SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Apple's Leopard has security holes, experts say

Apple's Leopard has security holes, experts say

By:  Robert McMillan  On: 30 Oct 2007 For: IDG News Service Creator

The company's latest operating system upgrade is expected to be a sales success, but some features designed to protect user data may not be implemented completely. What to watch out for

The security features introduced in Apple's Leopard operating system need work.

That's according to security experts who have been putting the new version of Mac OS X through its paces, since the upgrade was introduced last Friday.

Leopard introduces a number of important security features to the Mac, but they are often implemented incompletely, leaving users vulnerable to attack, said Thomas Ptacek, a researcher at Matasano Security, who Monday wrote a detailed assessment of Leopard's security.

"They've done a really good job of robbing Microsoft advocates of their talking points," he said. But, "I don't see anything that they've done out of the box, where it's really any more resistant to attack than Tiger was," he added, referring to the previous update to Apple's operating system. According to Ptacek, two of Apple's key security enhancements -- Sandboxing and Library Randomization -- are great ideas that are imperfectly applied within Leopard.

Take Library Randomization. It's a new feature that's supposed to make it hard for some of the most commonly used computer attacks like buffer overflows, where the attacker takes advantage of a software bug to place code somewhere in the computer's memory where he knows it will be run. Microsoft developed a similar technology for Vista, called Address Space Load Randomization. Library Randomization makes it much harder, if not impossible, for the attacker to know where to place this code, reducing the risk of attack.

The problem is that Apple did not randomize all of the parts of the operating system that it should have, according to Ptacek. In particular, Apple's Dynamic Link Library has not been randomized.

Security researcher Dino Dai Zovi said he's used this library in several of the Mac exploits he's written over the past few years. He has taken advantage of the fact that this library is not randomized, he agreed with Ptacek's assessment that this feature, as it's implemented in Leopard, would simply make things a little more difficult for attackers.

Sandboxing is another feature that could ultimately make Mac OS X more secure. Sandboxing restricts software running on Mac OS so that even if it's hacked, it can't do things that it shouldn't, such as add new software to the computer. The problem is that Apple hasn't sandboxed many of the most commonly attacked applications such as the browser, mail client, or instant messaging software, Ptacek said.

And the programs that have been sandboxed have not been walled off as thoroughly as they should be, he added.

For example, the Quick Look file viewer has been sandboxed, but only to restrict network access. The software can still be misused to write malicious files where they will be automatically launched, Dai Zovi said. "Most of the things that were sandboxed were network services," he said. "Increasingly these days IM, e-mail and Web surfing are where most of the attacks are coming from, not directly on your network."


Sign up for our Newsletters












Print |  Views: 863   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Robert McMillan Robert McMillan is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Microsoft, RIM, Oracle release critical patches
Microsoft, RIM, Oracle release critical patchesPatch Tuesday becomes extra busy as Oracle and RIM joins Microsoft in releasing a bevy security updates
Stop using Safari for now: Microsoft
Stop using Safari for now: MicrosoftMicrosoft Corp. has advised Windows users not to use Safari for Web browsing until either Apple or Microsoft releases a security patch. Apple has nothing to say for now.
Microsoft faces its next antitrust front
Microsoft faces its next antitrust frontIndustry observers say Microsoft’s foray into the security software market, coupled with certain protection features it has embedded on the recently launched Windows Vista operating system (OS), give third-party security vendors “legitimate” cause for concern.
Fortinet lists August’s most dangerous online threats
two viruses disguised as security software antivirus xp 2008 and xp security center have topped fortinet’s top 10 list of august’s most reported online threats. the sunnyvale, cali

Comments (4)

Marketing Manager
by Larry 11/1/2007 12:00:00 AM'I like the direction they're headed. I'm just saying that they've got a long way to go to catch up with Microsoft.' That's funny! Does he mean catch up with the volume of Windows security breaches and attacks?
RE: Marketing Manager
by Leo 11/5/2007 12:00:00 AMThat is not funny, it's bsht! Funny is to drink vodka without beer. What else you expect to comment from MS followers?
out of the box...
by brandon 11/1/2007 12:00:00 AM Apple is completely out of the box.
out of the box...
by brandon 11/1/2007 12:00:00 AM Apple is completely out of the box but its hard to tell if you are in one yourself.
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.