Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> MacOs X Exploit Code
mexLabs
post Oct 2 2006, 08:26 PM
Post #1


Newbie [ Level 1 ]
Group Icon

Group: Members
Posts: 3
Joined: 2-October 06
Member No.: 16,309



Security firms warned users of Apple's Mac OS X earlier this week about the existence of an exploit that could result in the execution of arbitrary code. The news has made upgrading to version 10.4.7 even more important, as the update fixes the issue. The vulnerability lies in an operating system file called "launchd."

The proof-of-concept code was created by Digital Munition security researcher Kevin Finisterre. He has written other exploits in the past, including another for a Bluetooth flaw within Mac OS X. Finisterre says he does his work out of a desire to show those who believe the operating system is completely safe that there are flaws that need to be addressed.
Go to the top of the page
 
+Quote Post
xboxrulz
post Oct 2 2006, 09:48 PM
Post #2


Colonel Panic
Group Icon

Group: [MODERATOR]
Posts: 2,730
Joined: 25-March 05
From: Toronto, Ontario, Canada
Member No.: 3,233



well, there are no such thing as a COMPLETELY SAFE operating system ever existed, so really, there's not that much to prove.

xboxrulz
Go to the top of the page
 
+Quote Post
Mark420
post Oct 2 2006, 10:23 PM
Post #3


The Modernator
Group Icon

Group: Members
Posts: 486
Joined: 6-August 06
From: The Interweb!
Member No.: 15,021



QUOTE(mexLabs @ Oct 2 2006, 09:26 PM) *

Security firms warned users of Apple's Mac OS X earlier this week about the existence of an exploit that could result in the execution of arbitrary code. The news has made upgrading to version 10.4.7 even more important, as the update fixes the issue. The vulnerability lies in an operating system file called "launchd."

The proof-of-concept code was created by Digital Munition security researcher Kevin Finisterre. He has written other exploits in the past, including another for a Bluetooth flaw within Mac OS X. Finisterre says he does his work out of a desire to show those who believe the operating system is completely safe that there are flaws that need to be addressed.


Was the above taken from here..

Here

Cos I kinds think it was wink.gif

All of us can google wink.gif
Go to the top of the page
 
+Quote Post
evought
post Oct 2 2006, 10:28 PM
Post #4


Advanced Member
Group Icon

Group: Members
Posts: 199
Joined: 3-October 05
Member No.: 8,888



QUOTE(xboxrulz @ Oct 2 2006, 04:48 PM) *

well, there are no such thing as a COMPLETELY SAFE operating system ever existed, so really, there's not that much to prove.

xboxrulz


It's also an exploit for a flaw which has already been fixed. Half the reason that OS X is safeer is that the turn-around time for patches is very fast. Linux distributions tend to be in the same boat. When I was administering a bunch of RedHat machines, the CERT warnings for a vulnerability usually had a link to the patch for RedHat Linux while MS or Sun would take weeks or months to make the same fix. The other thing is that I have had one issue with an OS X point upgrade since 10.1.x, whereas MS' patches often break apps and cause general havoc. This tends to be true of the RedHat Fedora Core updates as well, although I do not understand why: there is no systematic integration tetsing for point releases.

Anyway, the point is that nothing is completely safe, but little differences in process make a huge difference to security. I get tired of people jumping on every flaw as if it made OS X the same as Windows.
Go to the top of the page
 
+Quote Post
xboxrulz
post Oct 3 2006, 10:17 PM
Post #5


Colonel Panic
Group Icon

Group: [MODERATOR]
Posts: 2,730
Joined: 25-March 05
From: Toronto, Ontario, Canada
Member No.: 3,233



QUOTE(evought @ Oct 2 2006, 06:28 PM) *

It's also an exploit for a flaw which has already been fixed. Half the reason that OS X is safeer is that the turn-around time for patches is very fast. Linux distributions tend to be in the same boat. When I was administering a bunch of RedHat machines, the CERT warnings for a vulnerability usually had a link to the patch for RedHat Linux while MS or Sun would take weeks or months to make the same fix. The other thing is that I have had one issue with an OS X point upgrade since 10.1.x, whereas MS' patches often break apps and cause general havoc. This tends to be true of the RedHat Fedora Core updates as well, although I do not understand why: there is no systematic integration tetsing for point releases.

Anyway, the point is that nothing is completely safe, but little differences in process make a huge difference to security. I get tired of people jumping on every flaw as if it made OS X the same as Windows.


Apparently, I only see Fedora Core and Windows XP breaking patches. I've also seen MacOS X patches breaking the system on "illegal hardware" (which is fully understandable and not used for any excuse).

So, i don't know. I use SuSE Linux 10.1 and none of the patches have broken my install or caused more exploits.

xboxrulz
Go to the top of the page
 
+Quote Post
unimatrix
post Nov 27 2006, 05:01 AM
Post #6


Premium Member
Group Icon

Group: Members
Posts: 493
Joined: 15-August 05
Member No.: 7,873



rarely have I had issues. The latest system update seems to cause Safari 2 to crash a lot for no good reason. One more reason to finally switch to Opera (which I'm using now)

That being said, I've never had any issues with Mac patches screwing up other systems. I think I once had to download a new scanner driver or something because of an update conflict, but that's been about it.

Personally I enjoy administrating macs over other OS's. Mac OSX Server is a dream to work with and if you know Unix you can get under the Unix hood and do things the old fashion way.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Basic css code(2)
  2. Code To Send An Email From A Form(7)
  3. Rapid HTML code generation using simple PHP(8)
  4. Do You Program/code Your Own Games(11)
  5. VB.NET: Howto Add And Delete Files(8)
  6. Does Anyone Code Using Turing(2)
  7. Myspace Code Changing(10)
  8. Free Shoutbox? HTML, Flash or PHP Code(24)
  9. Programing Windows Joystick(2)
  10. Uploading Image File Through JSP Code To Server(9)
  11. Dynamically Change The Background Image On Mouse Effects!(3)
  12. How To Add Adsense Code In SMF(4)
  13. Cursor-for-loop Out Of Bounds Error(8)
  14. Disable Task Manager 1 Line Code![vb6](32)
  15. Tips For Modifying Wordpress Code(1)
  1. Decompile An Exe To Source Code(10)
  2. What's Wrong With My Php Webpage?(2)
  3. Whats The Ascii Code Of Your Name?(4)
  4. For .net Or Java, Consider Python(1)
  5. Hex Code Program?(2)
  6. Strange Ascii Code 22 Character Detected In Connection String(9)
  7. Domain.com Coupon Code(1)
  8. Dynamic Php Image And Better Php Code Question(10)
  9. Need Help With Code For Battle Calculator For An Mmorpg I Am Planning(0)
  10. Code To Text Ratio Tool(0)
  11. Php Random Selector(2)
  12. Activation Code(7)
  13. Instant Replay Code?(0)


 



- Lo-Fi Version Time is now: 5th September 2008 - 07:04 AM