Forgot your password?
typodupeerror
Worms Businesses OS X Operating Systems Security Apple

Worm Claimed For Apple OS X 398

Posted by kdawson
from the apple-trees-have-roots-too dept.
SkiifGeek writes "Controversy is slowly building over the development of a claimed new worm that targets OS X systems, dubbed by its inventor Rape.osx. Using a currently undisclosed vulnerability in mDNSResponder, the worm is said to give access to root as it spreads across the local network. As with a number of recent Apple-related security discoveries, the author, InfoSec Sellout, is delaying reporting the vulnerability to Apple until after completing full testing of the worm. While the worm has yet to leave a testing environment (with 1,500 OS X systems), it is bound to join the likes of Inqtana and Leap as known OS X malware."
This discussion has been archived. No new comments can be posted.

Worm Claimed For Apple OS X

Comments Filter:
  • by linuxmeltz (815217) on Tuesday July 17, 2007 @07:29PM (#19894793)
    Hey, there's a worm in my apple...
    • by Anonymous Coward on Tuesday July 17, 2007 @07:37PM (#19894873)
      ... which is much better than half a worm!
    • by dotpavan (829804) on Tuesday July 17, 2007 @07:38PM (#19894891) Homepage
      when God (Gates) specifically asked you NOT to eat the Apple (Inc), you should have listened :)
    • Re: (Score:3, Insightful)

      by catwh0re (540371)
      While I have no doubt that worms etc can be created for OSX (or any OS, given enough time.) I'm not really fond of companies blowing their trumpet until they're certain. It's very rich to claim all that publicity without notifing the vendor, or even being 100% certain. Otherwise it comes across as yet another company that is trying to claim solely for the benefit of the massive attention that it will draw on the company. Whether it's a fiasco involving wifi hardware or an antivirus company claiming endless
      • Re: (Score:2, Insightful)

        by Maniac-X (825402)
        If by "well versed in frauds and half-truths" you mean well versed in spreading their own brand of propoganda and half-truths, then yes, you are correct.
      • Re: (Score:3, Interesting)

        by kestasjk (933987)
        If you have a sandpit it's much easier to bury your head in it, rather than try and come up with a reasonable explanation of why this worm is part of Jobs' master plan.
        • Re: (Score:3, Interesting)

          by Anonymous Coward
          Your opinion? Is it the result of envy because a mac user spends more time using their system productively instead of configuring it? Those that spend all day configuring their system, installing software they'll never use and reinstalling stuff for "fun" are obviously envious of the productive mac users who spend their computer time creating content and not just playing with the content designed by others.
    • Who modded this as funny? It might have been funny in 1978, but most people thought the joke was a bit old back then.
  • by oogoliegoogolie (635356) on Tuesday July 17, 2007 @07:38PM (#19894881)
    That's impossible!
    • by kestasjk (933987) on Tuesday July 17, 2007 @10:25PM (#19896249) Homepage

      That's impossible!
      It's possible, but:
      • It doesn't exist in the wild; this is because of OS X's stunning security features
      • This vulnerability was probably placed into the system by Jobs himself. If there were no vulnerabilities in OS X people would realize Jobs was supernatural, so he has to put one in there from time to time.
      • This vulnerability is probably the last vulnerability in OS X. Once Apple fixes this there'll be no more
      • Way, way more vulnerabilities are found in Windows and Windows products; this is because of OS X's breathtaking security features
      • This is probably a bug in BSD or Mach code, or one of the recent Intel chip bugs, or a Microsoft employee infiltrated the Cupertino campus. It's not Apple's fault.
      • Microsoft spends its entire R&D budget looking for these elusive Apple holes just as a way of discrediting Apple. If the real number of Microsoft and Linux vulnerabilities were actually disclosed there would be no comparison.
      • Apple puts the occasional vulnerability in its system because they know that Microsoft blindly copies anything Apple does. If Apple puts one bug into their system they know Microsoft will put 10 bugs in theirs.
      • Microsoft worms spread spambots and steal credit card information, Apple worms are just a misguided attempt of a loyal Apple fan to spread the good vibes and let the community know he cares. With Mac OS X only your unquestioning loyalty is contagious.
      Such a breathtaking OS on a rock solid foundation with over 1 million configurations. Say hello to OS X Panda. Starting at $99. Small sentence. Reinvented.
      • Actually... (Score:5, Insightful)

        by LKM (227954) on Wednesday July 18, 2007 @07:38AM (#19898895) Homepage
        The only people I always see spouting such crap are the people who claim to hate Apple fanboys. I've never seen an Apple fanboy make absurd claims like yours. This is like a fucking self-fullfilling prophecy. Every damn article about Apple is run over by stupid Anti-Apple trolls who write hundreds of comments laughing about imaginary Apple fanboys and the imaginary stupid things they say. [crazyapplerumors.com]

        Here's an idea: Shut up, and let those who are interested in the article discuss it. Thanks.
  • *ahem* (Score:5, Insightful)

    by Duncan3 (10537) on Tuesday July 17, 2007 @07:44PM (#19894953) Homepage
    As with a number of recent Apple-related security discoveries, the author, InfoSec Sellout, is delaying reporting the vulnerability to Apple until after completing full testing of the worm.

    If by fully testing you mean "auctioning it to the highest bidder" then yea.
  • by mzs (595629) on Tuesday July 17, 2007 @07:45PM (#19894961)
    Disable mDNSResponder:

    sudo launchctl unload -w /System/Library/LaunchDaemons/com.apple.mDNSRespon der.plist
    • by dch24 (904899) on Tuesday July 17, 2007 @08:06PM (#19895157) Journal
      Very good. That might disable the security hole, if what has been disclosed so far is 100% accurate. If not, well, all you lose is Bonjour (useful for discovering iChat and iTunes connections on your local subnet).
      • also quite useless (Score:4, Insightful)

        by Jeremy_Bee (1064620) on Tuesday July 17, 2007 @10:10PM (#19896141)
        IMO the really funny thing is that this joker decided to use a Bonjour vulnerability to work on, when everything I've heard indicates a major reworking of the Bonjour code in Leopard anyway.

        Isn't this kinda like working out a vulnerability in AppleTalk a month before they stopped using it?
        • by zootm (850416) on Wednesday July 18, 2007 @06:53AM (#19898735)

          Many of the major Windows worms and so forth target vulnerabilities which have already been fixed (and the fixes pushed out) months before. Not only will many not upgrade to Leopard, if the OS X userbase is similar to the Windows userbase (I'm not sure if it is, but still), many will simply not click the button to install the updates, and leave themselves vulnerable.

        • Re: (Score:3, Interesting)

          by TheRaven64 (641858)
          I'd really be interested as to whether this vulnerability is OS X only. Apple have released mDNSResponder under an Apache 2.0 license, and it runs on Windows and *NIX. Is the vulnerability in mDNSResponder, or how it interacts with OS X?
  • by Swift2001 (874553) on Tuesday July 17, 2007 @07:46PM (#19894973)
    First of all, if he's found a real vulnerability, he reports it. I don't care if it's Apple or Linux or even Windows. "Waiting until I finish it" is a disgusting excuse. Will he sell it to the bad guys? Is this free publicity for some jerk? I think the Slashdot world ought to have a serious discussion of this kind of jerk. I think Congress might to. If what he's doing isn't illegal now, maybe it should be.
    • by Tobenisstinky (853306) on Tuesday July 17, 2007 @07:48PM (#19894995)
      Good idea. However, a serious discussion on /. is unlikely.
    • by sokoban (142301)

      Will he sell it to the bad guys? Is this free publicity for some jerk?
      To answer your questions:

      Yes and yes.
    • by Mr. Flibble (12943) on Tuesday July 17, 2007 @07:58PM (#19895077) Homepage

      I think the Slashdot world ought to have a serious discussion of this kind of jerk. I think Congress might to. If what he's doing isn't illegal now, maybe it should be.


      I agree. We should also question the ethics of Theo de Raadt. After all, this guy published an exploit for OpenSSH. Who does this guy think he is? Hell, he should have given the problem to the developers of OpenSSH to fix it, not be out there releasing exploits and stuff.
    • by QuantumG (50515) <qg@biodome.org> on Tuesday July 17, 2007 @08:02PM (#19895117) Homepage Journal
      Sounds like a great plan. Make it compulsory to report vulnerabilities eh? Maybe even ban the selling of vulnerabilities. Kinda makes you wonder why any third party would bother looking for them.

      • by QuietObserver (1029226) on Tuesday July 17, 2007 @08:15PM (#19895233)
        From my point of view, the original argument never said anything about making vulnerability reporting compulsory, but that concealing a vulnerability is morally reprehensible, and claiming to keep a vulnerability secret until an exploit is finished is a disgusting excuse.
        • by QuantumG (50515)
          Why do you think concealing a vulnerability is morally reprehensible?

          Some people think revealing a vulnerability is morally reprehensible.

          Some people think not revealing a vulnerability to anyone but the person who made the damn thing in the first place is morally reprehensible.

          You can't just make a blanket statement about a complex issue like this and assume we all know what your position is.

          • Re: (Score:3, Interesting)

            The only way for a person to improve is to receive constructive criticism and to listen when others point out their failings. I personally listen when others point out my mistakes, and do my best to correct them, so I likewise believe that concealing information for the sole purpose of one's own advantage, without consideration for anyone who might be hurt because of one's actions, is immoral. Furthermore, I don't understand how you can consider the creation of malware a complex issue; in the long run, no
            • by QuantumG (50515) <qg@biodome.org> on Tuesday July 17, 2007 @09:52PM (#19896007) Homepage Journal
              And that's the problem. You want to look at it in simple terms instead of considering the whole issue.

              Apple and other software vendors have chosen a development model that maximizes their ability to hide defects in their software. If people are morally obliged to report any of the defects they independently find in the software then the vendor has no incentive to ensure the defects are found before the product hits the market. To put it another way, time to market is much more important to them than making a product free of defects. The only thing that motivates them to ensure their products are defect free is malware. As such, creation of malware actually *helps* to make the vendor take more responsibility for the defects in their product.

               
    • by fox1324 (1039892) on Tuesday July 17, 2007 @08:17PM (#19895245)
      If what he's doing isn't illegal now, maybe it should be.


      Maybe it shouldn't be. There are hundreds of /. threads filled up with complaints about the US government and legal system. Our rights are constantly eroded by attempts to 'legislate morality'. Repeat with me: just because something is unethical or immoral does NOT mean it needs to be illegal. Ethics and morals are nothing more than opinions, and they vary greatly from person to person.

      Neglecting to report a vulnerability is not remotely criminal, no matter how much you disagree with his motivation.

    • by MadMidnightBomber (894759) on Wednesday July 18, 2007 @03:27AM (#19898005)
      Because Congress is well known for its mature and insightful discussion of computer and network security issues.
  • by dsdtzero (137612) on Tuesday July 17, 2007 @07:46PM (#19894979)
    The fact that the breaking news on slashdot is "someone found the third way to attack a mac machine" is a compelling argument to purchase a mac over a PC. Unless someone can explain to me how this is the seed of an impending snowball of mac-targeted malware.
    • by Daniel Dvorkin (106857) on Tuesday July 17, 2007 @08:05PM (#19895145) Homepage Journal
      Yes, exactly. Three proofs of concept vs. thousands, maybe millions, of vulnerabilities in the wild.

      The author claims, "While it is nothing special compared to Windows based Malware it does prove a point -- Apple Computers are just as susceptible to Malware as Windows based ones." Oh, bullshit. The fact that this particular security vulnerability exists does not mean that OS X is just as much a wide-open target as Windows is.

      In the "Classic" MacOS days, there was a fair amount of Mac malware -- never as much as in the PC world, of course, but plenty of it running around. Since OS X became the standard, this hasn't happened. The "vulnerability through popularity" argument just doesn't hold up to this fact.
      • Re: (Score:3, Interesting)

        by timmarhy (659436)
        the number of vulnerabilities is irrelvant, what matters is how easily it spreads and what it's payload is like.

        IF this is real, and it can spread quickly and cause maximum damage then it's just as bad as windows, because the end result is an unsafe system.

        • Re: (Score:3, Informative)

          by v1 (525388)
          I doubt they are nearly as worried as they could be. From the looks of it, it can only spread locally on your subnet. Internet worms like code red, that can infect 70% of the vulnerable machines in the world in eight minutes, vs this whic may infect up to 254 machines on the typical network. Anyone that even attempts to put those two exploits in the same timezone needs a beating with a ClueBat.
        • I would not say one potential laboratory specimen for OSX is as bad as all 180,000 known Windows threats in the wild even if it's real.

          Bad, though, yes, it is, if it's real.

          Did I mention it wasn't in the wild? Your mac cannot catch this one yet and likely won't ever, if it's even real.

          That is not as bad as zero to pwned in 23 seconds average just by connecting XP to the Internet. But bad, yes it may be.

          If it's real, then it's bad.

      • Re: (Score:3, Interesting)

        by toadlife (301863)

        In the "Classic" MacOS days, there was a fair amount of Mac malware -- never as much as in the PC world, of course, but plenty of it running around. Since OS X became the standard, this hasn't happened. The "vulnerability through popularity" argument just doesn't hold up to this fact.

        Why not? OSX has never had nearly the same install-base that classic Mac OS did during it's heyday, and of all the predominant methods that malware spreads simply can't work on OSX like they do on Windows because there are not enough potential hosts.

        Take the classic email based worm for example. Given that only about 4-8% of computers run OSX, how would an email worm spread on Macs? If you sent it to 100,000 email addresses you'd be lucky if 8,000 OSX users received the email. If 50% of those 8000 OSX use

      • Are there really all that many Windows attacks that can remotely exploit a default service? Seems to me the most common vector is people downloading sketchy software from sketchy places. Is there something about Mac OS X that protects users from themselves? Second to that are exploits for IE or Outlook. Aside from "Microsoft programmers are stupid and write bad code" is there some fundamental reason that Safari or Mail couldn't be exploited? I'm not being rhetorical, I really want to know if there is some a
  • Windows affected? (Score:5, Interesting)

    by nuckin futs (574289) on Tuesday July 17, 2007 @07:49PM (#19895007)
    exactly what vulnerability in mDNSResponder is it exploiting? Since mDNSResponder also runs on windows if you install bonjour for Windows, does that mean it can possibly be affected too?
  • by Anonymous Coward
    While InfoSec Sellout states that the worm only seeks out other systems on the same network for infection, they point out that it is not going to take much extra work for the worm to attack a much broader network segment.

    It's my understanding that the daemon in question works only on the LAN and is part of Bonjour/Rendezvous/Zeroconf/Avahi.... if this is the case, assuming a decent firewall, aren't you only vulnerable within your own local network?
    • by greed (112493) on Tuesday July 17, 2007 @08:49PM (#19895495)

      Sure, get infected on the school's lab LAN. Bring your iBook oops MacBook to the coffee shop and get everyone else there. They all go home and infect their room-mate's machines. Who go to a different lab and it gets loose on the LAN there.

      Most laptops aren't isolated to a single LAN these days; they move around. If there really is a flaw in mDNSResponder, then such a worm does have a chance to propagate. Especially if it is subtle and doesn't crash or overload machines, or do insane amounts of network I/O, or any of the other things that cause people to think something's wrong.

    • True. For now, zeroConf is not passed on at the router. However, they are working on an implementation of zeroConf that does get passed across the router. Hopefully, they'll check more closely now on that version for buffer overflows before approving it.
  • by Penguinisto (415985) on Tuesday July 17, 2007 @07:53PM (#19895037) Journal
    Serious question here:

    Somebody writes a worm for OSX that works across a specific test network (of which we have no clue as to settings, layout, patch levels, etc etc), and it's really, really, really big news. Media orgs around the planet sound the klaxon, and (nearly) everyone gets all hyper-ventilated. Claims of "OSX is just as vulnerable!!!1111!!" will fly off the pages.

    Meanwhile, the next near-periodic iteration of MSFT-specific malware in-the-wild will get not so much as a grunt outside of security circles (such as SANS ISC and F-Secure's blog as ferinstances). It will likely subvert 40x as many victims in its first hour, and the media won't say so much as 'boo' about it.

    Perspective (at least outside of security and some geek circles)? Never heard of it.

    /P

    • by PhotoGuy (189467)
      It's a really big story, because of how unusual any exploit on OS/X is (even without knowing the details, it's a big story), not because it means OS/X is insecure....
  • by MBCook (132727) <foobarsoft@foobarsoft.com> on Tuesday July 17, 2007 @07:58PM (#19895089) Homepage
    I was under the impression that mDNS was not routable (and specifically designed not to be routed). If that is true, doesn't that restrict this to propagating to computers on the same subnet? This could effect a business, or a computer lab (say at a university), but this fact should prevent it from spreading around the internet at large (as various Windows worms have).

    It's a bug, it's a problem, but it's no Blaster by a long shot.

    • by dch24 (904899) on Tuesday July 17, 2007 @08:09PM (#19895183) Journal
      Bundle it with a Windows worm. Exploit Macs on the same subnet as Windows boxes. Then the infected Macs scan for vulnerable Windows boxes and spread the infection. Every vector is useful in an attacker's bad of tricks.
    • by mzs (595629)
      mDNS uses the link-local multicast address 224.0.0.251. Link local addresses should not be routable, but there is always the possibility of some routers being misconfigured, most likely because some idiot that does not know better wants Bonjour to work across subnets without simply using DNS correctly.
    • by anticypher (48312) <[anticypher] [at] [gmail.com]> on Tuesday July 17, 2007 @08:55PM (#19895563) Homepage
      Multicast packets are routable, if the upstream routers support dealing with multicast packets correctly.

      mDNS/bonjour/zeroconf detects if a packet has crossed a router by setting the originating TTL to 255. If a multicast packet crosses a router, the TTL is supposed to be decremented, and zeroconf is supposed to ignore the packet as it is no longer considered local. Many suppositions there, as implementations vary.

      Worse, starting with a TTL of 255 means that the packets will be able to go anywhere on the internet where multicast packets can get routed. Better protected carriers will drop multicast packets with TTLs greater than 64 or 128, specifically to limit mDNS/zeroconf traffic while allowing reasonable traffic to flow. Most ISPs don't have the technical competence to deal with multicast, so they just block it, which will limit any spread of an mDNS worm.

      However, just because mDNS/zeroconf will ignore packets with TTL less that 255, doesn't mean that a buffer overflow bug isn't being treated by the protocol stack. Take a wait and see attitude on this disclosure, as it appears to be an extortion attempt rather than something from legitimate sources.

      the AC
  • by mbessey (304651) on Tuesday July 17, 2007 @08:03PM (#19895137) Homepage Journal
    So, not quite like the Internet-spanning, DDOS-producing Windows worms we've come to know and hate. I'm not too surprised the vulnerability was in MDNSResponder, though. Someone I work with found a few problems in the code when running it on Linux.
  • Market share? (Score:3, Insightful)

    by Dan_Bercell (826965) on Tuesday July 17, 2007 @08:04PM (#19895139)
    I havent really looked at the market share percentages of OSes recently, has Apple really grown large enough for Virus makers to start targeting Apple?
    • Y'poor bastard, Apache has a larger share of the web server market than IIS, and is just as often targeted, but is more secure. Your question, however, is about targeting, and you're spot on. Mac users are singularly useless when it comes to security. You got modded flamebait by an overzealous dickwad Mac user (and I use Macs m'self)
      • by toadlife (301863)

        Apache has a larger share of the web server market than IIS, and is just as often targeted, but is more secure.
        Proof?
    • by v1 (525388)
      It doesn't work that way. They don't get out the pie charts to decide who to exploit. Sure, a bigger "audience" for their handiwork is surely a bonus, but the typical malcontent, the easier targets always attract 95% of the attacks. Writing viruses for windows seems not too far off from script kiddie class work. There will always be a few "in it for the challenge" to try to hack the gibson etc but they are statistically minor. I view it from the other perspective, that by its intrinsic security and dif
  • I'm guessing Matasano Security is paying him for this vulnerability.

    They're the ones who challenged Joanna Rutkowska about her bluepill (see the "Hi Joanna" quote on the blog), and have had contact with infosec sellout in the past.
  • 200,783 to go...
  • by e. boaz (67350) on Tuesday July 17, 2007 @09:15PM (#19895739) Homepage
    If this is a real concern, there is a workaround to have mDNSResponder run without root privileges. Part of the claim is that they can deliver root payloads - this is likely because mDNSResponder runs as the root user and they might be using a buffer overflow exploit [NOTE: I have not analyzed the mDNSResponder code - this is a guess.]

    % sudo launchctl unload /System/Library/LaunchDaemons/com.apple.mDNSRespon der.plist
    % sudo chown nobody:wheel /usr/sbin/mDNSResponder
    % sudo chmod 4750 /usr/sbin/mDNSResponder
    % sudo launchctl load /System/Library/LaunchDaemons/com.apple.mDNSRespon der.plist

    If someone wants an explanation of what the above commands accomplish, please read further.
    1. launchctl is used to unload and load the mDNSResponder daemon.
    2. We change the owner of the mDNSResponder to nobody and ensure that wheel is the group. The group is used to ensure that members of the wheel group may launch mDNSResponder and not other users of the system (with the exception of root and anything else running as nobody.)
    3. We change the permissions of the mDNSResponder program to be setuid nobody. This means that mDNSResponder will run as nobody and only be able to affect files owned by that account or by files it may happen to have write privileges against.

  • by theolein (316044) on Tuesday July 17, 2007 @09:26PM (#19895807) Journal
    Apart from the claim by infosec sellout sounding less than adult - he says the payload was "weaponised" - and his claim that Apple will somehow not fix the "root cause" of the vulnerability if he gives it to them now - extortion anyone? mDNSResponder is Open Source - I seriously question how some independent reearcher can have, as he claims, a test base of 1500 systems. A big company with $1million to throw around might have that, or a university, but I seriously doubt he has the place or resources to afford a test base of this size unless he is using a local university or school, and judging by his spelling and grammar, he is either not English native or he is a teenager, or both. That says nothing about the veracity (truth) of his claim but it is somewhat juvenile, the whole thing.
  • This guy seems to be spending more time posting on his blog and reacting to the fireworks rather than getting his bug reporting done. Even if this is a proven malware app, the poster acts more like a script-kiddie and less like a researcher.
  • Rape.osx?

    "Hi, I'm an apple..urrgh"
    "unf unf unf"

    Well it would be an interesting ad I guess.
  • If this is the start of a run of viruses attacking macs, it's not funny or good for pc users. It shows an increasing skill in virus writers that indicates that in the future, every machine (even linux boxes) will need security and anti-virus software. And if the virus writers get good enough, that software won't be much of a comfort
  • Dear Apple Inc (Score:3, Interesting)

    by deke_kun (695166) on Tuesday July 17, 2007 @10:04PM (#19896093)
    Seriously, sit down with this guy. Put a suitcase full of large bills on the table, and tell him it's his if he can prove it works. And then, give the guy some incentive to continue to disclose his so-called "root causes". He is CLEARLY a total whore for cash, which means he is easily bought. You have pockets deep enough, you just sold a bojillion iphones, so buy this guy. If he's full of crap, make the fact that you wanted his "root cause" and he couldnt show you it publicly known, then he gets shamed into STFU and stops spreading FUD. If he does show the root cause, then great, put him on retainer and continue to have a fantastic OS. I know jobs likes to do things all secretive and on his own terms, but this is a public perception issue, it needs to be handled in the public eye. Get on the private jet and go see this guy in person, use the RDF to mess with him and get this shit cleared up. Microsoft got into the situation they're in now by ignoring things like this and pulling the secretive garbage, you don't wanna go down that road, otherwise this crap will get out of hand.
  • Wow (Score:4, Funny)

    by Enrique1218 (603187) on Tuesday July 17, 2007 @11:13PM (#19896613) Journal
    3 hypothetical worms in seven years. At this rate, I may have to switch to Linux next century!
  • by chthonicdaemon (670385) on Wednesday July 18, 2007 @01:06AM (#19897305) Homepage Journal
    Researchers say that safes are not completely immune to attack. Some off-the-shelf "safes" can be cracked in less than 5 minutes! They advise that a cardboard box is a more cost-effective way to store valuables, as "people will get in anyway".
  • Covered in shit? (Score:4, Insightful)

    by GrahamCox (741991) on Wednesday July 18, 2007 @03:02AM (#19897893) Homepage
    I frequently hear the old chestnut that the only reason Macs aren't infested with malware is their lack of market share. Whether true or not, it's a funny argument, especially if the person using it is defending their choice of Windows.

    "I'm not going to use Mac because while it may be clean now, I could get covered in shit at any time!"

    "But you're already covered in shit".

    "Errr... yes. But I'm sorta used to it..."
  • 10.4.10 (Score:4, Interesting)

    by djahz (1129611) on Wednesday July 18, 2007 @04:03AM (#19898139) Homepage
    10.4.10 isn`t on the affected systems list.
    • Re:10.4.10 (Score:4, Interesting)

      by fplinn (1129625) on Wednesday July 18, 2007 @04:56AM (#19898327)
      wasn't this patched in may ? http://docs.info.apple.com/article.html?artnum=305 530 [apple.com]

      mDNSResponder
      CVE-ID: CVE-2007-2386
      Available for: Mac OS X v10.4.9, Mac OS X Server v10.4.9
      A remote attacker may be able to cause a denial of service or arbitrary code execution
      Description: A buffer overflow vulnerability exists in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) code used to create Port Mappings on home NAT gateways in the OS X mDNSResponder implementation. By sending a maliciously crafted packet, a remote attacker can trigger the overflow which may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation when processing UPnP protocol packets. This issue does not affect systems prior to Mac OS X v10.4. Credit to Michael Lynn of Juniper Networks for reporting this issue.
  • by FST777 (913657) <frans-jan@ v a n -steenbeek.net> on Wednesday July 18, 2007 @05:26AM (#19898449) Homepage
    If it is, this might be patches relatively soon (allthough it might take a while before Apple approves and deploys the fix). It might also mean that more systems could be affected by this vulnerability. I know FreeBSD uses mDNSResponder (the laptop I'm typing this on is actively using it right now).

    Anyone knows if this might provide a way to write a FreeBSD worm?

Whenever people agree with me, I always think I must be wrong. - Oscar Wilde

Working...