Live data from Hacker News

OS X sudoers exploit found in the wild

blog.malwarebytes.org

151–160 of 193 posts

Re: OS X sudoers exploit found in the wild

#151

Earlier quoted context omitted.

> "sky is falling" implications, and then NOTHING absolutely happens Sure, just brush off a sudo vulnerability. > fight viruses off of Windows boxes Virus != vulnerability. Furthermore, while a rootkit is still a virus it's a long-shot from the relatively benign things running around on Windows machines (not that I mentioned Windows at first, but there ya' go - were on to that now). Just to avoid a Windows shitstorm,…

Viruses are not going to go poof unless your antivirus knows about them And in the typical case a vulnerability is a prerequisite for a virus. But local vulns are only a concern if someone already has access to your system. In which case your usually fucked anyway. Which is why Apple introduced developer certs and gatekeeper.

> Which is why Apple introduced developer certs and gatekeeper.

Yeah that is a really neat feature from a security standpoint.

Re: OS X sudoers exploit found in the wild

#152
post #72

Earlier quoted context omitted.

Is there a test to determine if the patch is successful? Edit: as noted in Esser's blog [1]: $ EDITOR=/usr/bin/true DYLD_PRINT_TO_FILE=/this_system_is_vulnerable crontab -e I found this test failed in both a patched (10.10.4) and un-patched system (10.10.1) so not sure what these results mean. [1] https://www.sektioneins.de/en/blog/15-07-07-dyld_print_to_fi...

Did you check the root directory for a file named "this_system_is_vulnerable"? I just tested this on a mid-2015 MBP running 10.10.4 and found that file in the root directory. :(

Thanks for clarifying: I was able to find the vulnerability on the unpatched system with:

  $ ls -al /
  (etc)
  -rw-r--r--   1 root  wheel       0 Aug  6 06:46   this_system_is_vulnerable
So I can a) confirm the vulnerability exists and it can write with root privileges.

and b) the patch works: I ran the patch, deleted the test file, rebooted and the file is no longer able to be written.

Re: OS X sudoers exploit found in the wild

#153
post #60

Earlier quoted context omitted.

So I've heard; I haven't confirmed this for myself.

I have to try this if I remember! That'd be very interesting. The console obviously has many legitimate uses. Why wouldn't I try it out if I were thinking about buying a mac?

I quite often open a terminal and run top or emacs and leave it that way, nobody ever commented on it

Re: OS X sudoers exploit found in the wild

#154
post #72

Earlier quoted context omitted.

Is there a test to determine if the patch is successful? Edit: as noted in Esser's blog [1]: $ EDITOR=/usr/bin/true DYLD_PRINT_TO_FILE=/this_system_is_vulnerable crontab -e I found this test failed in both a patched (10.10.4) and un-patched system (10.10.1) so not sure what these results mean. [1] https://www.sektioneins.de/en/blog/15-07-07-dyld_print_to_fi...

You ran the GitHub patch and it still failed?

The patch works. I now have 2 patched systems and I've instructed my team to run the patch immediately on every mac.

Re: OS X sudoers exploit found in the wild

#156
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

After spending quite some time deliberating on this, and not wanting my users in the wild without something, I finally settled on Bitdefender. I control clients from the cloud console, can push policies, run scans, updates, all without user interaction. Right now I'm only using the AV part for most devices though, as enabling the full package of internet firewall and website scanning was eating up lots of resources.

The two follow up contenders were ESET and Kaspersky.

Re: OS X sudoers exploit found in the wild

#157

Earlier quoted context omitted.

Stefan is not just some random guy on the Internet. I can assure you the relevant folks at Apple know him and most likely he knows them.

oh, well as long as you can assure us of that orthogonal point, I guess it's all good mr anonymous internet person

It's easy to prove. Just go look at the number of iOS and OSX security fixes attributed to him. Or you can go do a simple search on any reputable site posting security info and you'll see him all over it.

Re: OS X sudoers exploit found in the wild

#158
post #7
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

Little Snitch ( https://www.obdev.at/products/littlesnitch/index.html ) is excellent.

Does anyone know of a FOSS tool similar to littlesnitch?

Re: OS X sudoers exploit found in the wild

#159

Earlier quoted context omitted.

How do you intend to have money without a central bank? Should we all swap gold bars? What if I have a different view of the value of gold/bitcoin? Also, I'll play along if that's what you want. > You could just build a road and then ask people to pay for using it 1. I'm going to use your road and not pay. What are you going to do about it? 2. I don't believe you have rights to the land the road is on. How do you pro…

You didn't actually address any of my questions, so I'll just refrain from addressing yours.

Thought so.

Also this shouldn't need pointing out, but I did answer at least one of your questions:

> You do realize they're still taking your money by force, don't you?

... with the response:

> How do you intend to have money without a central bank?

I guess I could generalise it to "plus law courts, legal system and police force," if you like.

The real problem you have is that "someone taking your money" assumes you have money in the first place, and there's no such thing as money absent a framework that provides it. Otherwise it's just bits of green paper/coloured metal/bits on a computer.

Or would you like to swap ten chickens for my sheep? No? I think I'll just shoot you and take the chickens anyway then.

Re: OS X sudoers exploit found in the wild

#160

Earlier quoted context omitted.

How do you intend to have money without a central bank? Should we all swap gold bars? What if I have a different view of the value of gold/bitcoin? Also, I'll play along if that's what you want. > You could just build a road and then ask people to pay for using it 1. I'm going to use your road and not pay. What are you going to do about it? 2. I don't believe you have rights to the land the road is on. How do you pro…

He’s one of the anarcho-capitalist hardcore bitcoin defenders that hang out in #bitcoin-assets, too. Just ignore him, I wasted a week trying to talk to these kind of people, it’s of no use.

Aye. I just wish it were different.

Incidentally, I've just come back from the Netherlands, where the rather excellent Rotterdam Museum of Customs had a series of quite nicely inquiring exhibits going into exactly why we pay tax and all the nice things it gives to the Netherlands. I wish my own society (the UK) felt more confident about putting forward a pro-taxation argument. Ultimately, it's a kind of social glue that's needed I think.

Post reply on HN