Exploit Code Released for Mac OS X

By the Betanews Staff | Published June 30, 2006, 12:31 PM

Security firms warned users of Apple's Mac OS X earlier this week about the existence of an exploit that could result in the execution of arbitrary code. The news has made upgrading to version 10.4.7 even more important, as the update fixes the issue. The vulnerability lies in an operating system file called "launchd."

The proof-of-concept code was created by Digital Munition security researcher Kevin Finisterre. He has written other exploits in the past, including another for a Bluetooth flaw within Mac OS X. Finisterre says he does his work out of a desire to show those who believe the operating system is completely safe that there are flaws that need to be addressed.

Comments

View comments by with a score of at least

http://news.bbc.co.uk/2/hi/technology/5150508.stm
-------------------------------------------------
Security threats to PCs with Microsoft Windows have increased so much that computer users should consider using a Mac, says a leading security firm.

Sophos security said that the 10 most commonly found pieces of malicious software all targeted Windows machines.

In contrast, it said, none of the "malware" were capable of infecting the Mac OS X operating system.

http://news.bbc.co.uk/2/hi/technology/5150508.stm

Score: 0

|

The problem is that FRo1 comment is not correct. Starting last year when Apple achieved a whopping 4% of the market, they were hit with an onslaught of exploits. They had to issue vetween 20-30 security patches for exploits that were always there but not used. Things got so bad that Apple went to the same set-up as MS- once a month issue of patches. Heck, even their shinny new operating system has been hit with exploits so big you could drive a Mac truck through. Just shows that, to hackers, it doesn't matter what OS or Browser you use, just market share.

Score: 0

|

What i think that all of you fail to see is that Apple has never once said that it is totally immune to any virus, whether it is written or to be written. What they claim is that the Mac platform has fewer virus threats, and most of them are macros form Microsoft products, than its competitor Windows.

Score: 0

|

yup~~ no OS in the world is the most secure one. That includes Linux as well.

There will always be bugs for everything as long as it's made by us human.

Score: 0

|

The most secure OS is the least used OS. I'm sure you can find a secure Amiga or Atari 800 XL somwhere. Doesn't someone still use BeOS?

Score: 0

|

"The most secure OS is the least used OS."

That explains why Mac OS is so secure:-) LOL

Score: 0

|

I was just about to head down to the Apple store to buy myself a nice shiny overpriced iMac when I read this disturbing article. I can 't believe that Macs are Vulnerable to exploits as well. I was lead to believe that Macs were impervious to any sort of attacks.

Lies... lies… all lies…damn you, damn you all to hell. (must add some dramatic music to get the full effect) LMAO

Sorry, I just couldn’t resist. LOL

Score: 0

|

this all fuss is cu'z of intel processors !

Score: 0

|

Exactly my idea. Since Mac has Intel inside, OSX has gone downhill. It has been terrible, had to reinstall OSX twice because of a virus infection, it's very unstable too. I feel very unsecure now.

Score: 0

|

You feel unsecure???
Why is that?
Exactly what does a virus infection have to do with Intel CPU’s or any other CPU’s for that matter?

Score: 0

|

Well there was that buffer overflow problem... Blaster, anyone? At least AMD CPUs built-in a protection against those kinds of viruses. Did Intel do it yet?

Score: 0

|

Blaster was about 4 years ago, since 2004 Intel has added NX to their processors. As far as I know there are no buffer overflow problems on Linux or Windows PC’s. If there is a buffer overflow issue with Macs it could be that the error is with Mac OS its self. Of course the only way a virus can infect a computer is if the user is careless.

Score: 0

|

funny how everyone is making fun of Mac enthusiasts, yet I see no 'other' side to the name calling? Could you be inching closer to carpal tunnel to make comments that will perhaps not have any significant meaning? I find some Mac users annoying, but i'm sensing they're extinct at Betanews...Or at least gathering into their pack to begin a flame war...I dunno.

It seems like all that's in the news lately are flaws in software products. It's an easy way for companies like betanews,cnet,wired...whatever to keep stories flowing, but after awhile it just gets ollllld. I kinda wish Google would just release an OS so there can actually be something to talk about.

Score: 0

|

How much do you want to bet that some people will blame this on the switch to Intel processors

Score: 0

|

dont any of you realize this was probably a planned exploit to force Mac users into the upgrade ???
OS X sucks in many ways just as Windows does ....
just because they havent been discovered doesnt mean they're not there ...

Score: 0

|

tinfoil....hat...too.....tight....must....get it....off!

Score: 0

|

lmao...careful..you may want to leave that on for Apple could be scanning our brain waves in an effort to see what they can add to Mac OS to convert the Windows users.

Score: 0

|

If Apple has released updates which solve this issue, then what's the legitimate reason to then release exploit code?

Score: 0

|

The code will be released. These firms typically hold off and give the company's time to create a patch.

Anyone who says that an OS is immume to attacks is an idiot. I've said it before, software is made by humans and it's impossible to determine in advance what creative attack vector another human will attempt. We can try to patch as much up front, but something will eventually be discovered.

Score: 0

|

shh.... don't tell the truth. Mac lover don't want to hear it, they like to live in their perfect little world.

Score: 0

|

Anyone who says that an OS is immume to attacks is an idiot.

Damn.

You nailed it. Why does no-one understand this?

Score: 0

|

Ohs Nos! But Billy Bob I thought that I was safe from exploits if I bought a Mac!

Score: 0

|

even though i hate macs i have to say that you're an idiot.

Score: 0

|

even though I hate people like you I have to say that YOU'RE an idiot

Score: 0

|

What (precisely) is so wrong with macs that you feel you must hate them? I use Windows, Linux, and mac on a daily basis and while they all have their strengths and weaknesses, the mac (and OS X) is a pretty good environment.

Score: 0

|

please pull the feces soaked tighty whities from your a** and lighten up. thank you come again.

Score: 0

|

Probably for the same reason I do. No games.

Sorry, but gamers hate macs. It's a simple truth.

That said, for graphic design and basic home use, they exceed windows by a very wide margin.

Score: 0

|

PWN3D.

Score: 0

|

jeffk was seven years ago and this is not a CS forum ... stop being a douche.

Score: 0

|

Just kill Billy Bob! He lied to ye!

Score: 0

|

EC's Kroes to US senators: Mind your own business on Oracle + Sun

If the AP is accurate, the EU's antitrust chief just told the United States Senate that any merger that takes place in the world is more her affair than theirs.

What does AT&T's 'Mark the Spot' app say about service quality?

That's a question for Betanews readers to answer in comments to this post.

Windows fix for TLS security bug still forthcoming, won't be Tuesday

Anyone looking for a fix for last month's discovery of a potentially serious security hole in TLS and SSL may have to wait until everyone is ready to act together.

Google rolls out real-time search, Near Me Now, extended personalization

Over time, searches from PCs and mobile phones will grow even "more personalized." But what about user privacy and search results that give you "the truth"?

Betanews Podcast: Rupert Murdoch and the buying stuff online problem

We'll have a more difficult time paying for online news if the underlying protocol for online payment has a big gaping hole in it.

Not the first, not the last, technology predictions for 2010

Carmi Levy | Wide Angle Zoom: The real truth is probably that what went around in 2009, will come around to haunt us next year.

Google Goggles: Hands on with the Shazam of the Real World

Google today unveiled Goggles, its visual search lab for Android devices that identifies objects by sight.

Microsoft: Windows 7 Family Pack wasn't 'pulled,' it just sold out

If you hurry, you may still be able to find the last Family Pack upgrade editions hanging around retail store shelves, but probably not so much online.

Clever iPhone game returns after being bumped over a name dispute

The game's simple concept and multitude of platforms and puzzles manage to pull off a retro, 8-bit style that's reminiscent of an old Atari game given a modern makeover.

Intel's marriage of CPU and GPU not ready for prime time

Although there will be an Intel component this month that can compute and plot in parallel, Betanews was told today, it won't be based on Project "Larrabee."

An alternative to Research in Motion's enterprise e-mail? There's an app for that

Good Technology today released an iPhone app compatible with its enterprise e-mail solution.