RSS RSS Twitter Twitter
apple news/media reports

07/17/2007, 9:45am, EDT

Tuesday, July 17th

New worm developed for Mac OS X?

An independent coder claims to have developed a new worm for Mac OS X computers. An unnamed, proof-of-concept project, the worm exploits a variation of the mDNSResponder vulnerability recently addressed by Apple -- if not completely, according to the coder. Once an attack is successful, the worm grants remote root access, and places a text file on the desktop before moving on to other systems in the same network. Theoretically, an improved version could be a serious threat, randomly attacking networks across the world and depositing malcious software instead of text.

The writer of Information Security Sell Out, however, says he has merely tested it on local systems and will eventually share his information with Apple, so that the vulnerability can be fixed. Part of his stated goal is to dispel notions that Mac OS X is somehow more secure than Windows, an aim shared with many current security commentators.


Filed under: Apple

, , 24comments, del.icio.us, slashdot, digg, buzz , Twitter



24 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
Worm?
0
07/17, 10:01am, EDT
Any info on how this "worm" wold be able to spread?
Fresh-Faced Recruit
Joined Nov 2006
User is offline
Another Theory more FUD!
0
07/17, 10:02am, EDT
Another theory and more FUD! What does it prove? Absolutely NOTHING.
Fresh-Faced Recruit
Joined Apr 2002
User is offline
Somehow?
0
07/17, 10:10am, EDT
"Part of his stated goal is to dispel notions that Mac OS X is somehow more secure than Windows."

Well if he could "somehow" create a website that I could visit, and just by going there I become part of a botnet, maybe THEN he can start dispelling notions. Until then this is just more FUD piled on to the mountain of FUD already created.
Fresh-Faced Recruit
Joined Dec 2002
User is offline
????
0
07/17, 10:20am, EDT
Next headline for macnn?

Microsoft stock to reach $1,000,000 per share? gskibum3 sells one of his Ferraris?

What is with these headlines ending in question marks?

Isn't that inane?

???
Fresh-Faced Recruit
Joined Nov 2006
User is offline
be careful..
0
07/17, 10:23am, EDT
..what you wish for.
Fresh-Faced Recruit
Joined Jan 2006
User is offline
blah blah blah??
0
07/17, 12:56pm, EDT
actually no 'worm' here at all, just a hack to create a 'root' user, all one would need to do is have the OSX firewall turned 'on' and the mac would not respond to the 'dnsresponder' request at all... duh

what's wrong been running your mac again sans firewall?? don't ware seatbealts?? running with siccors again??

if your so conserned about security I'd think you would at least turn on the firewall... which sits on the mackernel and setup a non-admin user to surf the net with if your paranoid... keep your cash under the mattress and keep your front door unlocked and you too will find the milkman in bed with your teenager daughter... ugly thought

...who's the brilliant hacker this time??

can you say 'looser' in french??
Fresh-Faced Recruit
Joined Jan 2007
User is offline
re: blah blah blah??
0
07/17, 1:26pm, EDT
Where to start?

First - don't berate others for not using a firewall when you don't know enough to use a spell-checker if your spelling sucks.

The firewall does *not* sit on the Mach Kernel. It is a separate process, and most folks will not enable it, because Macs are "more secure".

mDNSResponder is a key and low-level part of the OS - it is what enables Bonjour discovery of services. Read http://developer.apple.com/networking/bonjour/faq.html for more. It is unlikely that your average user will know how to set up the firewall to block it. I'm fairly certain you don't.

It is unclear to me whether this worm would be limited to local networks, as bonjour and mDNSResponder is - it has the ability to do Unicast over the internet but I'm not certain that's enough for a worm to propagate. Even if it can, I'm not certain how it would create a root user for those who have not enabled it. If both of these are true, then this is a serious and huge vulnerability. In any case, it's definitely something worth taking seriously until disproven.

And it's 'loser', not 'looser'. In French it's roughly translated as 'hokizpokis est un cretin'.
Mac Enthusiast
Joined Sep 1999
User is offline
Not Professional
0
07/17, 1:28pm, EDT
While I believe my Mac is much more secure than Windows, I also understand that it's not invulnerable. Some of these coders who are bound and determined to expose security flaws in OS X claim to be part of professional services groups. If that's really the case, then they'll work with Apple to close any holes before they can be exposed in the wild.
Fresh-Faced Recruit
Joined Feb 2000
User is offline
Here we go again!
0
07/17, 1:52pm, EDT
"Part of his stated goal is to dispel notions that Mac OS X is somehow more secure than Windows, an aim shared with many current security commentators."

Even if this were true, here is the score.

Mac OS X = 1 Window = 110,000+

Yep, looks pretty close to me, I guess the Mac is just as unsecure as Windows!
Fresh-Faced Recruit
Joined Mar 2006
User is offline
firewall
0
07/17, 2:01pm, EDT
And why doesn't apple turn the firewall on by default, anyways?
Fresh-Faced Recruit
Joined Aug 2001
User is offline
additional comments:..1..2..Next
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News
Want To Sell Your Laptop? Any Condition - receive Top Cash. Get an instant quote. Free shipping www.CashForLaptops.com

Internet Marketing School - 100% Online: Master SEO, SEM, E Commerce, Media & More with a U of San Francisco Certificate.

Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.