Live data from Hacker News

Sophisticated OS X Backdoor Discovered

securelist.com

21–30 of 155 posts

Re: Sophisticated OS X Backdoor Discovered

#21
post #20

Is 'backdoor' the correct term if the vulnerability does not originate from Apple?

Backdoors can be installed after the fact. The vendor putting in a back door is only one way for it to be present.

This would be malware inserting a back door for further exploitation.

Re: Sophisticated OS X Backdoor Discovered

#22

Can someone explain how the vicim gets infected? As far as I can read from the article they discuss what happens if you are infected. Also, isn't running binary files on OS X from let's say "Finder" automatically triggers Security alert ( like App-vendor lock )?

This isn't a virus, it's a payload. Once an attacker exploits a vulnerability to gain RCE, this is the kind of thing they might install (if their goal isn't to immediately trash the machine).

Re: Sophisticated OS X Backdoor Discovered

#23
post #8

Earlier quoted context omitted.

It was definitely possible a couple years back - https://jscholarship.library.jhu.edu/handle/1774.2/36569 We describe how to disable the LED on a class of Apple internal iSight webcams used in some versions of MacBook laptops and iMac desktops. This enables video to be captured without any visual indication to the user and can be accomplished entirely in user space by an unprivileged (non- root) application.

> It was definitely possible a couple years back Yeah, a few years back studying MacBooks from 2008 .

Have they been updated since then?

Re: Sophisticated OS X Backdoor Discovered

#24
post #21
post #20

Is 'backdoor' the correct term if the vulnerability does not originate from Apple?

Backdoors can be installed after the fact. The vendor putting in a back door is only one way for it to be present. This would be malware inserting a back door for further exploitation.

I don't know much about security, but I had the impression that a "third-party" developed and installed backdoor is called a rootkit.

Re: Sophisticated OS X Backdoor Discovered

#27
post #21

Earlier quoted context omitted.

Backdoors can be installed after the fact. The vendor putting in a back door is only one way for it to be present. This would be malware inserting a back door for further exploitation.

I don't know much about security, but I had the impression that a "third-party" developed and installed backdoor is called a rootkit.

A rootkit is a different beast. A backdoor is simply a (covert) way to gain remote access to a system. A rootkit involves being able to elevate user permissions such that you have full control over the computer. Rootkits also typically use such permissions to hide themselves from normal user accounts.

I guess in a way you could see them as related, in that they both are access tools. A backdoor gets you remote access to the system in the first place. A rootkit gets you elevated access after you are in the system.

Re: Sophisticated OS X Backdoor Discovered

#29

Okay, but no information on what to do about it, or how to protect against it.

Install Kaspersky Endpoint Protection, friend! ;)

In all seriousness, when a company releases a malware write-up, they typically imply that their software would have prevented it or will prevent it.

Re: Sophisticated OS X Backdoor Discovered

#30

I thought MacOS was "Secure By Design". This is what Apple states in their official product descriptions. In fact, it says it on this current page: http://www.apple.com/business/mac/ "Because OS X is secure by design, there’s no need for IT to install additional tools or lock down functionality for employees. And with an automated zero-touch deployment process, they don’t even have to open the box."

By that level of standard, nothing is secure. Linux has vulnerabilities. Windows has vulnerabilities. I have a deadbolt on my door and the package read "Keep your home secure!" but someone could still get through if they really wanted to.

"Secure by design" doesn't mean 100% secure no matter what. Part of that design is the update/patch process that addresses vulnerabilities quickly, and mitigating controls like lower default permissions and application signing.

The fact that you're so quick to call everyone an astroturfer because you made a ridiculous statement just proves that your only interest is trolling.

Post reply on HN