Heise Security: Apple’s Mac OS X Leopard firewall fails every test

“The Mac OS X Leopard firewall failed every test. It is not activated by default and, even when activated, it does not behave as expected. Network connections to non-authorised services can still be established and even under the most restrictive setting, “Block all incoming connections,” it allows access to system services from the internet. Although the problems and peculiarities described here are not security vulnerabilities in the sense that they can be exploited to break into a Mac, Apple would be well advised to sort them out pronto,” Jürgen Schmidt reports for Heise Security

“Apple is showing here a casual attitude with regard to security questions which strongly recalls that of Microsoft four years ago. Back then Microsoft was supplying Windows XP with a firewall, which was, however, deactivated by default and was sometimes again deactivated when updates were installed. It was also the case that system services representing potential access points for malware were accessible via the internet interface by default. Despite years of warnings from security experts, the predominant attitude was that security must not get in the way of the great new networking functions,” Schmidt reports.

“Then along came worms such as Lovsan/Blaster and Sasser, which rapidly infected millions of Windows computers via security vulnerabilities in system services, causing millions worth of damage. Even today, an unpatched Windows system with no active firewall will be infected within a matter of minutes. However, Microsoft has since learnt its lesson — a serviceable firewall, activated by default, has been included since Service Pack 2. With the standard configuration, no services are accessible from the internet on a Windows system,” Schmidt reports.

Full article here.

Lisa Vaas reports for eWeek, “Instead of addressing perceived flaws in the firewall, an Apple spokesman told eWEEK only that the company ‘takes security very seriously,’ that it has ‘a great track record of addressing potential vulnerabilities before they can affect users,’ and that it always welcomes feedback on how it can make security better on the Mac.”

Full article here.

96 Comments

  1. DON’T panic, just use ipfw:

    1. If you have OS X Tiger, turn on the firewall in System Preferences
    2. Open Terminal in your admin account and type at the prompt: sudo ipfw list
    3. Apply these rules to Leopard
    4. For more info, type: man ipfw

    P.S. Imagine Apple is trying to help you learn something.

  2. I’ve maintained several Mac computers and servers running every Mac OS X version since 10.0 DP4, and every one of them remained online with a public static IP address on the internet, with no firewall enabled, and I use ARD, AFS, POP/SMTP, etc. No intrusions, no malware. Thwarted bot attempts in the logs, but no successful breaches.

    MDN word: deal

  3. This will teach those hacking bastards to allow Leopard to be installed on pc’s!!!!

    Those pc’s will be mauled by Win’s viruses, worms, trojans & combo’s of vwt’s to the point where any person having done the deed will be needing to replace their computers rather than disinfecting them.

    Mac’s of course will (“Although the problems and peculiarities described here are not security vulnerabilities in the sense that they can be exploited to break into a Mac”,) always run & run & run & run & run……………

  4. That’s pretty serious if it’s true. Apple can’t fall down on the job with security – it MUST keep OS X free from viruses, worms, spyware, etc. or Mac users could face the same sort of future as Windows users.

    The last thing Apple needs is a major PR issue over security when no viruses, better security is a big driving point for switchers.

  5. It’s likely that the firewall is off because the Mac is set up to receive connections from the internet, but that those connections only expose very specific items and are blocked from going anywhere else. Heise simply says, “the problems and peculiarities described here are not security vulnerabilities in the sense that they can be exploited to break into a Mac.”

    That said, Apple should comment on this.

  6. OK, I finally got it, and I am loading it now. Been waiting a long, long time for this. I was surprised that there wasn’t much of a line to buy it. Wow, two disc……I didn’t know the Eagles had that much left in them….(I hope it is better than Joni’s “I Hate America” CD I bought last month)

    Oh, and death to Jerken Schitt.

  7. Yeah, I thought it was weird that that I had to know enough to go into System Prefs to turn on and configure the Firewall.

    Even more surprising given that so much Little Snitch functionality has been co-opted into Leopard.

  8. @Reality Check: you need to RTFA buddy, and stop spreading your FUD around, because it stinks. Report back with the line just before: “The Verdict” – that’s the one in big fat letters at the end of TFA. Ok?

  9. I am with UltraVisitor on this one: This is just so much FUD until there is a successful exploit of Leopard in the wild. I rate the chances of that happening any time soon as pretty remote. In the meantime, some people will say things like “this sounds serious” while those of us who actually have to deal with network security issues are yawning. The vast, vast majority of personal computers sit behind firewalls in routers and other network devices. You have to get through one of them to get to your PC or Mac. And even if a hacker gets that far, the likelihood of anybody getting into your Mac and doing something harmful is incredibly small. Honestly folks, nothing to see here… move along.

  10. There are free websites that will attempt to penetrate your Mac for you to test it’s security.

    I must admit since the last few 10.4 updates and when the Intel Mac’s appeared, that Mac’s have been “visible” on the internet, which is the first step in locating a Mac to penetrate.

    Before the Intel Mac’s arrived Mac OS X was invisible online. No response, not even a ping response.

    Something has changed obviously, which is very bad.

    Then of course just look at EFI. A powerful OS like firmware level with it’s own partition on the hard drive that can contact the internet and do whatever it pleases without the OS or you even knowing about it. TPM module installed or not.

    I say Apple has adopted the Trusted Computing Group mentality.

    Your computer is not your own, you may buy it, but they control it.

  11. @ effwerd and others.

    OS X firewall is always turned off by default.
    Why?
    Because all other services are turned off by default.

    You can’t hack something you can’t see.

    I have had 3 OS X and OS 9 computers on my home Broadband network with no firewall on and no virus software for 8 years. Never a problem.

    This isn’t rocket science, these are Macs, not PCs with Windows, the swiss cheese of the universe.

  12. Basically these Heise douchebags are trolling for hits. Saying the firewall “doesn’t work as expected” is the same as saying “we [are clueless about Mac’s and therefore] expect the Mac to be vulnerable and behave like a Windows PC…”

    Reality: nearly 99% of Mac OS X users don’t have ANY substantial reason to enable the firewall, whatsoever. The remaining 1% may have a need to block certain services to enforce their own security and/or restricted usage policies, ie K-12 labs, public kiosks, government, etc.

  13. When I ran the install as an upgrade it retained the pre-existing firewall settings, as I would expect.

    Now lets see, I have installed pre-hardened versions of most of the major operating systems in the last 2 years alone and cannot remember one that had the firewall on by default in a clean install, however all retained the previous firewall settings when run as an upgrade. How is this not as expected?

    Seems like trolling for hits to me, just like those paragons of scientific excellence at GP.

  14. I always wondered what exactly does the firewall in OS X do. In other OS’s, turning on a firewall (like ZoneAlarm in XP. The built in firewall in XP isn’t a real firewall) blocks all programs from connecting to the network, until they are given permission to (for example, I set Firefox to always be able to the internet, while IE has to ask permission each time it tries to connect.)

    But in OS X, enabling the firewall does not make any noticeable changes to how applications access the internet. After enabling it, Firefox or iTunes or any program has just as much access to the network as they did before.

    It seems like the firewall in OS X isn’t about comprehensive control over all network activity, like ZoneAlarm is. Apple seems to have taken a different approach: one that doesn’t bother the user, or deny normal application net access. Instead OS X uses a variety of other means to prevent security threats.

    If anyone wants to correct my layman’s understanding of this, by all means.

  15. “What a load of waffle. Call me when there has been a real breach.”

    Are you people stupid? If the MacOSX firewall is ineffective, it needs to be reported and patched.

    Pointing out potential problems is how they are avoided in the future and is how a system is made safe.

    All this Apple fanboyism simply reenforces the idea that Apple users are elitist wankers.

    APPLE ARE NOT PERFECT.

    GET OVER IT.

  16. One difference between Mac OS X and Windows XP (and, maybe, Vista) is that some Windows XP services are turned on by default. In Mac OS X, no services are on by default so you don’t need to have the firewall on by default.

    That said, when you turn on services, it’s a good idea to consider turning on the Firewall to keep others from connecting to them inadvertently.

  17. Alex
    “Are you people stupid? If the MacOSX firewall is ineffective, it needs to be reported and patched.”

    What most of us Mac users are saying is, “Is this artice BS and trying to troll for hits?”

    You can’t honestly believe Apple extended the release date and got a major piece of security wrong. This just needs to be followed up by multiple, reputable sources, PC World, Mac World, ect. to prove or expose the original story.

  18. Who ARE all you guys? What are your credentials and real world experience? Why should I believe one word you say, pro or con of this issue?

    NOTE: Welcome to the wonderful world of chat rooms and bulletin boards where everybody is a f*cking genius, where everybody knows more than everybody else, where nobody else’s standards are as high as “mine.”

    You guys REALLY need to start your own company and show ’em what you’re truly made of.

    Until then, I call b*llsh*t all ’round.

  19. Keep in mind the lengths people will go to for their 15 minutes of fame.

    The oh so accurate laptop wireless hacking story comes to mind.
    The first week it was touted as true and us Mac fanboys better get used to it.

    Months later it was all proved very wrong multiple times. The idiot writer had a personal agenda against Apple.

    So when stories like this first come out, I take it with a grain of salt and then wait for others to duplicate the same thing.

    Keep in mind the Windows FUD machine is going to go into overdrive when sales of OS 10.5 take off and Vista just languishes in the retail market.

    Don’t forget how much money MS has in the bank to buy “stories” or slant reviews. It’s sad but it happens.

  20. @Alex: You need to appreciate that the issue of security here is ‘way more complex than just “oh-my-god the firewall isn’t turned on by default.” Aside from the FUD masquerading fact in the article, the author truly doesn’t seem to understand that Apple’s approach to security at the OS level is different than Windows, but he expects it to behave the same. That’s his problem, not Apple’s.

  21. @Raymond from DC –

    Per your request, I ran the Service Port Probe at http://www.grc.com using Leopard with the firewire first set to “Block all incoming connections”. I too received a perfect score (Full Stealth Mode). I then reset the firewall to “
    Set Access for Specific Services and Apps”. Once again a perfect stealth score was achieved.

    I running Leopard on a Powermac G5, Dual 1.8. My ISP service is also Verizon FIOS. (Pretty nice!)

    I do not know if the results would change for anyone using an Intel based Mac.

    Peace.

  22. After having just performed an nmap test matrix of a fresh install of Leopard, imagine my surprise at reading the FUD presented in this article. In my tests, the firewall (which is OFF by default just as in all previous versions of OSX), responses EXACTLY as one would expect. When “Block all incoming connections” is selected, nmap reports no ports are available. When “Allow all incoming connections” is selected, nmap reports any services/ports which have been enable (by default, none are enabled). When “Set access for specific services” selected, nmap reports the services, ports, applications which are listed in the box below that option. If you select “stealth” option in the Advanced button, nmap reports that “the host appears to be down”. I think either Heise Security has an agenda, or someone needs to go back to school.

  23. I think this quote from the report sums it up:

    “Although the problems and peculiarities described here are not security vulnerabilities in the sense that they can be exploited to break into a Mac”

    So, if it isn’t a security vulnerability, and can’t be exploited to break into a Mac, why the chicken little act?

  24. If there is really a serious problem, Apple will fix it, they always have.

    Also, if and when someone can “really” hack a Mac with OSX, let me know, even these vaunted security firms have never reported; “I broke right in”, yeah right.

    And as NOTED, the Firewall is OFF, because nothing is ON out of the box.

  25. The key phrase here is “doesn’t work as expected.” They state quite plainly that they actually don’t know what’s going on. Apple is doing everything different from their experience with other OS’s so they are mystified. Rather than find out what the facts are though, they wrote this scary article to let the world know how scary it seems to them. Does this have something to do with Halloween? ” width=”19″ height=”19″ alt=”smile” style=”border:0;” />

    The only thing they demonstrated as a *fact* is that the time server still works with the firewall turned on, which is the expected behaviour AFAIK.

  26. On a internet teste to my PowerBook (Tiger) i have this report:

    “One or more ports on this system are operating in FULL STEALTH MODE!…OUR computer has DELIBERATELY CHOSEN NOT TO RESPOND (that’s very cool!)”
    “All attempts to get any information from your computer have FAILED. (This is very uncommon for a Windows networking-based PC.) Relative to vulnerabilities from Windows networking, this computer appears to be VERY SECURE since it is NOT exposing ANY of its internal NetBIOS networking protocol over the Internet.”

    My firewire is turn-off! and i’m a very happy Apple costumer.

  27. @Raymond from DC @Lurker_PC

    I just did the test on my MacBook and got the same. Perfect score:

    GRC Port Authority Report created on UTC: 2007-10-31 at 02:34:20

    Results from scan of ports: 0-1055

    0 Ports Open
    0 Ports Closed
    1056 Ports Stealth
    ———————
    1056 Ports Tested

    ALL PORTS tested were found to be: STEALTH.

    TruStealth: PASSED – ALL tested ports were STEALTH,
    – NO unsolicited packets were received,
    – NO Ping reply (ICMP Echo) was received.

  28. @mfshroom:
    The equivalent of Zone Alarm for Mac OS is an excellent little application called Little Snitch. This allows you to grant/deny access to the Internet on an application-by-application basis, rather than by a port/protocol basis, as with the default firewall. It also allows you to control what applications dial out, whereas the default firewall controls what outside applications can connect in. You need both.

  29. Ok… let’s talk security for just a second – and Leopard.

    I would have to assume (yes, I know what it spells) that the for-the-distance Mac users are aware that Apple has had ZERO exploits of any kind since the introduction of Mac OS 10.X.

    I would also have to assume that everyone here has done their homework I assigned the last time on how the UNIX kernal works. No? Shame on you, class!

    Now for the reality injection – and be really clear as you read this:

    Leopard has implemented a completely new method of security that literally defies plainclothes explanation. Suffice it to say – you are protected. Your personal passcode is encrypted and then placed in different locations in segments so that it cannot be traced and accessed maliciously.

    And the firewall can be customised – goto Sys Prefs and click on security and click on firewall and then click the third button and then drag in what you want to be accessed in and out of your computer.

    Words of caution: know what and why you are giving permission for any access.
    Little Snitch was great – haven’t tried it with Leopard.

    I am cautious until I run the retail virgin a little longer – maybe a few more days.

    And that’s the word: days

    As in you would have to be in a days ” width=”19″ height=”19″ alt=”wink” style=”border:0;” /> to think that Apple is ignoring security.
    Shame on you class!

  30. PC “heros” just can’t grab that MacOX has a totally different build than wind-dose… It’s just too much for their brains!
    Damn it, win folks, give that windows a kick in the a*s and have some better computing experience!

  31. OSX’s firewall is pretty disappointing. All it adds is basic “allow/deny” rules for ports. There’s a lot more it could be doing, like restricting the number of connections to certain ports (like ssh) per minute, blocking spoofed packets, etc.

    Just because there are no viruses in the wild for OSX doesn’t mean it’s invulnerable to other types of attack. Don’t get complacent about security.

  32. “OS X firewall is always turned off by default.
    Why? Because all other services are turned off by default. You can’t hack something you can’t see.”

    An established security principle is defense in depth.

    You get a router. the vendor secures the OS services to the best of their ability. You turn off any and all services you don’t need. But you also turn on you machine’s firewall.

    That all goes to make it less likely that a yet undiscovered fault in any one component is fatal.

    “author truly doesn’t seem to understand that Apple’s approach to security at the OS level is different than Windows,”

    It seems like you’re advocating the “all eggs in one basket” approach to security.

    “Verizon DSL installation, I am deemed “invisible” – perfect score.”

    That may have more to do with your Verizon DSL modem’s firewalling capability than you Mac.

  33. “”All attempts to get any information from your computer have FAILED. (This is very uncommon for a Windows networking-based PC.) “

    This result is what you get with every Windows OS since Windows XP using the out of the box install (firewall enabled, no exceptions)

    Where do you come up with your FUD?

  34. >Now for the reality injection – and be really clear as you read this:

    Leopard has implemented a completely new method of security that literally defies plainclothes explanation. Suffice it to say – you are protected. Your personal passcode is encrypted and then placed in different locations in segments so that it cannot be traced and accessed maliciously.

    And the firewall can be customised – goto Sys Prefs and click on security and click on firewall and then click the third button and then drag in what you want to be accessed in and out of your computer.

    —-

    I’m all for reality checks! You forgot to mention that Windows also supports both of these approaches (randomising memory locations and customisable firewalls).

    Your point was what?

  35. @Think: if your computers are on your “home network” as you say, then they most certainly protected by the hardware firewall built into your router. In fact, if your machine is behind a router, tgen you dont need a software firewall at all.

  36. I just upgraded last night and saw the news on this issue. So, I went to grc.com and used shields up by Steve Gibson.

    With all the firewall settings where there should be there was one problem that shields up did turn up and that was the anonymous ping sent to my computer was actually returned.

    Also of note, if you want the real low down on Mac Security go to opendoor.com and check out Alan’s Blog. He talks about what the real issue is and how to work around it.

    I am sure this is something that will be patched very soon. However, as to what level of threat this really is will be hard to determine for a while.

    ” width=”19″ height=”19″ alt=”smile” style=”border:0;” />

  37. I went to the article and read some of their mumbo jumbo. I thought it was filled with techno jargen which can be used to cover the fact that you are not really saying anything at all. LOL

    Here is what they said (in part):

    “Risk

    Whether the accessible services currently represent a security risk is hard to judge. ” — WTF??? You are a security company and say that Leopard fails the test, yet you cannot judge??? FUD FUD FUD. ” width=”19″ height=”19″ alt=”grin” style=”border:0;” />

    “The fact that Apple uses versions of open source software in which bugs have already been found and documented by the developers is cause for concern. Apple uses ntpd 4.2.2, the current version is 4.2.4. It is not clear whether any of the bug fixes are relevant in this scenario and if Apple back-ported fixes from more recent versions. The same applies to the Samba package (3.0.25b-apple), of which releases 3.0.25c and 3.0.26a contained numerous bug fixes.” —— SO what are you saying. That you do not know if there is any problem??????? FUD FUD

    “Both system services run as root and do not appear to be supported by Leopard’s new sandbox functions. If, therefore, a security problem which can be exploited remotely to inject and execute code is detected, an attacker could gain complete control over the system – with all the consequences this entails, right up to mass distribution via a worm.” —— er, are you talking about a Windows system???? You seem to be saying that IF someone can get in, and IF the can do some root access, THEN there is a danger……….. WTF do you mean IF??? I thought you said earlier that the door was wide open. Now you can not seem to decide if there is a problem.??????

    YEP, the STORM trojan can be a danger. IF YOU ARE a windows system. Danger alert. —- for WINDOWS.

    In conclusion, I think that these guys are click whores looking to scare people into using Vista, where they can sell you their services. That makes ANYTHING that they say, total FUD and not worth listening to. JMHO. But after reading their article, I think its true.

    en
    MDN = running as in these guys are running scared.

  38. “I’m not sure how much credibility this author has. He spelled “learned” wrong!”

    Actually “learnt” is spelt perfectly correctly. This is how the English, who created the English language (for themselves) speak and write the English language.

    Compare:

    spelt
    knelt
    felt
    dealt
    burnt

    “heise Security” is based in London (England), so why would they speak (or write) American English as opposed to Standard (British) English?

    http://en.wikipedia.org/wiki/Learnt

    http://www.askoxford.com/asktheexperts/faq/aboutspelling/learnt

  39. Funny how so many people on here think they are secure because they have tried some lame-ass web-based port scan. Google for “penetration tests” and do some proper reading. Trusting a free web tool to test your security is like believing nobody can steal your car because a drunk with a screwdriver couldn’t get into the boot.

  40. I’m no newbie, but I still don’t know what a firewall is for! I know it’s supposed to protect the system, but it seems even more wasteful than antivirus software, which shouldn’t be necessary on any platform.

    1) If ports are closed, you don’t need a firewall.

    2) If ports are open, using a firewall effectively closes them!

    It seems to me that security has to start with the software that manages the ports, and Apple’s done a pretty good job there.

  41. Yo Reality Check…

    Thanks for quoting me – out of context – typical MS fanfluff!
    The point is that Apple uses a TRUE UNIX kernal. Microsoft uses its own bastardization of UNIX… Hmmm, where did they get that idea?

    So tell me how many Virus, Infections, Spyware, Trojan horses and Adware (VISTA) do you find on a Mac? In the last, oh, seven years?

    Yes, Microsoft knows how to copy – rarely knows how to innovate! And you proved my point. Do you have any more Micro$haft fan-fluff?

    Typical M$ Approach – MDN approach

  42. “1) If ports are closed, you don’t need a firewall.

    2) If ports are open, using a firewall effectively closes them! “

    Defense in depth.

    A firewall opens selected ports depending on a policy you set.

    With a more modern firewall, when some other application that shouldn’t be tries to listen on a port or start an outbound connection, it will tell you.

    Without the firewall, the app will succeed.

    For that reason, even though you think no services are running on your PC, it pays to have another line of defense that stops them should some piece of malware install one and try to phone home or listen on some ports for instructions.

  43. “Whether the accessible services currently represent a security risk is hard to judge.”

    Nevertheless open services always pose some risk. New exploits get discovered all the time. hence defects in firewall software should not be brushed off lightly.

    “SO what are you saying. That you do not know if there is any problem”

    No, they’re saying the versions Apple runs are known to have multiple defects, unless Apple has incorporated fixes from newer versions.

    “all the consequences this entails, right up to mass distribution via a worm.”

    What they mean is if you can exploit a hole in these services, you WILL get root access to the box.

    Perhaps you should confine your comments to things you know even the slightest thing about.

  44. It does seem that Leopard’s firewall may have a few kinks to be worked out. With few services running, the risk may be fairly minimal (though I think Bonjour, a.k.a mDNSResponder, is running out of the box, no?)

    However, I love the statement: “Instead of addressing perceived flaws in the firewall, an Apple spokesman told eWEEK only that the company ‘takes security very seriously,’ “

    They make it sound like they want the spokesman to sit down in front of them, whip out his MacBook with Leopard source code, and build a Security Update 2007-1234 right there to fix the firewall. Sheesh. Or at least give a dissertation on firewall design. He’s a PR person for crying out loud.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.