electro-music.com   Dedicated to experimental electro-acoustic
and electronic music
 
    Front Page  |  Radio
 |  Media  |  Forum  |  Wiki  |  Links
Forum with support of Syndicator RSS
 FAQFAQ   CalendarCalendar   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   LinksLinks
 RegisterRegister   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in  Chat RoomChat Room 
go to the radio page Live at electro-music.com radio 1 Please visit the chat
poster
 Forum index » News... » Apple Computers
Mac OS X Command Execution Vulnerability Test
Post new topic   Reply to topic
Page 1 of 1 [12 Posts]
View unread posts
View new posts in the last week
Mark the topic unread :: View previous topic :: View next topic
Author Message
elektro80
Site Admin


Joined: Mar 25, 2003
Posts: 21959
Location: Norway
Audio files: 14

PostPosted: Wed Mar 08, 2006 4:35 am    Post subject: Mac OS X Command Execution Vulnerability Test
Subject description: test your mac
Reply with quote  Mark this post and the followings unread

http://secunia.com/mac_os_x_command_execution_vulnerability_test/

If you have run all the security updates, Safari will tell you that the file secunia.mov.zip is a program.

If you are like any other computer user out there, this message will make a lot of sense and sure.. "a movie file that is a program.. YES.. I really need to run that program RIGHT NOW!!!"

Laughing

I reckon there is only a handful of seasoned computer users ( read: old farts ) who thinks like:

a movie file= an executible = a really bad idea= ma, we have a trojan!

_________________
A Charity Pantomime in aid of Paranoid Schizophrenics descended into chaos yesterday when someone shouted, "He's behind you!"

MySpace
SoundCloud
Flickr
Back to top
View user's profile Send private message Visit poster's website
brinxmat



Joined: Oct 24, 2005
Posts: 262
Location: Norway

PostPosted: Wed Mar 08, 2006 4:59 am    Post subject: Reply with quote  Mark this post and the followings unread

I post this one because I am nice. Please user-test this one thoroughly. It's a PDF, honest guv.


ProofOfConcept.tar.gz
 Description:
This is a PDF, not a program, honest.

Download (listen)
 Filename:  ProofOfConcept.tar.gz
 Filesize:  20.11 KB
 Downloaded:  557 Time(s)


_________________
-- Say "&Eth;onne hit wæs hrenig weðer"
Back to top
View user's profile Send private message
elektro80
Site Admin


Joined: Mar 25, 2003
Posts: 21959
Location: Norway
Audio files: 14

PostPosted: Wed Mar 08, 2006 5:09 am    Post subject: Reply with quote  Mark this post and the followings unread

yeah yeah.. PDF.. sure.. nice app though
_________________
A Charity Pantomime in aid of Paranoid Schizophrenics descended into chaos yesterday when someone shouted, "He's behind you!"

MySpace
SoundCloud
Flickr
Back to top
View user's profile Send private message Visit poster's website
brinxmat



Joined: Oct 24, 2005
Posts: 262
Location: Norway

PostPosted: Wed Mar 08, 2006 5:31 am    Post subject: Reply with quote  Mark this post and the followings unread

It worked? *shock*
_________________
-- Say "&Eth;onne hit wæs hrenig weðer"
Back to top
View user's profile Send private message
elektro80
Site Admin


Joined: Mar 25, 2003
Posts: 21959
Location: Norway
Audio files: 14

PostPosted: Wed Mar 08, 2006 5:45 am    Post subject: Reply with quote  Mark this post and the followings unread

Well, not quite. But you aren´t running Tiger now are you? Another matter is that I have various stuff hammering away on all downloads so this one made my mac jump with alerts. I did however run your PDF app on my honeypot box. Nice message!
_________________
A Charity Pantomime in aid of Paranoid Schizophrenics descended into chaos yesterday when someone shouted, "He's behind you!"

MySpace
SoundCloud
Flickr
Back to top
View user's profile Send private message Visit poster's website
mosc
Site Admin


Joined: Jan 31, 2003
Posts: 18263
Location: Durham, NC
Audio files: 229
G2 patch files: 60

PostPosted: Wed Mar 08, 2006 12:06 pm    Post subject: Re: Mac OS X Command Execution Vulnerability Test
Subject description: test your mac
Reply with quote  Mark this post and the followings unread

elektro80 wrote:
http://secunia.com/mac_os_x_command_execution_vulnerability_test/

If you have run all the security updates, Safari will tell you that the file secunia.mov.zip is a program.


Does Firefox also do this?

_________________
--Howard
my music and other stuff
Back to top
View user's profile Send private message Visit poster's website AIM Address
elektro80
Site Admin


Joined: Mar 25, 2003
Posts: 21959
Location: Norway
Audio files: 14

PostPosted: Wed Mar 08, 2006 2:02 pm    Post subject: Reply with quote  Mark this post and the followings unread

I am using various versions of Firefox. Right now I have 1.0.6 active. Default behaviour for this version is returning proofofconcepttar_133.gz

as text.

_________________
A Charity Pantomime in aid of Paranoid Schizophrenics descended into chaos yesterday when someone shouted, "He's behind you!"

MySpace
SoundCloud
Flickr
Back to top
View user's profile Send private message Visit poster's website
brinxmat



Joined: Oct 24, 2005
Posts: 262
Location: Norway

PostPosted: Wed Mar 08, 2006 2:21 pm    Post subject: Reply with quote  Mark this post and the followings unread

Woo! hot download! I reckon you should try bzipping it too, because a stacked bzip-gzip-tar might obliviate the contents. I am sure someone will find a way of fooling this enitrely 'doze way of building city walls. Apple need slapping and telling to sort themselves out. I mean, honestly!
_________________
-- Say "&Eth;onne hit wæs hrenig weðer"
Back to top
View user's profile Send private message
elektro80
Site Admin


Joined: Mar 25, 2003
Posts: 21959
Location: Norway
Audio files: 14

PostPosted: Wed Mar 08, 2006 2:39 pm    Post subject: Reply with quote  Mark this post and the followings unread

What we are talking about here is like dad leaving the gun cabinet unlocked and all the famly has free access to his excellent collection of 50 caliber rifles. And dad has all his candy coloured M-67 hand grenades in there too.

What Apple did was simply adopting the old nice smooth Microsoft way of accessing resources on the internet. This has been corrected some, but the way I see this there is still things to be improved. Seasoned computer users won´t have much of a problem with the current model, but personally I think the whole model for how to handle "foreign" files should be changed a bit. Basically we are really lacking a sensible security model for any platform out there for handling this issue.

_________________
A Charity Pantomime in aid of Paranoid Schizophrenics descended into chaos yesterday when someone shouted, "He's behind you!"

MySpace
SoundCloud
Flickr
Back to top
View user's profile Send private message Visit poster's website
mosc
Site Admin


Joined: Jan 31, 2003
Posts: 18263
Location: Durham, NC
Audio files: 229
G2 patch files: 60

PostPosted: Wed Mar 08, 2006 8:15 pm    Post subject: Reply with quote  Mark this post and the followings unread

I agree with that. The reason I asked about Firefox is that the security should be application independent. In fact, the entire OS should be application indepent to whatever degree that is possible.

I would guess Microsoft would build in a virus/security checker into windows these days but since there are companies selling these tools they might get sued. Maybe Apple isn't in that situation, but there are commercial anti-virus tools for OSX, so maybe they are. Juli's school district which gives Macs to every teacher has a lisence for Symantic for OSX.

I don't like allowing gz, rar, or zip files as attachments on this site because of possible secruity problems, but banning these files would be more trouble than the security problems that might be there.

Still, a lot of kids get killed every year from guns in Daddy's closet. Mad

_________________
--Howard
my music and other stuff
Back to top
View user's profile Send private message Visit poster's website AIM Address
Kassen
Janitor
Janitor


Joined: Jul 06, 2004
Posts: 7678
Location: The Hague, NL
G2 patch files: 3

PostPosted: Wed Mar 08, 2006 9:16 pm    Post subject: Reply with quote  Mark this post and the followings unread

mosc wrote:

I don't like allowing gz, rar, or zip files as attachments on this site because of possible secruity problems, but banning these files would be more trouble than the security problems that might be there.


That would be silly. Those aren't executables, if people set up their computer to try and execute any file without credentials then they get what they deserve; it's their computer they can format the HD or they can execte arbitrary files if they want to.

Quote:

Still, a lot of kids get killed every year from guns in Daddy's closet. Mad


True. Still; more kids get born every year because people don't take proper precautions. The irony....

_________________
Kassen
Back to top
View user's profile Send private message Send e-mail Visit poster's website
elektro80
Site Admin


Joined: Mar 25, 2003
Posts: 21959
Location: Norway
Audio files: 14

PostPosted: Thu Mar 09, 2006 5:20 am    Post subject: Reply with quote  Mark this post and the followings unread

Kassen wrote:

That would be silly. Those aren't executables, if people set up their computer to try and execute any file without credentials then they get what they deserve; it's their computer they can format the HD or they can execte arbitrary files if they want to.


At first launch ( or at first launch after a system update) OS X does in fact ASK the user if he/she really wants to run the application. It can be argued that a simple prompt on the screen is useless. Perhaps molten lead poured on top of the place you keep the family jewels or a slap in the face with a dead penguin would be more like it though.

_________________
A Charity Pantomime in aid of Paranoid Schizophrenics descended into chaos yesterday when someone shouted, "He's behind you!"

MySpace
SoundCloud
Flickr
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic
Page 1 of 1 [12 Posts]
View unread posts
View new posts in the last week
Mark the topic unread :: View previous topic :: View next topic
 Forum index » News... » Apple Computers
Jump to:  

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Forum with support of Syndicator RSS
Powered by phpBB © 2001, 2005 phpBB Group
Copyright © 2003 through 2009 by electro-music.com - Conditions Of Use