[Full-disclosure] Re: Re: Question about Mac OS X 10.4 Security



Paul Schmehl wrote:
--On Thursday, March 02, 2006 08:57:18 +1100 mz4ph0d@xxxxxxxxx wrote:

Sorry to spoil everyone's fun.
<http://docs.info.apple.com/article.html?artnum=303382>

Maybe, just maybe, Apple are actually better (able/positioned) to
respond quickly to vulnerabilities before the exploits in-the-wild
affect more than 50 people? Who knows.

It doesn't look like it. They seem to have addressed the
vulnerability as it applies to Safari, but not the underlying
vulnerability.

I don't know how you deduce that Z was referring to the Safari problem(s),
I thought it might have been the one about the mailer failing to warn for
some unsafe attachment types.

If I send you an email, with a zip attachment (naming
and extension is irrelevant), and I can get you to attempt to open
the attachment (fairly trivial with many users), I can execute
abitrary code on your machine. The only "restriction" is that, if I
attempt to execute code that requires admin privileges, I'd have to
convince you to type in your password (again, fairly trivial for most
users.)

Exactly. Some of the most successful viruses recently have arrived inside
encrypted zip files, with a GIF as an attachment, that contains a password
in graphical format, and the user has to open the gif attachment and note
down the password and open the zip and enter the password and extract the
executable and run it.

And they /did/, in their droves.

No matter what kind of protection Apple put in place, no matter how
quickly they fix drive-by-install vulnerabilities, no matter how big the
warning dialog that mail pops up when it detects executable files and even
if it isn't spoofable - people will still do it.

cheers,
DaveK
--
Can't think of a witty .sigline today....



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: Can just opening a winzip file introduce virus?
    ... sp1 are indeed vulnerable to foreign code being run simply by ... to the older described vulnerabilities I posted links to. ... recent vulnerabilities were discovered by the WinZip company themselves, ... >>foreign code could execute. ...
    (alt.comp.anti-virus)
  • [Full-disclosure] [ GLSA 200710-31 ] Opera: Multiple vulnerabilities
    ... Opera contains multiple vulnerabilities, ... execute arbitrary code with the privileges of the user running Opera by ...
    (Full-Disclosure)
  • [ GLSA 200409-09 ] MIT krb5: Multiple vulnerabilities
    ... MIT krb5 contains several double-free vulnerabilities, ... The implementation of the Key Distribution Center (KDC) and the MIT ... The double-free vulnerabilities could allow an attacker to execute ... arbitrary code on a KDC host and hosts running krb524d or vulnerable ...
    (Bugtraq)
  • [Full-Disclosure] [ GLSA 200409-09 ] MIT krb5: Multiple vulnerabilities
    ... MIT krb5 contains several double-free vulnerabilities, ... The implementation of the Key Distribution Center (KDC) and the MIT ... The double-free vulnerabilities could allow an attacker to execute ... arbitrary code on a KDC host and hosts running krb524d or vulnerable ...
    (Full-Disclosure)
  • [ GLSA 200409-09 ] MIT krb5: Multiple vulnerabilities
    ... MIT krb5 contains several double-free vulnerabilities, ... The implementation of the Key Distribution Center (KDC) and the MIT ... The double-free vulnerabilities could allow an attacker to execute ... arbitrary code on a KDC host and hosts running krb524d or vulnerable ...
    (Full-Disclosure)