4 ms·
New macOS zero-day bug lets attackers run commands remotely
- alphabettsy 5y agoThe news report seems to neglect to mention this requires the command execute something already available on the system and it doesn’t appear to allow passing arguments. Would be useful in chaining exploits possibly?
- NathanKP 5y agoThe GIF in the article shows it opening a shell and piping in an inline script that is just an exit command. There's nothing stopping you from piping in your own arbitrary bash commands and executing them, including commands to download a more complex malicious executable payload from the internet and execute it.
- rgovostes 5y agoIt looks as though the URL in the inetloc file is `file:///bin/sh`. Running the command `open file:///bin/sh` should cause the same effect; Terminal.app starts a new shell and executes `/bin/sh ; exit;`. Even if you managed to land an executable in the user's Downloads folder, and guess their username, I think there would be _multiple_ prompts the user would have to ignorantly click through.
- vondur 5y agoHeck. Have an rm -rf would probably ruin some peoples day on their home directory.
- bigbizisverywyz 5y agoA useful addition to the kernel could be a flag that disallows a thread from launching child processes. Then when doing any of this risky stuff like handling gif/png/ASN.1/etc data from outside sources you can handle it in a worker thread that simply isn't allowed to launch external processes and thus sidestep a lot of these exploits. Please get on that Apple kernel devs...
- EricE 5y agoBoggles my mind that we still seem to have fundamental issues with input sanitization!
- PhantomGremlin 5y agoApple's patch only partially addressed the flaw as it can still be exploited by changing the protocol used to execute the embedded commands from file:// to FiLe:// At some point some manager has to look at code like that and fire the developer: "You're too FUCKING STUPID to work here!!!". Let the downvotes commence. But really, there's this eternal wailing and gnashing of teeth about hiring the right people. But then what? If they can't implement case-insensitive string checks then what, exactly, did they learn in 4 years of college?
- bigbizisverywyz 5y agoActually any sufficiently imaginative and slightly evil tester could have also thought of that one too, which means Apple are either missing that skillset or rushed it out.
- hiyer 5y agoApple's QA for the non-obvious UI worflows is non-existent. Case in point - their MDM commands: 1. The inputs/outputs don't match the official documentation 2. Once you figure how to pass the command in such a way that it's accepted, it still doesn't work on many occasions Honestly it's sad that Mac has become the de-facto machine for dev computers these days - I'd be much happier with a Linux box (if it weren't for the damn battery life of the M1 :-) ). Edit: formatting
- taylodl 5y agoMacs are the de-facto machine for dev computers these days because they're easy to manage for the organizations employing those devs. Maybe the Linux community should be taking a look into that? If Linux had the same kinds of enterprise controls Mac OS and Windows provide then I'd wager you would see greater adoption of Linux on the desktop in corporations. I would then expect the greater adoption of Linux on the desktop in corporations would in turn lead to better Linux laptops.