On CBS MoneyWatch: Best Stocks to Buy Now
BNET Business Network:
BNET
TechRepublic
ZDNet

March 14th, 2007

Apple bumper patch vindicates MOAB, MOKB hackers

Posted by Ryan Naraine @ 7:22 am

Categories: Apple, Browsers, Data theft, Exploit code, Firefox, Hackers, Hirings and firings, Microsoft, Mozilla, Patch Watch, Responsible disclosure, Vulnerability research, Windows Vista

Tags: Apple Computer Inc., Security, Apple Macintosh, Hacker, Ryan Naraine

In Focus » See more posts on: Apple Security

When the controversial Month of Apple Bugs (MOAB) project ended earlier this year, a derisive "that was it?" reaction could be heard coming from the Mac faithful.

Outside of a QuickTime code execution exploit (which required user interaction), the majority of the MOAB vulnerabilities released dealt with denial-of-service crashes and privilege escalation bugs, prompting the dismissal of the project as a failed publicity stunt.

But, a close look at Apple's latest batch of bumper patches provides total vindication to LMH and Kevin Finisterre, the two hackers who went against the grain and called attention to serious defects in code coming out of Cupertino. Same goes for the researchers who participated in last November's MOKB (Month of Kernel Bugs), a sister project that highlighted kernel-level vulnerabilities in various operating systems, including Apple's flagship Mac OS X.

Apple's 2007 patch count is an eye-opener. Seven updates, 62 vulnerabilities.

Yesterday's bumper Security Update 2007-003 provided fixes for a whopping 45 security bugs affecting Mac OS X users.

The biggest takeaway from Apple's advisories since last November is the patches that address flaws found during the MOKB and MOAB disclosure projects. More importantly, in the brief notes in Apple's public bulletins, the company is making it clear that many of the MOKB/MOAB flaws were "high risk" issues that could lead to arbitrary code execution attacks. Very serious issues.

It's refreshing to see Apple reacting to those projects and getting fixes out in a timely manner, even crediting the MOKB/MOAB hackers in its bulletins but there's a lot of work to be done at Apple if the security reality is to match those Mac commercials.

Apple's marketing department gets a kick out of kicking sand in Microsoft's eye on security but, truth be told, Apple has a long way to go to match Redmond's seriousness around security. This is an issue that was raised almost a year ago by Microsoft's Stephen Toulouse and it's worth repeating.

Here are five recommendations that spring to mind:

1. Apple desperately needs a security czar to who is empowered to face the reality that there are serious problems with its code quality. When the first batch of code execution holes affecting Windows Vista comes from code created by Apple, those Mac commercials start to look rather silly. A job listing spotted by CNET's Robert Vamosi offers evidence that Apple is looking for a "security expert" to "help provide guidance on security topics to all groups across Apple, and help teams design security into new cutting-edge features and technologies." Hopefully, this is a high-level position (a la Window Snyder at Mozilla) with the power to make meaningful changes.

2. Apple needs to fix its patch release process and beef up the information in its advisories. It looks like they're on a monthly patch schedule but, who knows? I know it sounds sacrilegious to say Microsoft is a perfect example to copy but, roll your eyes all you want, it's the plain old truth. Set up a monthly patch release schedule — I say piggyback on Microsoft's and make it easy for admins to plan/prepare for patches — and start adding mitigations in the bulletins for customers who might not be able to patch immediately.

3. The bulletins need a makeover. In addition to mitigations and workarounds, the bulletins need a clearly marked severity rating. Adopt CVSS and add those severity scores alongside a color-coded scheme to let the average end user understand the risk. If your customers are at risk, you have a responsibility to let them know in an upfront, honest manner.

4. Apple is in the ThreatCode hall-of-shame because of serious warts in its patch deployment process. Read this lament from an IT administrator to see just how frustrating it is to apply a QuickTime patch in a Windows environment. If you're still not sold on how bad things are, check this and this. These are real, legitimate issues that need fixing. If you're deploying a patch, it needs to be a painless, automatic process for every customer, even if they're on a Windows box.

5. Why is there an "iPod Service" always running as LocalSystem on my mom's Windows XP machine? She doesn't own an iPod. If there's a security flaw in that service (MOAB proves that they do exist if you look hard for them), Apple would have put my mom at needless risk. Apple's security people should be recommending that these automatic services be unbundled from QuickTime and iTunes.

And a bonus:

6. A PR person that doesn't respond to media queries on legitimate security issues is a disservice to any company. Apple's weakness here tops the list.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 247 Talkback(s)
Apple Vs PC's
Good anecdotal evidence on the Dell pc, had mine for 4 years running every day 12 hours a day and one problem with the power cord. Inspiron 1100. Best bargain ever especially since the mac I was look... (Read the rest)
Posted by: littlewing Posted on: 04/03/07 You are currently: a Guest | | Terms of Use
Ryan, dont be surprised if...  Scrat | 03/14/07
Oooh. Nice.  frgough | 03/14/07
Ohhh...Nicerest  Cayble | 03/15/07
Horses not justified perhaps a cat or something...  Laff | 03/14/07
Haha, well done!!! (nt)  NonZealot | 03/14/07
If you feel compelled to reply  xuniL_z | 03/15/07
Interesting words coming from you.  Hrothgar - PCLinuxOS User | 03/18/07
Pre-emptive zealotry  tic swayback | 03/14/07
Wickedly brilliant.  Cayble | 03/15/07
Why should they be angry?  olePigeon | 03/14/07
FINALLY  shane@... | 03/15/07
And your point is?  chanthing | 03/15/07
Ou jr.  frgough | 03/14/07
So you admit you are a zealot?  NonZealot | 03/14/07
Scat was right  frgough | 03/14/07
Congratulations!  James T. Kirk | 03/14/07
Havent attacked the auther myself but I still don't see  Laff | 03/14/07
I was/am one of thos "that was it" people.  Laff | 03/14/07
The answer remains yes.  frgough | 03/14/07
Thats because you are hardly in the crosshairs.  osreinstall | 03/14/07
yes, of course...  doh123 | 03/15/07
Your logic is quite stupid.  osreinstall | 03/15/07
read again  doh123 | 03/15/07
Why? You are wrong no matter how you rephrase it.  osreinstall | 03/15/07
So when Windows folks argue the same idea, are they zealots?  ajole | 03/14/07
A flaw without and exploit is nothing to be overly concerned about  Cayble | 03/15/07
Sooooo you agree with me?  Laff | 03/15/07
Good question  whisperycat | 03/14/07
LOOK EVERYONE!!@$# HE MENTIONS ME!!  Loverock Davidson | 03/14/07
Yes look everyone , L.D. has been mentioned !  Intellihence | 03/14/07
Hmm, Apple thinks all OSX users are thieves  NonZealot | 03/14/07
Since when did you like LINUX ?  Intellihence | 03/14/07
Zealot's claimed his server(s) is(are) Linux but  MacCanuck | 03/14/07
You have me confused  NonZealot | 03/14/07
You must have him confused with the other user with the same name...lol  jjarman | 03/14/07
FWIW  People | 03/14/07
*ding* *ding* *ding* we have a winner! It's fairly obvious too...  HypnoToad72 | 03/14/07
ipod stats are misleading.  xuniL_z | 03/14/07
Now wait just a minute here....just because others  Laff | 03/15/07
Don't be clueless  xuniL_z | 03/15/07
Clue Impaired  chanthing | 03/15/07
THAT would be an interesting stat...so you are saying  Laff | 03/15/07
You find it odd that smart phones  xuniL_z | 03/16/07
Which chip is it?  Mr_Dave | 03/14/07
Ask and ye shall receive  NonZealot | 03/15/07
Thanks for the link  Mr_Dave | 03/15/07
Totally legal  robbyx | 03/15/07
You misunderstood  NonZealot | 03/15/07
Lock-In Advantage and Mac Pricing  robbyx | 03/15/07
robbyx: price comparisons done to death  NonZealot | 03/15/07
NonZealot: I priced it out, so prove me wrong  robbyx | 03/15/07
Uh, kinda like trying to buy a PC without Windows was in the 90's?  BillyB40 | 03/28/07
You just blew any credability you had to bits. Apples Cost More.  Cayble | 03/15/07
Actually, the opposite has been shown  msalzberg | 03/15/07
You just blew any credability you had to bits. Apples Cost More.  Cayble | 03/15/07
You just blew any credability you had to bits. Apples Cost More.  Cayble | 03/15/07
You just blew any credability you had to bits. Apples Cost More.  Cayble | 03/15/07
You just blew any credability you had to bits. Apples Cost More.  Cayble | 03/15/07
You are the most...  msalzberg | 03/15/07
If you are amoral, buy a Mac?  NonZealot | 03/15/07
I'm sorry, you didn't understand...  msalzberg | 03/15/07
Win Win  robbyx | 03/15/07
running OSX on non Apple isnt exactly a "crack"  doh123 | 03/15/07
doh123: you are right  NonZealot | 03/15/07
you are still wrong  doh123 | 03/15/07
Apple Vs PC's  littlewing | 04/03/07
Apple does not use a TPM chip....  doh123 | 03/15/07
So stupid it's funny  robbyx | 03/15/07
You won't like this reply  NonZealot | 03/15/07
Macs are cheaper, Apple doesn't think you're thief  robbyx | 03/15/07
Message has been deleted.  robbyx | 03/15/07
very wrong  doh123 | 03/15/07
You like Linux?  zkiwi | 03/15/07
30 times a second? Preach FUD much? (NT)  Badgered | 03/14/07
OS X never checks my machine for a TPM chip !  Intellihence | 03/14/07
Tilt Bits  frgough | 03/14/07
How is OSX's support for protected HD content?  NonZealot | 03/14/07
silly  jjarman | 03/14/07
This isn't about MS  NonZealot | 03/14/07
you misunderstood...  jjarman | 03/14/07
jjarman: FUD?  NonZealot | 03/15/07
like i said...  jjarman | 03/16/07
For what it's worth  People | 03/14/07
its not TPM but similiar.  doh123 | 03/15/07
"recipes, email and surfing to the BBC..."  Jack-Booted EULA | 03/14/07
You've only proven one thing  xuniL_z | 03/14/07
Apple doesn't "think" you're a theif  John Zern | 03/14/07
The absence of logic is frightening  robbyx | 03/15/07
Why can't you?  NonZealot | 03/15/07
Get a Mac and get over it  robbyx | 03/15/07
Obviously  NonZealot | 03/15/07
What's with you and freedom?  robbyx | 03/15/07
Your definition of freedom  NonZealot | 03/15/07
What freedom are you talking about?  msalzberg | 03/15/07
I'm FREE to do what I want, any old time  robbyx | 03/15/07
Get over what? A heart attack when the Visa bill comes in.  osreinstall | 03/15/07
No argument  robbyx | 03/15/07
My time is valuable but save $550 for 2 hrs work I cannot pass up.  osreinstall | 03/15/07
Dells may not be much for value, but...  msalzberg | 03/15/07
Windows is the best.  osreinstall | 03/15/07
Gee, try HP  justanitguy | 03/26/07
because  doh123 | 03/15/07
Microsoft and Linux offer you FAR more freedom  NonZealot | 03/15/07
FOR A REASON  robbyx | 03/15/07
wrong?  doh123 | 03/15/07
Mac Experience  morme | 03/15/07
Total vindication?  tic swayback | 03/14/07
Do you think?  ye | 03/14/07
Probably right  tic swayback | 03/14/07
Montlhy patch cycle snake oil  frgough | 03/14/07
Your Bias...  justanitguy | 03/15/07
The Apple obsessed more upset than the Mac zealots  YinToYourYang-22527499 | 03/14/07
It is an odd sickness  tic swayback | 03/14/07
You want sickness, I'll give you sickness  xuniL_z | 03/14/07
A terrorist group that happens to be Muslim does not  Laff | 03/14/07
Are you sure Jimbo?  xuniL_z | 03/14/07
Interesting. I like the line about "lock-in"  John Zern | 03/14/07
you got that right.  xuniL_z | 03/14/07
How many OS's do you actually use? Is it a MS product?  Laff | 03/14/07
What are you blurting out of your mouth now .  Intellihence | 03/14/07
It's called a report from Wired magazine.  xuniL_z | 03/15/07
Very sure....  Laff | 03/15/07
I guess that makes you  xuniL_z | 03/15/07
Lets go from a different angle shall we..but first.  Laff | 03/15/07
Lets go from a different angle shall we..but first.  Laff | 03/15/07
Heard you the first time.  xuniL_z | 03/15/07
Lets go from a different angle shall we..but first.  Laff | 03/15/07
Ok  xuniL_z | 03/15/07
I like Johnny Cash thanks!!!! He's the essence of cool.  Laff | 03/15/07
Sure thing, you remind me so much of a  xuniL_z | 03/15/07
YouTube and some writters with think skin is the total of your  Laff | 03/15/07
Serious?  xuniL_z | 03/15/07
Written off ALL the press? Now you are claiming all the press?  Laff | 03/15/07
What?  xuniL_z | 03/16/07
Takes one to know one  tic swayback | 03/14/07
wait a second here.  xuniL_z | 03/14/07
Not finished  xuniL_z | 03/14/07
I think Tic might be a GOOD Mac zealot!  ajole | 03/14/07
Apparently....  xuniL_z | 03/15/07
Guess you don't read a lot of posts  tic swayback | 03/15/07
I think you are falling into your own trap  xuniL_z | 03/15/07
No way  tic swayback | 03/15/07
huh?  xuniL_z | 03/15/07
Rough count  tic swayback | 03/15/07
huh?  xuniL_z | 03/16/07
Excellent questions  tic swayback | 03/16/07
Excellent reply...however  xuniL_z | 03/16/07
Let he who is without sin throw the first stone  tic swayback | 03/16/07
I will tell you what I already told Laff  xuniL_z | 03/16/07
So why add to it?  tic swayback | 03/16/07
I guess for the same reason you do.  xuniL_z | 03/16/07
Of all the zealots complaining about zealots  MacCanuck | 03/15/07
I remember you.  xuniL_z | 03/15/07
I see truth in what ARTHAS has said .  Intellihence | 03/14/07
Tic what you are referring to is what is called a jealous hater  Intellihence | 03/14/07
Jealous  robbyx | 03/15/07
Are you joking!!!  xuniL_z | 03/14/07
Really!?!  Laff | 03/14/07
No  xuniL_z | 03/14/07
OK...how many of said ie death threats and the like?  Laff | 03/15/07
One last time  xuniL_z | 03/15/07
You should understand this basic concept my friend...  Laff | 03/15/07
Here is a hint for you  xuniL_z | 03/15/07
Hmmmm lets see death threats vs a wish for some  Laff | 03/15/07
hmmm....a message of hope vs. nothing but belittlement  xuniL_z | 03/16/07
Suffering from over-simplication, generalization and prejudice  YinToYourYang-22527499 | 03/14/07
I'm not sure why you are telling me  xuniL_z | 03/14/07
Looks who's obessesed  John Zern | 03/14/07
Complete and Utter FALLACY  Arthas | 03/14/07
so apple has flaw in it's software to keep up with Microsoft?  JoeMama_z | 03/14/07
Good try. Nowhere near  John Zern | 03/14/07
Maca Notra Lunacy!  Sean_Ssss | 03/14/07
You're referring to your own post?!  HypnoToad72 | 03/14/07
Unconfused by truth  Manny_z | 03/19/07
A Little Calm Is In Order.....  IAHawkeye | 03/14/07
yup, that's why I'm out of here...  Arm A. Geddon | 03/14/07
Apple obsession causes delusions  YinToYourYang-22527499 | 03/14/07
It's very easy  xuniL_z | 03/14/07
Molehill, not mountain  robbyx | 03/15/07
Your language is not conducive to calm!  ajole | 03/14/07
Differences...  Laff | 03/15/07
Why then...  IAHawkeye | 03/15/07
Because of negligence  Old Techie | 03/15/07
I doubt it's not the case...  IAHawkeye | 03/15/07
Adequacy is key element  Old Techie | 03/15/07
I Can't Pretend To Know Yours Either...  IAHawkeye | 03/16/07
Cry me a river  robbyx | 03/15/07
Hooray!  justanitguy | 03/15/07
It's an appliance, not a computer  chanthing | 03/15/07
BAD ARGUMENT  JABBER_WOLF | 03/14/07
Five remote execution attacks for conscientious users.  Resuna | 03/14/07
ALL COMPLEX SOFTWARE HAS BUGS!!!!  Heatlesssun1 | 03/14/07
Re: seriousness  Kobashrer | 03/14/07
Did you read the article?  Heatlesssun1 | 03/14/07
Do some research for a change.  Scott Kitts | 03/14/07
These days a journalist's job is to blow things up  labarker | 03/14/07
Thank you.  HypnoToad72 | 03/14/07
I agree - to a point:  msalzberg | 03/14/07
Uninformed troll...  cmjrees | 03/15/07
If Apple had NEVER issued a security patch for 5 years ...  Reverend MacFellow | 03/14/07
Which is a point many have made. People don't write malware for Mac!  Heatlesssun1 | 03/14/07
Only PART of a greater puzzle.  Laff | 03/15/07
What If???  justanitguy | 03/15/07
Why does better translate into invulnerable?  Laff | 03/15/07
what are you saying?  xuniL_z | 03/17/07
Repeat it enough times and it's true?  chanthing | 03/15/07
A perfect reason to own/use a Mac!  mlindl | 03/26/07
You are right on the money !  Intellihence | 03/14/07
Whoopee!  RocketEater | 03/15/07
I've only had...  msalzberg | 03/15/07
Nobody attacks Mac  Boot_Agnostic | 03/14/07
Once again...  gfeier | 03/14/07
Now that's what I'm talking about ,  Intellihence | 03/14/07
What a load of crap  JoeBob_z | 03/14/07
Microsoft monthly patches? Yeah, right.  Fred Fredrickson | 03/15/07
moot point  richvball44 | 03/15/07
Can I get a Copy Editor job?  bidemytime | 03/15/07
Dude! That is great.  mag008 | 03/15/07
Misuse, no miss-use happy  msalzberg | 03/15/07
Microsoft serious about security? "Oh Please!"  mag008 | 03/15/07
There is a firewall  msalzberg | 03/15/07
But I thought Apple was immune from viruses, bugs, etc., etc.  IT_Guy_z | 03/15/07
Not immune  robbyx | 03/15/07
I'm immune  mlindl | 03/26/07
Big bad security boogeyman!  robbyx | 03/15/07
Would like to switch to Apple  mames1701 | 03/15/07
Are you for real?  robbyx | 03/15/07
I know you think...  msalzberg | 03/15/07
Thank God I Don't Use Apples!  Narg | 03/15/07
Apple Reality = GW Reality  adiede@... | 03/15/07
Gates did not invest in Apple....  msalzberg | 03/15/07
And your point is?  adiede@... | 03/16/07
My point is...  msalzberg | 03/16/07
Fact Check Much?  chanthing | 03/15/07
Yes now you get it  mames1701 | 03/15/07
Some of these are bugs, some are design flaws.  Resuna | 03/15/07
Really? NO Kidding?  chanthing | 03/15/07
Now you do...  chanthing | 03/15/07
GPL?  cmjrees | 03/15/07
Not True  chanthing | 03/15/07
And what are the video cards?  notsofast | 03/15/07
Infected "knowledgeable" users  DaNoch-PTY | 03/16/07
Name the hack, name the breach, name the damage  mlindl | 03/20/07
Ryan Naraine = Confused  bsn | 03/20/07
Not confused, decietful!  Reverend MacFellow | 03/21/07
You damn right  Chiatzu | 03/23/07
A little boat called the "Titanic"  honeybl | 03/26/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here