Live data from Hacker News

OS X sudoers exploit found in the wild

blog.malwarebytes.org

181–190 of 193 posts

Re: OS X sudoers exploit found in the wild

#181

Earlier quoted context omitted.

Sorry for not making this more clear. Create a shell script with the exploit, then remove the .sh extension. You can edit the icon to make it appear as any application and when double-clicked it will open and run in Terminal.app.

Ah, thanks for clarifying. I suppose it wouldn't have execute permissions if downloaded from a browser, but it could if copied with Finder from a network share (or directly accessed, of course), so that sounds like a potential vector.

It is a lot easier than you may think. Here is a simple demonstration: https://vid.me/gGQY

Re: OS X sudoers exploit found in the wild

#182

> a company that takes part in the usual tax and labor law evasion tactics Would you prefer to have most of your income forcefully taken away, or would you prefer as little as possible taken away? Tax evasion amounts to trying to keep your own property. If someone tries to avoid paying protection money to a mafia, is he a criminal, or immoral?

Please stop taking HN threads on ideological wild-goose flame chases.

Detached from https://news.ycombinator.com/item?id=10021219 and marked off-topic.

Re: OS X sudoers exploit found in the wild

#183
post #31

Earlier quoted context omitted.

Could you explain the dual-use export issue. I read a little about it here [1], but I don't understand. So, if Esser was to contact Apple and provide them with the vulnerability info for free, but with out first registering it as a dual-use export, he could get in trouble? Even if he didn't receive any compensation from Apple? Is that the case? [1] https://www.justsecurity.org/5703/export-control-arrangement...

He could basically be sent to jail for weapon smuggling, receiving any compensation is irrelevant.

That's a really sad state of affairs. Instead of promoting security, which is what the law claims to do, the law is actually promoting insecurity. Which is probably the true end goal of the law any way, if that's the way it's written. Threaten people with jail unless they first register security vulnerabilities with the government, than, when they do so, threaten them with even more jail time if they ever speak again about the said vulnerability, and keep the vulnerability for your self. I guess EU is just pissed that NSA has better toys. Really, truly sad state of affairs.

Re: OS X sudoers exploit found in the wild

#184
post #182

> a company that takes part in the usual tax and labor law evasion tactics Would you prefer to have most of your income forcefully taken away, or would you prefer as little as possible taken away? Tax evasion amounts to trying to keep your own property. If someone tries to avoid paying protection money to a mafia, is he a criminal, or immoral?

Please stop taking HN threads on ideological wild-goose flame chases. Detached from https://news.ycombinator.com/item?id=10021219 and marked off-topic.

In fairness, that post also appears to be barbed with an ideological appear to wild geese as well.

Re: OS X sudoers exploit found in the wild

#185
post #182

Earlier quoted context omitted.

Please stop taking HN threads on ideological wild-goose flame chases. Detached from https://news.ycombinator.com/item?id=10021219 and marked off-topic.

In fairness, that post also appears to be barbed with an ideological appear to wild geese as well.

It sounds like maybe the parent is the one we should have detached and marked off-topic? Can fix, if so.

Edit: it looks to me like the rest of the repliers managed to resist that particular provocation.

Re: OS X sudoers exploit found in the wild

#186

Earlier quoted context omitted.

Ah, thanks for clarifying. I suppose it wouldn't have execute permissions if downloaded from a browser, but it could if copied with Finder from a network share (or directly accessed, of course), so that sounds like a potential vector.

It is a lot easier than you may think. Here is a simple demonstration: https://vid.me/gGQY

Oh, yeah, I should've thought about dmgs. Yikes... that seems "not OK"; but if they made shell scripts require signing I imagine that'd probably break lots of stuff.

Re: OS X sudoers exploit found in the wild

#187
post #182

> a company that takes part in the usual tax and labor law evasion tactics Would you prefer to have most of your income forcefully taken away, or would you prefer as little as possible taken away? Tax evasion amounts to trying to keep your own property. If someone tries to avoid paying protection money to a mafia, is he a criminal, or immoral?

Please stop taking HN threads on ideological wild-goose flame chases. Detached from https://news.ycombinator.com/item?id=10021219 and marked off-topic.

.. As if you couldn't see that I'm making sense and speaking the truth.

In fact, that's probably why you're "silencing" me. Did you shadowban me already too? :P That's fine, I'll have a new IP soon.

Re: OS X sudoers exploit found in the wild

#188

Earlier quoted context omitted.

How do you intend to have money without a central bank? Should we all swap gold bars? What if I have a different view of the value of gold/bitcoin? Also, I'll play along if that's what you want. > You could just build a road and then ask people to pay for using it 1. I'm going to use your road and not pay. What are you going to do about it? 2. I don't believe you have rights to the land the road is on. How do you pro…

He’s one of the anarcho-capitalist hardcore bitcoin defenders that hang out in #bitcoin-assets, too. Just ignore him, I wasted a week trying to talk to these kind of people, it’s of no use.

More like, they wasted a week on talking to you.

Re: OS X sudoers exploit found in the wild

#189

Earlier quoted context omitted.

> And the police? Fire departments? Social security? I know, it's like.. how could supermarkets sell you ice-cream without 330 million people getting extorted?! It's ridiculous!

Hey sillygeese, whoever you are, just wanted you to know that I upvoted your comments. Keep up the good fight! Your position is a totally legitimate one. Anyone who objects to how the government uses their money is totally in their right to refuse to pay taxes. Given today's technology, governments have no excuses left.

Thanks. Check this out too: https://www.youtube.com/watch?v=yuC_4mGTs98

Re: OS X sudoers exploit found in the wild

#190

Earlier quoted context omitted.

Hey sillygeese, whoever you are, just wanted you to know that I upvoted your comments. Keep up the good fight! Your position is a totally legitimate one. Anyone who objects to how the government uses their money is totally in their right to refuse to pay taxes. Given today's technology, governments have no excuses left.

Thanks. Check this out too: https://www.youtube.com/watch?v=yuC_4mGTs98

Thanks! Utterly crazy stuff. I really pity this downvoters. Sad fools who pay folks to kick them in the nuts and then downvote anyone who points out their self-harming behavior.
Post reply on HN