to point only at root?

      Yup.

      In God we trust. All others must provide DSA keys.

      --
      120 character sigs suck. Make it 250.
    2. Re:Not Sharing a LAN? by Anonymous Coward · · Score: 0

      you be the troll, methinks.

  7. Re:Wouldn't work on me, or most net-savvy Mac user by Alex+Thorpe · · Score: 1, Funny

    A trojan that's the same size as an OS update? I'd think that a trojan wouldn't need more than a few kilobytes to do its damage. Many major updates in X even give you the EULA before the download starts. I doubt many Trojan authors would duplicate that.

    --
    "Common Sense Ain't" -Unknown
  8. wtf??? by Shadowcaster · · Score: 0, Flamebait
    Well, one workaround for this particular exploit is to not share a LAN with someone who would do that sort of thing.

    Oh, you mean like the whole internet. Gee, why didn't I think of that.
    "DUUUUUUHHHHHHHHHHHHHHH!!!!" -- Steve Oedekerk

  9. we already have that by g4dget · · Score: 2
    It's called "Fink" and "apt-get". You can configure your sources for apt-get in whatever way you like.

    Granted, it's still a bit shaky on Macintosh OS X, but it's getting better.

  10. Re:Wouldn't work on me, or most net-savvy Mac user by Anonymous Coward · · Score: 0

    Think about how dumb that comment was. Someone takes the time to forge an update, waits for an official update to come out, but is too lazy to add a bunch of extra 0's at the end of the file and add a simple dialog box.

    Yeah, don't worry. Nobody would have the time to do that. I guess there's no point for you to update your mac then. Just keep going unpatched, and enjoy ignorance.

  11. Re:Wouldn't work on me, or most net-savvy Mac user by diverman · · Score: 1

    I don't think you quite saw the vulnerability. It's not a matter of hacking the Apple SU server, but rather the individual resolution to the server, or other similar methods aimed at the end user.

    I always check the response from others before applying updates as well (yea VersionTracker). But, if someone targetted my network (DNS servers for example) _I_ would be the only one affected by the exploit with this particular attack.

    So, all someone has to do is coordinate an attack on you with an update from Apple, you go read the reports, people say "Great update, no problems," and you go ahead and apply the updates across your machines. All the while, your DNS server was hacked, and your machines are actually connecting to some eroneous source that just installed a backdoor... and while it's at it, installs the Apple update to appear real.

    For now, you need to just trust that your local network and DNS is secure. But some form of host certification should really be applied to ensure that the app is connecting to a valid machine... much like web browsers can do when connecting to an SSL server.

    Just my $0.02. :)

    -Alex

  12. "Easy" solution by bnenning · · Score: 3, Interesting

    Apple should sign all updates and Software Update should verify what it downloads against Apple's public key. An attacker would then have to modify the copy of Apple's public key on the victim's machine, or modify Software Update to disable the check, both of which would presumably require root privileges. Still not perfect, but an improvement.

    --
    How to solve most of our problems: 1.Lots of nuclear plants. 2.Cure aging.
  13. Re:Wouldn't work on me, or most net-savvy Mac user by Alex+Thorpe · · Score: 1

    Sorry, but I still think I'd have to seriously piss someone off to make them go to the trouble to do this to my one little iMac. Nothing between me and SWBell, to my knowledge. Anyway, I have no enemies, and most Mac users I know think I'm a great guy(example, my 5 star rating on the Macgamer.com forums). And I don't think someone picking a victim at random would find me.

    --
    "Common Sense Ain't" -Unknown
  14. Re:Wouldn't work on me, or most net-savvy Mac user by Alex+Thorpe · · Score: 1

    So, they'll hack the SWBell DNS servers to get to us home DSL users on Mac's running X... nah, I can't see it happening.

    --
    "Common Sense Ain't" -Unknown
  15. Re:Wouldn't work on me, or most net-savvy Mac user by Anonymous Coward · · Score: 0

    You, sir, are a quite funny little troll. I hope.

    That, or you're really really really stupid.

  16. Re:Wouldn't work on me, or most net-savvy Mac user by Anonymous Coward · · Score: 0

    From what I can tell, the way software update ensures that it's really talking to apple is based entirely on DNS lookups rightnow. No SSL, no md5sums, nada. All bad.

    Along with many other security measures, they should start using md5sums and setup a seperate server that only hosts the sums. Hardcode it's IP address into the software update client, and make sure that whereever the update comes from it's got md5's that match up with the sum server. I know hardcoding an IP seems like a bad idea, but to truly protect against DNS attacks it might be a good move in this case. (And apple owns their own IP blocks - surely they can pick a certain number and guarantee it will remain THE md5sum server.)

    It's easy to dismiss this threat as unlikely, but imagine running these prepackaged tools in a lab environment with a few hundred OS X macs...

    Apple better have an update out real quick on this one.

  17. Re:Wouldn't work on me, or most net-savvy Mac user by ztc · · Score: 1

    Actually, it could possibly be quite profitable for someone who had access to the DNS server to do such a thing as this. I would bet there's enough Mac users on the SWBell DSL network to find at least a few credit card numbers, addresses, names, ssn's, etc.

  18. Looks bad. How rapid a response? by feldsteins · · Score: 3, Interesting

    Apple appears to have blundered, although I am still watching for further news on how bad. The key will be to watch how quckly (or how slowly!) they respond with an appropriate fix. If it takes two weeks, that's bad. If it takes 3 days I'm not going to complain about that. We'll see what happens. Until then, no SW update for me.

    Meanwhile I actually sent Apple an email describing the problem and asking for a public advisory and a fix ASAP. Just doing my part.

    --
    You like your Macintosh better than me, don't you Dave? Dave? Can you hear me Dave?
  19. No easy fixes... by MacDork · · Score: 2, Insightful

    This is an old trick. Remember the stink raised recently about users 'uncapping' their cable modems? Same idea. It's a problem here primarily because the install runs as root.

    The solution is a bit hairy though. Let's say Apple builds authentication into the "SoftwareUpdate" mechanism. That doesn't stop someone from spoofing a third party software updating mechanism. It also doesn't stop someone from writing malicious software that poses as shareware. I downloaded a shareware app last week that asked for Admin privileges just so the installer could drop the application in /Applications.

    And should Apple build authentication into the installer process from the ground up, everyone will be wringing their hands with concerns about how Apple selects who gets signed. It will strongly resemble the code signing thing Microsoft said it would start doing in future versions of Windows. (Though, I'm more apt to trust Apple to 'do the right thing' when it comes to *not* stifling the competition.)

    Even then, a malicious code writer could craft an install process that 'looks' like Apple's long enough to get a password and then pipe it to sudo with something like java.lang.Runtime.exec(). Anybody that thinks Apple should/will have a solution to this problem in a few days really ought to rethink the problem a bit. It has as much to do with educating end users about code signing, security, privileges, and encryption as it does with any software fix Apple finally does produce.

    The irony here is this isn't a problem until an end user enters a password and clicks "OK". It isn't automatic like some javascript launched Outlook attachment. Whoever posted this 'testing' software could have done the same with Windows, or one of a thousand other auto-updating programs on the net, but chose Apple. Why? In my estimation he is tired about hearing how secure and virus free Macs are.

    1. Re:No easy fixes... by Wesley+Felter · · Score: 2

      And should Apple build authentication into the installer process from the ground up, everyone will be wringing their hands with concerns about how Apple selects who gets signed.

      I doubt it, since Software Update is only used to update Mac OS itself.

      It will strongly resemble the code signing thing Microsoft said it would start doing in future versions of Windows.

      Not really, since MS is talking about requiring code to be signed, while we're talking about having Apple sign updates for their own software. Debian signs their updates, right? Does that make them evil, too?

    2. Re:No easy fixes... by foniksonik · · Score: 2

      "Anybody that thinks Apple should/will have a solution to this problem in a few days really ought to rethink the problem a bit."

      It is entirely possible on the other hand that they have been addressing this issue for the last several months while developing OS X 10.2 and that the fix is right around the corner. Maybe not a few days but within a few weeks is reasonable. Especially as they are looking for high marks from the government regarding security.

      --
      A fool throws a stone into a well and a thousand sages can not remove it.
    3. Re:No easy fixes... by damiam · · Score: 1
      Debian signs their updates, right?

      Unfortunatly, no.

      --
      It's hard to be religious when certain people are never incinerated by bolts of lightning.
  20. No workaround my @$$ by red5 · · Score: 4, Informative

    There is a very simple workaround. Just add the following line to your /etc/hosts

    204.179.120.93 swquery.apple.com

    Now if somebody tries the DNS attack it won't work as we hardcoded swquery.apple.com -> 204.179.120.93 You will of course have to activate your /etc/hosts file but, I'm pretty sure that you people (/.ers) know how to do this already.

    --
    I know I'm going to hell, I'm just trying to get good seats.
    1. Re:No workaround my @$$ by jquirke · · Score: 2

      That's a nifty 'solution' but it doesn't prevent someone from spoofing the traffic from that particular IP address. So someone could pretend to be 204.179.120.93

    2. Re:No workaround my @$$ by batobin · · Score: 2

      I think the point was that it made things a lot harder. DNS servers are relatively easy to hack, compared to spoofing someone else's IP address.

      Obviously the workaround isn't perfect. What if apple changes the IP of their update server? What if they use akamai to host the updates, and the IP that was posted is actually some server halfway around the globe from you?

      It's not perfect, but give the man some credit for being creative, will ya? :)

    3. Re:No workaround my @$$ by Silas · · Score: 2
      There is a very simple workaround. Just add the following line to your /etc/hosts
      204.179.120.93 swquery.apple.com

      Oh, sure, and we're just supposed to trust that your DNS hasn't already been poisoned? :)

    4. Re:No workaround my @$$ by usr122122121 · · Score: 2, Informative
      Why not just do it in NetInfo?

      1) open it up /Applications/Utilities/NetInfo Manager
      2) click the lock to authenticate.
      3) use the browser to go to /machines/
      4) click the "Create New Directory" button.
      5) modify the new directory you just made to have these attributes:
      key:ip_address value:204.179.120.93
      key:name value:swquery.apple.com
      key:serves value:./local
      6) save the modified netinfo database. it will ask you if you "REALLY" want to do it. if you're sure, agree.

      --

      -braxton
    5. Re:No workaround my @$$ by red5 · · Score: 2

      Because I'm a unix guy damn it!.
      Take that newfangeled netinfo thingy and give my my flat files anyday. :)

      --
      I know I'm going to hell, I'm just trying to get good seats.
    6. Re:No workaround my @$$ by gr · · Score: 2

      As I posted on Bugtraq, no, that doesn't fix shit. Because I just arp flood your router, spoof the IP address, and you lose.

      Updates must be at least checksummed and really should also be cryptographically signed. Period.

      --
      Do you have a /. uid shorter than five digits? No? Then piss off.
  21. Yet another reason by noewun · · Score: 0, Redundant

    not to enable automatic updating.

    --
    I am a believer of momentum and curves.
  22. The NetInfo method by Slur · · Score: 4, Informative

    MacOS X doesn't use the hosts file except in single-user mode, but once you've changed the /etc/hosts file you can update the NetInfo database like so:

    sudo niload hosts / /etc/hosts

    --
    -- thinkyhead software and media
    1. Re:The NetInfo method by 2nd+Post! · · Score: 2

      Doesn't seem to work for me. There are two spaces between / and /etc/hosts as well?

    2. Re:The NetInfo method by red5 · · Score: 4, Informative

      Okay looks like I assumed wrong (you don't all know). You can activate your /etc/hosts file by setting /locations/lookupd/hosts/LookupOrder -> ( CacheAgent, FFAgent, NIAgent, YPAgent, DNSAgent, NILAgent ) in netinfo.

      Simply copy this file to lookupd.txt. Then type:
      niload -r /locations/lookupd / < lookupd.txt

      Yes, I "stole" all of this from this page. Except mine is modifyed to activate the /etc/hosts file also.

      --
      I know I'm going to hell, I'm just trying to get good seats.
    3. Re:The NetInfo method by foniksonik · · Score: 2

      Read the articles about netinfo if you don't KNOW what you are doing here. You could royally screw your system. AND for real, MAKE a BACKUP! of the database before you do anything.

      --
      A fool throws a stone into a well and a thousand sages can not remove it.
  23. The Other Major Operating System Corporation by avarame · · Score: 1

    Remind me why Microsoft's system ISN'T vulnerable to this?? If anything, it's more vulnerable, because a) people know about it and b) it's statistically certain there are exploitable holes in the update code.

    --
    Save time now so you can waste it later
    1. Re:The Other Major Operating System Corporation by Anonymous Coward · · Score: 0

      Because they use SSL and cryptographically signed packages (just like all linux vendors).

      Mistakes can happen to anybody. If Apple fixes this design mistake immediately there's no real problem, and they have become much better at it lately.

      But please... the _really_ embarrasing part is dozens of stupid users trying to "defend" a mistake either by not understanding what IP-spoofing can do, or by claiming that other systems could have the problem too.

      In this particular case both Microsoft and Linux happen to be better, but even if they weren't - is
      it suddenly quite OK to have bugs and holes as long
      as they are present elsewhere too?

      I actully happen to use a Mac, but do grow up and realize that it is just a tool like anything else.

  24. What's wrong with Netscape-Enterprise server? by 2nd+Post! · · Score: 2

    They could be running it with Web Objects on Solaris, couldn't they?

    Or what are you suggesting that I don't understand?

    1. Re:What's wrong with Netscape-Enterprise server? by batobin · · Score: 2

      I think what he's suggesting is that Apple should be hosting with their own hardware. If Microsoft gave their employees Macs, with OS X installed, with Internet Explorer, the same questions would be raised.

      In other words, possibly having just 1 piece of Apple software doesn't make it all OK. Hence, they're not practicing what they preach.

    2. Re:What's wrong with Netscape-Enterprise server? by phyxeld · · Score: 1

      I was merely sugesting that a company that sells hardware and software for running servers might use their own products for their own server. Yes, it could be running WebObjects on solaris. It should be running MacOS X Server though, and I bet it will be soon.

      --
      __
      Choose mnemonic identifiers. If you can't remember what mnemonic means, you've got a problem. - Larry Wall
    3. Re:What's wrong with Netscape-Enterprise server? by 2nd+Post! · · Score: 2

      Considering that they don't have the hardware to run such a server (yet), it's not unreasonable to be running on Solaris hardware at all.

    4. Re:What's wrong with Netscape-Enterprise server? by Hes+Nikke · · Score: 1

      most of the time they do pratice what they preach :)

      --
      Don't call me back. Give me a call back. Bye. So yeah. But bye our, well, but alright we are on a shirt this chill.
    5. Re:What's wrong with Netscape-Enterprise server? by piznut · · Score: 0

      Whats this? No good web clustering services available? Oh well..back in the niche box you go. Wake me up when apple becomes a viable alternative above the small business level.

    6. Re:What's wrong with Netscape-Enterprise server? by Refrag · · Score: 2

      Apple doesn't preach using Apple hardware for mission critical server operations.

      --
      I have a website. It's about Macs.
    7. Re:What's wrong with Netscape-Enterprise server? by batobin · · Score: 3, Interesting

      Are you serious? Doesn't Apple advertise that Xserve is the perfect server for mission critical purposes? You must be either kidding (which i hope is the case), or smoking crack, man.

      Why did Apple add hotswap drives, advanced monitoring tools, and 24/7 technical support? For shits and giggles? Why did they add REDUNDANT disk arrays? To impress the ladies? Why do they advertise this box to hardcore sys admins? Because they want sys admints to buy it. Do sys admins rely on boxes to handle mission critical operations? Yes. Is that not PREACHING?

      Why, yes, it is.

    8. Re:What's wrong with Netscape-Enterprise server? by Refrag · · Score: 2

      I don't see anything here indicating that they intended for the Xserve to be used for mission critical applications.

      --
      I have a website. It's about Macs.
    9. Re:What's wrong with Netscape-Enterprise server? by batobin · · Score: 1

      And I didn't see anything tattooed on Hitler's forehead identifying him as the devil, but does that change the facts?

      Refer yourself to my previous post to see the "circumstantial evidence" of Apple's intent. I'm sorry they didn't spell it out any easier for you.

  25. workaround != solution. by red5 · · Score: 2

    I never said it was a "'solution'" I said it was a workaround. If they could do all that they could easly spoof off Verisign and then HTTPS is fucked also. So whats your point?

    --
    I know I'm going to hell, I'm just trying to get good seats.
    1. Re:workaround != solution. by jquirke · · Score: 2

      My original post was taken the wrong way.

      It was not an attack on your idea, sir.

      I was merely pointing out to others who may have interpreted it as a solution and felt they were safe that this did not eliminate the vulnerability.

      --jquirke

    2. Re:workaround != solution. by ConsumedByTV · · Score: 2

      Actually you're mistaken.

      To spoof verisign and https it would require that you have a valid cert(yes it is possible to make them).To spoof a connection that used a false cert would alert the user to that fact. The fact of the matter is that apple swupdate doesnt even use SSL! So it doesn't matter if you can spoof SSL. This is why redhat up2date uses gpg, because if it is spoofed, they cant SIGN the packages! AND YOU KNOW YOU HAVE BEEN HACKED! Because you can't prevent the hack with the way the internet works! You can detect if the programmers who made the system are semi security minded.

      Apple is not that.

      --


      "Not my manner of thinking but the manner of thinking of others has been the source of my unhappiness." - M
    3. Re:workaround != solution. by red5 · · Score: 2

      To spoof verisign and https it would require that you have a valid cert(yes it is possible to make them).To spoof a connection that used a false cert would alert the user to that fact. The fact of the matter is that apple swupdate doesn't even use SSL! So it doesn't matter if you can spoof SSL.

      The story says that the vulnerable is because apple uses http and not https. My point was that if you can spoof IPs you cloud easly spoof both the https server IP and the signing authorities IP. Thus bypassing any https connection. Unless public keys for all the signing authorities are included with every https implementation.

      Anyhow it's a workaround. It workaround this exploit. Hopefully apple will update software update to use crypto signed packages and SSL connections. Till then I'm keeping the line in my /etc/hosts and checking every update first.

      --
      I know I'm going to hell, I'm just trying to get good seats.
    4. Re:workaround != solution. by red5 · · Score: 2

      I wasn't affeneded at all. Not quite sure what made you think that. Perhaps it's the '!' in the subject line.

      Wow, getting called "sir" I feel all giddy now. :)

      And yes you're right it wont be fully secure till they have cripto singned updates.

      --
      I know I'm going to hell, I'm just trying to get good seats.
    5. Re:workaround != solution. by Anonymous Coward · · Score: 0

      You are so fucking stupid.
      Did you read ANYTHING that ANYONE said?!?!?!?!

      You don't understand how certs work, you can spoof the ip but you can't spoof how the CERT works! It wouldn't be valid. Idiot!

      Also, check for a new update, when you get hacked it will because you updated and the person was waiting for a real update to mask it! How do you know the package is real? You DON'T! BECAUSE IT ISNT SIGNED!

      IDIOT!
      FUCK YOU!
      IDIOT!

  26. Re:Wouldn't work on me, or most net-savvy Mac user by Alex+Thorpe · · Score: 2, Insightful

    Troll? No, just disagreeing that this minor security flaw is a huge threat to the individual home user. Even if I did install this theoretical trojan horse(a big if), it's not going to do a great deal of damage without Root access, which I've not enabled, and my credit card numbers and SSN's are nowhere to be found on my hard drive. Unlike you, I'm also posting with my real name. I suppose a pissed hacker might use that info to try and DoS me, but that's all he could do to me. It'd give me more time for Warcraft III, once my copy arrives. ;-)

    --
    "Common Sense Ain't" -Unknown
  27. Re: Apple Servers by Saint+Fnordius · · Score: 2

    Well, according to this chart, Apple was hosting their websites on Solaris machines until late 2000. It looks like instead of just trashing the machines, Apple shuffled them off into the back rooms to handle lesser duties like SU and such.

    I think this is a good idea, as 1) the machines are still good, and 2) it saves resources by using them as long as possible. Apple's server forays are still relatively new (and against the spirit of building personal computers), so it's natural that they'd had somebody else's boxen.

  28. Re:Looks bad. How rapid a response? by feldsteins · · Score: 2

    Actually, I think Apple could use some sort of authentication or digitally sign their updates. That seems to be the general consensus.

    --
    You like your Macintosh better than me, don't you Dave? Dave? Can you hear me Dave?
  29. Bug Fix by cappadocius · · Score: 2, Funny
    Luckily there's a bug fix! Just go to Software Update right now to get it.

    Oh, but only if you're on my campus network.

    --

    omnia tua castra sunt nobis

  30. 1 possible security exploit.... by gsfprez · · Score: 2

    and one serious screw up of a installation app....is that the best you can muster after a year?

    Keep going, Apple. Maybe someday you'll be taken seriously as a operating system company and have thousands.

    Or at LEAST ship with one hole that you know about with Jagwire... that would probably jump start your reputation.

    --
    guns kill people like spoons make Rosie O'Donnell fat.
  31. Signs by Anonymous Coward · · Score: 0

    CHORUS:
    Signs Signs Everywhere there's signs
    Blocking up the scenery Breaking up my mind
    Do this Don't do that Can't you read the sign?
    And the sign says "Anybody caught trespassing will be shot on sight"...

  32. Please forgive me but I have a question... by mtec · · Score: 1

    I'm not an expert on these things...
    (I know - then get off'a /. !!! )

    ...but could someone tell me why in an otherwise pretty secure and tight implementation of the rollout of OSX over the past 1+ year would Apple overlook something so seemingly obvious?

    Any theories (besides the one I read elsewhere that "steve was fresh from graduation from assclown school" -Techfocus)?

    And what's an assclown? I can't recall seeing one.

    --
    Cake or Death? Cake Please!
    1. Re:Please forgive me but I have a question... by thoughtcrime · · Score: 1

      an ass-clown is the goatse guy coated in greasepaint.

      come on, why do you think they call them the ringling brothers?

      --

      ____ _______
      Duty now for the future!
  33. nevermind by mtec · · Score: 1

    the def

    I swear I didn't know. I guess I was a... dammit!

    --
    Cake or Death? Cake Please!
  34. Apple Has Released a Fix by Johnny+Mnemonic · · Score: 2


    The vulnerability discussed above has now been addressed by an from Apple. I would say pretty fast work--the exploit page on /. is still available for posts when the patch is released. Also, as other posters have mentioned, a number of updaters from other vendors still don't sign their updates.

    It's clear that Apple has a security focus now--although they may not always get it right out of the box, they have responded quickly to the last 3 major holes, patching the system in days, not weeks.

    --

    --
    $tar -xvf .sig.tar
  35. Re:Looks bad. How rapid a response? by feldsteins · · Score: 2

    The key will be to watch how quckly (or how slowly!) they respond with an appropriate fix. If it takes two weeks, that's bad. -- me, 5 days ago

    It's been five days and it seems the fix has been issued. I wonder if there will be a followup story where we can all go "gee, Apple handled that fairly well"?

    --
    You like your Macintosh better than me, don't you Dave? Dave? Can you hear me Dave?
  36. If you're going to be insulting... by greygent · · Score: 2

    you might as well post a fix that is actually LESS of a kludge than who you're insulting.

  37. Re:Wouldn't work on me, or most net-savvy Mac user by binarybits · · Score: 2

    Um, software update does effectively run with root access. How do you think it patches system files? So you're effectively giving root access to anyone who exploits it.

    Now is it *likely* that anyone would do this to you specifically? Not really. But this is a terrible way to think about computer security. The fact is you don't know what creative ways someone might come up with to exploit this hole. The fact that you can't think of an exploit that will work against you doesn't mean there isn't one-- if the software is exploitable, all that's needed is a bit of social engineering to find a way to make use of it in the real world.

    The "who would hack little old me" argument might have worked 5 years ago when there were relatively few people on the 'net and most of them were responsible adults. But these days the 'net is swarming with script kiddies, and if a vulnerability appears it's likely to be exploited quickly and in parallel.

    I'll grant that in this particular case, it seems unlikely that there's any way this could be exploited without access to your local network, which presumably is secure. But it's never a good idea to rely on such assumptions-- there are many examples where minor holes were discovered, were poo-pooed by the authorities, and were later discovered to be major holes because of a clever exploit no one thought of. That could happen in this case as well-- someone might figure out a way to trick your Mac into connecting to someone other than Apple.