This is topic Mac OS hole in forum Books, Films, Food and Culture at Hatrack River Forum.


To visit this topic, use this URL:
http://www.hatrack.com/ubb/main/ultimatebb.php?ubb=get_topic;f=2;t=041605

Posted by human_2.0 (Member # 6006) on :
 
http://www.heise.de/english/newsticker/news/69862

http://isc.sans.org/diary.php?storyid=1138&rss

As always, don't click on links or open files you don't trust. And be wary of things that just pop up, even if from friends. Ask them why they sent it. A virus/program would not be able to answer. If your friend really sent you something, then they would be able to answer.

[ February 22, 2006, 03:18 PM: Message edited by: human_2.0 ]
 
Posted by Storm Saxon (Member # 3101) on :
 
I bet it's a plot by M$ to undermine poor, ol' Apple.
 
Posted by Storm Saxon (Member # 3101) on :
 
[Wink] [Razz]
 
Posted by Boris (Member # 6935) on :
 
Actually, it's all the script kiddies getting ahold of the cracked version of OSX for x86 and finding all the holes in it. Now that they're using it, expect more than enough viruses to proliferate the Macintosh world. And congratulate Apple for signing the deal that made it all possible [Smile]
 
Posted by narrativium (Member # 3230) on :
 
Thank you, Boris, for that completely uninformed, technically inaccurate opinion.
 
Posted by human_2.0 (Member # 6006) on :
 
Can't blame script kiddies as they weren't the ones who found the hole. A security company found it. Security companies have been finding holes in Mac OS X since version 10.0. So this isn't new. If it were script kiddies, the discovery would have been by people noticing their computers were compromised (like last weeks' trojan).

What is new is the attention it gathers and the implied risk. I say "implied" risk because it seems like more malicious users are eyeing OS X as a target. I have no facts on that, though. One just assumes it because OS X seems to be more popular. But I do believe it to be false.

For career "black hats", the only appeal of OS X right now is when it is used for an important purpose, like a websesrver as most career bad guys either want thosands of compromised machines (which is only available by targeting Windows) or key machines.

And AFAIK, there is nothing that takes advantage of the hole anyway. In fact, I shouldn't have titled the thread "exploit" as there is no exploit yet. I'll change it to "hole".

I mainly posted this to get Mac users out of the "we are invulnerable" mind set and get them to learn safe computing practices. Like don't download anything/everything and make sure a person you know sent you that file rather than a bot or an impersonator.

And of course, until Apple comes out with a security update, you might want to be extra careful too.
 
Posted by twinky (Member # 693) on :
 
There's an obvious pun on this thread title that I'm not going to make. [Wink]
 
Posted by human_2.0 (Member # 6006) on :
 
Where's your mind twinky? [Big Grin]
 
Posted by Ela (Member # 1365) on :
 
http://secunia.com/advisories/18963
 
Posted by xxsockeh (Member # 9186) on :
 
quote:
If it were script kiddies, the discovery would have been by people noticing their computers were compromised (like last weeks' trojan).
What do you mean, last weeks' trojan? My friend complained about his computer being infected with one, and I haven't seen him on since that day. Do you know what it's called, or have any info. on it?
 
Posted by human_2.0 (Member # 6006) on :
 
http://www.hatrack.com/cgi-bin/ubbmain/ultimatebb.cgi?ubb=get_topic&f=2&t=041500
 
Posted by human_2.0 (Member # 6006) on :
 
quote:
Originally posted by Ela:
http://secunia.com/advisories/18963

Oh, I guess this guy found the hole.
 
Posted by Ela (Member # 1365) on :
 
quote:
Originally posted by human_2.0:
quote:
Originally posted by Ela:
http://secunia.com/advisories/18963

Oh, I guess this guy found the hole.
Yes, that seems to be the case.
 


Copyright © 2008 Hatrack River Enterprises Inc. All rights reserved.
Reproduction in whole or in part without permission is prohibited.


Powered by Infopop Corporation
UBB.classic™ 6.7.2