Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Apple hasn't patched admin privilege backdoor in 10.10.3, it's claimed
The Register ^ | 21 Apr 2015 at 21:03 | Shaun Nichols

Posted on 04/22/2015 12:15:54 AM PDT by Swordmaker

OS X Yosemite still open to Rootpipe hijacking, says ex-NSA bod

Apple's attempt to fix a serious security weakness in OS X has fallen short, leaving users still vulnerable to malware seizing their Macs, it is claimed.

Patrick Wardle, director of research at Synack, reckons Cupertino has not been able to fully kill off the so-called "Rootpipe" backdoor that was supposed to be eradicated in last week's OS X Yosemite 10.10.3 update. Apple has refused to address the vulnerability in older versions of OS X, such as version 10.9.x.

The Rootpipe vulnerability, present in OS X since at least 2011, allows software to gain administrator-level privileges without permission. It means innocent-looking applications can log keypresses and cause havoc on the machine, and malware exploiting the hole is apparently in the wild.

Writing on his personal Objective-See blog over the weekend, Wardle says he has written some proof-of-concept code in Python to exploit parts of the Rootpipe bug lingering in OS X 10.10.3, and has published a video of it in action: it appears to show him, as a normal user, adding read access rights to a previously inaccessible root-owned file.

(See video at source)

Wardle, an ex-NSA staffer and former NASA intern, declined to give any further details on the hack pending a fix from Apple; he says he has privately disclosed the bug to the iGiant.

The backdoor was reported in October 2014 by Emil Kvarnhammar. Authentication checks are missing in the part of the operating system that handles configuration settings for the computer, which can be exploited to escalate privileges.

"On my flight back from presenting at Infiltrate – amazing conference, by the way – I found a novel yet trivial way for any local user to re-abuse Rootpipe, even on a fully patched OS X 10.10.3 system," Wardle wrote on his blog.

"In the spirit of responsible disclosure, at this time, I won't be providing the technical details of the attack, besides of course to Apple. However, I felt that in the meantime, OS X users should be aware of the risk."


TOPICS: Computers/Internet
KEYWORDS: apple; osx; rootpipe

1 posted on 04/22/2015 12:15:54 AM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; altair; ...
Although Apple patched the "Rootpipe" vulnerability with the update to OS X10.3, an ex-NSA expert has found another "Rootpipe" vulnerability in OS X.10.3 . . . The Register falsely claims it is the same vulnerability that Apple closed in the update. Meanwhile, this is a local vulnerability, allowing an untrusted user to escalate privileges to Admin. — PING!


Apple Security Ping!

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 04/22/2015 12:26:02 AM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Demanded by nsa, most likely, not to be fixed.


3 posted on 04/22/2015 12:27:07 AM PDT by Secret Agent Man (Gone Galt; Not averse to Going Bronson.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Thanks for the heads up


4 posted on 04/22/2015 12:28:04 AM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 2 | View Replies]

To: basil

Self ping to read later.


5 posted on 04/22/2015 1:45:11 AM PDT by basil (2ASisters.org)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

I downloaded the patch last Friday, and it BORKED my Admin account, and couldn’t reboot. Was perfect before. Had to return it to Buy Best and have the Geek squad restore my computer. I wonder what the hell happened, now I wonder if this was any part of it.

No biggie, just a hundred miles each direction, twice. I’ve got nutting’ but time to waste.


6 posted on 04/22/2015 2:15:04 AM PDT by Big Giant Head
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Wow... This is the really bad part of the article. “Apple has refused to address the vulnerability in older versions of OS X, such as version 10.9.x.”

Come on Apple fix your crap!


7 posted on 04/22/2015 2:28:38 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Rootpipe attack sounds like something the current CEO might actually enjoy!


8 posted on 04/22/2015 3:04:49 AM PDT by Moltke ("The Press, Watson, is a most valuable institution if you only know how to use it.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Moltke

Lmao!!! Maybe that’s why he won’t fix it in previous versions of osx and why it’s not fully fixed in the current version. He just can’t wait that rootpipe.


9 posted on 04/22/2015 5:22:08 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 8 | View Replies]

To: for-q-clinton

Quit not wait (dang autocorrect)


10 posted on 04/22/2015 5:46:00 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 9 | View Replies]

To: for-q-clinton

No surprise here, for-q-clinton (is your name a public announcement of your secret passions?), to again throw the homosexual garbage into a thread with no constructive contribution to the discussion.


11 posted on 04/24/2015 8:58:15 AM PDT by TheBattman (Isn't the lesser evil... still evil?)
[ Post Reply | Private Reply | To 9 | View Replies]

To: TheBattman

Huh? I replied to someone else saying it first. Sorry I found it funny. Your love for Apple has stopped your sense of humor or are you always uptight?


12 posted on 04/24/2015 10:42:17 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 11 | View Replies]

To: for-q-clinton
Lmao!!! Maybe that’s why he won’t fix it in previous versions of osx and why it’s not fully fixed in the current version. He just can’t wait that root pipe.

Odd sense of humor you have there... Has nothing to do with my supposed "love for Apple". It has everything to do with being sick and tired of flames and puke being spewed about Apple and faggots... your participation just further inflamed that frustration. The homo agenda gets enough attention without folks using it to insult the intelligence of the rest of us.

13 posted on 04/24/2015 1:56:53 PM PDT by TheBattman (Isn't the lesser evil... still evil?)
[ Post Reply | Private Reply | To 12 | View Replies]

To: TheBattman

So you like the rootpipe?


14 posted on 04/24/2015 6:44:11 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 13 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson