Mac OS X Security Issue – Screensaver Security Issue/Hack

Mac OS X Security Issue – Screensaver Security Issue/Hack

Security Issue: Mac OS X Screensaver Password Protection Bug Systems Vulnerable: Mac OS X 10.2.6 and prior Date Fixed: TBA Apple’s Mac OS X screensaver apparently contains a buffer overflow vulnerability that causes the screensaver to dump not requiring the user to enter a legitimate…

July 7, 2003 • 1 min read
SoftwareUpdate DNS Spoof, Poisoning Exploit

SoftwareUpdate DNS Spoof, Poisoning Exploit

Resolution The issue described below was addressed and take resolved by Apple July 12th 2002 by adding checksums to downloads. Update to current version of Mac OS X via the software updates or visit AppleCare Document 75304 Information Anonymous writes “I have recently been forwarded…

July 6, 2002 • 2 min read
Cisco VPN UNIX Mac OS X Client Security Issue

Cisco VPN UNIX Mac OS X Client Security Issue

About Cisco VPN Client The Cisco VPN (Virtual Private Network) Client establishes an encrypted tunnel between a local system and a Cisco VPN Concentrator. The tunnel provides confidentiality and integrity for the data in transit, allowing a user on the local system to securely connect…

June 4, 2002 • 4 min read
Mac OS X root sliplogin permission error leads to root

Mac OS X root sliplogin permission error leads to root

Published: 5.07.2002 Fixed: Mac OS X 10.1.4 Effected OS: Mac OS X 10.1.3 and prior) Information The problems lies within the file /usr/sbin/sliplogin (sliplogin) bundled with versions of Mac OS X prior to 10.1.4 due to the permissions defined and a buffer overflow. The system…

May 7, 2002 • 2 min read
Mac OS X AppleShare Administrative access hack

Mac OS X AppleShare Administrative access hack

Today it was discovered in Mac OS X 10.1.4 (Not tested with prior versions yet) with multiple users I have stumbled across a rather large security hole when AppleSharing between a Mac OS 9.2.2 box and a Mac OS X box running v.10.1.4. If a…

May 4, 2002 • 2 min read
Mac OS X Server/ Client Sudo Local Root

Mac OS X Server/ Client Sudo Local Root

The folks at BSD-H have found a flaw that offers anyone in the admin group the ability to achieve root access via sudo. For those of you new to Mac OS X and the whole Unix environment do not get frustrated, this article will enlighten…

February 7, 2002 • 4 min read
Mac OS X nidump Security Issues (macosx)

Mac OS X nidump Security Issues (macosx)

  What is nidump? nidump reads the specified NetInfo domain and dumps a por- tion of its contents to standard output. When a flat-file administration file format is specified, nidump provides output using the syntax of the corresponding flat file. The allowed values for format…

July 5, 2001 • 2 min read
StaticUsers.net – AppleShare + NT Security Issues

StaticUsers.net – AppleShare + NT Security Issues

Information: This concerns Macs connected to NT servers using Service Pack 4. If a Mac changes its password when connected to NT SP4, from that point on, PCs can log into that user account with NO password (a null password.) – contributed by John Wolf…

June 2, 2001 • 3 min read
OSX -CGI Flaw

OSX -CGI Flaw

A fatal bug in MacOS X Server renders Apple’s new operating system practically useless as a web server. The problem is particularly critical since it affects MacOS Server X release 1.0 in one of its key features. During a server load test at c’t Labs,…

June 2, 2001 • 2 min read