Live data from Hacker News

OS X sudoers exploit found in the wild

blog.malwarebytes.org

111–120 of 193 posts

Re: OS X sudoers exploit found in the wild

#111

Earlier quoted context omitted.

> Do Apple employees not drive cars on roads (paid for by the taxpayer)? If a mafia built roads, would that make its extortion alright? > Of course Apple avoid taxes - anyone who can do so without fear of getting significantly punished does Exactly. Think about that for a while there. You're basically saying that no one would pay taxes without being forced to . Would anyone pay a mafia protection money without being…

Are you saying the government is extorting in the name of taxes? Taxes are important because some things ( like laying roads ) cannot be selectively implemented. You can't just ask some to pay for the road and the rest not to use it.

I'm saying taxation is extortion, and just as immoral as when a mafia does it.

You're trying to justify extortion with things that are built with extorted money, but could be built without extorting people too.

> You can't just ask some to pay for the road and the rest not to use it.

You could just build a road and then ask people to pay for using it, much like you can build an iPhone and ask people to pay for one if they want it.

Re: OS X sudoers exploit found in the wild

#112
post #96

I was wondering why Download Shuttle has so many more users than my app (Fat Pipe). Seems like they are playing with the world of adware marketing, I hope they aren't doing weird things with the OS as well :/.

Our app, Download Shuttle, has nothing whatsoever to do with this malware. We have no idea why the malware creator decided to open up Download Shuttle in the Mac App Store. We can only speculate that it was done in order to disguise what the malware is really doing (installing adware such as Genieo). Download Shuttle is a free app and makes up an insignificant part of our overall Mac app portfolio. FIPLAB is one of t…

Sorry about that, glad to hear that you guys are not involved.

From face value it does look very odd. I apologize in for assuming you guys were involved.

Re: OS X sudoers exploit found in the wild

#113

> a company that takes part in the usual tax and labor law evasion tactics Would you prefer to have most of your income forcefully taken away, or would you prefer as little as possible taken away? Tax evasion amounts to trying to keep your own property. If someone tries to avoid paying protection money to a mafia, is he a criminal, or immoral?

Apple is a company, i.e., a legal fiction. It is only right that it pays taxes to the entities that allow it to exist at all.

Re: OS X sudoers exploit found in the wild

#114
post #31

Earlier quoted context omitted.

Could you explain the dual-use export issue. I read a little about it here [1], but I don't understand. So, if Esser was to contact Apple and provide them with the vulnerability info for free, but with out first registering it as a dual-use export, he could get in trouble? Even if he didn't receive any compensation from Apple? Is that the case? [1] https://www.justsecurity.org/5703/export-control-arrangement...

He could basically be sent to jail for weapon smuggling, receiving any compensation is irrelevant.

Even if Apple is the only place that he can reasonably contact to have the vulnerability fixed, instead of exploited? This law is weird.

Re: OS X sudoers exploit found in the wild

#115
post #84

Earlier quoted context omitted.

> I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. One party makes billions off their users, and will most likely continue their practice of not supporting 3 year old systems even if they are still in wide use for the next time. This should pretty much clear up who is worse. > Esser has his reasons - "Sh…

> helping out a company that takes part in the usual tax and labor law evasion tactics Irrelevant. The moral question being raised here is about potentially hurting Apple users via irresponsible behaviour, not about helping Apple itself. Just because Apple does it (by sitting on the problem) does not make it right for other people to put the public at risk as well. Both parties can be in the wrong at the same time, t…

> The moral question being raised here is about potentially hurting Apple users via irresponsible behaviour

The logical next step is that Apple have been intermittently flippant about security (of late they have improved but their approach is still wholesale unacceptable). Why do users knowingly use an OS with this track record?

> anonymously informing the controlling party

With government surveillance could he have had any guarantee that his disclosure wouldn't have been snooped?

Either way this discussion can be argued ad infinitum. The real villain here is the European Commission for such a brain-dead policy.

Re: OS X sudoers exploit found in the wild

#116

Earlier quoted context omitted.

That 'fix' is going to break a lot of other stuff.

> That 'fix' is going to break a lot of other stuff. True, but a short-term replacement along the lines of: #!/bin/sh unset DYLD_PRINT_TO_FILE # Cleanse the sudo arguments here... # Check MD5 of /etc/sudoers against known good # value here... exec /usr/bin/the-renamed-sudo "$@" Would do the trick when put in the place of /usr/bin/sudo EDIT: Added the comments regarding sanity checks.

I'm not sure where you're going with this.

That `unset` is useless since they don't call sudo to initiate the exploit. The setuid/setgid bits on the newgrp binary are to blame here (combined with the env variable). They could just overwrite your new /usr/bin/sudo file if they wanted to. Hell, they could brick your entire system just out of spite. No sudo necessary.

Re: OS X sudoers exploit found in the wild

#117

Earlier quoted context omitted.

Are you saying the government is extorting in the name of taxes? Taxes are important because some things ( like laying roads ) cannot be selectively implemented. You can't just ask some to pay for the road and the rest not to use it.

I'm saying taxation is extortion, and just as immoral as when a mafia does it. You're trying to justify extortion with things that are built with extorted money, but could be built without extorting people too. > You can't just ask some to pay for the road and the rest not to use it. You could just build a road and then ask people to pay for using it, much like you can build an iPhone and ask people to pay for one if…

> I'm saying taxation is extortion, and just as immoral as when a mafia does it.

This is a ridiculous comment. I realise the social contract has broken down somewhat in recent years but if you can't see the difference between Mafia extortion and government taxation there's something wrong. Here's just one difference: we can vote for the government.

Re: OS X sudoers exploit found in the wild

#118
post #55

I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. Esser has his reasons - "Short reminder: Europeans are not allowed to disclose vulns privately to a foreign company like Apple without registering dual-use export"[1] - but it's hard to believe he couldn't have told them anonymously. Disclosures make caree…

> Stefan Esser for flinging the vulnerability into the breeze for anyone to catch Then let me help you with this one. The former is responsibility of the worlds most profit corporation with tens of thousands of employees, and the latter is under the responsibility of a random guy on the internet.

Both are in the wrong. The behaviour of neither is a valid defence for the behaviour of the other.

Apple are irresponsible for not addressing the issue in good time (they have known about it for long enough).

This fellow is irresponsible for not following decent "responsible disclosure" procedure. He released information of a serious exploitable problem without first making any attempt to inform the people who could do something about it or otherwise checking to see if they were already aware.

Relative size, income, employment/employee status, and so forth, are all irrelevant here.

Re: OS X sudoers exploit found in the wild

#119

Earlier quoted context omitted.

Are you saying the government is extorting in the name of taxes? Taxes are important because some things ( like laying roads ) cannot be selectively implemented. You can't just ask some to pay for the road and the rest not to use it.

I'm saying taxation is extortion, and just as immoral as when a mafia does it. You're trying to justify extortion with things that are built with extorted money, but could be built without extorting people too. > You can't just ask some to pay for the road and the rest not to use it. You could just build a road and then ask people to pay for using it, much like you can build an iPhone and ask people to pay for one if…

And the police? Fire departments? Social security? Town planning/maintenance/social policy/etc etc etc.

Essentially the only system without tax is anarchy, and if you are bona fide advocating that - well I wish you the best of luck in your brave new world.

Re: OS X sudoers exploit found in the wild

#120
post #93

Earlier quoted context omitted.

Do Apple employees not drive cars on roads (paid for by the taxpayer)? Do they rely on no technology whatsoever which did not rely on the taxpayer to exist (for example, er, the internet)? If they want to defend some other part of their property under the law, are they paying their own judges? Of course Apple avoid taxes - anyone who can do so without fear of getting significantly punished does. But the idea that thi…

> Do Apple employees not drive cars on roads (paid for by the taxpayer)? If a mafia built roads, would that make its extortion alright? > Of course Apple avoid taxes - anyone who can do so without fear of getting significantly punished does Exactly. Think about that for a while there. You're basically saying that no one would pay taxes without being forced to . Would anyone pay a mafia protection money without being…

    If a mafia built roads, would that make its extortion alright?
Yes
Post reply on HN