14 ms·
OS X sudoers exploit found in the wild
- ossreality 11y agoAugust 3rd. That's why I was so confused. Was it really not posted to HN? I must've gotten it from twitter then...
- mey 11y agoI keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?
- andykellr 11y agoOn public wifi, I use https://www.getcloak.com https://www.getcloak.com I also uninstalled Flash.
- 13 11y agoWhy do you trust Amazon AWS and this company more than your own connection?
- MaulingMonkey 11y ago"Public wifi", not "your own connection". You have two options for who you decide to trust: 1) A VPN company, who you've had the opportunity to research, who's primary business and reputation is based on handling your traffic. 2) Each and every WAP you connect to, in many cases with no real means to verify it's actually e.g. the official WAP of the hotel you're staying at, for something that likely costs the owners money rather than being seen as a profit center in and of itself. Their primary business and reputation is staked on something completely different than their handling of your traffic (be it their coffee, their accommodations, whatever.) If you trust #2, statistics eventually comes into play - you will trust someone who shouldn't have been trusted. This also ignores that "public wifi" frequently performs MITM attacks for the... not entirely unreasonable purpose of providing login gateways, terms of use, etc. when you initially open up your web browser. But if you're already MITM traffic, it's not as big a stretch to substitute your own (poorly vetted) advertisements and affiliate links for a little extra revenue. Even if you don't do that, there's no guarantees your MITM tech isn't accidentally weakening security ala Superfish.
- 13 11y agoI think you put far too much trust in one of thousands of clone VPN services. There's no reputation to taint, there's stock standard scripts running on commodity VPS boxes they rented from somewhere else. I would be shocked if at least some of the most commonly used ones weren't run by people looking to sniff credentials. You're paying to pipe all of your sensitive information through some random persons box, which is just ludicrous.
- MaulingMonkey 11y agoOh, wait. Were you suggesting VPNing into your home connection or similar instead?
- pyvpx 11y agoyou should trust your end points. assuming you trust the machine you are using, the other end of the tunnel should be just as trustworthy. that's great if you trust a company; but what incentive do you have to trust them?
- davepeck 11y agoWe're a well-known company with an earned reputation for doing the right thing. Not everyone can set up their own VPN endpoint. For those who can, and are willing to maintain it, great! More: https://blog.getcloak.com/2013/03/04/why-trust-matters-when-choosing-vpn/ https://blog.getcloak.com/2013/03/04/why-trust-matters-when-... (And what does AWS have to do with anything?)
- jdunck 11y agoAs a general rule, I don't use public wifi and council people to use VPN if they must. No flash, disable java in the browser, prefer chrome to safari, AdBlock and NoScript if you don't need JS.
- 72deluxe 11y agoI have removed Flash from my machines but using Chrome over Safari is like kissing your battery goodbye. It does not put the CPU to sleep properly for some tabs. It is sad.
- frio 11y agoLittle Snitch (https://www.obdev.at/products/littlesnitch/index.html https://www.obdev.at/products/littlesnitch/index.html) is excellent.
- noondip 11y agoSo excellent that some malware deletes itself if Little Snitch is even installed (https://www.f-secure.com/v-descs/trojan-downloader_osx_flashback_a.shtml https://www.f-secure.com/v-descs/trojan-downloader_osx_flash...). However, it's worth noting "DYLD_PRINT_TO_FILE" is a root exploit, which may circumvent or disable Little Snitch entirely if used by APT; Little Snitch may not see all network activity. In fact, a root exploit allows one to write malware completely hidden from userland altogether (lsof, ps, tcpdump, etc.) (https://github.com/hackedteam/driver-macos https://github.com/hackedteam/driver-macos). It is truly scary how vulnerable OS X is at the moment.
- rosser 11y agoAs a Little Snitch user, I'm inclined to agree, but I find that I sometimes end up in a state of "WTF wants to use the network now?!" saturation. My solution for that is to deny anything I don't recognize, and create rules for things I see more than twice, but if you're conditioned to click "OK" on everything you see, Little Snitch isn't going to to much for you...
- danudey 11y agoI really wish Little Snitch could generate aggregate rules for apps. I keep having situations where an app starts making requests over and over until I realize that the developer is using https requests to cdn###.somehost.com where ### is apparently a dozen or more different hosts, and the only option I have is to just allow all https traffic rather than more granular by-host rules.
- reubenmorais 11y agoAlthough be aware that it can be quite daunting for a novice user. If you're installing for a friend or family member, you should go through all of this apps to whitelist requests and maybe teach them how to identify bad requests, but it's non-trivial. The UI doesn't interact very well with CDNs, for example, sometimes telling you that "App Store" is trying to access "arstechnica.com" because they use the same CDN provider.
- superuser2 11y agoSecurity software is a band-aid on vulnerable software and users installing things they shouldn't. Part of the OSX security strategy is to minimize users installing things they shouldn't by making it difficult (enforced code signing, confirmations when opening an unsigned or new application). The other side is minimizing attack surface for exploits by staying up-to-date, not shipping crap like Java unless the user explicitly needs it, and (increasingly) sandboxing applications to user-approved subsets of the filesystem. Bolt-on detection and resolution of malware infections is just not a part of the OSX security ecosystem like it is with Windows. Little Snitch can help give you a picture of what's going on with regard to your network card, but at the end of the day malware can usually hide its traffic in an otherwise-trusted application to avoid that sort of detection.
- mey 11y agoI believe in defense in depth. There is always going to be an escape. Within the last month there has been several different privilege escalations possible in OSX. While I appreciate OSX having a strong security model, secondary solutions are desirable too me.
- AdieuToLogic 11y ago> I believe in defense in depth. ... While I appreciate OSX having a strong security model, secondary solutions are desirable too me. You might want to check out mtree(8) then. It's serves well as the FreeBSD/OS-X Tripwire[1] equivalent. 1 - http://www.tripwire.com http://www.tripwire.com
- r618 11y agofor preventive and (post)forensic measures see https://objective-see.com/ https://objective-see.com/
- code_sterling 11y agoRemove/Do not install Flash and Java, and make sure that Gatekeeper is at the middle setting. Turn your Firewall on regardless, and/or monitor your network activity. If you know what a packet is, then Little Snitch, if you don't Radio Silence is what I set my parents up with.
- georgerobinson 11y agoIt still pains me that OSX ships with the firewall disabled by default. I don't think its reasonable to presume that every OSX device will be on a private network behind a NAT, and that everyone else will know to turn their firewall on. However, this appears to be the assumption Apple are making! You can do better!
- donkeyd 11y agoEset now has security software for Mac. They were always my go to products on Windows.
- noondip 11y agoThere really is no good anti-virus software for Macs at the moment. Have a look at recent vulnerabilities in ESET and Sophos, for example: http://googleprojectzero.blogspot.com/2015/06/analysis-and-exploitation-of-eset.html http://googleprojectzero.blogspot.com/2015/06/analysis-and-e... https://lock.cmpxchg8b.com/sophailv2.pdf https://lock.cmpxchg8b.com/sophailv2.pdf
- j-pb 11y agoSecurity software (virus scanners e.t.c.) is snake oil. The code required for them to do their thing is so intrusive into the operating system that it has serious effects on stability. And they are not that effective anyhow. Since they won't be able to detect exploits in existing programs over authorised channels.
- arca_vorago 11y agoAfter spending quite some time deliberating on this, and not wanting my users in the wild without something, I finally settled on Bitdefender. I control clients from the cloud console, can push policies, run scans, updates, all without user interaction. Right now I'm only using the AV part for most devices though, as enabling the full package of internet firewall and website scanning was eating up lots of resources. The two follow up contenders were ESET and Kaspersky.
- JonnieCache 11y agoTCPBlock is a free version of little snitch. It's apparently abandoned, but it doesn't need any more features. http://www.macupdate.com/app/mac/35914/tcpblock http://www.macupdate.com/app/mac/35914/tcpblock You can set it up to disallow all network traffic until you whitelist the binary. Not sure if it's actually hashing them or just checking the path though.
- esusatyo 11y agoIsn't this the time when Mac App Store supposed to shine? When they found something that's dodgy and linked to a company that has apps on App Store, can't they just turn on the kill switch? That way the malware won't have anywhere to direct the users to.
- glhaynes 11y agoIt's not clear whether this "adware installer" is signed by a developer cert. I'm gonna guess it isn't, which means under the default settings, if a user double-clicks it to execute it, they'll be presented with a message saying that the app can't be run because it's "from an unknown developer" and the current settings disallow it. The user can get around that by right-clicking it and choosing "Open" (or switching Gatekeeper to be more relaxed), but the error message doesn't allude to this. Edit: And if it is signed: yes, I believe Apple could and presumably would push out a malware update that would invalidate the cert.
- noondip 11y agoOne could easily make an "app" which just runs a shell script with this exploit - no code signing needed.
- glhaynes 11y agoAnd users attempting to run it would encounter the things I mentioned above, so I'm not sure what you're getting at.
- noondip 11y agoI'm getting at the fact a shell script with this exploit can be made to look like an "app" and be "double-clickable", and doesn't require any code signing.
- jakobegger 11y agoGatekeeper also watches over shell scripts, so when you double click the shell script it will tell you that you can't open it because it is from an unidentified developer.
- deleted 11y ago[deleted]
- cmurf 11y agoThe top most thing is keeping the OS up to date. And I don't visit shady web sites. Flash stand alone is removed, and disabled in Chrome. Lastpass for passwords. Tunnelblick+privatetunnel for open networks. And even though I use some software that isn't signed, after I've installed such software I revert the Security & Privacy "allow apps" setting back to app store+identified devs. And relevant, just by coincidence, in this case, I'm using 10.9.5 (which is still currently maintained with security updates). The reality is that Mac users are simply used to trusting Apple to handle these sorts of things. And it's not a good alternative for that trust to be lost and placed in a 3rd party, e.g. on Windows where trust loss means a litany of 3rd parties to choose from in that space with no real practical way to differentiate, and the Windows Store described as a "cesspool of scams." Apple will get this fixed soon. It's definitely sub-optimal response wise, but I still trust this ecosystem compared to Windows at this point. Edit: Oh and Privacy Badger.
- linky123 11y agoKeeping the OS up to date wouldn't have helped with this.
- cmurf 11y agoI know that. Overwhelmingly in most cases it does help though, probably more than anything else short of air gapping the thing.
- geofft 11y agoYou can also install another OS. Putting an Ubuntu LTS or Debian stable on it will help you way more, compared to OS X 10.9.5, than any number of other mitigation strategies. Frankly, I'm way more comfortable taking my Windows 8.1 machine to public wifi hotspots these days than my OS X 10.9 machine.
- op00to 11y ago... Unless you use Firefox.
- linky123 11y agoThis is impossible! Apple's OS are _secure by design_ as they've said in their marketing copy for years.
- BinaryIdiot 11y agoBecause that means bugs are impossible?
- ikeboy 11y agoThis is what's mentioned in http://www.theguardian.com/technology/2015/aug/05/apple-will-fix-mac-os-x-bug-amid-security-concerns http://www.theguardian.com/technology/2015/aug/05/apple-will..., and will be fixed soon.
- x0 11y agoOh man, I really want to do it on all the macs at the Apple store, and start a little botnet. Problem is, I don't really have any use for 10 or so rooted macs. I mean, I could rm them, but I'd never do that, that's mean. And I wouldn't feel good about using the camera, even though the computers are in public, it's icky. Perhaps a DoS? There's nobody that I dislike enough for that. I think I'd be so rich if I wasn't so moral.
- VoiceOfWisdom 11y agoDon't be an ass.
- geofft 11y agoThere's a reason that the store staff are instructed to encourage you to leave the store if you open a terminal.
- odonnellryan 11y agoThey are?!
- geofft 11y agoSo I've heard; I haven't confirmed this for myself.
- odonnellryan 11y agoI have to try this if I remember! That'd be very interesting. The console obviously has many legitimate uses. Why wouldn't I try it out if I were thinking about buying a mac?
- justinhj 11y agoI quite often open a terminal and run top or emacs and leave it that way, nobody ever commented on it
- flashman 11y agoI'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. Esser has his reasons - "Short reminder: Europeans are not allowed to disclose vulns privately to a foreign company like Apple without registering dual-use export"[1] - but it's hard to believe he couldn't have told them anonymously. Disclosures make careers, though, so there's a strong incentive to go public. [1] https://twitter.com/i0n1c/status/624172774915973120 https://twitter.com/i0n1c/status/624172774915973120
- hurin 11y ago> Esser has his reasons - "Short reminder: Europeans are not allowed to disclose vulns privately to a foreign company like Apple without registering dual-use export" I don't think of this as strictly career advancement. I think he is making an important legal and political point. If there were never serious issues while we operate under said laws, then they would never be changed or subject to question either.
- lawnchair_larry 11y agoHow can you be mad at Esser? He didn't put the bug there. He has nothing to do with this.
- enneff 11y agohttps://en.wikipedia.org/wiki/Responsible_disclosure https://en.wikipedia.org/wiki/Responsible_disclosure
- acomjean 11y agoFrom the Author in the Comments "In Esser's original post revealing the vulnerability, he said, "At the moment it is unclear if Apple knows about this security problem or not."" So basically he just released it without disclosure. He claims reasons (see parent post), but its still kinda ick..
- 13 11y ago
- chjj 11y agoI'm seriously shocked. This is ridiculous. This looks like possibly the easiest root exploit ever discovered on a desktop OS (a one-liner in bash). Why in the world would they allow an env variable to write to a file in a setuid'd binary? I'm suddenly very glad I don't use my macbook as my main machine, but I guess I'll remove the set{u,g}id bits on newgrp for now. Don't know if that will break things, but it's better than getting a rootkit.
- abbeyj 11y ago> This looks like possibly the easiest root exploit ever discovered on a desktop OS Well there's always the classic "login -froot" bug [1]. Although, to be fair, you did say "desktop OS" and I'm not sure AIX exactly qualifies. [1] http://seclab.cs.ucdavis.edu/projects/testing/vulner/18.html http://seclab.cs.ucdavis.edu/projects/testing/vulner/18.html
- hew 11y agoThis one, albeit local only, was a lot of fun too: https://www.securemac.com/macosxsetuidroot.php https://www.securemac.com/macosxsetuidroot.php
- AdieuToLogic 11y ago> I'm seriously shocked. This is ridiculous. This looks like possibly the easiest root exploit ever discovered on a desktop OS ... Ignoring the nonexistent "root" privileges on Windows-95 (which allowed anything to change anything it felt like), also one of the easiest to fix: mv /usr/bin/sudo /usr/bin/some-other-name-that-you-like-and-there-ya-go
- NeutronBoy 11y agoThat 'fix' is going to break a lot of other stuff.
- AdieuToLogic 11y ago> That 'fix' is going to break a lot of other stuff. True, but a short-term replacement along the lines of: #!/bin/sh unset DYLD_PRINT_TO_FILE # Cleanse the sudo arguments here... # Check MD5 of /etc/sudoers against known good # value here... exec /usr/bin/the-renamed-sudo "$@" Would do the trick when put in the place of /usr/bin/sudo EDIT: Added the comments regarding sanity checks.
- athenot 11y agoWould it be possible to mitigate this by setting the immutable flag on /etc/sudoers: chflags uchg /etc/sudoers
- odonnellryan 11y agoThere's a patch here: https://github.com/sektioneins/SUIDGuard https://github.com/sektioneins/SUIDGuard
- geofft 11y agoNo, because the vulnerability is that you can write to arbitrary files with root privileges. It turns out that sudoers is the easiest file to write to to gain persistent root, but there are millions of other things: /etc/passwd, /etc/cron.d, /root/.ssh/authorized_keys, any binary that's run by root, etc.
- chjj 11y ago/etc/sudoers is not the only potential target here. Even if that did work, this vulnerability could still brick your entire OS. They could overwrite any file they wanted to.
- odonnellryan 11y agoFor anyone looking for the patch: https://github.com/sektioneins/SUIDGuard https://github.com/sektioneins/SUIDGuard
- marquis 11y agoIs there a test to determine if the patch is successful? Edit: as noted in Esser's blog [1]: $ EDITOR=/usr/bin/true DYLD_PRINT_TO_FILE=/this_system_is_vulnerable crontab -e I found this test failed in both a patched (10.10.4) and un-patched system (10.10.1) so not sure what these results mean. [1] https://www.sektioneins.de/en/blog/15-07-07-dyld_print_to_file_lpe.html https://www.sektioneins.de/en/blog/15-07-07-dyld_print_to_fi...
- Corrado 11y agoDid you check the root directory for a file named "this_system_is_vulnerable"? I just tested this on a mid-2015 MBP running 10.10.4 and found that file in the root directory. :(
- odonnellryan 11y agoBefore or after the patch?
- marquis 11y agoThanks for clarifying: I was able to find the vulnerability on the unpatched system with: $ ls -al / (etc) -rw-r--r-- 1 root wheel 0 Aug 6 06:46 this_system_is_vulnerable So I can a) confirm the vulnerability exists and it can write with root privileges. and b) the patch works: I ran the patch, deleted the test file, rebooted and the file is no longer able to be written.
- odonnellryan 11y agoYou ran the GitHub patch and it still failed?
- 11y ago
- deleted 11y ago[deleted]
- adamzubi700 11y agohttp://googler700.blogspot.com/ http://googler700.blogspot.com/
- adamzubi 11y agohttp://googler700.blogspot.com/ http://googler700.blogspot.com/
- qudat 11y agoDoesn't seem to work in 10.11
- marquis 11y agoThat's the correct behaviour. It's supposed to be patched in El Capitan by default.
- deleted 11y ago[deleted]
- kordless 11y agoI seriously wonder if issues that have highly polarized responses aren't some sort of rip in reality.
- chippy 11y ago..well, it's not cognitive dissonance - it's not holding two contradictory thoughts, it's more a refusal to believe and more so a defence of investment. Early innovators, technologists and many Hacker Newsers have spent thousands in both time and money on Apple. To attack Apple attacks their investment leading to defensive behaviour. To think to yourself "oh, now I'm going to ditch Apple and choose Linux" causes psychological harm as you have to 1) admit that your time and money was wasted on Apple 2) You made the wrong choice and 3) You don't want to learn another technology. Thus it's easier to fight an attacker than to admit defeat.
- kordless 11y agoDissonance is harder to resolve than it is to 'deal with'. I'd say you are on the mark with your last two statements and wrong about it not being cognitive dissonance. I can only claim that because I spend an inordinate amount of time thinking about it in terms of cloud services and trust. :)
- zwetan 11y agoI don't see in the article where they all blame the fault on Flash ?
- chadscira 11y agoI was wondering why Download Shuttle has so many more users than my app (Fat Pipe). Seems like they are playing with the world of adware marketing, I hope they aren't doing weird things with the OS as well :/.
- n9com 11y agoOur app, Download Shuttle, has nothing whatsoever to do with this malware. We have no idea why the malware creator decided to open up Download Shuttle in the Mac App Store. We can only speculate that it was done in order to disguise what the malware is really doing (installing adware such as Genieo). Download Shuttle is a free app and makes up an insignificant part of our overall Mac app portfolio. FIPLAB is one of the longest standing app developers on the Mac App Store and our apps have been featured multiple times by Apple themselves. Perhaps you shouldn't jump to conclusions?
- chadscira 11y agoSorry about that, glad to hear that you guys are not involved. From face value it does look very odd. I apologize in for assuming you guys were involved.
- sillygeese 11y ago> a company that takes part in the usual tax and labor law evasion tactics Would you prefer to have most of your income forcefully taken away, or would you prefer as little as possible taken away? Tax evasion amounts to trying to keep your own property. If someone tries to avoid paying protection money to a mafia, is he a criminal, or immoral?
- tragic 11y agoDo Apple employees not drive cars on roads (paid for by the taxpayer)? Do they rely on no technology whatsoever which did not rely on the taxpayer to exist (for example, er, the internet)? If they want to defend some other part of their property under the law, are they paying their own judges? Of course Apple avoid taxes - anyone who can do so without fear of getting significantly punished does. But the idea that this is a brave stand against The Man is transparently ridiculous - especially so for any technologist, given our industry's heavy historic reliance on both the academy and the military. Should you pay the mafia for 'protection'? No. Should you pay the security guard for actually protecting you? Yes.
- sillygeese 11y ago> Do Apple employees not drive cars on roads (paid for by the taxpayer)? If a mafia built roads, would that make its extortion alright? > Of course Apple avoid taxes - anyone who can do so without fear of getting significantly punished does Exactly. Think about that for a while there. You're basically saying that no one would pay taxes without being forced to. Would anyone pay a mafia protection money without being forced to? That's how extortion works you know. There you go. Governments force us to pay taxes, exactly because otherwise we wouldn't pay them, which shows how irrelevant all the services provided with extorted money are.
- krisgenre 11y agoAre you saying the government is extorting in the name of taxes? Taxes are important because some things ( like laying roads ) cannot be selectively implemented. You can't just ask some to pay for the road and the rest not to use it.
- ganessh 11y agoDoes this issue arise from Unnix or Mac OS?
- twic 11y agoWould it make sense for the kernel to use a fresh, empty environment when executing a setuid binary? Or perhaps a fresh environment with a few of the most important variables sanitised and copied over? And perhaps with the old variables available with a prefix (_UNPRIVILEGED_DYLD_PRINT_TO_FILE etc)? What would this break?
- delinka 11y agoThe kext at https://github.com/sektioneins/SUIDGuard https://github.com/sektioneins/SUIDGuard does something like that. For privileged processes, it neuters DYLD_* variables completely.
- deleted 11y ago[deleted]
- pqdbr 11y agoMore and more news about Apple's software quality degrading. They are really, really losing it.
- muaddirac 11y agoWill a major OS vendor ever start taking object-capability ideas seriously? It seems this is part of a class of vulnerabilities that simply couldn't occur under that model.