
“According to Matasano (home base for security researcher Dino Dai Zovi), the announced-but-unreleased web browser exploit that was used to win the CanSecWest MacBook Pro challenge involves browser support for Java. Turn off Java for Safari (or Firefox, or Camino) and your machine is immune,” Michael Rose reports for TUAW.
Full article here.
“The vulnerability affects Firefox as well as Safari,” Matasano Chargen reports.
Full article here.
[Thanks to MacDailyNews Reader “Adam W.” for the heads up.]
MacDailyNews Take: The story clarifies. As it always seems to do after the damage is done in the media (meanwhile, Mac users continue to surf the Web unaffected). So, that’s some Mac OS X “hack,” huh? Ten grand and a MacBook Pro for that? Pfft. We await InfoWorld’s next hysterical headline regarding this developing story with bated breath.
MacDailyNews Note: To protect yourself from this unreleased-in-the-wild, yet extremely over-publicized scourge, in Safari’s Preferences, uncheck “Enable Java” in the “Security” tab. In Firefox’s Preferences, uncheck “Enable Java” in the “Content” tab.
Related articles:
InfoWorld publishes false report on Apple Mac security – April 21, 2007
CanSecWest’s $10,000 ‘Hack a Mac’ challenge relaxes barriers, finds exploitable hole in Safari – April 20, 2007
Apple MacBooks hold strong, remain unhacked after first day of $10,000 ‘Hack a Mac’ challenge – April 20, 2007
CanSecWest sweetens ‘Hack a Mac’ contest pot to $10,000 – April 20, 2007
CanSecWest to hold ‘PWN to OWN’ contest: pits Apple MacBook Pros vs. hackers – March 26, 2007
Microsoft’s oft-delayed, much-pared-down Windows Vista hacked at Black Hat – August 07, 2006
Microsoft publicity stunt asks hackers to attack Windows Vista – August 04, 2006
Apple Mac remains ‘unhacked’ as University of Wisconsin’s Mac OS X Security Challenge ends – March 08, 2006
Mac OS X ‘unhacked’ over 24 hours and counting in genuine security challenge – March 07, 2006
and also stay away from unknown sites that may contain the malicious code.
Before I get 10,000 phone calls from people, won’t turning off Java affect how some web pages function?
In what way will turing off Java impact my usage of Safari?
Microdaft fanboys are the world’s best believers in George Orwell’s “doublethink.” In their addled minds Five Years = Six Months, Zune = iPod, and 1 = 100,000. Gawd, how I wish I could think like that sometimes.
It’s too late for a clarification.
I already ingested the poison and I’ll be gone in a matter of minutes.
Important to note: there was no OS hack. that was day 1 challenge.
I just looked at the number of cookies. Unbelievable!
99.9% of the websites you visit won’t be impacted by Java being disabled. With Flash taking over, Java isn’t used much anymore for web-based stuff…
Turning off Java will not affect stuff like rollovers, scripted stuff – thats Javascript, which is completely different. Java is used for applets and online Java apps and so on. You should barely notice that it is turned off.
Magic Word = remember.
Remember, Java and Javascript are two different, unrelated technologies (loosely used term…)
I have the same question as dergolem. Also, would we have to uncheck “Enable Javascript” as well as “Enable Java” in Safari’s Preferences?
BTW, The Register published a snarky article called:
Safari zero-day exploit nets $10,000 prize
Pwn’d in 12 hours
By Dan Goodin in Vancouver
A New York-based security researcher spent less than 12 hours to identify and exploit a zero-day vulnerability in Apple’s Safari browser that allowed him to remotely gain full user rights to the hacked machine…The exploit means that Dino Dai Zovi is the rightful owner of the 2.3Ghz 15-inch MacBook Pro and a $10,000 prize offered by Tipping Point, which runs the Zero Day Initiative bug bounty program… More importantly, his work effectively throws cold water on tired claims from Apple and its many lackeys that the Mac is all but immune from the kind of security attacks more regularly perpetrated against Windows-based machines…The ease Dai Zovi found in pwning the machine was all the more remarkable, given an update Apple pushed out yesterday patching 25 Mac security holes.”
My understanding was this hack did not allow someone “to remotely gain full user rights” as the article states. Is that correct?
Javascript is called Javascript because when Netscape invented it Java was the hot up-and-coming language that was going to take over the world, and they wanted a buzzword-bingo-esque name for it.
The two have absolutely nothing to do with each other.
REGARDLESS
Safari and Mac OS X should have safeguards against other programs or code doing things they are not supposed to do.
FYI: Java, and Javascript are not made by Apple.
With this exploit, just by clicking a link the entire contents of my user folder could be deleted.
What’s REALLY alarming is
That with Intel based Mac’s, there is a EFI firmware accessable partition on the hard drive that can be accessed by programs to install DRMware, monitorware, drivers etc.
EFI loads and runs, accesses the internet and downloads EVEN BEFORE THE OS HAS!!!
So basically the OS is not in charge anymore, it’s what one installs via third party programs.
Scary huh?
Look here for info.
http://refit.sourceforge.net/
I’m not turning off JAVA, give me a break.
@Islandgirl
Your understanding is correct. The hacker did not get root access.
Therefore if anything, the contest proved how the organisaers totally underestimated how secure OSX actually is.
Islandgirl, the way I understand it, Zovi gained access to one user account but not root access so he would have been only be able to do things in that one account.
Btw, I wonder if the Java hole he found also effects IE in windows….
@WiserGuy
So if this is the case, I’ll just make a toggle switch so that my computer boots with no net connection, and when its finished booting up I’ll hit the switch.
I use java for my online banking and so does alot of people in Sweden. it would be nice to be able to enable java for a select few sites and disable it for the rest.
And I am assuming the hack came from some Sun employee who understands the exploit all to well…
Nice contest. Not!
Look, if someone can’t hack the system so be it. But to go changing rules on the fly because it can’t be done, thus cannot create a nice rack up of web hits, please…
I’m betting running as a limited user avoids this exploit.
Running as a limited user is a piece of cake in OS X. It takes a few seconds to set up (and you rarely have to escalate once your mac is set up). Just make an admin account (don’t forget the login and password) and uncheck yourself as an admin user.
It is just another way to protect yourself (with little hassle).
If you think EFI is vulnerable to attacks, you might want to look into BIOS (which virtually every Windows PC out there uses). It’s far more vulnerable to different types of attacks than EFI is.
o if this is the case, I’ll just make a toggle switch so that my computer boots with no net connection, and when its finished booting up I’ll hit the switch.
That all sounds fine and dandy, but EFI sits between the OS and hardware, running all the time.
You install a program and won’t run unless the program in EFI contacts the internet.
Right now Apple is shipping EFI Mac’s with the partition empty, but that might not remain that way once people start installing programs.
What’s funny is EFI is not controlled by Apple, but by the UEFI.
http://www.uefi.org/home
So just like Java and Javascript, any bug or exploit in EFI is totally out of Apple’s control.
Remember the pop-unders you see here at MDN? Well that’s a Javascript exploit that was never fixed. Apple just makes the pop-under disappear after it’s done rendering. That’s not a fix, just a bypass, the exploit is still there.
If you think EFI is vulnerable to attacks, you might want to look into BIOS (which virtually every Windows PC out there uses). It’s far more vulnerable to different types of attacks than EFI is.
But EFI is much more powerful, when the bugs start appearing in EFI, Mac OS X security won’t mean much and Apple can’t do squat about it.
Much like Apple can’t do squat about Java and Javascript exploits.
Third party companies really don’t care about a computers security.
95% of exploits are application exploits. That’s amazingly high.
Turn off Java and Apple.com won’t work, I tried it earlier today.
So does this mean Mac users are getting paranoia about security.?
I hope not. There is nothing in the wild, and this exercise demonstrates how pointless it is for hackers to even bother.
Midlothian wrote, “Microdaft fanboys are the world’s best believers in George Orwell’s “doublethink.” In their addled minds Five Years = Six Months, Zune = iPod, and 1 = 100,000. Gawd, how I wish I could think like that sometimes.”
They also think 74 Microsoft Points = $1.
*sigh*
Yes… Sun make Java, but the runtime for OSX comes via Apple (a fact they seem to be very proud of), which is why it’s always a minor version or two behind.
A-Hole has this on the article…
EXCLUSIVE: MUST CREDIT MATASANO
More details as they become available. In the meantime, a drinking game: predict the rationalizations given by Mac zealots for why this finding “doesn’t count”.
I’ll start: “It took $10,000 to break a Mac, but people break Windows machines for free every day!”
What a windows fanboy trolling for hits…
You get what you ask for. Regardless of the technology used to hack into the mac, it was done. This is the problem with these kind of hyper visible contests.
I’m not drinking coffee nor traveling to Indonesia just to be safe.
No word on the remaining Mac and even more lowered barriers.
Seems the second one survived without so much as a say so.
@Macaday
Turning off Java doesn’t affect Apple.com at all. Silly boy.
” width=”19″ height=”19″ alt=”smile” style=”border:0;” />
You didn’t turn off “Javascript”, did you? Those are very different beasts, Java and Javascript.
I’m a bit surprised that the exploit uses Java instead of javascript. I always thought of Java as being very secure by design, a very strict and well thought out platform. Javascript, on the other hand, is pretty much anything goes, and is taken advantage of in the vast majority of browser hacks (in windows, at least.)
For a platform that has “security by obscurity”, there sure are a lot of high-profile attempts to hack it!
MW: “another” one bites the dust!
@WiseGuy – How the hell is the EFI going to connect to my wireless network (only one active on my home network)? Seriously, does the EFI load all the pieces necessary for an active network connection, I think not.
Stop the FUD!
MDN word: rest, as in give it a rest….
@WiseGuy – How the hell is the EFI going to connect to my wireless network (only one active on my home network)? Seriously, does the EFI load all the pieces necessary for an active network connection, I think not.
Stop the FUD!
MDN word: rest, as in give it a rest….
” width=”19″ height=”19″ alt=”cool smirk” style=”border:0;” />
Traveller wrote: “I’m a bit surprised that the exploit uses Java instead of javascript. I always thought of Java as being very secure by design, a very strict and well thought out platform. Javascript, on the other hand, is pretty much anything goes, and is taken advantage of in the vast majority of browser hacks (in windows, at least.)”
Actually, it’s the other way around, as far as security goes, because one can do so much more with Java. It has access, for example, to the underlying OS, and so it has access to your hard drive, etc. Javascript, on the other hand, is much more limited in what it can do.
Java has always posed a threat, in my mind, and so i have always kept it turned off. I am not surprised that someone was able to use it as an exploit. It bears saying that all the hacker had to do to win the prize was to read a file on the disc, and follow its instructions. With Java, one can access files. My understanding of this exploit is that they were able to trick Java into thinking they should be granted root access for reading files (and nothing more).
I think i have only ever encountered two or three websites which wanted Java turned on for one reason or another. On the other hand, i have encountered many websites which expected and/or depend on Javascript.
It’s unfortunate that Javascript is called what it is. As others have mentioned, they are completely different critters, and most folks don’t know that, nor the difference between them.
If you use NetNewsWire, remember to turn off Java in it as well. Java is enabled by default.
Rainy Day wrote “Actually, it’s the other way around, as far as security goes, because one can do so much more with Java.”
I highly doubt that. According to Wikipedia, “Java has similar security issues but these are considered less serious because the Java virtual machine provides a well-defined sandboxing model today (as of 2007) require Java, whereas many use JavaScript.”
This is pretty tough to explain exactly why, you probably won’t be able to really understand the subtle differences between Java and Javascript without having first hand programming experience.
Java is a high level object-oriented programming language, that has a strong emphasis on encapsulation. Every Java object and subroutine has a privacy modifier such as “public” or “private” that is meant to restrict access between different programs whenever possible. Javascript also has objects and privacy modifiers, but they were added to the language later, they are not an integral part of its design like Java. Many features have actually been added to Javascript over the years, that it is just as, if not more powerful, then Java. The advantage to Java is not it’s power, but it’s more restrictive design, which gives it better security and more coherent structures.
Also, Java runs between platforms as byte-code, semi-compiled programs that can run on any platform that implements a Java virtual machine. Javascript, on the other hand, runs as a script which is compiled as the browser reads the Javascript. It does not have a virtual machine to implicitly manage sandboxing it.
I also know for a fact that there are numerous websites that will instantly infect a Windows computer with a trojan by using Javascript (many, many websites! mostly porn sites.) I don’t know of any sites that do this through Java; I’m sure some exist, since both languages have similar security issues, but Javascript exploits are more common because they are easier and nearly every web browser uses Javascript.
Correction: The Wikipedia quote from it’s Javascript page reads:
“Java has similar security issues but these are considered less serious because the Java virtual machine provides a well-defined sandboxing model and few Web sites today (as of 2007) require Java, whereas many use JavaScript.”
While this does need to be addressed by Apple, the fundamental flaw revolves around java and QT interaction.
The solution, and one we have utilized for several years now is this.
1) Set up an Admin account and never use it. (Just for the most essential of installs)
2) Set up a clean standard account. Never touch it, only use when trouble shooting.
2) Set up your standard user accounts. Keep java enabled but only browse to sites that are trusted. We literally use only about a handful of sites on a daily basis, so it is not that difficult. Browsers such as Safari and Camino and Firefox allow some level of protections toward limiting what certain sites can do. Learn them and use them. Safari by parental control, Camino and FF by preferences.
3) Set up a seperate and either standard or limited user account that is used for general web surfing (ie. untrusted sites). This account is used only for web surfing and other non essential tasks if you so see fit. If you are so privileged, use an entirely different and isolated Mac for general web surfing, (instead of just a seperate account).
The web is a fun place and there are great sites out there, but as is always the case there are bad neighborhoods. I am not nieve enough to believe that Mac OS X is invulnerable, as it is always the things you don’t know that hurt you the most.
Either if it is Java or JavaScript, looks like just another job for NoScript
” width=”19″ height=”19″ alt=”smile” style=”border:0;” />
http://noscript.net
If you want to use Noscript, that’s fine for you. But I can’t be bothered to constantly give websites permission to run. Almost every website I use has Javascript. This website is using it right now to let us post comments!
There is so little chance of finding a malicious script that works on a mac. And with my kind of luck, (the bad kind), the one time I find one these websites on a mac, I will have clicked the allow button or whatever to let it run through NoScript, not knowing it was a bad script. I would have just wasted all that time blocking innocent scripts just to let the one bad one through. That’s some windows type security shit! I switched to mac to not have to worry about things like that.
“There is so little chance of finding a malicious script that works on a mac”
Well, it depends on your definition of “malicious”.
” width=”19″ height=”19″ alt=”raspberry” style=”border:0;” />
If stealing your credentials and/or peeking in your web mail is malicious enough, I bet you’ll have fun here:
After you understand what is XSS, what it can do and how it is completely OS-independent (it just needs any JavaScript enabled browser), you may reconsider NoScript
” width=”19″ height=”19″ alt=”wink” style=”border:0;” />
http://noscript.net
oops, it was http://sla.ckers.org — have fun