FacebookTwitter
Hatrack River Forum   
my profile login | search | faq | forum home

  next oldest topic   next newest topic
» Hatrack River Forum » Active Forums » Books, Films, Food and Culture » Mac OS hole

   
Author Topic: Mac OS hole
human_2.0
Member
Member # 6006

 - posted      Profile for human_2.0   Email human_2.0         Edit/Delete Post 
http://www.heise.de/english/newsticker/news/69862

http://isc.sans.org/diary.php?storyid=1138&rss

As always, don't click on links or open files you don't trust. And be wary of things that just pop up, even if from friends. Ask them why they sent it. A virus/program would not be able to answer. If your friend really sent you something, then they would be able to answer.

[ February 22, 2006, 03:18 PM: Message edited by: human_2.0 ]

Posts: 1209 | Registered: Dec 2003  |  IP: Logged | Report this post to a Moderator
Storm Saxon
Member
Member # 3101

 - posted      Profile for Storm Saxon           Edit/Delete Post 
I bet it's a plot by M$ to undermine poor, ol' Apple.
Posts: 13123 | Registered: Feb 2002  |  IP: Logged | Report this post to a Moderator
Storm Saxon
Member
Member # 3101

 - posted      Profile for Storm Saxon           Edit/Delete Post 
[Wink] [Razz]
Posts: 13123 | Registered: Feb 2002  |  IP: Logged | Report this post to a Moderator
Boris
Member
Member # 6935

 - posted      Profile for Boris   Email Boris         Edit/Delete Post 
Actually, it's all the script kiddies getting ahold of the cracked version of OSX for x86 and finding all the holes in it. Now that they're using it, expect more than enough viruses to proliferate the Macintosh world. And congratulate Apple for signing the deal that made it all possible [Smile]
Posts: 3003 | Registered: Oct 2004  |  IP: Logged | Report this post to a Moderator
narrativium
Member
Member # 3230

 - posted      Profile for narrativium           Edit/Delete Post 
Thank you, Boris, for that completely uninformed, technically inaccurate opinion.
Posts: 1357 | Registered: Mar 2002  |  IP: Logged | Report this post to a Moderator
human_2.0
Member
Member # 6006

 - posted      Profile for human_2.0   Email human_2.0         Edit/Delete Post 
Can't blame script kiddies as they weren't the ones who found the hole. A security company found it. Security companies have been finding holes in Mac OS X since version 10.0. So this isn't new. If it were script kiddies, the discovery would have been by people noticing their computers were compromised (like last weeks' trojan).

What is new is the attention it gathers and the implied risk. I say "implied" risk because it seems like more malicious users are eyeing OS X as a target. I have no facts on that, though. One just assumes it because OS X seems to be more popular. But I do believe it to be false.

For career "black hats", the only appeal of OS X right now is when it is used for an important purpose, like a websesrver as most career bad guys either want thosands of compromised machines (which is only available by targeting Windows) or key machines.

And AFAIK, there is nothing that takes advantage of the hole anyway. In fact, I shouldn't have titled the thread "exploit" as there is no exploit yet. I'll change it to "hole".

I mainly posted this to get Mac users out of the "we are invulnerable" mind set and get them to learn safe computing practices. Like don't download anything/everything and make sure a person you know sent you that file rather than a bot or an impersonator.

And of course, until Apple comes out with a security update, you might want to be extra careful too.

Posts: 1209 | Registered: Dec 2003  |  IP: Logged | Report this post to a Moderator
twinky
Member
Member # 693

 - posted      Profile for twinky   Email twinky         Edit/Delete Post 
There's an obvious pun on this thread title that I'm not going to make. [Wink]
Posts: 10886 | Registered: Feb 2000  |  IP: Logged | Report this post to a Moderator
human_2.0
Member
Member # 6006

 - posted      Profile for human_2.0   Email human_2.0         Edit/Delete Post 
Where's your mind twinky? [Big Grin]
Posts: 1209 | Registered: Dec 2003  |  IP: Logged | Report this post to a Moderator
Ela
Member
Member # 1365

 - posted      Profile for Ela           Edit/Delete Post 
http://secunia.com/advisories/18963
Posts: 5771 | Registered: Nov 2000  |  IP: Logged | Report this post to a Moderator
xxsockeh
Member
Member # 9186

 - posted      Profile for xxsockeh   Email xxsockeh         Edit/Delete Post 
quote:
If it were script kiddies, the discovery would have been by people noticing their computers were compromised (like last weeks' trojan).
What do you mean, last weeks' trojan? My friend complained about his computer being infected with one, and I haven't seen him on since that day. Do you know what it's called, or have any info. on it?
Posts: 63 | Registered: Feb 2006  |  IP: Logged | Report this post to a Moderator
human_2.0
Member
Member # 6006

 - posted      Profile for human_2.0   Email human_2.0         Edit/Delete Post 
http://www.hatrack.com/cgi-bin/ubbmain/ultimatebb.cgi?ubb=get_topic&f=2&t=041500
Posts: 1209 | Registered: Dec 2003  |  IP: Logged | Report this post to a Moderator
human_2.0
Member
Member # 6006

 - posted      Profile for human_2.0   Email human_2.0         Edit/Delete Post 
quote:
Originally posted by Ela:
http://secunia.com/advisories/18963

Oh, I guess this guy found the hole.
Posts: 1209 | Registered: Dec 2003  |  IP: Logged | Report this post to a Moderator
Ela
Member
Member # 1365

 - posted      Profile for Ela           Edit/Delete Post 
quote:
Originally posted by human_2.0:
quote:
Originally posted by Ela:
http://secunia.com/advisories/18963

Oh, I guess this guy found the hole.
Yes, that seems to be the case.
Posts: 5771 | Registered: Nov 2000  |  IP: Logged | Report this post to a Moderator
   

   Close Topic   Feature Topic   Move Topic   Delete Topic next oldest topic   next newest topic
 - Printer-friendly view of this topic
Hop To:


Contact Us | Hatrack River Home Page

Copyright © 2008 Hatrack River Enterprises Inc. All rights reserved.
Reproduction in whole or in part without permission is prohibited.


Powered by Infopop Corporation
UBB.classic™ 6.7.2