Live data from Hacker News

OS X sudoers exploit found in the wild

blog.malwarebytes.org

131–140 of 193 posts

Re: OS X sudoers exploit found in the wild

#131
post #72

For anyone looking for the patch: https://github.com/sektioneins/SUIDGuard

Is there a test to determine if the patch is successful? Edit: as noted in Esser's blog [1]: $ EDITOR=/usr/bin/true DYLD_PRINT_TO_FILE=/this_system_is_vulnerable crontab -e I found this test failed in both a patched (10.10.4) and un-patched system (10.10.1) so not sure what these results mean. [1] https://www.sektioneins.de/en/blog/15-07-07-dyld_print_to_fi...

Did you check the root directory for a file named "this_system_is_vulnerable"? I just tested this on a mid-2015 MBP running 10.10.4 and found that file in the root directory. :(

Re: OS X sudoers exploit found in the wild

#132
post #7
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

Little Snitch ( https://www.obdev.at/products/littlesnitch/index.html ) is excellent.

Does anyone know of anything like Little Snitch or ZoneAlarm for Linux? I miss the program-level firewall capabilities of these programs when I'm on Linux.

Re: OS X sudoers exploit found in the wild

#133
post #122

Earlier quoted context omitted.

Both are in the wrong. The behaviour of neither is a valid defence for the behaviour of the other. Apple are irresponsible for not addressing the issue in good time (they have known about it for long enough). This fellow is irresponsible for not following decent "responsible disclosure" procedure. He released information of a serious exploitable problem without first making any attempt to inform the people who could…

You can pin responsibility onto a huge corporation. They can be liable for it. But you cannot control the behavior of random people on the internet without seriously impinging upon the general freedom of people everywhere. So the question of liability and responsibility is irrelevant if placed upon a random individual (unless you want a police state). It's best to hold the huge corporation liable.

>But you cannot control the behavior of random people on the internet without seriously impinging upon the general freedom of people everywhere.

This isn't true at all. Shaming people for unethical or unprofessional actions which they make publicly is quite effective in altering behavior and doesn't require a police state.

Re: OS X sudoers exploit found in the wild

#134

Earlier quoted context omitted.

> I'm saying taxation is extortion, and just as immoral as when a mafia does it. This is a ridiculous comment. I realise the social contract has broken down somewhat in recent years but if you can't see the difference between Mafia extortion and government taxation there's something wrong. Here's just one difference: we can vote for the government.

> Here's just one difference: we can vote for the government. So what? Go ahead and tell me how and why that matters with regard to taxation itself. Again, if a mafia let you vote for the new mafia boss, would that make extortion alright? Would it be good to be bossed around by a mafia boss you voted for? Would getting elected make it alright for him to extort you? You do realize they're still taking your money by fo…

[deleted]

Re: OS X sudoers exploit found in the wild

#135

Earlier quoted context omitted.

> I'm saying taxation is extortion, and just as immoral as when a mafia does it. This is a ridiculous comment. I realise the social contract has broken down somewhat in recent years but if you can't see the difference between Mafia extortion and government taxation there's something wrong. Here's just one difference: we can vote for the government.

> Here's just one difference: we can vote for the government. So what? Go ahead and tell me how and why that matters with regard to taxation itself. Again, if a mafia let you vote for the new mafia boss, would that make extortion alright? Would it be good to be bossed around by a mafia boss you voted for? Would getting elected make it alright for him to extort you? You do realize they're still taking your money by fo…

How do you intend to have money without a central bank? Should we all swap gold bars? What if I have a different view of the value of gold/bitcoin?

Also, I'll play along if that's what you want.

> You could just build a road and then ask people to pay for using it

1. I'm going to use your road and not pay. What are you going to do about it?

2. I don't believe you have rights to the land the road is on. How do you prove you have that right?

3. I'm going to build a circular road around a village, then charge $1 trillion for anyone to cross it. Should they starve to death rather then disobey me?

4. I've just shot your best friend in the street because I didn't like the colour of their hair? What are your options?

Please feel free to explain how, in the absence of taxation or joint societal constructs like a government, you're in a good place here?

Re: OS X sudoers exploit found in the wild

#136

Earlier quoted context omitted.

> The moral question being raised here is about potentially hurting Apple users via irresponsible behaviour The logical next step is that Apple have been intermittently flippant about security (of late they have improved but their approach is still wholesale unacceptable). Why do users knowingly use an OS with this track record? > anonymously informing the controlling party With government surveillance could he have…

> The logical next step is that Apple have been intermittently flippant about security (of late they have improved but their approach is still wholesale unacceptable). Why do users knowingly use an OS with this track record? Perhaps because ever since 2001 there are 5-6 new stories like this with huge scaremongering headlines and "sky is falling" implications, and then NOTHING absolutely happens, at worse a tiny mini…

> "sky is falling" implications, and then NOTHING absolutely happens

Sure, just brush off a sudo vulnerability.

> fight viruses off of Windows boxes

Virus != vulnerability.

Furthermore, while a rootkit is still a virus it's a long-shot from the relatively benign things running around on Windows machines (not that I mentioned Windows at first, but there ya' go - were on to that now). Just to avoid a Windows shitstorm, the same thing could be said of BSD. I am absolutely certain that there is at least one virus for the platform; however, the damage it could possibly do is seriously mitigated by the security of the platform.

"Viruses" (used as a distinct term to "rootkits") can at worst log a few keys up until your next virus scan. After that, poof! They're gone.

A "rootkit" (which requires a sudo/UAC vulnerability) can also at worst log a few keys or something. When you do your virus scan you're going to find nothing. It's going to sit on your machine until kingdom come because the virus is more privileged than you.

Security is like a backup. You only care about it when you have the random bad experience of actually needing it. I'm sure there are a bunch of Windows users who lament turning off UAC now that their files are all encrypted by ransomware. It has nothing to do with "market share" and has everything to do with risk: "UAC is such a stupid feature."

I could leave my keys in my car ignition every night of my life. No matter how much "market share" that car brand has all it takes is the random misfortune of someone on the street noticing that I do that.

Just keep in mind that it was you that bought up all these tangential topics.

Re: OS X sudoers exploit found in the wild

#137

Earlier quoted context omitted.

> The moral question being raised here is about potentially hurting Apple users via irresponsible behaviour The logical next step is that Apple have been intermittently flippant about security (of late they have improved but their approach is still wholesale unacceptable). Why do users knowingly use an OS with this track record? > anonymously informing the controlling party With government surveillance could he have…

> Why do users knowingly use an OS with this track record? Knowingly might be a stretch there. Many don't know any better either through lack of education on such matters or deliberate ignorance. > The real villain here is the European Commission for such a brain-dead policy. I'd argue that this means there are three villains, rather than the bad law being the one and only problem!

> I'd argue that this means there are three villains

Good point. Specifically regarding Apple and EU: something really needs to change.

Re: OS X sudoers exploit found in the wild

#138
post #60

Earlier quoted context omitted.

They are?!

So I've heard; I haven't confirmed this for myself.

I have to try this if I remember! That'd be very interesting. The console obviously has many legitimate uses. Why wouldn't I try it out if I were thinking about buying a mac?

Re: OS X sudoers exploit found in the wild

#139
post #72

Earlier quoted context omitted.

Is there a test to determine if the patch is successful? Edit: as noted in Esser's blog [1]: $ EDITOR=/usr/bin/true DYLD_PRINT_TO_FILE=/this_system_is_vulnerable crontab -e I found this test failed in both a patched (10.10.4) and un-patched system (10.10.1) so not sure what these results mean. [1] https://www.sektioneins.de/en/blog/15-07-07-dyld_print_to_fi...

Did you check the root directory for a file named "this_system_is_vulnerable"? I just tested this on a mid-2015 MBP running 10.10.4 and found that file in the root directory. :(

Before or after the patch?

Re: OS X sudoers exploit found in the wild

#140
post #72

For anyone looking for the patch: https://github.com/sektioneins/SUIDGuard

Is there a test to determine if the patch is successful? Edit: as noted in Esser's blog [1]: $ EDITOR=/usr/bin/true DYLD_PRINT_TO_FILE=/this_system_is_vulnerable crontab -e I found this test failed in both a patched (10.10.4) and un-patched system (10.10.1) so not sure what these results mean. [1] https://www.sektioneins.de/en/blog/15-07-07-dyld_print_to_fi...

You ran the GitHub patch and it still failed?
Post reply on HN