image
image

|


Go Back   macosx.com > Content & Information > Apple News, Rumors & Discussion

Reply
 
Thread Tools
  #1  
Old November 17th, 2007, 01:23 AM
Registered User
 
Join Date: Jul 2005
Posts: 52
Thanks: 2
Thanked 1 Time in 1 Post
midijeep is on a distinguished road
Post Apple admits to ‘misleading’ Leopard firewall settings

November 15th, 2007
Apple admits to ‘misleading’ Leopard firewall settings
Posted by Ryan Naraine @ 11:14 am

Apple has fessed up to at least three serious design weaknesses in the new application-based firewall that ships with Mac OS X Leopard.

The acknowledgment from Cupertino comes less than a month after independent researchers threw cold water on Apple’s claim that Leopard’s firewall can block all incoming connections.

[ SEE: Apple monster update fixes 41 Mac OS X, Safari vulnerabilities ]

In an advisory accompanying the Mac OS X v10.5.1 update, Apple admitted that the “Block all incoming connections” setting for the firewall is misleading.

“The ‘Block all incoming connections’ setting for the Application Firewall allows any process running as user “root” (UID 0) to receive incoming connections, and also allows mDNSResponder to receive connections. This could result in the unexpected exposure of network services,” Apple said.

[ SEE: Researchers pooh-pooh Mac OS X Leopard security ]

With the fix, the firewall will more accurately describe the option as “Allow only essential services”, and by limiting the processes permitted to receive incoming connections under this setting to a small fixed set of system services, Apple said

Two other Application Firewall flaws are addressed:

CVE-2007-4703: The “Set access for specific services and applications” setting for the Application Firewall allows any process running as user “root” (UID 0) to receive incoming connections, even if its executable is specifically added to the list of programs and its entry in the list is marked as “Block incoming connections”. This could result in the unexpected exposure of network services.

[ SEE: Memory randomization (ASLR) coming to Mac OS X Leopard ]

CVE-2007-4704: When the Application Firewall settings are changed, a running process started by launchd will not be affected until it is restarted. A user might expect changes to take effect immediately and so leave their system exposed to network access.

The Leopard firewall patch comes less than 24 hours after Apple shipped a monster update to cover at least 41 Mac OS X and Safari for Windows (beta) vulnerabilities.
Reply With Quote
  #2  
Old November 17th, 2007, 07:04 AM
Damrod's Avatar
Registered User
 
Join Date: Aug 2002
Location: Aachen, Germany
Posts: 408
Thanks: 0
Thanked 0 Times in 0 Posts
Damrod is on a distinguished road
I still don't trust the new application firewall. I rather rely on the still present ipw (configured quite solid with Flying Buttress) combined with LittleSnitch.
__________________
PowerMac G4 MDD '03 1.25GHz, 1 GB RAM, 2x80 GB HDD, on OS X 10.4.x/10.5.x
iPod nano 2nd Gen 2GB
Part of the party since MacOS 7

My Last.fm Profile
Reply With Quote
  #3  
Old November 17th, 2007, 08:22 PM
Registered User
 
Join Date: Sep 2005
Location: Australia
Posts: 771
Thanks: 0
Thanked 0 Times in 0 Posts
Thank The Cheese is on a distinguished road
The biggest security flaw of all is simply the fact that it is not on by default. If there is one thing they should have learned from Windows, it's that the firewall should be on by default.

btw, the article cited is from by Ryan Naraine
Reply With Quote
  #4  
Old November 20th, 2007, 08:41 AM
zynizen's Avatar
Registered User
 
Join Date: Sep 2006
Posts: 223
Thanks: 0
Thanked 0 Times in 0 Posts
zynizen is on a distinguished road
so why is Leopard even released if its nothing its cracked up to be? What did they actually improve then? I've been reading tons of articles posted here over the last few weeks about leopard and issues, it seems its not even worth the headaches, but so many millions of people are still happy?

Did they rush the OS? Geeez...
Reply With Quote
  #5  
Old November 21st, 2007, 08:45 AM
lurk's Avatar
Mitä?
 
Join Date: Mar 2002
Location: Land o' skeeterz
Posts: 2,076
Thanks: 0
Thanked 0 Times in 0 Posts
lurk is on a distinguished road
The happy people don't complain. Even I complain and I am happy so go figure. There are some things that are not working right but there are many more that are and I for one cannot imagine going back.

Reading these kinds of threads and the discussion threads at apple.com in not a good way of forming an opinion.
__________________
Wenn ist das Nunstruck git und Slotermeyer? Ja!...
Beiherhund das Oder die Flipperwaldt gersput!
Reply With Quote
  #6  
Old November 21st, 2007, 09:46 AM
ElDiabloConCaca's Avatar
U.S.D.A. Prime
 
Join Date: Aug 2001
Location: San Antonio, Texas
Posts: 9,713
Thanks: 2
Thanked 33 Times in 31 Posts
ElDiabloConCaca will become famous soon enough
Quote:
Originally Posted by zynizen View Post
so why is Leopard even released if its nothing its cracked up to be? What did they actually improve then? I've been reading tons of articles posted here over the last few weeks about leopard and issues, it seems its not even worth the headaches, but so many millions of people are still happy?

Did they rush the OS? Geeez...
For starts, this is a "help" forum -- so you're going to be reading about problems and issues with Mac OS X here. Rarely does a person simply post the good things about Mac OS X because this is mainly a place to get help fixing problems.

Imagine going to a car repair shop. Sure, you'd see a ton of broken cars, but it would be silly and unreasonable to infer that ALL cars are broken, no? I mean, you went to a place where a very small fraction of cars go to be fixed... similar to here: you came to a place where problems with Mac OS X are discussed, debated, and/or solved -- it's silly to infer that Mac OS X is inherently "broken" by what you read here.
__________________
Power Macintosh G4/500MHz "Yikes!" 10.4.11 Server • 1024MB • 3 x 120GB + 320GB • DVR-111D • 2 x Radeon 7000 PCI • 2 x 17" CRT
MacBook 2.0GHz Core 2 Duo - White 10.5.4 • 2048MB • 80GB • CD-RW/DVD-ROM
iPod Photo 60GB • iPod nano 1GB • AT&T DSL 6Mb/768k
http://www.jeffhoppe.com
Reply With Quote
  #7  
Old November 21st, 2007, 10:43 AM
Ferdinand's Avatar
V. Tech
 
Join Date: Mar 2006
Location: Vienna, Austria
Posts: 1,111
Thanks: 0
Thanked 2 Times in 2 Posts
Ferdinand is on a distinguished road
Quote:
Originally Posted by ElDiabloConCaca View Post
Imagine going to a car repair shop. Sure, you'd see a ton of broken cars, but it would be silly and unreasonable to infer that ALL cars are broken, no? I mean, you went to a place where a very small fraction of cars go to be fixed... similar to here: you came to a place where problems with Mac OS X are discussed, debated, and/or solved -- it's silly to infer that Mac OS X is inherently "broken" by what you read here.
Great said! I agree completely.
__________________
MacBook / 2 GHz / 1.5 GB RAM / 100 GB HD / Mac OS X.5.4
iBook G4 / 1 GHz / 768 MB RAM / 40 GB HD / Mac OS X.5.4
iMac G3 / 266 MHz / 320 MB RAM / 6 GB HD / Mac OS 9.2.2
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump


All times are GMT -5. The time now is 07:55 PM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.