On GameSpot: Thinking about buying a PlayStation 3?
BNET Business Network:
BNET
TechRepublic
ZDNet

May 25th, 2007

Bonjour Apple, connect to this Mac OS X exploit

Posted by Ryan Naraine @ 8:09 am

Categories: Apple, Botnets, Browsers, Cisco, Data theft, Exploit code, Hackers, Metasploit, Open source, Patch Watch, Pen testing, Responsible disclosure, Rootkits, Spam and Phishing, Spyware and Adware, Vulnerability research, Zero-day attacks

Tags: Security, Apple Mac OS, Apple Macintosh, Apple Inc., Apple Mac OS X, Exploit, Flaw, Ryan Naraine

Apple Mac OS X Bonjour

Less than 24 hours after Apple patched a serious flaw in its Bonjour zero-configuration networking service, a private security research company has released exploit code that puts Mac OS X users at risk of code execution attacks.

The exploit code has been shipped to members of Dave Aitel’s Immunity Partner’s Program, the $40,000 subscription service that offers up-to-the-minute information on new flaws and exploits to IDS companies and larger pen testing firms.

Aitel announced the exploit on the Daily Dave mailing list this morning:

[It is] essentially a reliable remote root on everyone at Starbucks or on all those OS X fiends at security conventions. The Immunity exploit will do so on either PPC or Intel, your pick, and since the service restarts, you get to pick twice.

“If this doesn’t shut up the Apple fanboys, nothing will,” Aitel said in a brief conversation over IM.

The vulnerability, patched with yesterday’s Security Update 2007-005, is a buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) code. Apple’s implementation of the protocal, called Bonjour, allows devices to automatically discover each other without the need to enter IP addresses or configure DNS servers.

However, the bug in the code used to create Port Mappings on home NAT gateways in the OS X implementation could open the door for an hacker on the local network to launch a denial-of-service or code execution attack.

Juniper Networks researcher Michael Lynn (of Black Hat/Cisco/ISS fame) is credited with finding and reporting the vulnerability to Apple.

ALSO SEE: Apple patch batch fixes 17 Mac OS X vulnerabilities.

[UPDATE: May 25 @ 12:43 PM]  Rob Lemos reports that this Bonjour flaw was in play during the CanSecWest MacBook hijack contest last month.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 63 Talkback(s)
Dictatorships...
I bet you like dictatorships that shove things down your throat and tell you what to do and think, just like you are with this.

Pretty darn close. He's obviously a Mac fanboi and we all ... (Read the rest)
Posted by: Wolfie2K3 Posted on: 06/13/07 You are currently: a Guest | | Terms of Use
Sounds like Aitel  frgough | 05/25/07
One more thing  frgough | 05/25/07
This bug  Ryan NaraineZDNet Moderator | 05/25/07
Then  frgough | 05/25/07
The exploit wasn't working  Ryan NaraineZDNet Moderator | 05/25/07
So, in other words  frgough | 05/25/07
Love the Mac zealot logic  NonZealot | 05/25/07
Re: NZ  frgough | 05/25/07
.ANI patch was released out-of-cycle  ye | 05/25/07
Whhoooooa!!!!  Kid Icarus-21097050858087920245213802267493 | 05/25/07
I said "patch" and "vulnerability".  ye | 05/25/07
Unreal  frgough | 05/25/07
I don't know. But, as of this writing I have yet to see any...  ye | 05/25/07
But its no big deal!  NonZealot | 05/25/07
Not that it will do any good  frgough | 05/25/07
No, that link does no good.  ye | 05/25/07
ye: isn't it amazing?  NonZealot | 05/25/07
NZ: I think they need them to exist because...  ye | 05/25/07
Only because  frgough | 05/25/07
Reason is irrelevant. You said:  ye | 05/25/07
Yeah, Aitel was wrong to say that  NonZealot | 05/25/07
Learn to read  frgough | 05/25/07
Fact?  Ryan NaraineZDNet Moderator | 05/25/07
I'm sorry  frgough | 05/25/07
Poor frgough just digs himself deeper with every post  NonZealot | 05/25/07
Are you being serious?  Ryan NaraineZDNet Moderator | 05/25/07
It truly boggles the mind  NonZealot | 05/25/07
It would be a resonable deduction  zkiwi | 05/25/07
Your facts smell bad  NonZealot | 05/25/07
Logical fallacy  frgough | 05/25/07
HAHAHAHAHA!!!  NonZealot | 05/25/07
frgough: You're being silly  j.m.galvin | 05/25/07
Please  zkiwi | 05/25/07
One thing to say  NonZealot | 05/25/07
It should be noted....  Stuka | 05/25/07
Yes it does  ImaGremlin | 05/27/07
Look in the mirror  Chiatzu | 05/25/07
Aitel's a turd  YinToYourYang-22527499 | 05/25/07
Careful or frgough will get mad!!  NonZealot | 05/25/07
Get past the childish emotions  YinToYourYang-22527499 | 05/25/07
If it quacks like a duck  TonyMcS | 05/27/07
The Mac obsessed are not Mac users  YinToYourYang-22527499 | 05/27/07
Apple fanboys unite  Chiatzu | 05/25/07
Eh, who cares  tic swayback | 05/26/07
I guess OSX isn't perfect after all!!  NonZealot | 05/26/07
It's not perfect....  RealNonZealot | 05/28/07
Know-it-all  daMan25 | 05/28/07
Get help  RealNonZealot | 05/28/07
You didn't express an opinion!  ajole | 05/28/07
Do I have to do everything? wink  RealNonZealot | 05/28/07
One more great link  RealNonZealot | 05/28/07
Dictatorships...  Wolfie2K3 | 06/13/07
Your post is funny  NonZealot | 05/28/07
LOL, you win  RealNonZealot | 05/28/07
Correction!  netzd | 05/28/07
Exactly.  RealNonZealot | 05/28/07
grin  toadlife | 05/28/07
Yes, there being...  msalzberg | 05/29/07
poor baby  dick lechter | 05/28/07
It's disappointing to see  drahardja | 05/28/07
Lack of professionalism, but useful  RealNonZealot | 05/28/07
My question; is everyone in this group here today?  ajole | 05/28/07
Now fanboy is a name?  andrej770 | 05/29/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here