Followers | 3 |
Posts | 1473 |
Boards Moderated | 0 |
Alias Born | 07/17/2003 |
Monday, March 06, 2006 8:24:43 PM
6 March 2006 10:00 AM CST
In response to the woefully misleading ZDnet article, Mac OS X hacked under 30 minutes, the academic Mac OS X Security Challenge has been launched.
The ZDnet article, and almost all of the coverage of it, failed to mention a very critical point: anyone who wished it was given a local account on the machine (which could be accessed via ssh). Yes, there are local privilege escalation vulnerabilities; likely some that are "unpublished". But this machine was not hacked from the outside just by being on the Internet. It was hacked from within, by someone who was allowed to have a local account on the box. That is a huge distinction.
Almost all consumer Mac OS X machines will:
Not give any external entities local account access
Not even have any ports open
In addition to the above, most consumer machines will also be behind personal router/firewall devices, further reducing exposure
The challenge is as follows: simply alter the web page on this machine, test.doit.wisc.edu. The machine is a Mac mini (PowerPC) running Mac OS X 10.4.5 with Security Update 2006-001, has two local accounts, and has ssh and http open - a lot more than most Mac OS X machines will ever have open. Email das@doit.wisc.edu if you feel you have met the requirements, along with the mechanism used. The mechanism will then be reported to Apple and/or the entities responsible for the component(s).
Mac OS X is not invulnerable. It, like any other operating system, has security deficiencies in various aspects of the software. Some are technical in nature, and others lend themselves to social engineering trickery. However, the general architecture and design philosophy of Mac OS X, in addition to usage of open source components for most network-accessible services that receive intense peer scrutiny from the community, make Mac OS X a very secure operating system. There have been serious vulnerabilities in Mac OS X that could be taken advantage of; however, most Mac OS X "vulnerabilities" to date have relied on typical trojan social engineering tactics, not genuine vulnerabilities. The recent Safari vulnerability was promptly addressed by Apple, as are any exploits reported to Apple. Apple does a fairly good job with regard to security, and has greatly improved its reporting processes after pressure from institutional Mac OS X users: Apple is responsive to security concerns with Mac OS X, which is one of the most important pieces of the security picture.
The "Mac OS X hacked under 30 minutes" story doesn't mention that local access was granted to the system. While local privilege escalation exploits can certainly be dangerous - and used in conjunction with things like the above Safari exploit - this isn't very informative with regard to the general security of a Mac OS X machine sitting on the Internet.
I have commented a bit on Mac OS X security in general.
Is there a prize?
There is no prize but recognition (if desired). This is an academic effort.
Objections to this test
Some have objected to this test as doing nothing more than testing the security of apache or ssh on a PowerPC architecture. That is correct. And that is how most of the world will see Mac OS X externally. The original article was not fair, because it did not note, or even imply, or hint in any way, that local account access was granted. The whole point of Apple using proven open source services like OpenSSH and apache on Mac OS X is exactly because of their secure nature as a result of years of scrutiny by the community. Most users of Mac OS X in a consumer or desktop setting will never even enable any of these services at all. It's unfortunate that the initial coverage was so journalistically poor and sensationalistic on what might otherwise have been an article about an interesting local vulnerability. Instead, it chose to leave people with the impression that a Mac OS X machine can be "hacked" just by doing nothing more that being on the Internet. That is patently false.
Important note
This page may be updated by me. Any changes will be announced via this site. Last update: Mon Mar 6 16:46:30 CST 2006
http://test.doit.wisc.edu/
"The illiterate of the 21st century will not be those who cannot read and write, but those who cannot learn, unlearn, and relearn." ~ Alvin Toffler
Recent AAPL News
- Artmarket.com: Q3 2024 revenue +13%. Study on AI search engines shows Artprice has the world's biggest, best and most useful art market database, thanks to its Intuitive Artmarket® AI • PR Newswire (Canada) • 11/14/2024 07:30:00 AM
- Artmarket.com: Q3 2024 revenue +13%. Study on AI search engines shows Artprice has the world's biggest, best and most useful art market database, thanks to its Intuitive Artmarket® AI • PR Newswire (US) • 11/14/2024 07:30:00 AM
- Final Cut Pro 11 begins a new chapter for video editing on Mac • Business Wire • 11/13/2024 11:00:00 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 11/07/2024 11:30:16 PM
- Trump Media Shares Surge 32% Pre-Market; Tesla Jumps 13%; Coinbase Rises with BTC All-Time High • IH Market News • 11/06/2024 11:09:49 AM
- Boeing Ends Strike; Leadership Changes at Dollar Tree and Southwest; PLTR, HIMS, and ALAB Soar; MQ and LSCC Decline • IH Market News • 11/05/2024 11:43:15 AM
- Election Uncertainty May Lead To Choppy Trading On Wall Street • IH Market News • 11/04/2024 02:04:17 PM
- U.S. Futures Edge Up as Election and Fed Rate Decision Loom; Oil Prices Rise as OPEC+ Delays Production Increase • IH Market News • 11/04/2024 11:13:21 AM
- Upbeat Earnings News Contributes To Rebound On Wall Street • IH Market News • 11/01/2024 08:39:11 PM
- Upbeat Amazon, Intel Earnings May Spark Rebound On Wall Street • IH Market News • 11/01/2024 01:06:54 PM
- Amazon Up 6%, Atlassian Jumps 20%; Intel Posts Surprising Profit; Abbott Wins Infant Formula Lawsuit • IH Market News • 11/01/2024 10:55:39 AM
- Form S-3ASR - Automatic shelf registration statement of securities of well-known seasoned issuers • Edgar (US Regulatory) • 11/01/2024 10:49:43 AM
- Form 10-K - Annual report [Section 13 and 15(d), not S-K Item 405] • Edgar (US Regulatory) • 11/01/2024 10:01:36 AM
- Form 8-K - Current report • Edgar (US Regulatory) • 10/31/2024 08:30:25 PM
- Apple reports fourth quarter results • Business Wire • 10/31/2024 08:30:00 PM
- U.S. Index Futures Decline; Oil Prices Rise on Strong Demand and OPEC+ Production Outlook • IH Market News • 10/31/2024 11:15:53 AM
- Apple introduces M4 Pro and M4 Max • Business Wire • 10/30/2024 03:00:00 PM
- Apple’s new MacBook Pro features the incredibly powerful M4 family of chips and ushers in a new era with Apple Intelligence • Business Wire • 10/30/2024 03:00:00 PM
- Mixed Earnings, Economic News May Lead To Choppy Trading • IH Market News • 10/30/2024 01:09:50 PM
- Google Cloud Revenue Grows 35%; AMD Stock Drops 8%, Qorvo Plummets 18%, Reddit Surges 24% in Pre-Market • IH Market News • 10/30/2024 10:35:21 AM
- Nasdaq Reaches New Record Closing High But Dow Moves Lower • IH Market News • 10/29/2024 08:44:00 PM
- Apple’s all-new Mac mini is more mighty, more mini, and built for Apple Intelligence • Business Wire • 10/29/2024 03:00:00 PM
- HSBC Reports $8.5 Billion Profit; Boot Barn Announces New CEO and Projections; TMDX Drops 24%, VFC Surges 22% • IH Market News • 10/29/2024 09:39:09 AM
- Apple Intelligence is available today on iPhone, iPad, and Mac • Business Wire • 10/28/2024 03:00:00 PM
- Apple unveils the new iMac with M4, supercharged by Apple Intelligence and available in fresh colors • Business Wire • 10/28/2024 03:00:00 PM
Alliance Creative Group (ACGX) Releases Q3 2024 Financial and Disclosure Report with an increase of over 100% in Net Income for 1st 9 months of 2024 vs 2023 • ACGX • Nov 14, 2024 8:30 AM
Unitronix Corp. Publishes Its Cryptocurrency Portfolio Strategy • UTRX • Nov 14, 2024 8:05 AM
Avant Technologies and Ainnova Tech Form Joint Venture to Advance Early Disease Detection Using Artificial Intelligence • AVAI • Nov 12, 2024 9:00 AM
Swifty Global Announces Launch of Swifty Sports IE, Expanding Sports Betting and Casino Services in the Irish Market • DRCR • Nov 12, 2024 9:00 AM
Oohvie App Update Enhances Women's Health with Telemedicine and Online Scheduling • HLYK • Nov 11, 2024 8:00 AM
SANUWAVE Announces Record Quarterly Revenues: Q3 FY2024 Financial Results • SNWV • Nov 8, 2024 7:07 AM