troubleshooting/tutorials/security

05/12/2005, 3:20pm, EDT

Thursday, May 12th

New security vulnerability threatens Tiger

A security vulnerability in Mac OS X 10.4 Tiger allows a malicious .mov file to leak information to an external host. The exploit, which was discovered by David Remahl in Sweden, takes advantage "compositions," which have access to powerful tools known as "patches." Combining patches that provide advanced system information with patches that load information from the Internet allows an embedded .mov file to leak system details. A temporary workaround includes disabling the QuickTime plug-in and treating Quartz Composer files with suspicion. An alternative workaround involves disabling QTZ support in QuickTime by removing QuartzComposer.rcomponent in the QuickTime section of the system Library.

Leaked information:

  • Local user name (long and short)
  • Computer name
  • Local IP
  • OS / kernel version
  • CPU / RAM / GPU configuration
  • Names (human-readable) of Bonjour services on the local network
  • Local or system time
  • Volume of audio input
  • Lists of images (including pdfs) matching arbitrary spotlight queries
  • Lists of images (including pdfs) in specific directories (relative to / or ~)
  • The existence of image and movie files can indicate the existance of certain software packages


    Filed under: troubleshooting

  • , , 19comments, del.icio.us, slashdot, digg, buzz


    19 comments
    Reader Reactions (Please use <i></i> for italic text)

    subscribe to comments
    for this article




    Expand All   Global Settings
    Another exploit please!
    0
    05/12, 3:50pm, EDT
    Unlike the Dashboard vulnerability, this ones seems a bit more concerning. However, I am once again confident Apple will patch this very fast. They have always been quick to respond, and I doubt this will be any different.

    Everytime I see one of these exploits, I think of hearing on the news about a critical Windows XP update that Microsoft released for an exploit that was found six months prior to the fix.

    No OS is going to be perfect but at least Apple seems to always be on their toes with Security patches and updates.

    Fresh-Faced Recruit
    Joined Oct 2003
    User is offline
    its beginning...
    0
    05/12, 3:51pm, EDT
    to look a lot like windows with all this security ca ca going on
    Fresh-Faced Recruit
    Joined Sep 2002
    User is offline
    Well done..
    0
    05/12, 3:59pm, EDT
    Another security alert that needn't have been announced in such a way that it pretty much tells unscrupulous people who were not previously aware of it, exactly how to do it!
    Grizzled Veteran
    Joined Jun 2001
    User is offline
    agreed
    0
    05/12, 4:08pm, EDT
    They could have been a little less clear on the details, all right.
    Fresh-Faced Recruit
    Joined Jan 2002
    User is offline
    But is it fatal
    0
    05/12, 4:37pm, EDT
    The info is leaked, yes. That isn't good.

    But, it is fairly innocuous info… it isn't like an apple script co-opting Mail and spamming the 'verse.

    Here is hoping it is still addressed in short order.

    OS X security flaw = Headlines WIn Security flaws = Little Notice

    T
    Senior User
    Joined Sep 2003
    User is offline
    show and tell
    0
    05/12, 4:38pm, EDT
    What's with show and tell. If I find a security issue I call apple and tell them. I also log it with apple's bug reporting. That's at the very least. I don't post anything about it in public for a good 2 weeks. Making a website to demo something, like the widget one, or this kind of report is negligent. If you tell people how to circumvent the security of a system and they do it you are responsible for it, regardless of how we define 'responsible'. In short, this kind of stuff (that almost seems orchestrated) will make the people doing wish that I had never been born if they come face to face with me.
    Fresh-Faced Recruit
    Joined Jul 2000
    User is offline
    isn't fatal??
    0
    05/12, 4:39pm, EDT
    Leaked username and password might be considered fatal to some.
    Fresh-Faced Recruit
    Joined Jul 2000
    User is offline
    Re: isn't fatal??
    0
    05/12, 4:49pm, EDT
    Where is there any mention of a leaked password?
    Fresh-Faced Recruit
    Joined Feb 2005
    User is offline
    RE:isn't fatal??
    0
    05/12, 4:53pm, EDT
    Crevatis is right, no mention of passwords anywhere...
    Fresh-Faced Recruit
    Joined Jan 2002
    User is offline
    isn't fatal??
    0
    05/12, 4:55pm, EDT
    No mention of leaked password at all. It provides basic information about the computer and various user accounts to someone who may be interested in breaking into it. That information would make it easier (than blindly guessing) to target the machine for a break-in but it would still require more effort.
    Fresh-Faced Recruit
    Joined Oct 2002
    User is offline
    additional comments:..1..2..Next
    Your Comments

    In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


    Registered Member?
    macnn forums login:

    macnn forums password:

    Not a member of the MacNN forums? Register now for free.

    RSS Feeds

    Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



      MacNN -all

      MacNN Reviews

      MacNN Podcasts

      iPodNN

      Electronista

      Left Lane News
    Turn your laptop into CASH: Sell us your used laptop. Working or not. Get money FAST. Instant online quote. Shipping is FREE.

    Check Out the VIERA from Panasonic!: Enter a New Visual Era with Panasonic VIERA HDTVs. An Enhanced Experience.

    CNC Tooling 2-Year Warranty: Mori Seiki, Daewoo, Nakamura, Okuma, Eurotech, Mazak, Collets, Chucks.

    Electrical Cable Tie, Tie Wrap, Zip Tie: Electrical Cable Tie, Tie Wrap, Zip Ties Tie-wraps, Cable Tie, cable bundling, electrical fastening, miniature tie-wraps, standard Cable Tie, heavyduty tie-wraps, heavy duty & extra heavy.

    Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.