Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
National broadband plan: What’s in it for businesses?
Mobile developers take measure of Windows Phone 7
Comcast, ISC offer IPv6 transition tool
New Cisco Ethernet switches to play broader video, security roles
Windows XP: No IE9 for you
Microsoft lowers Windows licensing costs for virtual desktops
Apple's Ban on Screen Protectors Makes (Some) Sense
Corporate IT eager to deploy Windows 7, survey shows
MIT researchers enable self-assembling of chips
8 things you didn't know about Windows Phone 7
Microsoft touts 'browser with no name' in Windows Phone 7
Microsoft touts speed, HTML 5 support in IE9
It's Official: Facebook Rules the Web
It does not take a village -- or a country
New Internet browser threat sneaks by traditional defenses
Security /

Mac OS X Software Update security issue uncovered

Today's breaking news
Send to a friendFeedback


Apple has been using an automated system to update users computers on Mac OS X since the software was first released over a year ago. According to the Bug Traq Security list, Mac OS X's implementation of the Software Update is vulnerable to attack.

According to the list, HTTP is used with no authentication when running the Software Update application. "Using well known techniques, such as DNS Spoofing, or DNS Cache Poisoning it is trivial to trick a user into installing a malicious program posing as an update from Apple," according to the site.

Apparently an exploit for this vulnerability has been released to the public for what Bug Traq says is "testing purposes." The exploit is being distributed as a Mac OS X package, which includes DNS and ARP spoofing software. The package also includes the cgi scripts, and apache configuration files required to impersonate the Apple Software Update Server.

"The exploit is done by tricking a DNS server into thinking that Apple's update server is in fact a different IP address - that server can then provide the bad app to download," Scott Anguish of Stepwise told MacCentral. "This is not a new trick, it's a well-known issue, and can be done with anything that connects on the net that doesn't have an authority system (like public/private key authentication)."

Of course, you don't have to check for updates automatically, but setting Software Update to check manually doesn't protect you. "You'll click 'Update now' and the bad application could still be downloaded," said Anguish. "The malicious user would need to make sure that the update just looked legitimate ... not hard at all."

Anguish also confirmed that Mac OS 9 is susceptible to the same exploit.

In order to fix the problem, Anguish said Apple has to do a couple of things:

  • Use an SSL Certificate so it is possible to verify that the Web-server that Software Update is downloading from is Apple's.
  • Start signing its downloads with a public/private encryption key pair, so Software Update or the Installer can verify that it is the package posted by Apple.

    An Apple spokesperson contacted for this report said, "Apple takes all security notifications seriously and is actively investigating this report."

    RELATED LINKS

    Apply for your free subscription to Network World. Click here. Or get Network World delivered in PDF each week.

    Get Copyright Clearance
    Request a reprint or permission to use this article.


  • NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
    Click here to sign up!
    New Event - WANs: Optimizing Your Network Now.
    Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
    Attend FREE
    Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.