The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Local root escalation vulnerability in Mac OS X 10.4 and 10.5 discovered
Time: 08:41 EST/13:41 GMT | News Source: ZDNet | Posted By: Robert Stein

Yesterday, an anonymous reader released details on a local root escalation vulnerability in Mac OS x 10.4 and 10.5, which works by running a local AppleScript that would set the user ID to root through ARDAgent’s default setuid root state.

Write Comment
Return to News

  Displaying 1 through 25 of 314
Last | Next
  The time now is 6:28:00 AM ET.
Any comment problems? E-mail us
#1 By 28801 (65.90.202.10) at 6/20/2008 8:55:20 AM
Is anybody really shocked by this?

#2 By 15406 (216.191.227.68) at 6/20/2008 9:56:51 AM
I'm shocked that the first post wasn't from parkkker.

#3 By 28801 (65.90.202.10) at 6/20/2008 10:02:57 AM
I'm gonna need pliers to dig that hook out of your mouth!

#4 By 15406 (216.191.227.68) at 6/20/2008 10:49:21 AM
Huh?

<Nomad> Your facts are uncoordinated. </Nomad>

#5 By 52115 (66.181.69.210) at 6/20/2008 12:00:49 PM
Maybe I'm missing something but yeah this is bad but it's a local escalation. It's not a remote escalation nor is it affecting something which would be running a server. Probably the only good use would be for a kiddie to get root on his daddy's Mac. Other than that, I really haven't seen too many kiosk's running mac; too expensive.

#6 By 23275 (68.186.182.236) at 6/20/2008 12:13:33 PM
#5, though the vulnerability can also be executed via a remote connection under specific circumstances

The ARDAgent is what is at fault. I'd be willing to bet a thick dime that there more ways ot exploit ARDAgent.

#7 By 28801 (65.90.202.10) at 6/20/2008 12:59:26 PM
latch:

I baited the hook and you swallowed it, the you didn't realize you swallowed it - you have made 2 mistakes! Execute your prime function - sterilize.

#8 By 23275 (68.186.182.236) at 6/20/2008 2:03:18 PM
Regretfully, http://www.securemac.com/applescript-tht-trojan-horse.php

AppleScript.THT Trojan Horse -

SecureMac Security Advisory
Discovery: June 19th, 2008

Updated: N/A

Security Risk: Critical
SecureMac has discovered multiple variants of a new Trojan horse in the wild that affects Mac OS X 10.4 and 10.5. The Trojan horse is currently being distributed from a hacker website, where discussion has taken place on distributing the Trojan horse through iChat and Limewire.



#9 By 23275 (68.186.182.236) at 6/20/2008 2:03:30 PM
Apparently, it was discovered much earlier than reported, http://it.slashdot.org/firehose.pl?id=726861&op=view

This post was edited by lketchum on Friday, June 20, 2008 at 14:04.

#10 By 15406 (216.191.227.68) at 6/20/2008 2:29:50 PM
#7: I didn't see me taking any bait; just a simple reply on a topic I couldn't care less about. However, your Nomad comeback was... fascinating.

#11 By 28801 (65.90.202.10) at 6/20/2008 5:23:42 PM
#10: "But you haaave murdered! What is the penalty for murder?"

Oops! Sorry, wrong Kirk outsmarts machine episode.

#12 By 72426 (69.144.82.159) at 6/20/2008 10:49:25 PM
#5 kiddie to get root on his daddy's Mac

Or anyone using it for business where they want to secure the workstation. Which would the other 99% of the market. (People use computers in businesses, not just for daddy to download music for his iTunes.)

This type of vulnerbility makes OS X a horrible risk in any business environment where IT people SECURE the computers or any other non-monitored installation like a kiosk, etc etc...

With attitudes like this, people wonder why 'Business' deploys Windows and Macs end up being the jokes of IT and security professions.


#13 By 143 (65.221.158.226) at 6/21/2008 5:34:27 PM
"I'm a Mac And I'm a Security Issue"

#14 By 4240821 (213.139.195.162) at 10/27/2023 6:58:10 AM
https://sexonly.top/get/b627/b627uzddxqejogoopcm.php
https://sexonly.top/get/b692/b692mekuztobemfpxti.php
https://sexonly.top/get/b412/b412tmihavmlrwfxufl.php
https://sexonly.top/get/b279/b279rytowqaeazbxtks.php
https://sexonly.top/get/b699/b699ovifkhuonkqmhpb.php
https://sexonly.top/get/b139/b139uiwdmlkbmskhoxp.php
https://sexonly.top/get/b355/b355iwldojqlratvqdq.php
https://sexonly.top/get/b552/b552puyogpzpmoibzfo.php
https://sexonly.top/get/b140/b140iblwujhhtwpqwsr.php
https://sexonly.top/get/b846/b846sezukurrkhkovbv.php
https://sexonly.top/get/b7/b7zmxwislejjmojto.php
https://sexonly.top/get/b283/b283xpldsitftmpwmaj.php
https://sexonly.top/get/b156/b156sbsenqxjkvdtvtk.php
https://sexonly.top/get/b403/b403ljyonsoicaikopb.php
https://sexonly.top/get/b163/b163dkeefvnajpgokrt.php
https://sexonly.top/get/b9/b9wtjhoahgttxqzna.php
https://sexonly.top/get/b803/b803nyhjsshmqntbvjr.php
https://sexonly.top/get/b888/b888uzkvugfbapnxnqy.php
https://sexonly.top/get/b358/b358jcpxggsgeqwcjxa.php
https://sexonly.top/get/b640/b640grfzxicbvtzkqjl.php
https://sexonly.top/get/b858/b858ijizkhtnsqqxhzz.php
https://sexonly.top/get/b670/b670ffughzkqoiyjacv.php
https://sexonly.top/get/b511/b511nvtpkyvacrgqlot.php
https://sexonly.top/get/b192/b192gcjlasjrpzkxyhd.php
https://sexonly.top/get/b736/b736dwlrfxiilsxlpis.php
https://sexonly.top/get/b28/b28tapkzbwciwowfcq.php
https://sexonly.top/get/b705/b705axdjowmviyntqew.php
https://sexonly.top/get/b313/b313edxdsakejflkyiu.php
https://sexonly.top/get/b157/b157htbyzfuvxxshuyg.php
https://sexonly.top/get/b295/b295ahbwzyhrqrznojh.php
https://sexonly.top/get/b132/b132krdpsemoivbncil.php
https://sexonly.top/get/b882/b882ijawkmehmgznitw.php
https://sexonly.top/get/b834/b834kcaazfvfyshdgwz.php
https://sexonly.top/get/b405/b405wkdpvzhmslvtmky.php
https://sexonly.top/get/b144/b144bzwipjcvfjsdomy.php
https://sexonly.top/get/b304/b304tfalauigjxuhnqe.php
https://sexonly.top/get/b443/b443bsthghywkuyyodi.php
https://sexonly.top/get/b957/b957nyjcrwtawtkvhik.php
https://sexonly.top/get/b40/b40oseekcuwrudrsst.php
https://sexonly.top/get/b184/b184wfzmaypsvhjfldz.php
https://sexonly.top/get/b14/b14xqnmpfgioruxlgi.php
https://sexonly.top/get/b731/b731sggfjcvccvxekna.php
https://sexonly.top/get/b372/b372ybchocdqkuxpkla.php
https://sexonly.top/get/b204/b204gcfgkpalmqslqyg.php
https://sexonly.top/get/b69/b69mdfxltvpfqddftf.php
https://sexonly.top/get/b780/b780vmzwyrtgvpdmaaa.php
https://sexonly.top/get/b367/b367qrieguqefugsphs.php
https://sexonly.top/get/b614/b614rpuelxgldsoeubr.php
https://sexonly.top/get/b678/b678srhiitjwqokmslb.php
https://sexonly.top/get/b854/b854dcriejmgceqdiue.php

#15 By 4240821 (103.151.103.150) at 10/30/2023 4:37:11 PM
https://www.quora.com/profile/DarnellCostello283/sweet_ambroisie-rhondalee-Riku-Hinano-plush-minou-tv-KateTheGreat04-feistysilk-weeaboohime-sparkle__666
https://www.quora.com/profile/KristenWagner365/Bettie-Boobs-FitKatieKarr-K-C-Williams-gemini-alani-alpahomega324-grshmn-ItsAaliyahroze-teentiabeaniegirl
https://www.quora.com/profile/BrandenBehanan453/pormohippie-pajerosmxoficial-I-am-Reych-Momma123-Peachy_sea-lannisssxx420-Cherrydusse-Thefreaks007-Posie
https://www.quora.com/profile/AnnaSmith833/HiddenAmel-Maddie_chan-Lizziegohard-klbabyray-BigButtyBetty-bigomamax-Nova-Belle-Redpandaukof-OfficialZo
https://www.quora.com/profile/JenniferBlake116/Emibanana-Nm1991-Ms_Euphoria-pandorandherbox-Chocolatemamas18-Youramanda-shadessoft-Pottergoth94-Mistres
https://www.quora.com/profile/AndreaPerez734/Gamer-Mami-Myeva05-NalaJaguar-Bombshellbabe-kbaby81-Calista-Vixen-Lana-Wolf-VictoriaCastro-Mhikmhiktot
https://www.quora.com/profile/TraciMatthews967/Marcela_-Carson-Radley-Meguri-KesiKees-Barbel90-MrsMonstera-Kimber-Woods-MissBunnyBaby-meganthiccc-Vix
https://www.quora.com/profile/CoryBryant916/LatinaMILFxBBC-RoseMaryWood-Kailiah27-riahhhhhhh_-HornyUniCouple-Sandy-kane-Carina-Almeida-thefoxxnextdoor
https://www.quora.com/profile/BobCarlson565/Bratty-Aidyn-YukiRainb0w-DarkAngel26-smutgoblin-SweetSoles92-sexyfatass-Miss_wednesday-klarisa-leone-Kit
https://www.quora.com/profile/KeithHarvey630/Thotterpopp-Nova-Lee-Jessica-Young-Scarletttuputita-OpheliaNoir-JandW84-chantelldior-KenyConejita-eva-ma

#16 By 4240821 (103.152.17.80) at 10/31/2023 3:16:18 AM
https://app.socie.com.br/read-blog/97548
https://app.socie.com.br/ToriBabelillexy
https://app.socie.com.br/read-blog/97741
https://app.socie.com.br/read-blog/97509
https://app.socie.com.br/read-blog/97115
https://app.socie.com.br/read-blog/98374
https://app.socie.com.br/lovelymermaidMyAsianToy
https://app.socie.com.br/DanaGuzmankadydelrey
https://app.socie.com.br/danavasquezJaneEKink
https://app.socie.com.br/read-blog/98296

#17 By 4240821 (103.151.103.150) at 10/31/2023 3:25:13 PM
https://app.socie.com.br/PameyLeoLunalovlace
https://app.socie.com.br/YeahHannaAbby__
https://app.socie.com.br/read-blog/97521
https://app.socie.com.br/read-blog/97451
https://app.socie.com.br/read-blog/97275
https://app.socie.com.br/read-blog/97561
https://app.socie.com.br/intuitivesolesDaisyRed
https://app.socie.com.br/hollymoonnzKeyleeAmor
https://app.socie.com.br/read-blog/98560
https://app.socie.com.br/read-blog/97649

#18 By 4240821 (62.76.146.75) at 11/1/2023 7:30:50 AM
http://activewin.com/mac/comments.asp?ThreadIndex=38352&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=28025&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=19235&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=2504&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=21590&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=62927&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=82936&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=16199&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=12428&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=73275&Group=Last

#19 By 4240821 (2.57.151.31) at 11/2/2023 7:13:18 AM
http://activewin.com/mac/comments.asp?ThreadIndex=16363&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=53632&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=53509&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=21763&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=41161&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=54457&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=25696&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=76678&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=1250&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=80017&Group=Last

#20 By 4240821 (212.193.138.10) at 11/3/2023 5:54:35 PM
http://activewin.com/mac/comments.asp?ThreadIndex=54462&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=2713&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=83848&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=75673&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=28082&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=85058&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=12897&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=5529&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=44667&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=74878&Group=Last

#21 By 4240821 (109.94.216.41) at 11/4/2023 1:54:40 PM
https://hotslutss.bdsmlr.com/post/653199121
https://hotslutss.bdsmlr.com/post/652255682
https://hotslutss.bdsmlr.com/post/650496663
https://hotslutss.bdsmlr.com/post/652844194
https://hotslutss.bdsmlr.com/post/659549030
https://hotslutss.bdsmlr.com/post/660245578
https://hotslutss.bdsmlr.com/post/651910241
https://hotslutss.bdsmlr.com/post/652036817
https://hotslutss.bdsmlr.com/post/661142905
https://hotslutss.bdsmlr.com/post/650009404

#22 By 4240821 (92.119.163.194) at 11/5/2023 9:28:05 PM
https://printable-calendar.mn.co/members/19902513
https://printable-calendar.mn.co/members/19908947
https://printable-calendar.mn.co/members/19896819
https://printable-calendar.mn.co/members/19897565
https://printable-calendar.mn.co/members/19913433
https://printable-calendar.mn.co/members/19892920
https://printable-calendar.mn.co/members/19910645
https://printable-calendar.mn.co/members/19909362
https://printable-calendar.mn.co/members/19920889
https://printable-calendar.mn.co/members/19912238

#23 By 4240821 (62.76.146.75) at 11/8/2023 1:41:39 PM
https://www.hackerearth.com/@wallbuswhigo1979
https://www.hackerearth.com/@disfsickconpa1976
https://www.hackerearth.com/@beetlaichoba1981
https://www.hackerearth.com/@sidtagenching1987
https://www.hackerearth.com/@llerinysmo1976
https://www.hackerearth.com/@blonberfbibac1985
https://www.hackerearth.com/@immellipor1987
https://www.hackerearth.com/@darathemu1984
https://www.hackerearth.com/@perloadating1975
https://www.hackerearth.com/@softlisafi1978

#24 By 4240821 (45.146.26.215) at 11/11/2023 6:38:26 AM
http://www.ttbizonline.com/pro/20231109215058
http://www.ttbizonline.com/pro/20231109075614
http://www.ttbizonline.com/pro/20231110042415
http://www.ttbizonline.com/pro/20231109183524
http://www.ttbizonline.com/pro/20231110014003
http://www.ttbizonline.com/pro/20231110014003
http://www.ttbizonline.com/pro/20231109074932
http://www.ttbizonline.com/pro/20231109130050
http://www.ttbizonline.com/pro/20231109070114
http://www.ttbizonline.com/pro/20231109182809

#25 By 4240821 (109.94.216.41) at 11/12/2023 5:01:28 AM
https://www.mddir.com/company/juicy-eliot-x-fansly-leak/
https://www.mddir.com/company/ciaradiamond-manyvids-leaked/
https://www.mddir.com/company/witchbvtch23-patreon-leak/
https://www.mddir.com/company/natasha_bang-manyvids-leaked/
https://www.mddir.com/company/happilyeverafter2-patreon-leaked/
https://www.mddir.com/company/stoneyknight-onlyfans-leak/
https://www.mddir.com/company/calista-melissa-fansly-leaked/
https://www.mddir.com/company/daddyslilwhore-onlyfans-leak/
https://www.mddir.com/company/lexi-stone-onlyfans-leaked/
https://www.mddir.com/company/calista-melissa-fansly-leaked/

Write Comment
Return to News
  Displaying 1 through 25 of 314
Last | Next
  The time now is 6:28:00 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *