OS X sudoers exploit found in the wild
81–90 of 193 posts
Re: OS X sudoers exploit found in the wild
#82Earlier quoted context omitted.
"Public wifi", not "your own connection". You have two options for who you decide to trust: 1) A VPN company, who you've had the opportunity to research, who's primary business and reputation is based on handling your traffic. 2) Each and every WAP you connect to, in many cases with no real means to verify it's actually e.g. the official WAP of the hotel you're staying at, for something that likely costs the owners m…
I think you put far too much trust in one of thousands of clone VPN services. There's no reputation to taint, there's stock standard scripts running on commodity VPS boxes they rented from somewhere else. I would be shocked if at least some of the most commonly used ones weren't run by people looking to sniff credentials. You're paying to pipe all of your sensitive information through some random persons box, which i…
Re: OS X sudoers exploit found in the wild
#83I'm seriously shocked. This is ridiculous. This looks like possibly the easiest root exploit ever discovered on a desktop OS (a one-liner in bash). Why in the world would they allow an env variable to write to a file in a setuid'd binary? I'm suddenly very glad I don't use my macbook as my main machine, but I guess I'll remove the set{u,g}id bits on newgrp for now. Don't know if that will break things, but it's bette…
It's a good contender, but in 10.2, you could hold down a key in the screen saver lock screen and overflow a buffer, crashing the screensaver and logging you in. Seriously. Not a root exploit but embarrassing. http://www.cvedetails.com/cve/CVE-2003-0518/ btw, discoverer claims to have written a kext fixing the hole http://www.sektioneins.de/blog/15-07-07-dyld_print_to_file_l...
Re: OS X sudoers exploit found in the wild
#84I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. Esser has his reasons - "Short reminder: Europeans are not allowed to disclose vulns privately to a foreign company like Apple without registering dual-use export"[1] - but it's hard to believe he couldn't have told them anonymously. Disclosures make caree…
One party makes billions off their users, and will most likely continue their practice of not supporting 3 year old systems even if they are still in wide use for the next time. This should pretty much clear up who is worse.
> Esser has his reasons - "Short reminder: Europeans are not allowed to disclose vulns privately to a foreign company like Apple without registering dual-use export"[1] - but it's hard to believe he couldn't have told them anonymously.
You're suggesting that he should feel ethically obliged to break the law for helping out a company that takes part in the usual tax and labor law evasion tactics (not to mention customer protection evasion in the US)?
Re: OS X sudoers exploit found in the wild
#85I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?
Re: OS X sudoers exploit found in the wild
#86Re: OS X sudoers exploit found in the wild
#87I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. Esser has his reasons - "Short reminder: Europeans are not allowed to disclose vulns privately to a foreign company like Apple without registering dual-use export"[1] - but it's hard to believe he couldn't have told them anonymously. Disclosures make caree…
> I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. One party makes billions off their users, and will most likely continue their practice of not supporting 3 year old systems even if they are still in wide use for the next time. This should pretty much clear up who is worse. > Esser has his reasons - "Sh…
It has nothing to do with what's good for the company. That's not what responsible disclosure is about.
Re: OS X sudoers exploit found in the wild
#88Would you prefer to have most of your income forcefully taken away, or would you prefer as little as possible taken away?
Tax evasion amounts to trying to keep your own property. If someone tries to avoid paying protection money to a mafia, is he a criminal, or immoral?
Re: OS X sudoers exploit found in the wild
#89Earlier quoted context omitted.
You forget your key when leaving for work, and don't lock your door. It was accidental, you have a lot on your plate. Your neighbour sees you didn't lock it, and tweets out, "Hey Mike at 321 Greyhat Bvld, you didn't lock your front door". He didn't send that to you as a text, he tweeted it. You come home, and you've been cleaned out. I'm sure we can all agree, you should have locked your door. Why be mad at your neig…
I'm sure we can all agree we can make up shit that can happen till the cows come home. I'm not going to act as if someone robbed me until they do. Hold Esser responsible if someone hacks a large number of people because of what he did. Otherwise, stop living a thousands lives.
Esser put people at risk. Whether or not anything happens is irrelevant. He put them at risk and we need to recognize that is the cost of full disclosure.
If you're fine with that, cool, but don't pretend he didn't do anything.