Clan x86

Technical (Development, Security, etc.) => General Security Information => Topic started by: iago on February 25, 2006, 03:19:40 AM

Title: OS X on the radar of exploit-developers
Post by: iago on February 25, 2006, 03:19:40 AM
http://isc.sans.org/diary.php?storyid=1145

Getting scary! 

Of course:
QuoteThe recent news of these vulnerabilities in the OS is getting plenty of attention.  [...]  I think there is some lazy journalism, and sensationalism afoot.  Yet, like any FUD-storm there is usually some kernel of truth. 
Title: Re: OS X on the radar of exploit-developers
Post by: Ergot on February 25, 2006, 03:38:33 AM
Mmm I read about two of those vulnerabilities, both seem rather hard to pull off though.
Title: Re: OS X on the radar of exploit-developers
Post by: deadly7 on February 25, 2006, 09:25:29 AM
Yeah.  They don't seem very easy to pull off.

There's an exploit I've seen with Safari that allows a user to basically "rootkit" you, for the lack of a better word.  Basically the person gains complete access to your computer just because you visited a website via Safari.
Title: Re: OS X on the radar of exploit-developers
Post by: Warrior on February 25, 2006, 09:44:33 AM
It's going to get pummeled by exploits, think about it: Apple has never had experience with being "under the scope" of hackers so to say. It should be interesting to see how it fares against how XP fairs (Seriously, it isn't hard to fare better)
Title: Re: OS X on the radar of exploit-developers
Post by: iago on February 25, 2006, 11:38:02 AM
It's hard to say.  OS X was designed with security as a forethought rather than as an afterthought, so I think it could fair pretty well. 
Title: Re: OS X on the radar of exploit-developers
Post by: Nate on February 27, 2006, 09:38:08 PM
Increasing Market Share will result in an increase in security issues.  Also targeting college students for your product is going to result in problems.

Anyways im waiting for the virus that corrupts iPods.
Title: Re: OS X on the radar of exploit-developers
Post by: Sidoh on February 27, 2006, 09:40:58 PM
Quote from: Nate on February 27, 2006, 09:38:08 PM
Increasing Market Share will result in an increase in security issues.  Also targeting college students for your product is going to result in problems.

Not necessarily.  I don't see anyone exploiting Google.
Title: Re: OS X on the radar of exploit-developers
Post by: iago on March 09, 2006, 10:55:04 PM
Quote from: Sidoh on February 27, 2006, 09:40:58 PM
Quote from: Nate on February 27, 2006, 09:38:08 PM
Increasing Market Share will result in an increase in security issues.  Also targeting college students for your product is going to result in problems.

Not necessarily.  I don't see anyone exploiting Google.

There are actually a lot of exploits involving Google + other sites.  There was a recent worm spreading that used Google to find vulnerable hosts.  A guy at work had the book Google Hacking for Penetration Testers (http://www.amazon.ca/exec/obidos/ASIN/1931836361/qid=1141963569/sr=8-1/ref=sr_8_xs_ap_i1_xgl/701-6030488-6538751).  I flipped through it and it looked like a hell of a good read, but I never got around to reading it. 

My point is that although Google isn't directly targetted, some of its "weaknesses" are indirectly used. 
Title: Re: OS X on the radar of exploit-developers
Post by: Sidoh on March 09, 2006, 11:00:27 PM
Quote from: iago on March 09, 2006, 10:55:04 PMThere are actually a lot of exploits involving Google + other sites.  There was a recent worm spreading that used Google to find vulnerable hosts.  A guy at work had the book Google Hacking for Penetration Testers (http://www.amazon.ca/exec/obidos/ASIN/1931836361/qid=1141963569/sr=8-1/ref=sr_8_xs_ap_i1_xgl/701-6030488-6538751).  I flipped through it and it looked like a hell of a good read, but I never got around to reading it. 

My point is that although Google isn't directly targetted, some of its "weaknesses" are indirectly used. 

Hehe, I heard about those.  I misused the word "exploit."
Title: Re: OS X on the radar of exploit-developers
Post by: iago on March 09, 2006, 11:14:12 PM
Quote from: Sidoh on March 09, 2006, 11:00:27 PM
Hehe, I heard about those.  I misused the word "exploit."

Welll, in a way.  I was kind of taking the word "exploit" to have a different meaning than you intended it to.  I realized I was doing it, but I still thought it was useful to point out. 
Title: Re: OS X on the radar of exploit-developers
Post by: Joe on March 10, 2006, 04:52:54 PM
Quote from: iago on March 09, 2006, 10:55:04 PM
Quote from: Sidoh on February 27, 2006, 09:40:58 PM
Quote from: Nate on February 27, 2006, 09:38:08 PM
Increasing Market Share will result in an increase in security issues.  Also targeting college students for your product is going to result in problems.

Not necessarily.  I don't see anyone exploiting Google.

There are actually a lot of exploits involving Google + other sites.  There was a recent worm spreading that used Google to find vulnerable hosts.  A guy at work had the book Google Hacking for Penetration Testers (http://www.amazon.ca/exec/obidos/ASIN/1931836361/qid=1141963569/sr=8-1/ref=sr_8_xs_ap_i1_xgl/701-6030488-6538751).  I flipped through it and it looked like a hell of a good read, but I never got around to reading it. 

My point is that although Google isn't directly targetted, some of its "weaknesses" are indirectly used. 

I don't know if you'd consider this harmful, but there used to be a tool that would mount your Gmail account as a local hard drive and allow you to save files on to it, in the form of attachments.
Title: Re: OS X on the radar of exploit-developers
Post by: iago on March 10, 2006, 05:28:01 PM
I don't think that's an exploit in any way.  I'd be surprised if Google did anything about it.  In fact, Google is planning (maybe beta-testing? I forget) a program called GDrive, I think, which lets you store your files on Google.