CanSecWest’s $10,000 ‘Hack a Mac’ challenge relaxes barriers, finds exploitable hole in Safari

Apple StoreAfter two Apple MacBook Pros survived the first day of CanSecWest’s ‘PWN to OWN’ contest that dared hackers to take control of default Mac OS X installations, CanSecWest earlier today lowered the barriers as planned since “there has not been a successful attack.” Both MacBook Pros were connected to a wireless router and with all security updates installed, but without additional security software or settings. The contest’s second-day relaxed rules allowed attackers will be allowed to place exploit code online and launch drive-by exploits on the Mac’s built-in Safari browser.

“Time to expand your attack surface,” CanSecWest’s contest organizers stated. Hackers were invited to email links to organizers who would then visit the hackers’ exploit attempts from the target machines using Safari.

Two hours and 24 minutes later, CanSecWest reported, “One OSX box has been owned! At this point all we can say is there is an exploitable flaw in Safari which can be triggered within a malicious web page. Of course all of the latest security patches have been applied. This one is 0day folks. Technical details will be forthcoming as the winner works out the release. There is still one more Mac to go. (the same flaw cannot be used again, but other Safari bugs are allowed).”

“Just to review the rules, the first box required a flaw that allows the attacker to get a shell with user level privilages [sic]. The second box, still up for grabs, requires the same, plus the attacker needs to get root,” CanSecWest reported.

Full article here.

Joris Evers reports for CNET News, “Shane Macaulay just got himself a free MacBook [Pro]. Macaulay, a software engineer, was able to hack into a MacBook through a zero-day security hole in Apple’s Safari browser… The successful attack on the second and final day of the contest required participants to surf to a malicious Web site using Safari–a type of attack familiar to Windows users. CanSecWest organizers relaxed the rules Friday after nobody at the event had breached either of the Macs on the previous day.”

Evers reports, “Macaulay teamed with Dino Dai Zovi, a security researcher until recently with Matasano Security. Dai Zovi, who has previously been credited by Apple for finding flaws in Mac software, found the Safari vulnerability and wrote the exploit overnight in about 9 hours, he said.The vulnerability and the exploit are mine, Dai Zovi said. Shane is my man on the ground.

“Dai Zovi plans to apply for a $10,000 bug bounty TippingPoint announced on Thursday if a previously unknown Apple bug was used. ‘Shane can have the laptop, I want the money,’ Dai Zovi said in a telephone interview from New York,” Evers reports.

Evers reports, “Apple spokeswoman Lynn Fox declined to comment on the MacBook hack specifically, but provided Apple’s standard security comment: ‘Apple takes security very seriously and has a great track record of addressing potential vulnerabilities before they can affect users.'”

Full article here.

“The URL opened a blank page but exposed a vulnerability in input handling in Safari, Comeau said. An attacker could use the vulnerability in a number of ways, but Di Zovie used it to open a back door that gave him access to anything on the computer, Comeau said,” Nancy Gohring reports for IDG News Service. “The vulnerability won’t be published. 3Com’s TippingPoint division, which put up the cash prize, will handle disclosing it to Apple.”

“‘Currently, every copy of OS X out there now is vulnerable to this,’ said Sean Comeau, one of the organizers of CanSecWest,” Gohring reports.

Full article here.

MacDailyNews Take: Our headline is accurate. Some of the articles to which we’ve linked above have sensationalist headlines and/or contain the usual “Security via Obscurity” myth. As we’ve seen recently, a proof-of-concept piece of malware exists for a handful of iPods running Linux. Now, that’s real obscurity. Obviously, 22 million Mac OS X installs are not “obscure.” We expect other articles to incorrectly headline and/or incorrectly report on this story. Prepare for a deluge of FUD, as the thirst in some quarters for Mac OS X to be “hacked” is insatiable.

The bottom line: Apple’s Safari web browser has a hole (not the first and probably not the last, by the way) that will not be published and will be disclosed to Apple to fix. That is the extent of this story as it currently stands.

Presumably, if you use browsers other than Safari (Firefox, for one example) on your Mac or don’t visit Dai Zovi’s particular web page with Safari, you’re invulnerable to this exploit.

We would expect Apple to issue a update for Safari to close this hole ASAP. CanSecWest’s contest has helped to make Safari more secure.

Reminder: Apple’s Mac OS X Security Configuration Version 10.4 Tiger or Later Second Edition (PDF) provides an overview of features in Mac OS X that can be used to enhance security. It is available here.

Related articles:
Apple MacBooks hold strong, remain unhacked after first day of $10,000 ‘Hack a Mac’ challenge – April 20, 2007
CanSecWest sweetens ‘Hack a Mac’ contest pot to $10,000 – April 20, 2007
CanSecWest to hold ‘PWN to OWN’ contest: pits Apple MacBook Pros vs. hackers – March 26, 2007
Microsoft’s oft-delayed, much-pared-down Windows Vista hacked at Black Hat – August 07, 2006
Microsoft publicity stunt asks hackers to attack Windows Vista – August 04, 2006
Apple Mac remains ‘unhacked’ as University of Wisconsin’s Mac OS X Security Challenge ends – March 08, 2006
Mac OS X ‘unhacked’ over 24 hours and counting in genuine security challenge – March 07, 2006

176 Comments

  1. They should run contests like this more often. It proves that Macs are completely secure. The only way this exploit could be used is through a phishing email to get you to go to a bad website. The more holes Apple plugs the better it will be for everyone, and these contests certainly bring out the exploits.

  2. “Relaxing barriers” or “lowering the bar” is not a excuse.

    Most Mac users use Safari and it’s used more often on the dangerous internet than any other program.

    Apple needs to rethink and develop a sandbox environment for internet based apps to run in.

    Also they need to demand developers treat the admin password with utmost security respect and quit demanding it for marketing code installs, “hooks” and fixes for shoddy coding practices.

    95% of exploits are application exploits, Mac OS X “hacks” enable these app exploits to gain much more power than they would normally have.

    Apple needs to also address EFI’s lack of security and normal user control and privacy issues.

    I would like to hear of some fantastic security changes in the next version of Mac OS X because we are rapidly traveling down the road Windows took security wise.

    I’ve already withheld any new Mac purchase until 6 months after 10.5’s release. If the security issue doesn’t improve and remain reliable by then, I’m not buying.

    I refuse to become like a Windows security sufferer.

  3. Just putting here what I posted elsewhere on MDN tonight.

    It’s 5.25am in the morning in Ireland (& yes tonight, it’s sad, I’ve nothing better to do!)

    I came across this story of which we on MDN forums were following earlier today.
    The majority of us were right in our assumptions about the “Hack a Mac” competition!

    I sent the following to MDN:

    Dear MDN,

    I don’t often swear, but please read this fu*kin crap:

    Link:
    http://www.macworld.com/news/2007/04/20/hacker/index.php

    Just as we all predicted on MDN! & after CanSecWest stated:

    “On the second day, the barrier will be lowered a bit and the attackers will be allowed to put exploit code on a special wiki and launch drive-by exploits on the Mac’s built-in Safari browser.

    “the barrier will be lowered”

    Of coarse the above is not stated in the released statment, as we all knew would be the case!

    FUD, FUD & again I say FUD!!

    “According to the security blog Matasano Chargen, Shane Macaulay and Dino Dai Zovi won the contest by gaining shell access to a Mac by pointing the Mac’s Safari browser at a specially-constructed Web page.”

    “You see a lot of people running OS X saying it’s so secure and frankly Microsoft is putting more work into security than Apple has,” said Dragos Ruiu, the principal organizer of security conferences including CanSecWest.

    !!!!

    If your going to exploit OS X, do it for real & don’t lower the barrier. Then I will Listen.

    From,
    A not surprised, but really annoyed,

    Another Irish Dude

    PS:Link
    http://www.matasano.com/log/806/hot-off-the-matasano-sms-queue-cansec-macbook-challenge-won/

    Quote:
    More details as they become available. In the meantime, a drinking game: predict the rationalizations given by Mac zealots for why this finding “doesn’t count”.

    I’ll start: “It took $10,000 to break a Mac, but people break Windows machines for free every day!”

    PPS,
    An exploit in Safari, yes, but I fail to see how you can claim that a MacBook has been hijacked (the original term in the rules of “Hack a Mac”) when you had to lower the barrier.

  4. Whatever. Your brother-in-law has probably cleaned out numerous viruses and spyware over the last number of years, whereas I’m STILL running without any anti-anything software since 10.1. He can laugh all he wants but is is irrelevant.

  5. > I wonder why this hole wasn’t exploited before. Security via obscurity seems to be the true explanation, whatever some Apple users say.

    It’s not a virus. It doesn’t self-replicate and infect other Macs (it doesn’t even infect the target Mac). The user would have to be “lured” into visiting the malicious web site, and the end result is that the hacker has some user-level access to the target Mac, not root-level access. Can’t do too much with the exploit; a lot of effort for not much “profit.” It’s not security via obscurity, but security via Internet Explorer and Windows being much easier and more profitable targets.

    If that other MacBook gets “owned” (root-level access), now that would be something…

  6. Exactly. Apple has a better track record because it’s security is better. Sure, if you turn it off and run special attacks against it, you’re bound to find something.

    Drive through any well-to-do neighborhood. Most of those houses don’t get robbed due to alarm systems and the like. However, I guarantee there are some in those neighborhoods that still get hit because they are smug and think they can leave their car doors unlocked. Same thing. Regardless of how good things seem, keep your security on at all times.

  7. I wonder why this hole wasn’t exploited before. Security via obscurity seems to be the true explanation, whatever some Apple users say.

    Panther’s Safari’s URL handler exploits were posted on Slashdot where tens of thousands of IT and hacker types visit.

    Apple was notified and didn’t do squat for several months.

    Was there a botnet? virus? Nope. A few hundred compromised Mac boxes, perhaps.

    Why? The URL Handler exploits are just like this new Safari exploit, it requires a malicious website. So it requires a little more effort than just something that can spread on it’s own through open ports like Windows machines have “out of the box.”

    However If Mac OS X and Windows market share was reversed, this would be a serious exploit because the attackers would be targeting this flaw for maximum botnet gain.

  8. Call us back when a Mac out in the wild gets hacked and then we’ll talk….

    As for the morons still spouting bullshit claims of security by obscurity, I’ve got two stats for ya….

    OS X was released over 6 years ago and has 22+ MILLION users. Sorry, but that’s hardly obscure.

  9. We need more details. Was the account that had Safari loaded an admin account? If so, then I don’t consider this a successful attack.

    I would just about bet that the attack would not work on a limited user account…

  10. Bull, only “after” the security was REMOVED did they find an exploit. OK, so how many people have opened up their machines to the world?

    If I give you access to my account and turn off the “built” in firewall and allow sharing and other things, then maybe you can hack it.

    OK, I might as well give you my passwords and my credit card numbers for christ sake.

  11. ” I wonder why this hole wasn’t exploited before. Security via obscurity seems to be the true explanation, whatever some Apple users say.”

    PLEASE educate yourself as to what this exploit actually means!

    You are embarrassing yourself.

  12. I just discovered webkit nightly. The improved rendering engine is very robust, faster, and much more compatible. I can use Google Docs and Google Pages all within Safari. I love it. I wish I would have discovered this gem earlier.

    http://nightly.webkit.org/

    It makes me wonder if Leopard will use the new knoquorer engine and if this so called vulnerability still exists in it.

  13. @bullsheet

    This is a “driveby” exploit.

    Meaning you would have to be using Safari and visit a malicious website.

    Then it would only gain “user” access. But eventually it could gain “root” access by installing a auto-start process and wait for you to use your admin password.

    “Security” wasn’t removed, this is Zero Day exploit for all Safari users. In fact the contest is rigged, the Mac’s were not on the internet, just a local network.

    Big difference, there is a lot more exploits out there online.

  14. Nobody ever uses limited user accounts. You might, but you’d be one of the very few.

    And to ‘irish dude’ going on about “lowering the barrier”.. the fact remains that this is a zero-day exploit that affects all current Macs (running Tiger at least.. not sure about older) that are connected to the internet. Who cares what the conditions of the competition were?

    No I’m not scared, I’m not a Windows user or Microsoft employee, and I don’t think its the end of my wonderful Mac security. 5 years running incident free and I don’t think this is going to change that.

    I’m just saying you need to at least admit to yourself that the mac, like all computers, has vulnerabilities. Don’t run around thinking (and bragging) its the computer designed by God.

  15. Wiseguy;

    “Apple was notified and didn’t do squat for several months.”

    Pretty disengenuous, making it sound like Apple simply “chose not to fix” the problem. Do you have any idea just what it takes, and just how long, to just “throw together” a fix? Hmmm?
    Mebbe you don’t, but I’ll let you in on a little secret…
    If it DIDN’T take “a few months”, then I’d have been scared as s**t to install it, ‘cos the QA process ALONE takes that amount of time.
    QA… like, you know… actually TESTING these things before releasing them to the public?
    Hmmmm?

  16. >”Hmmm. Let me get this straight. Nobody could hack the OS itself, therefore, the OS is not secure. Got it.”

    Umm, the OS was hacked. They went through Safari to get to it. They got a shell with user level privileges. It would not be cool to have your entire user account wiped. No, not admin – but anyway you look at it, it’s not good. Don’t downplay it. The details will only be disclosed to Apple and they will patch it – that is the only good news.

    >”We need more details. Was the account that had Safari loaded an admin account? If so, then I don’t consider this a successful attack.”

    Same answer as above… Look, admin or no admin they got access and could delete files – NOT good. Like I said, the only good news is that it will be fixed. Please be realistic about it.

  17. @ no jeff,

    I don’t believe that there is any OS impervious to attack.

    All OS’s have vulnerabilities.I do believe that
    OS X is more secure than Windows (I have used both).

    So like you I am not worried & like you I am 5 years running OS X incident free (OS9, 8, &7 before that, with 2 Word viruses on OS 8 in all that time) and this exploit is not going to change that.

    I do have to say that I was quoting “lowering the barrier” from CanSecWest’s own statement.

    What I want to know is what would have happened if they had stuck to their own original rules! If you had read my posting properly & CanSecWest’s statement about changing the rules on day 2, you would have understood what i was saying.
    I am fed up FUD.

    “Who cares what the conditions of the competition were?”
    Plenty of people.

    “I don’t think its the end of my wonderful Mac security”
    That is my point.

    “Don’t run around thinking (and bragging) its the computer designed by God”
    Here you totally make up a statement & I think you should go take your meds.

  18. Another quick point: I don’t believe allowing the hackers to use Safari as an attack vector was relaxing the barriers at all. Let’s be honest, there are millions of Macs on the web every day and the majority of them are using Safari. That’s a real-world situation. It is in no way some obscure way of attacking an OS X machine. M$ was highly criticized for integrating IE so deeply with it’s OS (and all the ensuing problems it caused). While Safari in no way compares to that, the hackers were able to gain a decent level of access by exploiting a hole in it.

    Bottom line: It’s bad news, and we’ll (myself included) just have to deal with it.

  19. “Whee! I’m gonna do the Smug Dance now! Smug smug smuggy smug, I’m so smug! Woo-hoo! Eat it, Windows-lovers!

    Every time someone tries to engineer a publicity stunt to show folks like me how “insecure” our Macs are, it always backfires and demonstrates just how ridiculously safe Mac OS X really is!

    Smugness level at 9 and climbing!”

    Name of poster witheld.

  20. I’M SURE that a windows PC with all the latest patches probably would fare about the same as a Mac.

    Little known secret about Windows… current versions, when properly patched, are similar, security wise to PCs.

  21. Security by Obscurity – Yes to exploit the mac they required Safari to visit an obscure web-site that could then exploit the machine.

    Who the hell visits obscure web sites looking for someone to attack their machine ?

    If Dai zovi sets up a porn website to attract ‘customers’ they deserve what they get !!!

  22. why there are no attacks to the Mac currently.

    Mac users at large, and anyone with a brain, have always said that phishing and drive-by attacks are always a possibility. This is not the point.

    The point is that doing that is pretty useless to organize attacks to the Mac platform exactly because the 1st day no one has been able to compromize the two Macs.

    These kind of attacks on Windows are used to then instill something that propagates and start the exponential infections we all know on Windows.

    Attacks that work on single machines and then the process has to be repeated again user after user individually makes absolutely no sense. So, again, it is not obscurity that protects the Mac: pretty much the opposite. The fact that a drive-in is possible on the Mac actually reinforces the robustness of the OS: it is useless if then there is nothing in the OS that can be exploited to turn the Mac into a zombie. Not worth the effort in that, again, the results are essentially meaningless in terms of hacking and spreading: zero.

  23. Very interesting news! I always knew Mac OS X security was not perfect, indeed nothing created by people can perfect. It’s nice to finally see an exploit, that works under real world – type conditions, and the whole incident documented and discussed in public forum. Finally, proof that OS X, despite its near impervious security, falls short of perfection.

    Whenever you expect perfection in life, you set yourself up for disappointment. Small imperfections exist everywhere, and in my opinion, make life more interesting. (Giant imperfections, like IE, ActiveX, and Vista’s CD & DVD-rom format, are just a pain in the arse.)

    That being said, this still is bad news for apple, and problems like this and the delay of Leopard are starting to chip away at my overall opinion on the company. Hopefully, they will redeem themselves with near perfect releases of the iPhone and Leopard, but it’s very well possible that hiccups in these products will just add to Apple’s trouble.

    Too bad I don’t have any real alternative to Apple at the moment, since both Windows and Linux have offended my sensibilities. Maybe Linux will someday get their act together, and finally release an OS that will more-or-less work the way I want out of the box without making me spend hours configuring and trouble shooting. Linux at least has a chance of redemption. Windows is just dead to me. And Mac, while still on top, may be starting down a slippery slope.

  24. A non-story if I ever saw one.

    To the guy who is witholding his purchase … who gives a fat rats ass what you are doing. Listen, assclown cry baby, go buy a Dell and shut the fuck up.

  25. One thing that pisses me off is that macs out of the box do not come with the Firewall turned on by default.
    Alot of newbies wont even know its there. This is a stupid default setup.

    this whole thing isnt good, but i bet it was either funded by microsoft or some windows fanboy that just couldnt take the ‘Get a Mac’ ads anymore.

    As the mac gets more and more popular there will be more and more of these losers who make a specific competition to ‘advertise” the lack of security of a mac. I mean theres none of these competitions for windows, its just known that its an unsecure piece of shit.

    their whole attitude is, ‘well if my windows machine it inherently less secure by design, im going to create as much FUD as possible about the mac’

    and just so you can correct the pc crowd, this is NOT a virus. its a vulnerability in an application, in this case safari. Which no, isnt good enough.

  26. I really have to say to some of you, “cup half full people please!!!!”

    Now the facts remain that Mac OS X is still the most secure mainstream OS out of the box. One exploit has been created by a security expert and programmer after 9 hours of work that requires you to go to a website using a vulnerability in Safari. Well who said OS X was totally secure.

    They had a whole 24 hrs, a pretty big dangling carrot and a room full of security experts and hackers on a LAN with 2 macs and they couldn’t get in so the bar had to be lowered. If they didn’t change the rules there would be no winner. Try that with XP or Linux. Linux would take a while yes but with XP, I’d give them 10 minutes including a coffee break to get in.

    This is not serious. 200,000 viruses is serious. Apple will patch this and it will make OS X even more inpenetrable. It’s not a virus people, OX X is still the best, let’s move on please. Oh and to Traveler, do you know if Ubuntu has no vulnarabilities? Go buy a Mac. this proves macs are fantastically secure. Use Firefox if you’re scared of being hacked. I’m sticking with Safari and I refuse to turn on my firewall!!!

  27. The most secure OS is STILL the most secure. No successfull exploit yet.

    These exercises are one of the reasons it is so secure.

    Having a competition like this for Windows would be plain pointless.

    And MOST importantly of all:

    The Mac community is a very different one to WIndows.

    For Mac users Apple is a partner to be supported. For Windows users Microsoft is the enemy.

    Enough said.

  28. Hey can anyone explain the logic in a Windows user who refuses to switch to OS X because he believes that even though there are no viruses for OS X and 200,000 for XP, he may as well stick with XP as in his mind one day there will be loads of viruses for the Mac as well and therefore there is no point buying the more secure system.

    That sort of delusional logic eludes me. It’s like saying:
    “I am going to buy a make and model of car with a reputation for poor breaks and an unreliable engine even though it only costs fifty quid more for a car with a great reputation for safety and reliability. I mean, there are loads more cheapskates out there who put up with these lesser quality cars they are becoming a standard. I may as well because one day someone in one of those reliable cars will have an accident or get stuck out in the middle of nowhere. It could be me. At least with this Microsoft car I will be prepaired when it happens. “

    I hear it all the time with my windows using customers when I suggest they think about switching.

    Stockholm syndrome & cognitive dissonance all the way baby…

    Some people are Idiots!!!

  29. I’ll have to give em credit for this, as much as I hate to.

    So the score stands at:

    OSX: 1
    Windows: 100,000+

    I’m OK with that. But still, I cannot in all honesty say zero anymore. Knew some day that would happen.

  30. So they had Root access and no firewall to contend with? Is that right? If I leave the keys in my car with the engine running I wouldn’t be surprise if someone had a little go (especially if I’d asked them!!). Not sure what this proves.

  31. @ Wiseguy

    Since you are postponing a new Mac purchase for 6 months, perhaps you could also refrain from posting for those 6 months? And get your friend/alterego Traveler to do the same. Many of us would really appreciate it.

    Just a thought…

  32. Reading a bit further on the subject I may amend my score to one-half a point. The way I read it, the attacker had user-level access, not admin, so he cannot install any software (without an admin pw). The attacker could certainly wreak havoc on the user’s files, but with no installed code it can’t spread to another machine or become part of a botnet. What was demonstrated couldn’t spread anyway unless the infected user was himself running a web server serving up pages with the embedded exploit.

  33. So the score stands at:

    OSX: 1
    Windows: 100,000+

    WRONG, this is not a virus. It still is OS X: 0 an Windows over 100k.

    Apple releases security updates. It even had security updates ALREADY covering Safari where if a user was lured to browse a malicious web site, click something, do something etc THEN there could be a compromised environment. Period.

    This is not the first. Also the MOAB showed some examples of these or people have already forgotten them? And THESE things are going to be discovered and fixed and discovered and fixed etc.

    The important result is that during the first day, with a hall full of security experts and experts hackers all bent to get those $10000 not one has been able to compromise the two Macs, which is what Apple always stated: a vanilla Mac OS X online, is pretty much safer than any other OS around.

    Luring users into malware is always a possibility, always present: Apple cannot release a user security update. If you are visiting sites you have no idea of, interact with them without not knowing what you are truly doing you are exposing yourself to malware. Some OS might protect you better than others, some browsers might protect you better than others but there is no 100% shield.

    So, it pretty much still is:

    Mac OS X: 0
    Windows: over 100k

    And as stated in a post above, these kind of exploits have little interest if the only thing I could do is compromise ONE machine THEN I have to hope to repeat the process with a second user.
    These exploits are meaningful if they provide a door into the system so that I can thence control the compromised system and start an automatic spread of installed malware. As it happens on Windows.

    So far the above is not possible and the unaffected MacBook Pros in the first day exactly show that.

  34. The bad first-
    —————

    Macs can be succeptable to driveby attacks. These attacks can be implemented just by going to a web page no further actions by the user are required.

    With XSS(cross site scripting) hackers can inject malicious code into a non-malicious web site that you may visit.

    However, an attack like this is most likely some sort of buffer overflow, which can allow an hacker to get a shell and open a backdoor. A firewall can not protect against this type of attack. Apple does have some built protecton to guard against the most common type of buffer overflow attacks, but it is not able to stop “return to libc” buffer over flow attacks.

    Attackers are more commonly exploiting weaknesses in applications to gain access to a computer as this is now the path of least resistance compared to directly attacking an Operating System. Obviously phishing is even easier.

    This type of attack is very common in the real Windows world! But probably not the best attack for Macs unless they can gain root access. To be safer from these attacks do surf the web under the Admin account, then the attacker would have admin rights.

    The Good-
    ———–
    It is doubtful that they will gain root access, since it is disabled by default(Go Apple!). Opening a backdoor to a non-root account will not gain an attacker very much.

    Here’s why-
    They can then attempt to download additional malicious software to corrupt operating system files, install rootkits, keystroke loggers, botnets, or even viruses.

    For the Mac OS X, they would not have very much luck since they would not be able to modify system files or install low level code like keystroke loggers or rootkits. Viruses, would have a very hard time since they would not be able to modify system files or executable files or expand their activities beyond the users account. They would be able to delete the users file and run scans on their directory.

    Installing an autostart program would be difficult on OS X, I believe they would need at least admin rights to do that. So I don’t think this would be a factor.

    So the equivalent of this exploit would be like breaking into a house and finding out that you are only in the garage and cannot break into the main house. Not very useful.

    This contest will Macs more secure in the long run. I wish Apple and Microsoft would eliminate buffer overflows completely at the operating system, this would frustrate attackers the most because buffer overflows are one of the oldest and most common types of attacks that allow attackers to gain access to a system. They are least 20+ years old and continue to be very common.

    Macs are still more secure than windows. After Apple provides a patch, I hope they release some more information on the type of attack was used.

    Macs are still awesome and provide great security…folks please make sure at a minimum not to use an Admin account for everyday use! Use a regular account.

  35. Nothing is perfect…

    The fact that this will become such a big deal is…

    Apple is up 33% and gained another point of marketshare. That should
    be the story but thats not sexy enough..

    I think the kid should get the money and the laptop. Apple should
    admit the problem, fix it and hire the kid to do it again. Once he can’t,
    publish the sh@t out of that and make this a non-issue.

    Apple is still the best regardless..

    Just a down to earth, we are all human, even Steve, thought…

  36. @ Tacoma

    I agree….in fact Apple should keep a running contest open for zero day exploits for all of its products.

    Even further, Apple really should eliminate all buffer overflows at the operating system level, so exploited applications will be stopped by the OS. I am currently researching this area and it can be done without any additional hardware registers and without degrading performance.

    They should open this contest up to the world and fix the exploits as they come in. At least they will have the opportunity to fix them before some hacker uses them in the wild secretly.

  37. “Whee! I’m gonna do the Smug Dance now! Smug smug smuggy smug, I’m so smug! Woo-hoo! Eat it, Windows-lovers!

    Every time someone tries to engineer a publicity stunt to show folks like me how “insecure” our Macs are, it always backfires and demonstrates just how ridiculously safe Mac OS X really is!

    Smugness level at 9 and climbing!”

    Name of poster witheld.

    Why, that would be me!! And I’m still just as damned smug as I was yesterday! And I will be smug until I hear the first report of a Mac user being affected in the wild!

    Let’s look at what really happened here. They’ve proven that they can gain user-level access to a Mac if they can get the user to visit a malicious webpage. But what are they gonna do with it? No criminal wants to waste his time manually searching through individual computers for useful information. You don’t know where I store my financial stuff or passwords on my Mac, if I even do.

    A hack of a *nix machine is only useful if you can root the machine. And while there are ways to start with user-level access and escalate it, they all require too much engineering to be worth it, especially since Apple will close both the user-level and escalation holes. (And unlike Windows, Unix OSs are not so full of countless holes that you can just move on to the next one.)

    As I’ve said before, the scourge of Windows is automated attacks, the worms that jump from machine to machine, 0wning them without human intervention and assembling botnets. And the first day of this contest proved that “hands-off” hacking still isn’t possible on a Mac.

    So yeah, I’m smug. And as long as the scoreboard shows a big fat zero next to “actual Mac OS X users compromised by hackers or malware”, I’m gonna stay smug!

  38. “Wrong” said:This is not the first. Also the MOAB showed some examples of these or people have already forgotten them? And THESE things are going to be discovered and fixed and discovered and fixed etc.

    Wow. Is that ever a good point! This is no different that the MOAB flaws, which everyone laughed at! I guess the fact that Safari is an Apple application, and the sensationalism of the $10,000 prize makes people overreact.

  39. So, out of the billions of pieces of computer malware (counting replications) available on the internet, they had to direct this computer to the one piece of malware in existence that could attack Safari.

    That one piece of malware is not out in the wild.

    The Safari vulnerability has not been published.

    My Mac is not vulnerable to attack this morning.

    I can buy a new Mac whenever I feel like it.

    I can update to Leopard the morning it is released.

    FUD spreaders, especially those paid by Microsoft, go fsck yourselves.

  40. “I’ve already withheld any new Mac purchase until 6 months after 10.5’s release. If the security issue doesn’t improve and remain reliable by then, I’m not buying.”

    How much more could it improve? One person out of 6 billion people was able to hack into a mac with no firewall after being invited to do so. It required that the user go to a specific website that was e-mailed to the person that was allowing his machine to be hacked. I have 4 macs all on the internet. 2 of them are on nearly 24 hours a day. One of them for 5 years, 2 of them for 2 years and one of them for four months. To date: No viruses, no spyware, no adware.

    We also bought a Dell PC which was used to run one excell file that wouldn’t open on the mac. We hooked it to the internet as well. After the FIRST DAY there were ads that would pop out of the task bar on the bottom of the screen…..very annoying.

    My next question is, then what would you buy? I have an old Commodore 64. I’ll sell that to you for the price of the Mac you were saving for. I guarantee nobody will hack into it.

  41. wiseguy:”Apple needs to rethink and develop a sandbox environment for internet based apps to run in.”

    Sounds like good idea to me. I wonder if they can run Safari inside jail.
    Fil Downloads may cause minor problem.

  42. Is this bad: yes, but not in any practical sense.

    This is probably no more dangerous than previous Safari expoits. Details are few, but if it’s a relatively simple bit of code to add to a warez or pr0n site, which is where many Windows computers get hit with malware. No phishing emails required.

    That it’s limited to a user account is irrelavent–how saguine would *you* be if an attacker got shell access to your account and wiped out your photos, music, documents, etc? Yes, you should have backups… but I bet dollars to donuts over half of the Mac community doesn’t do regular backups.

    This was a good excercise though, as Apple has supposedly been informed of this exploit (which is NOT zero-day, since there are no reports of this exploit being used maliciously in the wild) and should fix it promptly.

  43. @ (un)wiseguy
    It’s pretty obvious you’re not a Mac user, just someone pretending to be part of the pack just so you can cause confusion and be able to serve FUD.

    Seems like your FUD isn’t tasty at all.

    Like what the other guy said, nobody will give a damn if you’re going to postpone your Mac purchase, assuming the intent is there. You can buy a Dell or an HP PC. That will make you busy for the next 6months I bet, removing malwares, adwares, installing anti-virus apps, formatting your drive and re-installing your crap OS.

    ON TOPIC:
    Again, the windows fanboys will forever gloat over the fact that there’s still no virus, spyware in Macs. Neither is there a mass take over of Macs nor a single take over in the wild.

  44. Wingsy & Co. –

    It’s still…

    OS X: zero
    Windows: 100,000+

    There still are zero viruses. Zero adware and spyware, as well. This exploit simply allows a hacker to attack a single machine with the user’s cooperation, and the attack is not self-replicating. How widespread can the damage be? Who’s going to bother? As long as you don’t visit the bad guy’s web page, your Mac is totally secure.

    C’mon folks, let’s not get all Chicken Little here. Yes, the damage to a particular machine could be disastrous. But, how many machines are likely to be affected? Precious few. The fact is, talking users into shooting themselves in the foot is still infinitely easier than hacking a Mac.

  45. So the only way they could win is by cheating and lowering the normal security level in OSX. Sounds like OSX wins again and is still king in security. If Windows was put out in the same manner it would have been compromised in less than 2 minutes.

  46. The hacker was able to obtain a User level account that granted access to files. They did not (as far as I read admittedly) achieve Root level or an Admin acct where they owned the machine. Frankly, that’s a big difference. I remember my Windows Servers being totally owned and rootkitted within hours after exposing it to the internet. This was during original WinNT days and before I learned about the threat levels on the Windows side. Amazing to see a new server with a 500GB drive, on which I had installed about 60GB of data, tell me within days that my disk was full. I was shocked to see directories full of game software, porn, and movies, with a fullon FTP server running. It took less than a week for my server to belong to someone else. It took be three massive exploits and complete server rebuilds before I finally got educated enough to protect the machine (Win2003 Server helped).

  47. I’m a Mac geek and I have read stories over the years about “viruses” and “exploits” and when I looked into the details all were set up in a non-default way that no Mac user would set up, or they required somebody to run a Trojan horse (something no platform could ever be immune from, period — if you intentionally run a malicious program you’re on your own pal!).

    I checked out the details on this one and this is the first exploit I have ever seen that stands up to scrutiny. I’m not going to whitewash, or deny it, and other Mac users shouldn’t, either. The fact is, on a standard Mac running Safari you are potentially insecure “in the wild” because if somebody takes the time to construct a clever enough ruse to lure you in, there is no way you could tell that this website should not be visited — and you are vulnerable.

    Don’t tell me that I shouldn’t visit any websites whose names aren’t written in Alexa in gold, because that’s not convenient: it’s not the way I want to use the web, nor does anyone really use the web that way “in the wild”. We all click on links given to us by friends to things that might be funny or whatnot; we don’t always recognise the URLs; and we don’t know where our friends got them. So this exploit is real. It’s serious.

    However: don’t let anybody tell you that this is a “virus” or that this makes writing a virus for the Mac any easier, because it doesn’t.

    So I give it to you WinGeeks: you scored on this one. (Well, actually Mac security experts scored against themselves and you gloated, but — you deserved to gloat.)

    That makes the score basically fifty hundred thousand to one. Enjoy your point.

  48. Majikthize & John, if you start spreading lies to downplay this hack, you’re just as bad as the other Windows FUD spreaders. The security levels were in no way actually lowered, everything was on the default settings with all the latest security patches. The “relax boundaries” refers to the user opening a web browser and going to potentially malicious websites, under default security settings, something that people do all the time with their macs.

    @ Those clamoring that this is not technically a virus: your missing the whole point. This exploit gives a hacker the ability to modify files in the administrator’s account by merely tricking the user to open a website. If the details of this exploit fell into the wrong hands, then it could easily become a terrible OS X virus.

    I’m not some sort of undercover Windows fan. I hate Microsoft, and I love my iMac more then any normal person should love a computer. But I keep it real. I don’t have to spin facts, spread lies, or be delusional to know that Mac OS X is the most advance operating system in the world, and it’s security is second to none. I don’t have to ignore a potentially serious flaw, because there is still plenty of evidence proving Mac OS X is superior to Windows, in almost every single way, especially in security. I’m just a mac fan who keeps it real.

  49. 114,000 vs. 1

    And the one requires you to be a completely naive ass to take over your machine. Anyone here have their machine crippled by this “expoit”?

    Let’s get a hold of oursleves. One exploit does not an unsecure OS make. And an exploit that has yet to cripple *anyone’s* machine in the wild.

    Oh, and Wiseguy: you are absolutely the dumbest fu*ker I have ever heard. Do us all a favor and shove that sh*t dribble you spit up your ass.

  50. @setting the record

    114,000 vs 1

    Wrong again. This is not different from what has been found in MOAB. Why then didn’t you set the record straight (whatever) to 114,000 vs 8 or 9?

    Again, it is a MOAB thing. Nothing more, nothing less.

  51. @Traveler, first off the hack only gave him access to a user level account not the root. Yes, it has the ability to modify the Admin account ONLY if the user is stupid enough to use an admin account while surfing the web.

    @wrong, so the point being? windows is still way loaded with craps, viruses, spywares and adwares with ACTUAL MASS INFECTIONS/TAKEOVERS in the wild unlike OSX. Yeah, it is a MOAB thing and the only thing they’ve proven was that their some bunch of idiots trying to make a name. Yeah, they found some vulnerabilities but NONE of them Macs were exploited in the wild. Oh, whatever happened to that flaw that they tried to exploit by writing malicious codes in their site. Haha.

    @This one can’t be spun, i don’t go to websites that i’m not familiar with even if they’re sent “supposedly” by my friends. Not all surfers, especially Mac users, are that trigger happy and addicted to porn. But you’re right, it can and will still be used someway somehow to exploit a Mac especially for clueless and reckless users out there.

  52. @cheese

    @wrong, so the point being? windows is still way loaded with craps, viruses, spywares and adwares with ACTUAL MASS INFECTIONS/TAKEOVERS in the wild unlike OSX. Yeah, it is a MOAB thing and the only thing they’ve proven was that their some bunch of idiots trying to make a name. Yeah, they found some vulnerabilities but NONE of them Macs were exploited in the wild. Oh, whatever happened to that flaw that they tried to exploit by writing malicious codes in their site. Haha.

    Cheese, indeed my point. It’s a MOAB thing. And we laughed at it. Why now people are all upside-down with this MOAB-like exploit.

    Really very little to see still.

  53. Why not sending the $10,000 to the MOAB people. After all they pointed out to vulnerabilities in Safari, iChat, QuickTime and other third party applications.

    What the contest showed is that Mac OS X still cannot be exploited remotely as Windows without user collaboration.

    And THIS is why the Mac is of little interest to be attacked.

  54. If you count this as a virus, you’re wrong. If you count it as an exploit, your count is way under.

    There are two lab-created worms and more than a couple of exploits through Safari. But for the worms to be successful, your machine would have to be in the lab, too, and you’d have to follow a list of printed instructions and perform moves like Rosemary Wood’s (look her up — use Nixon in the search) to allow the worms access.

  55. Traveler –

    Please explain which of my statements was a lie. Also, please explain the following claim:

    “If the details of this exploit fell into the wrong hands, then it could easily become a terrible OS X virus.”

    How could this become self-replicating?

  56. IT IS STILL ZERO
    Zero viruses, zero malware

    A drive by is neither a virus nor malware.

    What they did was get a user shell, big woop. On OS X that gets you next to nothing
    You cannot “gain “root” access by installing a auto-start process and wait for you to use your admin password” (wiseguy)
    You cannot use the Mac as a bot (next logoff or restart will terminate the shell and any processes spawned from it)
    You cannot gain control of the box.

    This is a security flaw in Safari, there have been flaws before and there will most likely be more.

    The theme here is that when a program has an entry point (like this drive-by) little is gained (nothing that could be used) because OS X is based on a very secure kernel (BSD UNIX)
    Obtaining passwords gaining root access installing auto-executing code are all impossible.

    This is not make OS X equivalent to the security nightmare that is the NT kernel.
    OS X is more than a thousandfold more secure than than 2K XP or Vista, anyone who tries to equate the two (security wise) is lying clueless or delusional.

  57. http://www.roughlydrafted.com/RD/RDM.Tech.Q2.07/616874CC-35CE-49D3-B859-C2719B6FF352.html

    has posted an informed article on this exploit. I suggest you read it to get a better understanding of how the Mac was owned.

    This issue needs to be addressed, but you should be concerned only if you are likely to open unsolicited email links or visit nefarious websites on a regular basis.

    As a positive, perhaps it will instil a modicum of self-restraint on the smug attitude that oozes from MDN.

    This adolescent chest-beating makes me understand just why the negative perceptions of Mac-users remain so prevalent.

    Instead of trying to spin every article it mirrors, MDN would better serve its readers by removing the adolescent diatribes and presenting the facts in an honest and balanced way.

  58. Majikthize

    First of all the lie: “There still are zero viruses [in OS X]. Zero adware and spyware, as well.”

    The total count of viruses and other malware in OS X is slightly more then zero, my guess is it’s somewhere between 1 and 8. I have plenty of evidence that their was at least one real virus that infected OS X:

    http://www.sophos.com/virusinfo/analyses/osxleapa.html
    http://en.wikipedia.org/wiki/Leap_virus
    http://www.sophos.com/pressoffice/news/articles/2006/02/macosxleap.html
    http://www.symantec.com/security_response/writeup.jsp?docid=2006-021614-4006-99
    http://www.macworld.com/news/2006/02/16/leapafaq/index.php

    This was a real Mac OS X virus, it was self replicating, and it really effected a number of real users in the wild.

    Second issue, my speculation:
    “If the details of this exploit fell into the wrong hands, then it could easily become a terrible OS X virus.”

    This is a hypothetical statement, and it requires a bit of creative thinking. Here is one way I could imagine it happening. Someone sends out a mass email, targeting Mac users (perhaps promising screenshots of Leopard, something making fun of Microsoft, or something else that will trick mac users.) That email contains a link, or even the embedded code itself, that takes advantage of the exploit. An unix script is now uploaded remotely into the victims computer. That script then somehow uses that computer to send more emails (or IMs) to replicate itself. The payload could be reading, deleting, or modifying any file the user has access privilege to. It may not have root access, but it could still do significant damage. This is of course all speculation, most likely none of this will happen, because Apple will try to patch the hole before anyone else learns how to use it.

    So, in light of the fact that OS X security is not 100% perfect, what should the average Mac user do to protect his or her computer? My suggestion: do nothing! You have the most secure OS on the planet. All you should do is make sure you have an admin password good enough that random people won’t be able to guess it. Spending time implementing any more security precautions is excessive, unnecessary, and not worth the trouble. No matter what you do, their will always be a chance, albeit a very small chance, that something bad might happen. You are safe enough as is, so don’t waste time trying to protect your self from the nearly insignificant chance that you might someday get malware.

  59. “So the equivalent of this exploit would be like breaking into a house and finding out that you are only in the garage and cannot break into the main house. Not very useful.”

    it’s more like breaking into a house and finding you can go anywhere in that house a normal person who lives in that house can go, and can take all their stuff that they haven’t specifically locked up, but can’t get into the locked safe in a bedroom without a bit more work.

  60. “What they did was get a user shell, big woop. On OS X that gets you next to nothing”

    OK, why not set your Mac up on the Internet with a telnet daemon enabled so that anyone can connect and log in using your standard user account with an open invitation to do whatever damage they can.

    Lets see if all that you care about on your Mac isn’t wiped out within minutes.

  61. @@wingsy
    You can only wipe out the user data NOT the system files, applications or data of other users. Now if i’m using that account to only surf the net and not to store any data that is of particular importance, what will I lose? Cookies? Haha.

    Sadly, it’s not the case in window$ world.

  62. “It works. It is real. This is not something that I have made up,” Dai Zovi said. “It seems that a lot of people harbor the belief that the Mac doesn’t have these problems, but it does.”

    but more realistically, the developer who actually put the exploit in place at the conference makes a distinguo:

    “This is more realistic,” Macaulay said of the exploit. “Everyone is going to be behind a router, so you are not going to have a chance to use a fully remote exploit.”

    So a stunt capable of winning ONE of the two MacBooks: at the conference no one has been able to remotely attack any of the Macs nor getting a root-level privilege.

    So the “Pwn to Own” result was: A Mac was owned but none was Pwned.

  63. This is a hypothetical statement, and it requires a bit of creative thinking. Here is one way I could imagine it happening. Someone sends out a mass email, targeting Mac users (perhaps promising screenshots of Leopard, something making fun of Microsoft, or something else that will trick mac users.) That email contains a link, or even the embedded code itself, that takes advantage of the exploit. An unix script is now uploaded remotely into the victims computer. That script then somehow uses that computer to send more emails (or IMs) to replicate itself. The payload could be reading, deleting, or modifying any file the user has access privilege to. It may not have root access, but it could still do significant damage. This is of course all speculation, most likely none of this will happen, because Apple will try to patch the hole before anyone else learns how to use it.

    Traveler, the only correct thing above is that it is all speculation. In order to do all above you have to have root-level privileges in the Mac.

    Pretty much what could happen today with this exploit is: “Someone sends out a mass email, targeting Mac users (perhaps promising screenshots of Leopard, something making fun of Microsoft, or something else that will trick mac users.) That email contains a link, or even the embedded code itself, that takes advantage of the exploit. An unix script is now uploaded remotely into the victims computer. ” And the script can only run at user level.

    As even the author of the exploit an the conference said: “you are not going to have a chance to use a fully remote exploit.”

    And this is the very reason why there are no such attacks on Mac OS X, because once you get in you get nothing that will allow you to start an automatic replication, control of the machine and spreading to infect others. It is like you may get in into the tool shed of a property but still you can’t figure out how to break in into the house. So far, the effort is truly for nothing on Mac OS X.

    On Windows people access the tool-shed, the garage, the cave, the house and break at ease in the attics. The only thing this will bring is silly Windows users gloating “Mac OS X is as unsafe as Windows”. Yeah, right.

    PS
    The second MacBook Pro and prize went undelivered: no one has been able to pwn the Mac, that is achieving a root level shell privilege.
    Again, till a way to get the above is found, there will be no malware for Mac OS X, people will still wonder why and morons will say “look, they did it” nope, they did not “at a conference time ago. It does not happen because Macs are such a tiny target”.

    Yeah, right, like over 20 millions users are not a target to people who collect zombies PCs and sell them with profit at only few thousands each lot. Whatever.

  64. Do people know that crackers have delivered the first virus for iPod? To be more precise, it works on iPod where the user have installed Linux as it exploits a weakness of a Linux installation tailored for the iPod.

    Uhhhmmmm, wait. Were not virus writers only interested in cases where millions and millions of users, hint: way more than 20 mil OS X users of course, could be infected?

    Were not virus writers only interested in finding way to break into Windows because of the sheer numbers of their installation?

    How comes they got interested in the iPod market with Linux installed? What market is that? Hundred people in the world? A THOUSANDS USERS at MOST?

    Yes, I can see it. Virus writers only look at numbers to decide where to operate: Linux iPod installations case is a clear example of that.

    To all lobsters out there: if it can be done it will be done. Period.

  65. If it has not been done so far, it is because it can’t be done (so far).

    And yes, even with the Safari weakness exposed last day: useless without self-replication, privilege escalation to root-level, automatic distribution.

    If it cannot replicate, work as root, spread automatically it is not malware, it is a joke, a prank.

    “you are not going to have a chance to use a fully remote exploit.” — Pwn to Own contest winner.

  66. @Traveller

    Whenever you expect perfection in life, you set yourself up for disappointment.

    Too bad I don’t have any real alternative to Apple

    So? If you are not looking to the perfect OS

    AND

    you have not found anything better than OS X, why are you whining?!?

    Try logic reasoning before posting.

  67. @Traveler:
    “This was a real Mac OS X virus, it was self replicating, and it really effected a number of real users in the wild.”

    Really? In the wild? Is that so? Here’s a quote about the Leap ‘virus’ from the wikipedia article YOU referenced:

    “Unlike most widely-reported worms for Windows, Leap cannot spread over the Internet. It can only spread over a local area network reachable using the Bonjour protocol.”

    So which “wild” is this you’re talking about, exactly? Your apartment?

    News flash: if a virus cannot spread over the internet and cannot infect removable media to be carried physically to another machine, then it is NOT in the wild. Being in the wild requires actually being able to SPREAD in the WILD!

    No, there are still zero viruses for the Mac that anyone has to worry about. But there is this little Safari exploit I’m sort of worried about…

  68. Debunker,

    with own admission from the very same guy who won the contest with the Safari exploit, it is not something that can be used to get an exploitable hack in the wild.

    MOAB has shown already few of this *hacks*, they should get the $10k rather. They showed even more *dangerous* things (which Apple fixed in the following days)

  69. News flash: if a virus cannot spread over the internet and cannot infect removable media to be carried physically to another machine, then it is NOT in the wild. nor it is a virus.

    News flash, pee is yellowish, as a unique taste, has bubbles but IT IS NO CHAMPAGNE.

    This is no virus, no remote exploits, it is basically a prank, a twist that allowed those guys to win a prize.

    NEWS again: the other Mac went UNAWARDED: no one has been able to remotely hacks the Macs nor getting a root privilege access.

    So no PWN to Own.

  70. Some people here have quoted the contest winner saying: “Everyone is going to be behind a router, so you are not going to have a chance to use a fully remote exploit.”

    Where did you get this quote from? From what I’ve read, I got the impression that any machine viewing the malicious page in Safari could be effected. But these quotes seem to imply that this would only work in a local network. I Googled these quotes, and got 0 results, so I’m wondering if you guys are making it up or if the contest winner really said. If you guys are right, this exploit wouldn’t work on regular users viewing the page in safari, then I stand corrected on a number of things.

    @ “Still Some Debunking Left To Do”

    You’re saying that for a virus to be in the wild, it must spread over the Internet? I remember the days when viruses spread to most people over floppy disks (that seemed pretty wild to me.) There are many ways to spread viruses to unsuspecting users, it’s not limited to just the World Wide Web. I consider the wild to be any condition where average users unexpectedly get infected. (Not in the wild, means existing only on the computers used to create and test the virus. The wild is everywhere else.)

    Granted, Leap virus was not nearly as bad as a wide spread Windows viruses. It did not have very good delivery method, so only a hand full of people were infected. But it still counts, it was a virus that infected some OS X users in the wild.

  71. You’re saying that for a virus to be in the wild, it must spread

    over the means of communication of the time. it was floppy disks when there was no internet, today is internet, tomorrow it could be brain waves?

    To be a virus it has to spread, period. If it doesn’t it is a joke, not a virus.

  72. this is exactly why there are no malware on Mac OS X so far: It did not have very good delivery method

    Malware that do not have a reliable, good, replicable delivery method is meaningless. You may have things like the MOAB have shown, or this contest showed with Safari but if it is not something that could truly spread the entire exercise is POINTLESS.

    THERE ARE ways to break into OS X, there are even white papers on it. There are proof-of-concept, some coulda/woulda/shoulda but if then there is no subsequent effective good delivery method all those ARE POINTLESS.

    The problem that virus writers face with Mac OS X is: “Ok, I get this possible crack here. I could get into a Mac with some effort. THEN WHAT!???”

    Capish?

    Numbers of machines is a none factor: there are plenty of Macs out there. The issue is the as yet unsolved problem of replication, self-installation, auto-delivery. Till a reliable mechanisms is found all the efforts are vane, useless, at the level of a prank, worthless.

    On Windows, crack into one Windows machine you have 100% certainty that cracked machine starts working for you to crack all others.

    On Mac OS X not. Thence, so far, not a target.

  73. On Mac OS X not. Thence, so far, not a target.

    Better, IT IS a target, but people so far have not been able to HIT IT.

    Question: What is the most attacked large installation in the world of Mac OS X platform?

    I give you a hint: it has the largest db of tracks in the world and had already over a BILLION transactions. Starts with i and ends with Tunes.

    Cheers

    MDN “sense” like in: does it finally digs in all your minds and make finally SENSE? ‘Nuff said.

  74. “You can only wipe out the user data NOT the system files, applications or data of other users”

    That’s a great result, since I don’t care about loosing any of my documents, photos, music, mail etc, but I do care about loosing OS files I can reload from CDs. Not.

  75. Thanks for bringing a sense of sanity. A lot of the posters here are deluding themselves.

    The intruders were able to gain a shell with user level privileges – NOT GOOD no matter how you look at it. This cannot be disputed or spun – make as many twists and turns as you like and that fact remains the same – PERIOD. Being that it was through Safari makes no difference. Millions of Mac users surf the web everyday and seek out/visit new sites. This *could have* been imbedded in one of those sites. What is it that people don’t seem to understand about that? Yes, it will be patched pronto – great news. I still don’t like the idea that someone was able to gain *any* level of access.

    All that said, OS X *still* has a stellar security record. I will continue to use it and I’m not losing any sleep over it. I’m not denying it either.

  76. @traveler

    This is what Still Some Debunking Left To Do” posted.
    ==========
    News flash: if a virus cannot spread over the internet and cannot infect removable media to be carried physically to another machine, then it is NOT in the wild. Being in the wild requires actually being able to SPREAD in the WILD!
    ==========

    I dont know what part of that statement do you not understand for you to say that he limited the definition of “WILD” to just the web.

    See you really have to read carefully before you post. Just like thinking a lot of times before buying a windows PC though we know it’s a no brainer that Macs are just superior compared to their windows laden PC brethren.

  77. What is it that people don’t seem to understand about that?

    That the exploit does work on a LAN. Even the very same contest winner put it very clear: people in real world are behind a router. You cannot use this exploit for a real remote attack.

    Both the malicious web site and the affected Mac WERE ON THE SAME SUBNET.

    If you do not grasp the implication of the above I am not here to explain the obvious.

    The prank has been able to get the developer a win at the conference but it is NOT something that can be reproduced elsewhere but in a LAN.

    AGAIN, there is very little to see.

  78. “You can only wipe out the user data NOT the system files, applications or data of other users”
    That’s a great result, since I don’t care about loosing any of my documents, photos, music, mail etc, but I do care about loosing OS files I can reload from CDs. Not.

    What people still do not get is that BECAUSE of this limitation, attacking Mac OS X is STILL not interesting.

    Do you think a virus writer or a cracker is interested into stealing your own document, Mac after Mac manually? Even if it is 100% that s/he will find your full bank details, do you truly believe that s/he will be interested in spending time to examine practically MANUALLY Mac after Mac to find this information?

    For attacks to be interesting, once into a machine you HAVE to be able to GET FULL CONTROL, system level access. Just being able to get user level is POINTLESS. Why? Because you will not get any sizeable number this way: one need automation, something that can break in, install malware with full access to the machine resources, replicate and use the machine to automatically repeat the process. If you need a user having to enter the admin password in order to do every single step of the process and hit OK then YOU HAVE NOTHING!!!

    And that means attacking Mac OS X is useless, hence still not a TARGET. The installed user base is WAY MORE THAN ENOUGH to make it a juicy platform to attack if an efficient, automatic method to deliver the malware, install it, replicate and control the machine so that the process repeats itself AUTOMATICALLY without user intervention. Till that happens the Mac will not be an interesting target.

    So yes, it is a great result because the malware author does not care about your user data if he has to manually operate on every single machine.

    It is still amazing that people does not get it. An OS and a platform becomes a target when an infection that allows automatic repetition of the process can take place. For as long as attacks are limited to user space, without full control of the OS resources a platform remains unscathed, that is, no malware circulating because it would be POINTLESS.

  79. “Do you think a virus writer or a cracker is interested into stealing your own document, Mac after Mac manually?”

    No, but I do accept that once they’re on my box, with my privileges there’s a lot of things they can do, not the least of which us use local privilege escalation attacks.

    But lets assume for argument’s sake all they ever get are my rights. If all they’re going to do is automatically run a script which searches my machine and mails them any confidential information it finds, sends the link for the bad URL to everybody in my address book, then deletes all my data files, that’s enough of a compromise for me.

    However why is OS X not interesting?

    Two guys are hiking thru the woods when they come across a blood thirsty bear. The first guy starts taking off his boots and putting on running shoes. The second guy says ” hey, what are you doing, you can’t outrun that bear!” and the first guy replies ” I don’t have to outrun the bear, I only have to outrun you.

    OS X doesn’t have to be completely secure to be uninteresting. The combination of better security and low market share make it uninteresting.

  80. @great

    You still don’t get it do you? 22million Macs that work as a botnet, ASSUMING IT IS POSSIBLE even though we know it’s not, is enough money on the bank.

    Assuming one can derive 1USD per Mac that is exploited and is made part of a botnet sending spams and all then you have basically 22million USD. Of course, it’s not nearly a tenth of what you can make out of windows machines using the same computation because of the huge installed base of windows BUT you can bet your ass nobody’s going to refuse it if he knows he can earn 22MillionUSD.

    To put it simply, security via obscurity is just a myth that is repeatedly being used by windows fanboys to lessen the stupidity that they feel when they’re buying Anti-viruses, installing anti-spam, anit-spywares and worse reformatting their hard drives as a result.

    Now, if I have confidential information that I need to keep secure why would I surf the net using that account that has access to these confidential informations? It’s not hard to create another user account that’s only meant for surfing which is what I’ve been practicing for the longest time. Again, security does not only end in a person having a more secured OS but it also entails how the user implements his security procedures. Even if you have the best security systems installed in your house, it will still be compromised if your security pin is written in a post it that’s placed in a table near your window.

    Again, no OS is completely secure so thinking that OS X is completely invulnerable is plain stupidity. However, the fact still remains that when it comes to security OS X still leads the pack by a mile while Windows lags at the tail end to the dismay of millions upon millions of windows users.

  81. No, but I do accept that once they’re on my box, with my privileges there’s a lot of things they can do, not the least of which us use local privilege escalation attack

    that is not really the *real* point. The point is that till a way is found in OS X to lure a user to open up (as with this Java exploit – note, not Safari per se), let something in that will install, replicate, use the computer resources to spread automatically without further user intervention, THENCE the platform is not an interesting target.

    As soon as that will happen (but Leopard tightens up things nicely: less to try an attack to than in Tiger) people will realize that 20 million users is a HUGE number not a tiny puny little target. It is a huge target. The problem is that this fruit, so far and for now, is way up in the trees and juicier fruits are low hanging and within reach.

    What you say is true about the damage once in your box. But so far is “once in your box”. I have to repeat the process with the next Mac user: the fact that I got into yours does not advance me at all for what concern another Mac box. Tedious, long and tedious.

    For your arguments’s sake: Mac OS X is not that interesting because there is not yet an automatic infecting procedure, thence spreading and ROI is very little. If I have to wait for each user to actively infect themselves without any hope, so far, to create an avalanche effect then the platform is not that interesting. Why will I spend time and effort for that when on Windows I can get an exponential automatic spreading and 10 times the result in a fraction of the time? Again, the fruit (Mac OS X) is good and attractive but it is not within easy reach. There are others that are far more easy and with greater return.

    Notice, I get at least 10 times the result NOT because there are so many installations but because infection spreads exponentially with the number of already infected machines.
    20 millions Macs will get me the very same result I obtain with infecting Windows. Why? Because it does not last forever: in a couple of days admins take preventing measures and stop the spreading: I never NEVER HAVE any chance to infect the entire Windows base. At most a hundred thousands machines.
    My claim as that with 20 million machines I DO HAVE the same chance to get 100k infected machines in a similar amount of time.

    The combination of better security and low market share make it uninteresting.

    Pretty much so what you say BUT the market share is more a hype than a real factor. 20 Millions users are way enough for it to be interesting. As you say, the Mac OS X hiker runs much faster than the other. It will still be the same if the split in market share was 50/50. It is enough for Mac OS X to run faster than Windows against the blood thirsty bear.

    Low hanging fruit: that is the ones that are picked up first. For as long as there will be those easy to grasp I have no interest in sweating my shirt off to pick the one at the top branch.

  82. Two guys are hiking thru the woods when they come across a blood thirsty bear. The first guy starts taking off his boots and putting on running shoes. The second guy says ” hey, what are you doing, you can’t outrun that bear!” and the first guy replies ” I don’t have to outrun the bear, I only have to outrun you.

    Indeed. And to the bear both hikers constitute a great meal. Windows is the best AV for all others OS around because what it says is “hey, I cannot outrun the bear thence why bother really?” while other OS get better at running all the time and will always run much faster than Windows that simply wait to be eaten.

    Mac OS X is not 100% secure, that would be a silly assumption, but it is very safe to be with. There is very little Tiger *listen* to today, so it offers very little to attack. Leopard tightens up things even more: it runs faster than Tiger already. Windows is still sitting as a duck waiting for the bear.

    Zombies PC groups are sold by the thousands. I could get plenty of those out of a 20+ million target, don’t you think?

    If you have 800 juicy apples in the low branches, within your hand reach, and 100 juicy apples in the tallest branch, which apples will you start picking? Especially when you know you only have time to pick 10 at the very most before the guard dogs will run at you?

    PS
    I bet the same answer would apply even if there were 100 juicy low hanging fruits reachable and 800 in the tallest branches. Windows would be the target even if its market share was to be reversed with Mac OS X.

  83. For those talking about the contest winner’s remark regarding most people being behind routers;

    Being behind a router will NOT protect you from this attack because you click on a link that will run code through port 80, which is the internet, and is OPEN on your router.

    What he WAS referring to was the first level of the contest, which was the open ‘behind the router” attack. The contest was structured so that the hackers did not need to penetrate the router – it was assumed that they can. The point was to test the Macs security, so they put them all on the same subnet to test just that security. Both units passed that first test. So any Mac, exposed to the raw internet, is “supposedly” safe from attack.

    His point is that most users ARE behind a router, which provides a safety barrier. Not an impenetrable one, for sure, they CAN be penetrated! But at least they are relatively safe from random attacks, and that was his point.

    But he was NOT talking about routers making you safe from the successful attack! Just turn off Java and Javascripting to be safe until a patch is issued.

    MW: defense, as in that’s a good temporary defense!

  84. …port 80, which is the internet,

    LOL

    Port 80 is the port that the server “listens to” or expects to receive from a Web client, assuming that the default was taken when the server was configured or set up. A port can be specified in the range from 0-65536 on the NCSA server. And if port 80 *is* the internet, what is port 8080? You may set the web server to listen to anything, not 80. It is just a default.

    Additionally, what do you mean with run code through port 80 ? You cannot RUN code through a port, you can only transmit packets and the other side accept them. The problem is with Java, not with listening to port 80. That is why disabling Java you become immune to this problem: there is no code that runs through a port.

  85. AND, since the problem is with Java, even this contest showed no Mac OS X weakness. You are affected by any browser using the same engine as Safari. Specifically you are in trouble even with Firefox. So, is this still a problem with Mac OS X?

    As said time and again. This is nothing more nothing less than one of the MOAB problem surfaced in February. Nothing to do with Mac OS X but other stuff that we happen to use together with it, like Java. What Apple will probably do is for Safari to be tighter on what Java can do and watch more carefully what could happen and when. Unfortunately this will probably make Safari a bit slower if it has to be as well the watchdog for Java security weaknesses.

  86. Found this on a site: “One reason Macs haven’t been much of a target for hackers is that there are fewer to attack, said Terri Forslof, manager of security response for TippingPoint. “It’s an incentive issue. The Mac is not as widely deployed a platform as say Windows,” she said. In this case, the cash may have provided motivation.

    Why amazing? So this Terri Forslof spins again the events saying Mac is not much of a target because there fewer to attack. 22 Millions apparently is peanuts. THEN continue saying “It’s an incentive issue: […] the cash have provided motivation”

    And tell me oh silly sausage, do you think that a good botnet is not easily sold for $10k ??? Does the simpleton that 22 Millions Macs out there could not provide enough target to get MANY botnet rings EACH generating $10k to their *pwners*? So if money is a good motivation THENCE there is already plenty of motivation to attack Mac OS X.

    If it is not done it is because it is far more easier to do it on Windows than on Mac OS X. Otherwise, the incentive is already there Terri, 22 Mil machines ready to be turned into a bot and provide potentially multi-million $ market for the *pwners*.

    Crackers go after the easy target: Windows, not the most difficult one: Mac OS X.

    Tell you a secret: what about attacking the clusters running iTunes? Not enough incentive all those credit cards details? 1 Billion transactions full with credit cards details… Yummmm how juicy could any system with that information available?

    Terri, Terri, Terri, how comes you do not see it by yourself? $10k enough motivation? Plenty of cash out there from 22 Million machines target. PLENTY.

  87. Terri, a hint for you: all those security experts have not been able to get a remote attack and a root shell. Something they probably learn of first day of hacker school.
    This is why there are no malware on OS X and everyone flocks around Windows.

  88. “Zombies PC groups are sold by the thousands. I could get plenty of those out of a 20+ million target, don’t you think?”

    One branch holds about 860,000,000 various fruits, and another holds 22,000,000 apples. Assume you have to build a specialized fruit picking tool that will take the same time to build for either branch. Once you get going, you will get 0.01% or less of the fruit off the branch you chose.

    Now assume that the rational fruit picker will try to pick the most fruit possible for his effort.

    You can have either 86,000 of the various fruits, or 2,200 of the apples.

    Lets assume that for your purposes either fruit is worth the same.

    You can now see why somebody hacking for money is going to completely ignore Apple.

    Quite the contrary, Macs would need to be about 40 times more likely to be compromised to make them as interesting a target as Windows machines (so the attacker could compromise a greater percentage of the population and get the same absolute number of zombies)

    So the only inference you can take from the lack of interest in Mac hacking for commercial gain by sombody looking for best return for effort expended is that the average Mac is no more than 40 times more likely to be able to be compromised than a Windows PC.

    Counterintuitive for sure, but nevertheless true.

    Arguments that OS X is more secure than Windows or harder to hack just shifts the balance further away from choosing the Apples, it may be that OS X is more secure, but it is not necessary for OS X to be any more secure in order for it to be uninteresting.

  89. Ooo, another cherry picker! Cherry picking numbers out of a hat to suit his chosen outcome!

    Your logic is screwed. Amazing has it right, the logical choice has nothing to do with raw numbers of machines. It has everything to do with numbers of VULNERABLE machines. Percentages like yours are only valid if one assumes that the two systems being compared are equally vulnerable. They are not.

    In the latter five years of the twentieth century, Apple had less than three percent of the US market. There were no botnets, thus no financial incentive to write exploits for anybody.

    Yet there were 30,000 for Windows vs. less than 150 for Mac OS 7, 8, 9. WITH NO FINANCIAL INCENTIVE, there were over a hundred exploits written for the Mac OS! In spite of a lower market share than today!

    Today, for Mac OS X, there are NO exploits in the wild for Mac OS X. Yet its market share is double what it was then, and the raw numbers of installed machines is plenty higher, as well.

    Numbers are irrelevant. Logic is a better answer, and logic says that it is ease of exploitability that means everything. Low hanging fruit and all that.

    Sorry if it disturbs your neat world view.

  90. @What 2;

    Semantics, my friend. The point remains the same. Port 80 is a default, so that is the port at issue, I think there is another port whose number I cannot remember that is also open for internet traffic. (Ergo, one can say “this is the internet”, so its not technically correct. It’s like you point to a window and say, “That’s outside”. We know the window isn’t “outside”, but the statement conveys the point.) So one’s firewall being open or not is irrelevant, as one’s clicking the link to the malicious web page exposes you to the attack through your own action.

    Yeah, passing packets, but some of those contain code, which your machine runs. So you are running it through that open port, so say it another more technically accurate way if you please, the point is the same. A firewall will NOT stop this attack.

    I mentioned that because there are some dorks that were taking issue with some of this and didn’t seem to understand the issues surrounding it.

    Yes, disabling Java will stop this attack. I didn’t say it wouldn’t. As a matter of fact, Gruber over at Fireball has a new item that this is actually a result of QuickTime’s handling of Java, which is why disabling it stops the attack.

    So since this is APPLE’s implementation of Java, then yes, this is Apple’s problem. It may not be OS X itself, but it is inherent in apps that are installed by default in OS X, so again, we are just talking semantics. A weakness is a weakness, and its up to Apple to fix it, which I trust they will quickly.

  91. “Percentages like yours are only valid if one assumes that the two systems being compared are equally vulnerable. They are not.”

    Wrong, it’s a comparison of inequalities. As I stated quite clearly OS X may be less vulnerable but it’s not required to be less vulnerable in order to explain the result if you assume that that attacker is a rational maximizer.

    “Logic is a better answer, and logic says that it is ease of exploitability that means everything. Low hanging fruit and all that.”

    And logic leads you to the answer that to defeat the installed base disadvantage an OS X machine would need to be about 40 times more likely to be compromised than a Windows machine to make the pool of OS X machines equally interesting to a financially driven hacker assuming equal utility for one hacked machine.

    I think we all assume that that is not the case that OS X is 40 times more likely to be compromised than a Windows box, therefore lower installed base provides a sufficient explanation for lack of interest in OS X hacking by profit driven individuals.

    Your logic could be true if you assume that the attacker is not a rational maximizer, or you assume different utility functions for hacked OS X machines. Even then you’d have to find an OS X machine to be 40 times more useful to defeat the share disadvantage.

    If you assumed OS X was 2 times harder to hack, you’d have to find the OS X machines to be 80 times more useful. See how the math works?

    Until OS X is equally interesting by whatever utility function you use, it wouldn’t meet the definition of low hanging fruit because by definition there is other fruit which can be gathered with less effort.

    OS X doesn’t have to be completely secure to be uninteresting. The combination of better security and low relative installed base make it uninteresting.

  92. No, you are not comparing two inequalities. The percentage you were using is the same for both systems, thus you are assuming the same infection rate for both systems. Numbers are only valid if the market share myth is true.

    I repeat, numbers are not the determining factor, the relative security is. If Macs were just as vulnerable as windows machines, I guarantee you they’d be used in botnets as well. You are assuming a zero sum game, with macs supplanting PCs as botnets. That is NOT my assumption. I am simply saying that if Macs were as vulnerable as PCs, they’d be used too. Numbers, as I said, are irrelevant. Run all the numbers you want, they don’t make any difference.

    Refer again to my comparison with the late 90’s. Your numbers don’t work with that scenario, so you ignore it.

    It’s late, good night.

  93. You can now see why somebody hacking for money is going to completely ignore Apple.

    Nahhhh. You are oversimplifying. We are talking about IP numbers and network. You can only play with analogies up to a certain point, to give an idea.

    Fact is, for malware a computer is an IP number. It does not matter whether behind that IP number there is a Mac or a Windows PC. They get exactly the same *hits* from a malware probing it. You do not access *all* the Windows PCs in one go vs all Macs in one go. Moreover, the same malware CAN detect which computer is behind, that is what OS is running. If there was an easy way to compromize a Mac OS X platform as a Windows the malware could carry the platform independent code plus variation for the specific OS and API. It is computing programs we are talking about, mostly C++ program. What difficulty you see in having the virus or worm program having a
    #ifdef _Mac_OS_X

    #elif _WINDOWS_NT

    #elif _XP_

    #elif _VISTA

    #elif Linux

    #etc

    and act specifically for each variants? It takes absolutely nothing. If it was possible to put code under #ifdef _Mac_OS_X_ it would be there. Guaranteed.

    How do you think a same virus attacks practically ALL versions of Windows?

  94. k, got you. I might have been picky.

    Hopefully it is Apple installed Java VM that needs a patch and not Java at large. I would hate if Safari had to become the watchdog for whatever third party technology it uses with overhead and slowdowns because of that.

  95. You did not pick up the message from the analogy. Your point would be correct if all fruits were as easily picked. They are not. This is the most important point. If the 22 Mil fruits were very easy to pick and the 800 Mil were very difficult to pick, we would pick the easy low hanging fruit.

    22 Mils fruit when you may at most collect 100,000 before the warden closes the gates again are plentiful for any purpose.

  96. Your logic would be valid if we were seeing a percentage of malware proportional to the installed base. Your logic fails in that there is ZERO malware around for Mac.

    Again, there is a virus that has been written for the tailored version of Linux for it to be installed in iPods.

    What market is there, tell me? A couple hundred users?

    ZERO malware is where all the logic about market share fails. If it could be done, it would be done. It is computer code for krissake, not mechanical cherry pickers that requires investment and specialized effort. It is CODE.

    It took what to find the Safari exploit over a LAN? 9 hours? You think that if there truly a way to achieve automatic installation, replication and spreading of malware on Mac OS X a 9 hours mental work will put off a cracker or a virus writer?

    C’mon….. be serious.

  97. Until OS X is equally interesting by whatever utility function you use, it wouldn’t meet the definition of low hanging fruit because by definition there is other fruit which can be gathered with less effort.

    OS X doesn’t have to be completely secure to be uninteresting. The combination of better security and low relative installed base make it uninteresting.

    Yes, but the installed base is just the cherry on the cake. With no cake, there would be no cherry.

    Windows virus have shown an infection rate at peak of over 50%: That is one in 2 Windows machines when probed by the virus would have been infected.

    On Unix the infection rate has been so far around 5%.

    Windows would give you a higher absolute number of infected machines even if you reversed the % with Mac OS X. It is quite easy to see it: algebra 101.

    But again, that is just to show it. People rationalizing on the market share give 90% relevance to it while instead is, as I said, just the cherry on the cake.

    The only one factor that makes for ZERO malware on Mac OS X: there is as yet not a proved distribution mode that will allow for automatic and exponential infection of Mac OS X platform. Rest assured that if Apple stops being proactive vs security problems and sits waiting for the bear, one day the bear will come and there will be a serious infection on Mac OS X. This is the only reason why ZERO malware: no distribution, repeatable, user independent infection mode. Till that day, Mac OS X could have 80% of the market, still ZERO malware. You need a reliable distribution mode first before you meaningfully attack an OS. What do you think all these proof-of-concepts are all about? People are trying, and trying HARD.

    One could only hope Apple will always look ahead and with the OpenSource community plug holes before one could allow for the realization of an exponential infection rate. It is the only factor.

    Otherwise Mac OS X would have already its virus as it is there for people having installed Linux on their iPods, all the 300 hundred in the world.

  98. Another example that totally falses the theory that malware is only against large numbers, what about the Witty worm?

    It only targeted some 12 thousands installations in the entire world.

    No, I make the amazing claim that 22 Million users of Mac OS X are a larger target than 12 thousands attackable systems.

    Why the Witti worm and ZERO for Mac OS X still?

  99. “Windows virus have shown an infection rate at peak of over 50%: That is one in 2 Windows machines when probed by the virus would have been infected.”

    The key to your comments are “When probed by the virus”

    there’s no virus ever that’s come close to infecting half the Windows installed base.

    Infection of 0.1% of the installed base is a huge deal and gets you on the news worldwide.

    Most Windows viruses end up affecting less than a millionth of the installed base before being detected and a signature published. Most Windows vunerabilities are reacted to within 24 hrs.

    “one day the bear will come and there will be a serious infection on Mac OS X.”

    Which is my point, that day will come when the Mac is a more attractive platform to hack than Windows.

  100. The flaw in your thinking on Witty is that it attempted to probe 900 million systems eventually compromising 12,000 of them for an infection rate of 0.0014% of the PC base.

    The Mac equivalent given the same infection rate would have compromised 300 machines (while still probing 900 million to find the Macs)

    As I said, uninteresting.

  101. That Windows is attacked BECAUSE it has the largest installed base.

    Some facts about Witti:

    Witty was wildly successful. Twelve thousand machines was the entire vulnerable and exposed population, and Witty infected them all — worldwide — in 45 minutes. It’s the first worm that quickly corrupted a small population.

    Witty was speedily written. Security company eEye Digital Security discovered the vulnerability in ISS’s BlackICE/RealSecure products on March 8, and ISS released a patched version on March 9. EEye published a high-level description of the vulnerability on March 18. On the evening of March 19, about 36 hours after eEye’s public disclosure, the Witty worm was released into the wild.

    Witty was very well written. It was less than 700 bytes long. It used a random-number generator to spread itself, avoiding many of the problems that plagued previous worms. It spread by sending itself to random IP addresses with random destination ports, a trick that made it easier to sneak through firewalls. It was — and this is a very big deal — bug-free. This strongly implies that the worm was tested before release.

    Witty was released cleverly. Witti propagated through a bot network of about 100 infected machines. This technique has been talked about before, but Witty marks the first time we’ve seen a worm do it in the wild. This, along with the clever way it spread, helped Witty infect every available host in 45 minutes.

    Target? 12 thousands installations. Infected them all. Time: 45 minutes.

    AGAIN, if one does this against a target of 12000 it is BECAUSE it CAN BE DONE, not because 12000 is more interesting or less interesting that 100000, 20 Mill, or 200 Mil.

  102. Which is my point, that day will come when the Mac is a more attractive platform to hack than Windows

    which will happen if and when Mac OS X becomes easier to crack into than Windows, NOT if Mac OS X installed base becomes comparable to Windows one.

  103. Most Windows viruses end up affecting less than a millionth of the installed base before being detected and a signature published. Most Windows vunerabilities are reacted to within 24 hrs.

    Which is my point. With 20+ million users base and network speed you would reach the same infection rate on Mac OS X than on Windows. Pretty much the same.

    EVERY machine, EVERY SINGLE one, on average receives 400 to 500 probes per hour from malware, it does not matter whether behind the IP there is Windows, Linux, Unix, or Mac OS X.

    With 20 Million users and 24 hrs time to spread you have enough base to get practically the same numbers infection on Windows and on Mac OS X.

    20, 200, or 2 Billion machines you get essentially the same: you can only reach so many in 24 hrs. The assumption that it is a simple percentage of the installed base is… simply put… silly.

  104. The flaw in your thinking on Witty is that it attempted to probe 900 million systems eventually compromising 12,000 of them for an infection rate of 0.0014% of the PC base.

    The Mac equivalent given the same infection rate would have compromised 300 machines (while still probing 900 million to find the Macs)

    As I said, uninteresting.

    You do not know what you are talking about. Read about Witti please. What you say is meaningless.

    Witti was specifically targeting those 12000 available installation. It required 45 minutes to FIND THEM or do you think the virus had a database of 12000 IP numbers and only contacted those?

    The point is that a virus on 20+ Mil Mac OS X users will provide a very similar absolute number of infection before the plug is pulled.

    Easily a 6 digit number as it happens with Windows exactly because virus could hope for 24~48 hrs before admins will block it. IF there was much more time available then the actual user base will start to make a difference on the total number of infected machines and the reason is that the absolute result is not a simple % of the user base but a % of those reachable before admins stop the plague. And the % of those reachable in the amount of time is not a % of the total user base but one PC infected, two, then 4 then 8 etc.

    With the Mac user base of 20+ Mil you would get exactly the same before the ACTUAL user total base has any effect at all.

  105. The flaw in your thinking on Witty is that it attempted to probe 900 million systems eventually compromising 12,000 of them for an infection rate of 0.0014% of the PC base.

    WRONG. Witti infection rate was 100%. It infected the ENTIRE target it was written for.

    0.0014% my a$$

  106. you would reach the same infection rate on Mac OS X than on Windows. Pretty much the same.

    sorry, not infection rate but absolute infection number.

    A Witti worm for Mac OS X would get hundred thousands infections in the first 24hrs before a reaction stops it exactly as it happens for Windows.

    With 20+ mil installed system it would be absolutely no problem to get 100,000 in 24hrs. Absolutely to problem.

    Again, Witti had a 100% infection rate, corrupting its entire target of some 12000 installations worldwide in just 45 minutes. After that, it had NO MORE MACHINES to infect: it got them all.

  107. To give an idea of the time it takes today for malware to be visible and reach everyone in the world which are connected online. This comes from the analysis done at UC Berkeley on the Witti worm:

    “Because
    Witty’s single-packet nature is naturally fast, an unseeded Witty
    would have still spread worldwide in under two hours.”

    UNDER TWO HOURS and unseeded. Unseeded means letting the worm start from one single infected platform.

    Not only that, Witti could only work on system it found running version 3.6.16 of iss-pam1.dll
    or about 12000 at the time of release.

    Great, the problem with your thinking is not in being flawed or not, it is in not knowing what you are talking about. Like most who say “it is all in the numbers”.

  108. Let me repeat it in case you still do not get it:

    Witti only could infect 12000 machines. It had 100% infection rate. It took, seeded, 45 minutes to find and infect them ALL.

    If unseeded it would have taken under 2 hrs to find and infect them all.

    The user base of machines that Witti could hope to compromise was 12000 or the systems having vs 3.16.16 of iss-pam1.dll

    If the version was not there Witti was trying AT RANDOM another IP number.

    12000. Mac OS X is 20 MILLIONS at least.

    Does the scale start to finally reach your neurons?

  109. that people believe you need a Mac to infect a Mac or a Windows machine to infect a Windows machine.

    You need a machine where you can inject code that can run on that OS replicate and look for other machines.

    Injecting a different code depending on the OS that is running on the machine behind a specific IP number is trivial.

    Then a Mac could be used to search for Windows machines and Windows machines can be used to look for Mac OS X to infect.

    It is the entire installed base of all computers that is a one single target. Among them, some are very easy to infect and corrupt. It only happens they are as well the majority out there which helps in focusing just on the easy prey.

    Being easy does not come from being the majority. But we all know this is the theory Microsoft spin doctors have been able to make their users fully gobble.

  110. pretty much.

    The funny thing, or rather tragic, is that Microsoft have been able to turn a factor that should make them the most secure OS around into a factor that gives them an excuse to divert from the real reason behind being the most vulnerable.

    Exactly because Windows is in the majority it should also be the most secure system around. It is not, and by far.
    And they dare to say they are vulnerable because they are more under scrutiny.

    There is no such more strict scrutiny as the one existing in the peer-to-peer scrutiny of OpenSource community around Unix and Linux. Which is why they are more secure.

    Windows fragility is just the result of being sloppy, being an open architecture, and not having in place sandboxed areas where the damage of any single application would be limited and not expose the entire OS.

    So, keep your eyes closed and still believe that Windows is attacked just because it is in the majority.

    Too bad real world examples prove the opposite: Apache anyone?

  111. It wouldn’t be too hard to build a script that determines your browser version and serves up an exploit for either Apple or Windows.

    The only problem is that I do not have at hand the exploit that would work for Mac OS X.

    MDN “waiting” My gosh, how do they do that? LOL

  112. Final comment in that otherwise becomes stale. I am not here to convince you really, I do not care that much but the “nobody’s invulnerable, everybody has bugs” argument is one of the most toxic in security.

    If you believe everyone’s qualitatively the same, you wind up nowhere; we might as well stop finding bugs altogether.

    It is just good to know that the above is simply not the case.

  113. “only happens they are as well the majority out there which helps in focusing just on the easy prey.”

    Your entire stream of posts just confirmed my initial comments. Widows machines are a more interesting target. Nobody hacking for money is interested in Mac OS X.

    “corrupting its entire target of some 12000 installations worldwide in just 45 minutes. After that, it had NO MORE MACHINES to infect: it got them all”

    As to the 12,000 number as the vulnerable population, ISS claims to have 11,000 corporate clients and 330 million in revenues. Are you saying that they all brought about one copy each of the vulnerable ISS software and paid $27,500/yr for it. Strange indeed since the basic BlackIce sold for less than $100 retail.

    “Again, Witti had a 100% infection rate”

    Any virus will infect 100% of the machines it manages to infect. That’s a completely moronic statistic.

  114. you are really thick, are you?

    Go read about Witti by yourself, will’ya?

    Any virus will infect 100% of the machines it manages to infect. That’s a completely moronic statistic

    Are you stupid or what?

  115. what is so difficult to understand in “After that, it had NO MORE MACHINES to infect: it got them all”

    NO MORE MACHINES possible to infect. That is 100%, not the “100% of machines it managed”

    It is ALL machines that were vulnerable: the ones having the specific version of the dll library.

    is English your mother tongue? I seriously doubt it.

    Shees, some people

  116. Widows machines are a more interesting target.

    Because they are frigging easy to infect lobster, not because they are in the majority.

    They will still be the more interesting target even if their market share was to reverse with Mac OS X one.

  117. @deleted;

    Pay no attention to that man behind the curtain.

    He is only here to troll, he isn’t interested in facts, as they only disturb his pretty rose-colored world view that Windows is secure. I tried to tell him the same things in a different way yesterday, but he insists that his numbers are real, despite the facts.

    So ignore him, maybe he’ll go away, back to a Windows site where he belongs.

  118. @deleted
    Dude, seems like mr great isn’t great at all. HAHAHA.

    English isn’t my native tongue but I sure do understand what you’re saying.

    Word of the day dude, GIVE UP.
    As in GIVE UP on him as he’s hopeless as his windows OS.

  119. “Because they are frigging easy to infect lobster, not because they are in the majority.”

    How do Windows machines infect lobster?

    “Twelve thousand machines was the entire vulnerable and exposed population, “

    Measured by the fact that Witty infected them. There were many more copies of the vulnerable software in the field. Again a circular argument Witty infected 100% of the proportion of the population that it could infect.

    “They will still be the more interesting target even if their market share was to reverse with Mac OS X one.”

    Take p1 to be the probability that you can compromise a given machine
    Take n1 to be the number of machines of that type in the field.
    Take u1 to be a measure of how much you value a machine of a given type.

    so now the utility of a particular outcome is p1*n1*u1, the probability you will compromise any one machine, times the number of machines out there, times the value of that machine to you.

    Assume the values p2,n2,u2 defined similarly for another machine type.

    For one machine type to be more “interesting” than another the following inequality must hold.

    p1*n1*u1 > p2*n2*u2.

    So lets assume the utility is the same, say 1, and substitute some real world installed base numbers, then machine type 1 is more interesting of:

    p1*860 > p2*22

    Clearly from this you can determine that p2 must be about 40 times p1 for the machine types to be equally “interesting”

    Your argument is that Macs are “Interesting enough” despite the lower utility and the smaller likelihood of compromise.

    You could model that by saying Macs are many times more interesting to own e.g.

    p1*860*1 > p2*22*u2

    pick your own values for p2 and u2.

    Using real world numbers the following two things are true:

    Mac OS X being harder to hack makes hacking Mac OS X less desirable.

    Mac OS X having less market share makes hacking Mac OS X less desirable.

    You need a very large difference in the utility to you of Mac OS X machines compared to Windows machines to make you choose to hack Mac OS machines instead. The more secure you believe mac OS X to be, the even more useful you need to believe those machines are compared to Windows machines to bother hacking them. If you value Windows and OS X machines the same, you don’t even touch Macs unless you think you can compromise them much more easily than Windows boxes. And nobody here seems to believe that premise.

    So if you you are hacking for profit, you choose Windows machines, plain and simple and EITHER smaller installed base OR better security (or some blend of both) are sufficient to explain that outcome.

  120. @Great;

    Boy, you just can’t give up those numbers, can you?

    Get it straight.

    The numbers are useless.

    If Apple had 90% market share, and Windows under 10%, given what we know today of the relative security of the two systems (Windows overall, not just Vista), there still wouldn’t be a Mac botnet. The system just doesn’t have the vulnerabilities within the correct system structure to allow the creation of a botnet as they are known today. There would, however, be Windows botnets, just not as many of them, although due to scarcity, they would be worth more.

    It isn’t the numbers that matter. It is the relative security that matters.

    You just like those numbers so much you can’t see past them.

  121. “It isn’t the numbers that matter. It is the relative security that matters.”

    So in essence you’re agreeing with my equations which express that relative security.

    Keep arguing in agreement with me, it’s funny how you do that, think I’m putting a different position yet agree with my principles.

  122. From YOUR remark, you seem to agree that its the security that matters. Your numbers have been trying to prove that they don’t.

    I have noted over and over that your numbers are picked out of thin air and really don’t speak to the issue.

    You can stop trying to twist the argument in your favor. I’ve noted the same thing over and over, and you don’t seem to understand, or just seem to want to bash the Mac platform using your made up, irrelevant numbers.

    I’m finished arguing with someone that refuses to understand and just wants to twist things his way.

    It’s bedtime, good night.

  123. “you seem to agree that its the security that matters”

    No, I show how either security or installed base, or both can explain the phenomenon.

    “Your numbers have been trying to prove that they don’t.”

    Look at the numbers and equations again. Actually forget the numbers, point out the flaws you see in the equations. That might help you remove your emotional bias from the analysis.

    “your numbers are picked out of thin air and really don’t speak to the issue.”

    All numbers are 100% verifiable. and look at the equations, pick your own favorite numbers. The conclusion remains the same.

    “just seem to want to bash the Mac platform”

    Where’s the bashing? You’re inventing the bashing in your mind.

    Unless you’re trying to say that my statement that nobody wants to hack a Mac for commercial gain is somehow bashing the platform? I would have thought that’s a good thing.

    Would you feel more accepted and less bashed if people hacked Macs more?

  124. Great,

    it actually is the opposite. You agree with us but don’t see it, which is quite funny.

    Even with your formula (which is pretty much correct):

    p1*860 > p2*22

    What we claim is that p1 is so much greater that p2 to make the difference between 860 and 22 simply a non factor.

    You don’t even have to know programming to break into Windows, not even know its API or how it works. There are literally thousands of programs and SDKs out there, freely downloadable, that generate malware for Windows: you just have to be able to read and understand english.

    An entire convention of security experts have not been able to get root access on the MacBook, vanilla installation, with even the firewall off. And it is like this since over 6 years.

    p1 is so much greater than p2 that even this holds true: p1*22 > p2*860

    or, since you like formulas p1 >> p2

  125. “You agree with us but don’t see it, which is quite funny.”

    You’re the one trying to state that I said anything other than greater Mac security can account for the differences. My point is while that may be the case, low installed base alone is also a sufficient explanation unless you accept that Macs are much less secure than Windows boxes, which almost nobody does.

    “What we claim is that p1 is so much greater that p2 to make the difference between 860 and 22 simply a non factor.”

    As I said, if that is so, that just makes makes Windows boxes more desirable to hack for profit and reduces the possibility that people will be bothered to try to hack Macs.

    Thanks for finally making my argument for me. It’s good to see the light-bulbs going on in your head.

  126. Great,

    there are virus around for SunOS, OS2, BeOS/ZETA and others.

    All combined they make for less than 1% market share.

    If market share was TRULY a major factor, since Mac OS X with over 5% has ZERO, then even more the above OSes should have ZERO as well.

    It is NOT THE CASE.

    I rest my case: low installed base alone is NOT a sufficient explanation.

    Thanks for finally making my argument for me. It’s good to see the light-bulbs going on in your head.

    LOL, not at all: your english comprehension just slightly improved from all the posts in the recent days. I never said anything different from the above.

    Market share alone is not enough. OSes with much smaller share than Mac OS X have virus. The main factor is how easy it is and if it can be done at all with current knowledge. Number of machines are inconsequential.

  127. “As I said, if that is so, that just makes makes Windows boxes more desirable to hack for profit and reduces the possibility that people will be bothered to try to hack Macs.

    Thanks for finally making my argument for me.”

    ^^^ whoa, so persistent.
    i wanna have what this guy is smokin’. ^^^\
    hehehe.

  128. You’re the one trying to state that I said anything other than greater Mac security can account for the differences.

    Actually, this is what me and others affirmed all along and you tried to counteract that with market share. Greater Mac security accounts for ZERO virus. Mac OS X has lots of attention from virus writers but so far they failed to find an effective delivery, installation, replication, user independent procedure.

    Market share is WAY more than enough for Mac OS X to be an interesting target and we claim people are actually trying hard but no one hear from failures.

    As I said before, you agreed with us all along but have been, and still is, miffed from the market share myth.

    Again, BeOS, SunOS and others with invisible market share with respect to Mac OS X, they ALL HAVE VIRUS.

    Again, market share is practically IRRELEVANT. You can have 100 machines available. If it can be done someone will do it. Linux for iPod has already a virus. Market share? what about 0%?

    The only thing to make Windows the most attacked is because it is the easiest and has nothing to do with how many are out there but because they are the lowest hanging fruit of all.

    Other OS with much lower market share than OS X have virus.

    Mac OS X has ZERO virus and it has nothing to do with the fact it commands 5 to 6% market share, 22 million user base or 20 TRILLIONS.

  129. Anyway, after all we believe you finally are making sense while you believe it is what you always said.

    The important thing is that “if that is so, that just makes makes Windows boxes more desirable to hack for profit and reduces the possibility that people will be bothered to try to hack Macs.” it is not an IF but a BECAUSE.

    Because Windows security is practically non existent this makes Windows boxes more desirable to hack.
    All boxes, irrespective of their market share have malware and virus for them.
    OS X still has ZERO and it is because it is more difficult than with others.

    ZERO has nothing to do with market share.

  130. if that is so, that just makes makes Windows boxes more desirable to hack for profit and reduces the possibility that people will be bothered to try to hack Macs.

    What we claim is that people are not only bothered to try to hack Macs, but they are trying HARD but without success so far.

    Otherwise, Mac OS X will have some malware as ALL OTHERS OSes, even minuscule, less known OS that have such a small market share that the 5% of Mac OS X seems so distant as Proxima Centauri and so higher to dwarf mount Everest.

  131. There is also another factor that people never take into account but that it is as well VERY important.

    The only thing to make Windows the most attacked is because it is the easiest and has nothing to do with how many are out there but because they are the lowest hanging fruit of all.

    the above makes so that everyone can, if they want, attack successfully Windows. Literally everyone, for as little as they technical skills are they can successfully attack Windows. The work is already done for them and freely available off the net.

    With more difficulties to break an OS the % of population capable of attacking that particular OS start to shrink and the age of those having the required capability increases.

    When it becomes VERY difficult, practically all those that could have the capability to successfully attempt a break are serious professionals, involved professionally into security business, and actually providing advisors at FIRST, CERT, and others. Essentially the number of people that would put their knowledge to create a virus goes to zero while the number of people that puts their knowledge to fix security problem grows a lot.

    So the situation is, irrespective of market share. If you put your money visible on a table, in a shop in a lousy neighbor, only protected by a Window (pun intended) every punk in town will be able to break that window and steal your money. No skill required.

    If you put your money in a vault an Fort Knox, only few in the world would have the knowledge to actually break in successfully and attempt to steal your money but they probably work already for the government and work to make Fort Knox even more secure.

    This is just an analogy, not 100% describing the reality, in that people believing they have the capabilities to break into Mac OS X abound BUT their efforts have been frustrated since 6 years already.

    It is as if you were allowed to try breaking into Fort Knox but so far only people with showel or hand grenades have tried to break into.
    We believe people who truly could do either work at Apple or work at security firms and will not put their skills into trying to release a virus but coming from time to time (as it happens) with security advisors, white papers, proof-of-concept and thence disclose their findings with Apple who thence releases their Security Updates making Mac OS X even more secure.

    By the way, Leopard raises the bar even higher with security features that makes Tiger look like a little kitten in comparison. And don’t ask for details, believe what you like, make fun of this statement: I do not care. An NDA is an NDA.

  132. I found a datum: In December 2006 the user share of Linux was 0,36%, up from 0,29% in January.

    Linux have virus and malware.

    “deleted” logic is flawless.

    If Linux has malware with 0.36% Mac OS X should have as well its share with 6%. MUCH MORE malware than what exist on Linux.

    I mean, it is SO EVIDENT I am amazed intelligent people could even argue against that.

    Oh wait, I have my answer: intelligent

  133. from the same link:

    SunOS were on the list in January with a market share of 0.01%,

    If SunOS have virus (you may google for them) with 0.01% market share, what other proof we need to say once and for all that market share is MEANINGLESS and not a factor to explain malware presence or not.

  134. “but they are trying HARD but without success so far.”

    What possible evidence do you have for that? Somebody tries, 2.5 hrs later the own the box. How much harder do people need to be trying? Is breaking into the box not success? What will it take to convince you?

    “”deleted” logic is flawless.”

    Sorry, it’s flawed because it rests upon unproven assumptions and much of deleted’s rambling post just repeats one of my core premises, that Mac OS X machines would need to be significantly easier to hack than Windows machines in order for anyone hacking for profit to be interested in them.

  135. my core premises, that Mac OS X machines would need to be significantly easier to hack than Windows machines in order for anyone hacking for profit to be interested in them.

    LOL, this guy changed his mind and doesn’t even realize it !!!!!!!!!!

    GRAND!

    2.5 hrs later the own the box

    LOL, your english comprehension lowered again and you lost grasp of numbers as well. HAHAHAHAHHAHHAHHAHAHA

  136. One branch holds about 860,000,000 various fruits, and another holds 22,000,000 apples. Assume you have to build a specialized fruit picking tool that will take the same time to build for either branch. Once you get going, you will get 0.01% or less of the fruit off the branch you chose.

    Now assume that the rational fruit picker will try to pick the most fruit possible for his effort.

    You can have either 86,000 of the various fruits, or 2,200 of the apples.

    Lets assume that for your purposes either fruit is worth the same.

    You can now see why somebody hacking for money is going to completely ignore Apple. — Great

    The above is all rambling about Mac not being interesting because it would get you 2.200 fruits vs 86,000. Nothing but a rambling about market share.
    Next time you repeat that your initial take was that Mac are difficult to hack thence less interesting you officially will be called BAGDAD JOE.

  137. “Nothing but a rambling about market share.”

    Implicit in that statement is the understanding that for it to be true that the platforms would have to be equally easy to hack as noted in the statement:

    “Once you get going, you will get 0.01% or less of the fruit off the branch you chose. “

    and if one branch is tougher to pick fruit from, it just makes it less likely, not more that people will pick from that branch.

    “Next time you repeat that your initial take was that Mac are difficult to hack thence less interesting you officially will be called BAGDAD JOE.”

    Sorry you didn’t get it the first go around, but the world needs dumber types like you for low level jobs too. Don’t feel bad about it. It’s just where Evolution has lead you. I understand that there’s not much you can do about it.

    So for the benefit of slower individuals, I will repeat the position.

    So if you you are hacking for PROFIT, you choose Windows machines, plain and simple and EITHER smaller installed base OR better security (or some blend of both) are SUFFICIENT to explain that outcome.

  138. “So if you you are hacking for PROFIT, you choose Windows machines, plain and simple and EITHER smaller installed base OR better security (or some blend of both) are SUFFICIENT to explain that outcome.”

    Glad to see that you’ve finally admitted that what I said all along is true.

    Now try to get this through your craw:

    If better security is sufficient to “explain that outcome”, then the amount of market share is irrelevant. Period. End of story. There is no reason even to consider the number of machines, because in the universe of those machines with better security, THERE ARE NONE TO INFECT, BECAUSE YOU CAN’T INFECT THEM!

    So, of course, you must then consider the ones that are left – those with the poorer security which you CAN infect, and thus, have a sufficient number available for your use.

    Now, we’ve explained the phenomenon of botnets, thank you very much.

    MW: military, as in, where the hell did that one come from?

  139. Can please someone tell Great that it is not that malware is Windows only.
    Malware is EVERYWHERE, it is that there is NONE on Mac OS X.

    botnets run with Windows machines, run with Linux machines and run with mixture of Windows/Linux machines as well.

    Linux has 0.36% of the market share. Market share is irrelevant, but Great simply put himself into a corner. How difficult it is to admit it: Market share is NOT sufficient to explain ZERO MALWARE!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

    I doubt he will ever see it.

  140. I think “deleted” said it above: Market share is the cherry on the cake.

    No cake? No cherry.

    IT IS enough to have a cake to attract eaters. Cherry alone does not fill seats at the table.

    For Great so that it is easier to understand the message:

    Cake == ability to crack efficiently into an OS
    Cherry == market share

    Mac OS X has the cherry but there is no cake. Result: ZERO MALWARE

    Windows has the cake and the cherry. Result: OctoberFest of Malware

    Other OS have the cake but no cherry. Result: You have Malware anyway

    As one can see, no cherry or cherry is totally irrelevant toward having or not malware. The only thing it changes is the amount of malware around. Some or a lot like on Windows.

    You can only get ZERO malware if there is no cake.

    Clearer now?

    I doubt: the only thing that is great in Great is the fog he lives in.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.