The Mac Observer

Skip navigational links

Featured Article: Podcast - Mac Geek Gab #158: Bad RAM, iSights, Drive Speeds, and Startup Shortcuts

OS X, Apache Security Hole Discovered

by , 2:00 PM EDT, June 13th, 2001

For years, Mac users were able to more or less ignore many of the virus and security risks that existed in the Windows and Unix worlds. OS X has changed that, and combined with the growing number of "always on" broadband connections, Mac users have to take more security precautions now than ever before.

With that said, a new security hole has been identified with OS X and the built-in Apache Web server. Due to the way that Apache handles commands, and the HFS+ disk structure of most OS X enabled Macs, not all private files on a machine are safe. According to SecurityFocus.com;

A vulnerability exists when Apache webserver is used with Mac OS X Client.

The standard filesystem for Mac OS X is HFS+. HFS+ is case insensitive while Apache's filtering is case sensitive. The result is that Apache will filter all file requests that match filters exactly (including case), but it will not filter requests made with mixed or upper case characters. Since HFS+ is case insensitive, these requests will result in the "filtered" files being disclosed.

The impact is that arbitrary privileged files may be disclosed to unprivileged remote users.

You can find more information by going to the SecurityFocus.com Web site, and then clicking on "Vulnerabilities," and then "Advisories." You will see the "MacOS X Client Apache File Protection Bypass Vulnerability" advisory listed, and you can get more information from there.

Observer Comments

Show: Subjects Only | Full Comments
Comment on this Article

Log in | Register | Having Problems? Reset TMO Cookies & Try Again
Username:   Password:   Log me on automatically each visit   

You are not logged in, and this post will appear as "Guest." Log in with your username and password from the TMO forums. If you do not have a username, you can register here.
Please note that guests are limited to including a maximum of two URLs per post.


Post A Comment
  Subject


  Your Comments



Please enter the word exactly as you see it in the image above. Registered users aren't prompted for this. Having trouble reading the image get a new one.


Recent Headlines - Updated Friday, July 4th, 2008

Fri., 7:30 AM
Happy Fourth of July!
Thu., 4:50 PM
Apple Slashes $400 from SSD Drive in MacBook Air
4:05 PM
It's Official - Firefox Sets Guinness Record for Downloads
3:30 PM
Apple Files Patent for a Multi-touch Gesture Language
2:20 PM
Editorial - Mac's Market Share and the Cascade Failure of Windows
1:35 PM
iPodObserver - Apple Slurps Up Samsung's NAND Flash for iPhone 3G
1:05 PM
WSJ: Tips for Switching from Windows to Mac
12:05 PM
iPodObserver - Google Intros Google Talk for iPhone
11:35 AM
iPO Just a Thought - iPod nano Versus iPhone: Decisons, Decisions...
10:55 AM
YouTube Ordered to Turn Over All User Records to Viacom
10:10 AM
Hot Forum Topic - Apple vs. Cell Carriers: Who's Winning the Game
9:25 AM
iPodObserver - Rumor: Best Buy, Radio Shack to Sell iPhone 3G
8:45 AM
.Mac Bookmark Sync Deadline Extended to July 6
8:10 AM
Adobe Reader 9 Hits the Streets
 

The Mac Observer Reader Specials

  • Special Report: WWDC 2008
  • Special Report: iPhone
  • __________
  • Help TMO Grow
  • Podcast: Mac Geek Gab
  • Podcast: Apple Weekly Report
  • TMO on Twitter!
  • New Media Expo 2008

Apple Stock Quote

  • AAPL: $170.12. Change Today: +1.94.
  • (Prices delayed up to 20 minutes.)
  • Discuss in our Apple Finance Board

Hot Topics

Top Deals From DealsOnTheWeb