Newsletters

Select newsletters below and click the button to sign up!

Boston News NY News
DC News Internet Daily
SiliconValley News
InternetNews Business Report




Become a Marketplace Partner



Partner With Us















Internetnews Bloggers

Recent Entries

Archives

April 2009
Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    

Monthly Archives

Search The Blog

Netstat -vat by Sean Michael Kerner (bio)

A command line view of IT



Black Hats hack Macs

blackhat.jpg
From the "security by obscurity doesn't work" files:

LAS VEGAS -- Though Apple isn't officially presenting at Black Hat, Apple is definitely in the crosshairs of security researchers.

In a session given by famous security researcher Petko D. Petkov, attendees were told about how a particular Apple QuickTime URI handling flaw was discovered. Petkov  also gave the audience a tip, that there are plenty more Zero Day bugs to be found for other researchers who concentrate on looking at applications that will accept addresses that then trigger a file protocol URI function.

Ever heard of Mac OS X rootkits?


Neither had I, but I sat in part of a session in wish Jesse D'Aguanno talked about his MAC OS X rootkit called iRK.  From the part of the talk that I saw it sure looked like the real deal to me, but of course to get a rootkit onto a  Mac (to do whatever damage you want) you have to have root.

So I skipped out on the rootkit session halfway to sit in on another session about reverse engineering on the Mac OS X. Tiller Beauchamp and David Weston gave a revised version of their talk from Black Hat DC about using Dtrace as a tool for security research. This time out their tool is called Re:Trace and it's in Ruby and targets the Mac.

"You can fuzz an application and easily find all the places that are vulnerable to heap overflow," Beauchamp said. "Then we could figure what parts would be susceptible to arbitrary code execution."

So no, there were no major exploits for Apple actually revealed at Black Hat, but it sure looks to me like researchers are looking.

| Comments (1) | TrackBacks (0) | Share

0 TrackBacks

Listed below are links to blogs that reference this entry: Black Hats hack Macs.

TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/4326

1 Comments

ex2bot said:

Ok, I'll bite.

This is from the "security through obscurity + good old Unix robustness has worked for seven years now" department. (I know, I know, as the Mac gets more popular . . . Any day now.)

We Mac users have been enjoying virtually no malware for the last 8 years.

Why virtually no malware? The

Virtually no malware threat. No antivirus or antispyware needed (unless one uses Office macros). No system lag from security software. And despite the fact that Macs are becoming more popular, they'll likely not become nearly as popular as Windows. Therefore not nearly the malware problem in the foreseeable future.

Not even close.

Bot
Mac fanbot

Leave a comment