Welcome | Sign In
LinuxInsider.com
Internet

Mac OS X Flaw Exposes Safari Users

Print Version
E-Mail Article
Reprints
Mac OS X Flaw Exposes Safari Users

The Month of Apple Bugs continues as researchers discovered a vulnerability in Mac OS X that allows hackers to hijack computers running Apple's Safari Web browser. The vulnerability, which impacts Mac OS X 10.4.8 and possibly earlier versions, has been confirmed by other Internet security firms along with a proof of concept code that the project has also released.


Researchers have discovered a serious vulnerability in Mac OS X that allows hackers to hijack computers running Apple's (Nasdaq: AAPL) Safari Web browser.

The flaw was uncovered as part of the Month of Apple Bugs project, which kicked off at the beginning of the month with the goal of discovering one vulnerability or flaw per day. Thus far, the researchers have uncovered 10 or so flaws.

Apple's operating system vulnerability, which impacts Mac OS X 10.4.8 and possibly earlier versions, has been confirmed by other Internet security firms along with a proof of concept code that the project has also released.

The vulnerability is caused due to an integer overflow error in the "ffs_mountfs()" function when handling UFS (Unix file system) disc images, according to an advisory by Internet security firm Secunia. This can be exploited to cause a heap-based buffer overflow via a specially crafted UFS DMG image, Secunia noted, allowing the execution of arbitrary code.

Some Good News

The good news is that users can rid their systems of the vulnerability, Patrick Hinojosa, CTO of CyberDefender, told MacNewsWorld. "Users can disable the setting as a work around until a patch is released."

The vulnerability is only remotely exploitable when the "opening safe files after downloading" option is enabled, Secunia reported. However, Hinojosa said, "Anything automated like that isn't well secured. This type of feature should always require a user prompt."

This newly discovered flaw adds to a growing body of evidence that Apple's computer products may not be as secure as once thought.

Last year, the company's reputation took a hit when the first Mac-specific worms began circulating on the Internet, at least one of which unveiled another vulnerability in Safari.

Hackers and malware creators have largely concentrated their efforts on circumventing Windows. However, as Mac's market share increases, especially among corporates, this is changing.

New Users Most Vulnerable

Apple's once spotless image as a secure computing environment will mean that these newer users -- as opposed to its hard-core, consumer-savvy base -- will be even less likely to have appropriate protections in place.

"It is part of a continuing trend," Hinojosa noted. "I have seen more hackers probing OS X far more often than in previous years."

Despite Apple's market share gains, its overall presence among consumers remains very small -- a still less-than-tempting target for hackers.

Instead of generating mass worms, Hinojosa speculated, hackers are more likely to target Apple-specific sites. "That would be the most efficient way of exploiting this user base," he claimed.

A vulnerability in any operating system -- be it OS X or Windows -- is a serious exposure, Kaspersky Lab's Senior Technical Consultant Shane Coursen told MacNewsWorld.

"The flaws themselves are rated or accessed individually. That doesn't change Apple's position though -- it is an OS provider and like any other OS provider today is vulnerable to attack," he stated.

Responsible Disclosure

So far, about 10 vulnerabilities have been uncovered in Apple's products this month, and more are expected to be announced over the next two weeks. Month of Apple Bugs was launched by independent security researcher Kevin Finisterre and another researcher identified only as LMH.

Their goal, they stated, is to highlight vulnerabilities in Apple's products, especially as the company is not as forthcoming as it might be. This complaint has been voiced before about Apple by some Internet security providers.

At the same time, however, many in the Internet security industry are aghast at the road map to the discovered vulnerabilities the researchers are providing hackers.

Kevin Finisterre's Month of Apple Bugs is a continuation of attempts to raise the profile of the full disclosure versus responsible disclosure debate in the Internet security industry, Symantec (Nasdaq: SYMC) noted in a statement. Symantec has always followed responsible disclosure practices and believes it is the best way to serve its customers and to protect the computing public.


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Windows 7 Flies Off the Shelves
November 06, 2009
Early sales figures on Windows 7 boxed software suggest a high level of consumer enthusiasm for the OS. Unit sales were a whopping 234 percent higher than Vista's out of the gate. The revenue haul was not as impressive, as Microsoft offered sharp discounts to spur presales. Also, sales of PCs with Windows 7 preinstalled have been lackluster -- but October is historically a weak month for PC sales.
Southwest Doesn't Fool Around
November 06, 2009
Either Southwest Airlines had better deals for my favorite route than its competitors or its superior Web site tools made it easier for me to ferret them out. Either way, kudos to Southwest. In the not-so-hot department were the airline's long list of what passengers weren't allowed to do and its very short list of what Southwest was obliged to do for them. Left me feeling a little chilly.
Commerce Search Puts Google Inside Retailers' Catalogs
November 05, 2009
Google has launched a new cloud-based search tool targeting enterprise-level e-commerce operations, just in time for the 2009 holiday selling season. Commerce Search provides a set of features designed to improve the relevance of results for consumers searching a retailer's own product catalog, while boosting cross-selling opportunities.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network