Apple Still Hasn't Fixed Major OS X Security Flaw

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
A security flaw in a flawless operating system that, despite being "fixed," still isn't fixed. Think different indeed. ;)

Earlier this month, Apple released an update that was supposed to patch a serious flaw in OS X, albeit only for Yosemite users. But, according to a recent report by an independent researcher, the company from Cupertino failed to fix the problem.
 
It sounds like regardless, the "hacker" has to get access to the users environment to actually do this. Meaning you have to be able to open a command tool as the user.

The overall hack is built on the idea of using a system call to generate a file (any file) which has the "s" setuid bit, which if you are not familiar with Unix/Linux is a special attribute that allows a binary owned as root to be executed by anyone as if root is executing it.

It's a huge security risk in Unix & Linux as well, by the nature of the S bit. The very purpose of the S bit is to allow nefarious stuff, but usually in a practical way.

This is almost like saying I have found a *SERIOUS* security flaw in Windows because if I get access to the desktop environment I can run anything as Superuser by simply hitting continue on the UAC dialog box.
 
Back
Top