On TechRepublic: 10 must-have Android apps
BNET Business Network:
BNET
TechRepublic
ZDNet

August 1st, 2008

Did Apple forget to patch something?

Posted by Ryan Naraine @ 10:06 am

Categories: Anti Virus, Apple, Arbitrary Code Execution, Botnets, Browsers, Data theft, Exploit code, Locally Running Web Servers, Malware, Metasploit, Microsoft, Passwords, Patch Watch, Pen testing, Responsible disclosure, Vulnerability research

Tags: DNS, Domain, IP, Server, Apple Inc., BSD, Client Library, Domain Names, Networking, Internet

Apple DNS patch misses markLess than 24 hours after Apple (belatedly) released a patch for the DNS cache poisoning vulnerability, there are reports circulating that the DNS client on the OSX 10.4.11 distribution still has not been patched.

According to nCircle’s Andrew Storms, the client libraries on a fully patched OSX 10.4.11 system still does not implement source port randomization, which is the recommended to help improve resilience against DNS cache poisoning attacks.

Storms provided a comparison between a patched FreeBSD 6.3 system and a patched OSX 10.4.11 system:

FreeBSD 6.3

  •     08:49:58.405934 IP [BSD].64328 > [SERVER].domain: 39741+ A? www.yahoo.com. (34)
  •     08:50:02.708123 [BSD].51023 > [SERVER].domain: 45758+ A? www.yahooooo.com. (35)
  •     08:50:07.625034 IP [BSD].50648 > [SERVER].domain: 23806+ A? www.www.net. (29)

OSX 10.4.11

  •     08:05:47.741385 IP [OSX].49193 >[SERVER].domain: 55613+ A? www.cnn.com. (29)
  •     08:05:48.207547 IP [OSX].49194 >[SERVER].domain: 1106+ PTR? 21.91.236.64.in-addr.arpa. (43)
  •     08:05:51.717245 IP [OSX].49195 >[SERVER].domain: 27650+ A? www.cnn.com. (29)

This clearly shows no source port randomization happening on OS X 10.4.11.

For Apple, it matters most that they patch the client libraries since there are so few OSX recursive servers in use. The bottom line is that despite this update, it appears that the client libraries still aren’t patched.

Apple does not respond to media queries about security issues.

ALSO SEE:

* Microsoft joins ‘patch DNS now’ chant; Apple patch missing

* Vulnerability disclosure gone awry: Understanding the DNS debacle

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 34 Talkback(s)
you misunderstand...
I thought they did implement port randomization for DNS servers, which is what was affected by that issue?

Just not the DNS client stub, which was not affected by that issue. They did fully im... (Read the rest)
Posted by: jjarman Posted on: 08/08/08 You are currently: a Guest | | Terms of Use
Apple  russguill | 08/01/08
The key word being "supposed"  tikigawd | 08/04/08
No..no...  DCMann | 08/01/08
You need the iShuffle DNS Ports accessory...  jjarman | 08/04/08
Ryan, Question?  jjarman | 08/04/08
Anyone tested Leopard  jifbrodeur@... | 08/01/08
Good point, this will spur Leopard sales  NonZealot | 08/01/08
Copied from your Good Buddies at Microsoft happy  mahalotmm | 08/01/08
Copied from your Good Buddies at Microsoft  deowll | 08/02/08
Also...  CarlitosLx | 08/04/08
did they add port randomization to all those dns clients?  jjarman | 08/04/08
I'm having no trouble with Tiger  Laraine Anne Barker | 08/01/08
you do realize  rtk | 08/01/08
if there is not attack then there is no problem...:P  James Quinn | 08/04/08
So that means...  tikigawd | 08/04/08
Just go use OpenDNS and you're protected  GiveMeGizmos | 08/01/08
There is no need to fix it  ted185@... | 08/01/08
In this case ...  Mach5RR | 08/01/08
set up for using OpenDNS  deowll | 08/02/08
Does Apple know something that y'all don't?  mlindl | 08/01/08
considering....  Rick_K | 08/01/08
Your argument is ridiculous  cslycord@... | 08/04/08
Ryan, this article is misinformed  jon.oberheide | 08/01/08
Welcome to ZDNet;-) (nt)  Richard Flude | 08/01/08
So you are saying they don't need to fix bind?  deowll | 08/02/08
WAKE UP IDIOT!  Kaiwai | 08/03/08
Post, Flame and the real Issue, Apple did a lousy job!  jifbrodeur@... | 08/04/08
understanding?  jjarman | 08/04/08
Understanding, all of the above.  jifbrodeur@... | 08/04/08
thanks for the clarification, i agree...  jjarman | 08/04/08
not sure if this is correct, but i beleive they are saying...  jjarman | 08/04/08
Apple did not completly correct the issue  jifbrodeur@... | 08/07/08
you misunderstand...  jjarman | 08/08/08
Message has been deleted.  MIKEC0X | 08/01/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here