YOUR IT - Technology for you

No. 1 Story

Cloud alliance sides with Optus on copyright

OzHub, the Macquarie Telecom-led cloud computing alliance, has come down firmly on the side of Optus over the copyright controversy surrounding Optus TV Now, warning that any moves to change the law "risk branding Australia a global luddite state."

read more

'Apple Bugs' tussle gets snippy

Your IT - Home IT

Day 8 of the Month of Apple Bugs brings what appears to be a personal attack on one of the team that has voluntarily taken on the task of providing interim fixes.

The flaw utilised is that the standard permissions on the /Library/Frameworks folder allow an admin user (eg the default account created when Mac OS X is first set up) to gain root privileges without authenticating. Today's exploit uses this to give root privileges to Application Enhancer, which it then patches to provide a persistent backdoor into the affected system.

Using Unsanity's Application Enhancer for the proof of concept is an interesting choice. Not only is it the software used by the MoAB Fixes team to deliver several of its patches, but Rosyna Keller - a tech support person at Unsanity - is a member of MoAB Fixes and spoke out against the suggested coordination between the two groups.

In a blog posting subtitled "The Month of Trolly Trolls and Trolli Gummy Bears" on Unsanity's site, Keller suggested the Month of Apple Bugs was "being put on by someone with a severe need for attention."

In turn, today's MoAB disclosure by LMH and Johnny Pwnerseed states "If the developers [of Application Enhancer] have left a binary executed with root privileges at an user-writable path, they are certainly capable of doing other non-sense" and refers to "a jackass third-party which has no security background at all and spends more time flaming and insulting on a delusional IRC channel than on real work".

The workaround suggested by LMH and Johnny Pwnerseed is to "Stay away from Application Enhancer", however that would appear to leave the potential for similar exploits of other applications that put components into /Library/Frameworks. MoAB Fixes offers a more general workaround that changes to privileges on that folder. That change is easily reversed, but no guidance is given about when that might be necessary, and in any case repairing permissions will reset the privileges to their original state.

Loading comments ...

- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more