On CBS MoneyWatch: 6 things NOT to do on Twitter, Facebook
BNET Business Network:
BNET
TechRepublic
ZDNet

October 30th, 2007

Researchers pooh-pooh Mac OS X Leopard security

Posted by Ryan Naraine @ 11:41 am

Categories: Apple, Botnets, Browsers, Data theft, Digital rights management, Exploit code, Hackers, Metasploit, Microsoft, Open source, Passwords, Patch Watch, Pen testing, Punditocracy, Spam and Phishing, Vulnerability research, Zero-day attacks

Tags: Firewall, Apple Macintosh, Network, Leopard, Thomas Ptacek, Firewalls, Apple Mac OS X, Network Security, Apple Mac OS, Security

Researchers pooh-pooh Mac OS X Leopard securityThe first independent reviews of the security enhancements in Mac OS X Leopard are in — and they’re not entirely pleasant for the folks in Cupertino.

First up is Heise Security’s takedown of the new application-based firewall in Leopard, which Apple promises will specify the behavior of specific applications to either allow or block incoming connections.

However, Heise Security’s Jürgen Schmidt finds cause for concern:

The most important task for any firewall is to keep out uninvited guests. In particular, this means sealing off local services to prevent access from potentially hostile networks, such as the internet or wireless networks.

But a quick look at the firewall configuration in the Mac OS X Leopard shows that it is unable to do this. By default it is set to “Allow all incoming connections,” i.e. it is deactivated. Worse still, a user who, for security purposes, has previously activated the firewall on his or her Mac will find that, after upgrading to Leopard, the system restarts with the firewall deactivated.

In contrast to, for example, Windows Vista, the Leopard firewall settings fail to distinguish between trusted networks, such as a protected company network, and potentially dangerous wireless networks in airports or even direct internet connections. Leopard initially takes the magnanimous position of trusting all networks equally.

(More at Techmeme)

Researchers pooh-pooh Mac OSX Leopard security

The new firewall in Leopard isn’t the only security feature being pooh-poohed by security researchers. According to Thomas Ptacek (right), co-founder of Matasano Security, Apple’s implementation of memory randomization in Leopard doesn’t make the operating system immune from virus and worm attacks.

[ SEE: Memory randomization (ASLR) coming to Mac OS X Leopard ]

For starters, Ptacek found that the dynamic linker library (dyld) is not randomized. “From what I can tell, ten different Leopard Macs booted at ten different times will have the same offset to dyld,” Ptacek said in a first-take on Leopard security.

“Can I say right now that you can exploit this to take over a Mac? No. But ASLR is either something you get right, or is simply a speed bump for attackers,” he added.

Ptacek said memory randomization, also known as ASLR (address space layout randomization), removes a talking point argument about Microsoft Windows Vista’s superior security, but doesn’t address the underlying point of that argument.

Cocoa programs running in Darwin are less secure than Win32 programs running under NTOSKRNL, and aren’t even in the same ballpark as Managed C++ or C# programs.

Ptacek’s analysis also found problems with Apple’s implementation of Sandboxing (systrace) without any documentation for developers.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 121 Talkback(s)
RE: Researchers pooh-pooh Mac OS X Leopard security
See wirelesswall.com for the panultimate Mac Leopard security solution. Strong end-to-end seamless layer 2 encryption for wireless and wired networks that's FIPS certified and least cost. It makes networks "unsniffable".... (Read the rest)
Posted by: aphilsmith Posted on: 01/11/09 You are currently: a Guest | | Terms of Use
Let the bashing begin!  ye | 10/30/07
Let the bashing begin! - Exactly - Way to recognize it for what it is.  jjarman | 10/31/07
Second Time...  ivanotter | 10/31/07
It's not bashing if its true  Liveware Problem | 10/31/07
It must be bashing then, 'cause it ain't true  MarcB_z | 10/31/07
Just ignore the idiots  labarker | 10/31/07
Actually, it IS....  drprod@... | 10/31/07
Back to my Mac  MarcB_z | 10/31/07
Digital Signatures  Liveware Problem | 10/31/07
What does a firewall do?  santuccie | 10/31/07
aw shucks...  catseverywhere@... | 11/19/07
I really like this "feature" in Leopard  NonZealot | 10/30/07
Hard lessons learned  net-com | 10/30/07
You've been saying that for nearly 10 years...  olePigeon | 10/30/07
Too many POCs to feel safe  NonZealot | 10/30/07
Countless proof of concepts?  olePigeon | 10/30/07
I'll bet you can't find a single virus for OS X  i8thecat | 10/31/07
Perhaps this?  ye | 11/01/07
That's a Trojan, NOT a virus ...  Jens T. | 11/01/07
You people are pathetic. Stop being so pedantic. You might look less a fool  ye | 11/01/07
not a even a trojan - but thanks for playing  i8thecat | 11/01/07
@i8thecat: Maybe I could employ that circular referencing to...  ye | 11/01/07
@ye: HILARIOUS!!!  NonZealot | 11/01/07
Confirmation  santuccie | 11/02/07
These two statements are at odds with one another:  ye | 10/30/07
As NonZealot mentioned...  olePigeon | 10/30/07
If you consider PoC valid then...  ye | 10/30/07
easy answer  CowLauncher | 10/30/07
Well, d-uhhh!  Mike Cox, Sr. | 10/30/07
And by the way...  Mike Cox, Sr. | 10/30/07
@CowLauncher: How is it "incredibly difficult" to write...  ye | 10/31/07
and Mike, SR loses...  ivanotter | 10/31/07
slight correction  JoeysLapTop | 10/31/07
RE: slight correction  joe6pack_z | 10/31/07
You should never rely on a software firewall...  olePigeon | 10/30/07
Sounds like a great idea!  NonZealot | 10/30/07
You do have a good point...  olePigeon | 10/30/07
The default configuration has always been the metric. At least when...  ye | 10/30/07
Is there a double standard for MS and Apple?  bka1959 | 10/30/07
Have you...  cashaww | 10/31/07
*sigh*  Spiritusindomit@... | 10/31/07
But, it's got electrolytes! (nt)  rtk | 10/31/07
you had me thinking you were logical until...  ivanotter | 10/31/07
ummm  JoeysLapTop | 10/31/07
agreed  Spiritusindomit@... | 10/31/07
and yet...  ivanotter | 10/31/07
Two good reasons...  Wolfie2K3 | 10/31/07
Hardware Firewall suggestion  aginj@... | 10/31/07
A lot of people think it's a great idea...  handydan918 | 10/31/07
Linux Firewall links  aginj@... | 11/01/07
Hardware is Software  DarienHawk67 | 11/03/07
Vista NonSecurity  jjarman | 10/31/07
and he put them there...  ivanotter | 10/31/07
maybe...  Spiritusindomit@... | 10/31/07
they can't afford a real machine and they don't surf porn...  jjarman | 10/31/07
Windows Vista rocks!  qmlscycrajg | 10/30/07
Wow.  handydan918 | 10/31/07
Well things will change now that the processor Apple uses now  mrOSX | 10/30/07
yep...  Spiritusindomit@... | 10/31/07
and then,,,  ivanotter | 10/31/07
Windows compatibility  lauren.glenn@... | 11/01/07
Speed-bumps are all the security there is  YinToYourYang-22527499 | 10/30/07
Well this just can't be !!!  BFD | 10/30/07
Sure Windows!  DebianDog | 10/30/07
Firewall ignoring Tiger settings on upgrade  frgough | 10/30/07
Dawns Apple fanboi hat:  ye | 10/30/07
of course it does  woot! | 10/30/07
Oh I know that. It's the Mac fanbois that don't.  ye | 10/30/07
ok  woot! | 10/30/07
Hey, you and I are in complete agreement:  ye | 10/30/07
Waterboy  SquishyParts | 10/30/07
@ SquishyParts: Oh but I DO use a Mac. Even prefer it.  ye | 10/31/07
Read the article  frgough | 10/31/07
At the risk of starting flame wars...  japac | 10/31/07
Are you sure the firewall was on?  NonZealot | 10/30/07
Confusion  frgough | 10/31/07
NonZealot. Can you get non-zealous about Windows?  YinToYourYang-22527499 | 10/30/07
LOL, like that will ever happen! NT.  bka1959 | 10/30/07
How about some fact checking  People | 10/30/07
The same goes for criticism of Visa.  ye | 10/30/07
I personally don't agree with credit cards pay cash.  James Quinn | 10/30/07
The funny part of that joke  xuniL_z | 10/30/07
Irony.....gotta LOVE it...:P  James Quinn | 10/31/07
Once a Windows user who now loves the new Leopard.  LinuxandMacforlife | 10/30/07
Dream On...nt  socialism=nowhere | 10/31/07
when computers were fun...  ivanotter | 10/31/07
RE: Researchers pooh-pooh Mac OS X Leopard security  crgray | 10/30/07
So your saying?  Mujibahr | 10/30/07
NTP servers  crgray | 10/30/07
no you can sync to any time server  jjarman | 10/31/07
Pooh-Poohing the Pooh-poohers  MarcB_z | 10/31/07
More interesting back-info here  MarcB_z | 10/31/07
Way to much POOH in the article and the replies...  Laff | 10/31/07
Heise security is owned by MSFT  comp_indiana | 10/31/07
Ohhh geezz... nt  socialism=nowhere | 10/31/07
Well while I can't argue with your well thought out  Laff | 10/31/07
True, but...  RocketEater | 10/31/07
You're missing the point  thx-1138_@... | 10/31/07
That's a stupid statement.  Spiritusindomit@... | 10/31/07
oh suure...  ivanotter | 10/31/07
RE: Researchers pooh-pooh Mac OS X Leopard security  chris.copp@... | 10/31/07
RE: Researchers pooh-pooh Mac OS X Leopard security  rcharles@... | 10/31/07
yay a Troll (NT)  ivanotter | 10/31/07
He isn't a troll, he's straight up crazy.  rtk | 10/31/07
Where were the "researchers" during the extensive beta process?  vikingnyc@... | 10/31/07
logically...  ivanotter | 10/31/07
Probably not though  JoeysLapTop | 10/31/07
The firewall test was bogus, and the address space argument is in error.  Resuna | 10/31/07
Huh?  rtk | 10/31/07
And along comes the bash happy people  genefitz1976 | 10/31/07
well thought out...  ivanotter | 10/31/07
oh yeah and reason 2  ivanotter | 10/31/07
Use two fingers  online@... | 10/31/07
Whadda ya know? Apple has problems too!  butler360 | 10/31/07
And so does Linux  santuccie | 10/31/07
RE: Researchers pooh-pooh Mac OS X Leopard security  thierrycmercier@... | 10/31/07
Unlike MS?  rpmyers1 | 10/31/07
Former PC user going Mac anyway...  3dtodd | 10/31/07
RE: Former PC user going Mac anyway...  joe6pack_z | 10/31/07
RE: Researchers pooh-pooh Mac OS X Leopard security  carma23 | 12/08/07
RE: Researchers pooh-pooh Mac OS X Leopard security  aphilsmith | 01/11/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and