HomeinetVery serious vulnerability in Apple's Mac OS X

Very serious vulnerability in Apple's Mac OS X

A security flaw in Apple 's Mac OS X , discovered 5 months ago, gives hackers unrestricted access through clock and timestamp settings.

As reported by Ars Technica, a bug discovered five months ago has resurfaced after new tests conducted with security and penetration testing software Metasploit. The software could make life easier for hackers trying to exploit the Mac vulnerability.

The bug is found in a Unix feature called sudo. Sudo is designed to require a password before granting root access to a user. The vulnerability exploits the authentication process by first changing a Mac's date to January 1, 1970. By setting the clock to 01/01/1970, hackers can gain root access without needing a password.

metasploit

Metasploit is an open-source application that will make it easier for security researchers to penetrate control networks. While useful for security researchers to identify and patch vulnerabilities, it can also be used to exploit the sudo vulnerability .

“The vulnerability is significant because it allows any user to gain root access. So as root they can access plaintext passwords from the Keychain. It also allows an attacker to install a permanent rootkit,” said HD Moore, founder of Metasploit.
“I think Apple should take this more seriously, but I’m not surprised since they’re always very slow to patch vulnerabilities.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS