Live data from Hacker News

OS X sudoers exploit found in the wild

blog.malwarebytes.org

1–10 of 193 posts

Re: OS X sudoers exploit found in the wild

#3
I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions.

What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

Re: OS X sudoers exploit found in the wild

#4
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

On public wifi, I use https://www.getcloak.com

I also uninstalled Flash.

Re: OS X sudoers exploit found in the wild

#5
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

As a general rule, I don't use public wifi and council people to use VPN if they must. No flash, disable java in the browser, prefer chrome to safari, AdBlock and NoScript if you don't need JS.

Re: OS X sudoers exploit found in the wild

#6
Isn't this the time when Mac App Store supposed to shine? When they found something that's dodgy and linked to a company that has apps on App Store, can't they just turn on the kill switch? That way the malware won't have anywhere to direct the users to.

Re: OS X sudoers exploit found in the wild

#7
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

Little Snitch (https://www.obdev.at/products/littlesnitch/index.html) is excellent.

Re: OS X sudoers exploit found in the wild

#9
post #7
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

Little Snitch ( https://www.obdev.at/products/littlesnitch/index.html ) is excellent.

So excellent that some malware deletes itself if Little Snitch is even installed (https://www.f-secure.com/v-descs/trojan-downloader_osx_flash...). However, it's worth noting "DYLD_PRINT_TO_FILE" is a root exploit, which may circumvent or disable Little Snitch entirely if used by APT; Little Snitch may not see all network activity. In fact, a root exploit allows one to write malware completely hidden from userland altogether (lsof, ps, tcpdump, etc.) (https://github.com/hackedteam/driver-macos). It is truly scary how vulnerable OS X is at the moment.

Re: OS X sudoers exploit found in the wild

#10
post #7
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

Little Snitch ( https://www.obdev.at/products/littlesnitch/index.html ) is excellent.

As a Little Snitch user, I'm inclined to agree, but I find that I sometimes end up in a state of "WTF wants to use the network now?!" saturation.

My solution for that is to deny anything I don't recognize, and create rules for things I see more than twice, but if you're conditioned to click "OK" on everything you see, Little Snitch isn't going to to much for you...

Post reply on HN