Live data from Hacker News

OS X sudoers exploit found in the wild

blog.malwarebytes.org

91–100 of 193 posts

Re: OS X sudoers exploit found in the wild

#91
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

Eset now has security software for Mac. They were always my go to products on Windows.

Re: OS X sudoers exploit found in the wild

#92

I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. Esser has his reasons - "Short reminder: Europeans are not allowed to disclose vulns privately to a foreign company like Apple without registering dual-use export"[1] - but it's hard to believe he couldn't have told them anonymously. Disclosures make caree…

> Disclosures make careers, though, so there's a strong incentive to go public.

And Apple is doing their part by not emphasizing the role of the person who did disclose responsibly:

This is obviously very bad news. Apple has evidently known about this issue for a while now – not due to Esser, but thanks to a responsible researcher going by the Twitter handle @beist, who had alerted Apple some time before Esser discovered the bug.

As an outside observer, all I see here is: Don't alert Apple.

Re: OS X sudoers exploit found in the wild

#93

> a company that takes part in the usual tax and labor law evasion tactics Would you prefer to have most of your income forcefully taken away, or would you prefer as little as possible taken away? Tax evasion amounts to trying to keep your own property. If someone tries to avoid paying protection money to a mafia, is he a criminal, or immoral?

Do Apple employees not drive cars on roads (paid for by the taxpayer)? Do they rely on no technology whatsoever which did not rely on the taxpayer to exist (for example, er, the internet)? If they want to defend some other part of their property under the law, are they paying their own judges?

Of course Apple avoid taxes - anyone who can do so without fear of getting significantly punished does. But the idea that this is a brave stand against The Man is transparently ridiculous - especially so for any technologist, given our industry's heavy historic reliance on both the academy and the military. Should you pay the mafia for 'protection'? No. Should you pay the security guard for actually protecting you? Yes.

Re: OS X sudoers exploit found in the wild

#94
post #40

I'm seriously shocked. This is ridiculous. This looks like possibly the easiest root exploit ever discovered on a desktop OS (a one-liner in bash). Why in the world would they allow an env variable to write to a file in a setuid'd binary? I'm suddenly very glad I don't use my macbook as my main machine, but I guess I'll remove the set{u,g}id bits on newgrp for now. Don't know if that will break things, but it's bette…

An other contender:

https://thehackernews.com/2013/08/apple-mac-os-x-vulnerabili...

Re: OS X sudoers exploit found in the wild

#95

> a company that takes part in the usual tax and labor law evasion tactics Would you prefer to have most of your income forcefully taken away, or would you prefer as little as possible taken away? Tax evasion amounts to trying to keep your own property. If someone tries to avoid paying protection money to a mafia, is he a criminal, or immoral?

Spurious reasoning. You can't negotiate with the mafia, they do not represent your will and they offer no services. If you want to argue that governments do none of these things, then by all means do so via the democratic process. If you want to argue that the mafia DOES, my cousin Vinny would like to meet you for a coffee.

Re: OS X sudoers exploit found in the wild

#96

I was wondering why Download Shuttle has so many more users than my app (Fat Pipe). Seems like they are playing with the world of adware marketing, I hope they aren't doing weird things with the OS as well :/.

Our app, Download Shuttle, has nothing whatsoever to do with this malware. We have no idea why the malware creator decided to open up Download Shuttle in the Mac App Store.

We can only speculate that it was done in order to disguise what the malware is really doing (installing adware such as Genieo).

Download Shuttle is a free app and makes up an insignificant part of our overall Mac app portfolio. FIPLAB is one of the longest standing app developers on the Mac App Store and our apps have been featured multiple times by Apple themselves.

Perhaps you shouldn't jump to conclusions?

Re: OS X sudoers exploit found in the wild

#97
post #40

I'm seriously shocked. This is ridiculous. This looks like possibly the easiest root exploit ever discovered on a desktop OS (a one-liner in bash). Why in the world would they allow an env variable to write to a file in a setuid'd binary? I'm suddenly very glad I don't use my macbook as my main machine, but I guess I'll remove the set{u,g}id bits on newgrp for now. Don't know if that will break things, but it's bette…

> This is ridiculous.

Not as ridiculous as the response here, which is to bend over backwards to excuse the richest company on the planet, when compared with the scathing responses vulnerabilities in Adobe, Oracle, or Microsoft products receive.

Re: OS X sudoers exploit found in the wild

#98
post #89

Earlier quoted context omitted.

I'm sure we can all agree we can make up shit that can happen till the cows come home. I'm not going to act as if someone robbed me until they do. Hold Esser responsible if someone hacks a large number of people because of what he did. Otherwise, stop living a thousands lives.

At least read about responsible disclosure before being so flippant about things like that. Esser put people at risk. Whether or not anything happens is irrelevant. He put them at risk and we need to recognize that is the cost of full disclosure. If you're fine with that, cool, but don't pretend he didn't do anything.

Well, Apple knew about the vulnerability long before Esser reported it though. So "responsible disclosure" whould have achieved nothing, so we should not be comparing public disclosure to it, but be comparing public disclosure to no disclosure.

Re: OS X sudoers exploit found in the wild

#99

I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. Esser has his reasons - "Short reminder: Europeans are not allowed to disclose vulns privately to a foreign company like Apple without registering dual-use export"[1] - but it's hard to believe he couldn't have told them anonymously. Disclosures make caree…

So are you suggesting to wait with the disclosure until Apple release a patch? Because there's a good chance that would never happen without it going public.

Re: OS X sudoers exploit found in the wild

#100
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

Security software (virus scanners e.t.c.) is snake oil.

The code required for them to do their thing is so intrusive into the operating system that it has serious effects on stability.

And they are not that effective anyhow. Since they won't be able to detect exploits in existing programs over authorised channels.

Post reply on HN