image
image

|


Go Back   macosx.com > Mac Help Forums > Mac OS X System & Mac Software

Reply
 
Thread Tools
  #33  
Old April 11th, 2005, 01:09 PM
lurk's Avatar
Mitä?
 
Join Date: Mar 2002
Location: Land o' skeeterz
Posts: 2,076
Thanks: 0
Thanked 0 Times in 0 Posts
lurk is on a distinguished road
I am curious what kind of local root exploits are there in PHP? You have made a big accusation that I find hard to believe as it implies a fundamental failure in the basic structure of the OS (both Linux and Darwin).
Reply With Quote
  #34  
Old April 12th, 2005, 12:44 AM
Andrew Adamson's Avatar
Got root? Sudoes.
 
Join Date: Mar 2005
Location: Osaka, Japan
Posts: 97
Thanks: 0
Thanked 0 Times in 0 Posts
Andrew Adamson has a spectacular aura aboutAndrew Adamson has a spectacular aura about
Quote:
Originally Posted by lurk
You have made a big accusation that I find hard to believe as it implies a fundamental failure in the basic structure of the OS (both Linux and Darwin).
I wouldn't say 'fundamental failure' of the OS. If you regularly visit Secunia.org, you'll see that exploits like this are pretty routine. Specifically, regarding PHP and permission escalation, see http://secunia.com/advisories/13481/. There are plenty more if you dig.

I guess I should point out that I am not a security wonk. I am a programmer. Because I write things with my client's security in mind, the security of the products I use is important to me. So I try to keep my eyes and ears open about vulnerabiilties. Also, I live in Japan, while I maintain banking and credit card accounts in Canada -- so a key logger or rootkit could pretty much ruin my day. As a result, I regularly visit Secunia, I watch the processes that are running, I read my logs. I try to be safe.

I guess, regarding TommyWillB's comments, all I can say is that 'novice users' 'installing things' was the chief reason Windows is the security nightmare it is (in my opinion). Simply saying that 'it's your fault; if you installed it, you should have known what you were doing' is not enough for Microsoft users, so it shouldn't be for anyone else. Furthermore, certain vulnerabilities can mean things get installed without the user's help. So, leaving things like PHP installed when the overwhelming majority of Mac users don't know what PHP is and certainly would never use it, is dumb enough. Leaving it installed when vulnerabilities exist now and will probably exist for some time to come is dumb and risky. And leaving it installed when vulnerabilities in other products might be used to run PHP scripts locally, dumb and VERY risky.

I'm real sorry for saying this, but I get the impression that I am beating a dead horse here. Just because 'Product X' (PHP, iTunes, AppleScript...) is cool, just because it's been around forever, just because everyone and their cousin uses it, doesn't mean it is secure. Before you say something is secure, you should first try to find out if it is not. Otherwise, assume it is not.
Reply With Quote
  #35  
Old April 12th, 2005, 03:50 AM
Tetano's Avatar
Registered User
 
Join Date: May 2004
Location: Italy
Posts: 355
Thanks: 0
Thanked 0 Times in 0 Posts
Tetano is on a distinguished road
Quote:
Originally Posted by lurk
I am curious what kind of local root exploits are there in PHP?
you may check in this forum....
__________________
iBook G3 800 MHz
384 MB SDRAM
Tiger
4G iPod, 20 GB
Reply With Quote
  #36  
Old April 25th, 2005, 06:05 AM
HomunQlus's Avatar
Artifical Lifeform
 
Join Date: Mar 2005
Location: Dublin, Ireland
Posts: 384
Thanks: 0
Thanked 0 Times in 0 Posts
HomunQlus is on a distinguished road
People, it's done. It's true. There's the first trojan known to me for OS X. It puts in some entries into the start up files and opens some back doors that allow intruders to run commands on root level.

http://www.sophos.com/virusinfo/analyses/maccowhanda.html
__________________

Mac OS X User for life

"You know what is worse than being all alone in the night, captain?
To be all alone in the crowd."
- Ambassador Delenn


Reply With Quote
  #37  
Old April 25th, 2005, 06:28 AM
Lt Major Burns's Avatar
"Dicky" Charlteston-Burns
 
Join Date: Jan 2005
Location: Manchester
Posts: 3,329
Thanks: 0
Thanked 0 Times in 0 Posts
Lt Major Burns will become famous soon enough
so... er, what do we do? none of us have anti-virus software
__________________
Dual 1.8GHz G5 2GB, 1TB, Radeon 9600XT 128MB, 10.5
20" Apple Cinema Display + Dell 2005FPW 20" dual-head
iBook G3 700MHz
640MB, 40GB, Rage128 16MB, 10.4, dying battery
Reply With Quote
  #38  
Old April 25th, 2005, 06:30 AM
HomunQlus's Avatar
Artifical Lifeform
 
Join Date: Mar 2005
Location: Dublin, Ireland
Posts: 384
Thanks: 0
Thanked 0 Times in 0 Posts
HomunQlus is on a distinguished road
On the link I posted, I think on the bottom, they give you instructions or tool of some sort to remove it. Have to check that out either
__________________

Mac OS X User for life

"You know what is worse than being all alone in the night, captain?
To be all alone in the crowd."
- Ambassador Delenn


Reply With Quote
  #39  
Old April 25th, 2005, 06:35 AM
Lt Major Burns's Avatar
"Dicky" Charlteston-Burns
 
Join Date: Jan 2005
Location: Manchester
Posts: 3,329
Thanks: 0
Thanked 0 Times in 0 Posts
Lt Major Burns will become famous soon enough
i assume it's a patch for Sophos antivirus - it's just not a recognised file
__________________
Dual 1.8GHz G5 2GB, 1TB, Radeon 9600XT 128MB, 10.5
20" Apple Cinema Display + Dell 2005FPW 20" dual-head
iBook G3 700MHz
640MB, 40GB, Rage128 16MB, 10.4, dying battery
Reply With Quote
  #40  
Old April 25th, 2005, 06:41 AM
HomunQlus's Avatar
Artifical Lifeform
 
Join Date: Mar 2005
Location: Dublin, Ireland
Posts: 384
Thanks: 0
Thanked 0 Times in 0 Posts
HomunQlus is on a distinguished road
Hmm.... maybe they release something for OS X in particular, some sort of removal tool. We can also watch the Apple download sites, maybe they're aware of that also and provide something
__________________

Mac OS X User for life

"You know what is worse than being all alone in the night, captain?
To be all alone in the crowd."
- Ambassador Delenn


Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump


All times are GMT -5. The time now is 04:25 PM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.