|
|||||||
| Register | Members List | New Posts | Mark Forums Read |
![]() |
|
|
Thread Tools | Display Modes |
|
|
#1 |
|
Kasper's Automated Slave
Join Date: Nov 1997
Posts: 6,165
|
New Mac OS X Security Update patches dangerous DNS hole
Apple late on Thursday offered up its fifth security update of 2008 to cover an industry-wide and potentially dangerous exploit of Domain Name System server access for spoofing attacks.
Security Update 2008-005 is available for client versions of Mac OS X Leopard (65MB) and Tiger (Intel, PowerPC) as well as Tiger Server (Intel, PowerPC). Among the multiple fixes, the most essential is one for the Berkeley Internet Name Domain server feature in the operating system, or BIND. While not enabled by default, the service when switched on is potentially vulnerable to exploits of a fundamental flaw in the DNS system that helps govern the Internet protocol and translates website names (such as appleinsider.com) to IP addresses. Any computer left exposed and unpatched against the attack, regardless of operating system, can have its DNS cache "poisoned," tricking the computer into visiting a malicious website even when the user chooses to visit what would normally be a legitimate address. The Apple fix randomizes the source port for DNS information and so prevents an easy attack when BIND is active. Other security updates are also rolled into the update and include guards against arbitrary code execution in CarbonCore, CoreGraphics, Data Detectors, Disk Utility, OpenLDAP, Open Scripting Architecture, OpenSSL, PHP, and rsync. Mac OS X Leopard users are specifically affected by a potential exploit in the software's QuickLook feature and its handling of Microsoft Office files that could allow malicious code. |
|
|
|
|
|
#2 |
|
Registered User
Join Date: Nov 2001
Location: Southern CA
Posts: 1,265
|
Just installed it a few minutes ago.
|
|
|
|
|
|
#3 |
|
Registered User
Join Date: Feb 2007
Posts: 22
|
|
|
|
|
|
|
#4 |
|
Registered User
Join Date: Jun 2008
Posts: 11
|
Banned
|
|
|
|
|
|
#5 |
|
Privileges Revoked
Join Date: Jan 2008
Location: Currently where I am located.
Posts: 1,067
|
Let the banning begin.....
|
|
|
|
|
|
#6 |
|
Registered User
Join Date: Jan 2008
Posts: 77
|
If you want to be immature, I suggest going to the dell forums.
iMac 24" 2.4ghz, 1GB Ram, 250GB, OSX 10.5
Last edited by IAmMacUser; 08-01-2008 at 03:52 AM.. |
|
|
|
|
|
#7 |
|
Registered User
Join Date: May 2007
Location: Inside Out
Posts: 145
|
Does this flaw apply to Panther? Or has Apple officially abandoned us 10.3.9 ers?
Believe nothing, no matter where you heard it, not even if I have said it, if it does not agree with your own reason and your own common sense.
Buddha |
|
|
|
|
|
#8 |
|
Registered User
Join Date: Aug 2006
Posts: 2,077
|
|
|
|
|
|
|
#9 |
|
Registered User
Join Date: Nov 2001
Location: France/Germany
Posts: 117
|
|
|
|
|
|
|
#10 |
|
Registered User
Join Date: Nov 2007
Posts: 75
|
10.3.9
Vista SP1 wasn't on the notice either.
|
|
|
|
|
|
#11 |
|
Registered User
Join Date: May 2007
Location: Inside Out
Posts: 145
|
What? A couple of months ago there was a QuickTime update for us - but that was to make us ITS compatible. So Apple are happy to update us to try and make a bit more profit from their 10.3 customer base, but they are not prepared to secure that same system? Not good. I accept that this is a 5 year old system, but surely they have a moral (even legal?) responsibility to maintain the very minimal level of support required to keep their customers safe? A few pennies from their $1bn+ quarterly profits? I'm sure we would all enjoy being snotty if MS did the same thing, this is a very cynical stance from Apple.
Believe nothing, no matter where you heard it, not even if I have said it, if it does not agree with your own reason and your own common sense.
Buddha |
|
|
|
|
|
#12 | |
|
Rev B, Bug Free
Join Date: Dec 2003
Posts: 4,166
|
Quote:
Yea, Dell isn't really immature, in fact, I am going to go out on a limb here and say that their OS choices for Servers are better than Apples for security sake. after this, and even before, you would be nuts to use apple servers running OSX Server for mission critical apps outside of FinalCut server and the 2 or 3 other mac only server apps.
You can't quantify how much I don't care -- Bob Kevoian of the Bob and Tom Show.
|
|
|
|
|
|
|
#13 | |
|
Registered User
Join Date: Jun 2007
Location: Tiraspol, Pridnestrovie
Posts: 491
|
Quote:
Mac user since August 1983.
|
|
|
|
|
|
|
#14 |
|
Registered User
Join Date: May 2007
Location: Inside Out
Posts: 145
|
No. From the article: "Any computer left exposed and unpatched against the attack, regardless of operating system, can have its DNS cache "poisoned," tricking the computer into visiting a malicious website even when the user chooses to visit what would normally be a legitimate address."
Are you saying that this flaw cannot affect my normal web-surfing? Edit: I just read elsewhere that this flaw is only exploitable on servers - the AI article did not make this clear. In light of this I withdraw my gripe above!
Believe nothing, no matter where you heard it, not even if I have said it, if it does not agree with your own reason and your own common sense.
Buddha |
|
|
|
|
|
#15 | |
|
Registered User
Join Date: Jul 2008
Posts: 135
|
Quote:
iMac 1.83 GHz C2D (Mac OS X Snow Leopard 10.6.2) • G-Drive External HDD (500 GB) • Time Capsule (1 TB)
iPhone 3G (iPhone OS X 3.1.2) • iPod shuffle (1 GB, 1st gen) |
|
|
|
|
|
|
#16 |
|
Registered User
Join Date: May 2007
Location: Inside Out
Posts: 145
|
Rather dull explanation I'm afraid. My iMac G4800 came with 10.2, I happily bought 10.3 when it came out, but 10.4 didn't seem such a big thing. Plus, I have been teetering on the brink of buying a new machine for ages, but this one keeps ploughing away so I have got into that 'wait for the next update' rut!
I was thinking about getting 10.5, my machine was originally within the spec, but when it was released the spec had changed and I was out in the cold. Still, 10.3.9 is super stable, the only feature I would really like to add would be Spotlight. One added bonus is that when I do finally take the plunge with a Nehalem, 10.6, 24 (or even 30) inch iMac deluxe think how that will smoke... ![]()
Believe nothing, no matter where you heard it, not even if I have said it, if it does not agree with your own reason and your own common sense.
Buddha |
|
|
|
|
|
#17 | |
|
Registered User
Join Date: Jul 2008
Posts: 135
|
Quote:
) in anticipation of Apple's offerings next year. If your machine meets 10.4.x spec, you'd certainly do well to upgrade to Tiger. Tiger for me, and many, was (and for some still is) rock solid! You shouldn't lose any of the stability you've come to rely on, and you'd have the added benefit of Spotlight and Smart Folders (I can't remember if 10.3.9 had those). But if you don't NEED Spotlight right now, there's no harm in leaving well enough alone... at least for the next year or so. ![]()
iMac 1.83 GHz C2D (Mac OS X Snow Leopard 10.6.2) • G-Drive External HDD (500 GB) • Time Capsule (1 TB)
iPhone 3G (iPhone OS X 3.1.2) • iPod shuffle (1 GB, 1st gen) |
|
|
|
|
|
|
#18 | |
|
Registered User
Join Date: May 2007
Location: Inside Out
Posts: 145
|
Quote:
Believe nothing, no matter where you heard it, not even if I have said it, if it does not agree with your own reason and your own common sense.
Buddha |
|
|
|
|
|
|
#19 | |
|
Registered User
Join Date: Dec 2004
Location: South East, UK
Posts: 126
|
Quote:
So this is great for those people running OSX or OSX Server as DNS servers, the rest of us need to check/hope that our ISP's done their patching. or use opendns.org, which has... Cheers, Martin.
15" PB, 15" MBP, MB, MBA, G5 iMac, C2D iMac, Mac Mini, UK iPhone 3G, SGI RealityEngine2, SGI/Division Virtual Reality Rig, NetApp F760C
|
|
|
|
|
|
|
#20 |
|
Registered User
Join Date: Aug 2008
Posts: 1
|
Same issue ...resolved!
I run into the same issue, using automatic updates. To solve it I manually grabbed the update file from Apple's download page and the installation finished without hiccups.
|
|
|
|
|
|
#21 | |
|
Registered User
Join Date: Jul 2008
Posts: 135
|
Quote:
iMac 1.83 GHz C2D (Mac OS X Snow Leopard 10.6.2) • G-Drive External HDD (500 GB) • Time Capsule (1 TB)
iPhone 3G (iPhone OS X 3.1.2) • iPod shuffle (1 GB, 1st gen) |
|
|
|
|
|
|
#22 |
|
Registered User
Join Date: Feb 2006
Posts: 657
|
My 75 year old mother is staying at 10.3.9. Why, her eyesight is failing and she finds learning new things to very difficult. As long as things don't break we don't change.
What goes online stays online. What is online will become public.
|
|
|
|
|
|
#23 |
|
Registered User
Join Date: Aug 2008
Posts: 2
|
|
|
|
|
|
|
#24 |
|
Registered User
Join Date: Feb 2007
Posts: 22
|
Resolved, too
I did the same thing by the end of the day and it worked too. The weird thing is that software update patch had to be run after shutdown, but the downloaded bundle ran straight while I am still using the computer.
|
|
|
|
|
|
#25 |
|
Global Moderator
Join Date: Jul 2002
Location: UK
Posts: 3,820
|
Apostrophes are simple - they are used to indicate either missing letters or possession. Missing letters take precedence. So:
|
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|