Researcher Finds New Mac OS X Vulnerability
by , 1:30 PM EDT, July 19th, 2007
An anonymous researcher has found a serious vulnerability in Mac OS X, related to mDNS, written a worm to exploit it, and has claimed that Mac OS X "has a long way to go" on security. Apple has officially replied, according to ComputerWorld.
The researcher said that he (or she) will report the vulnerability to Apple at some point.
Apparently, there is a "still-unpatched bug in mDNSResponder, a component of Apple's Bonjour automatic network configuring service, [that] could be exploited by a worm," Gregg Keizer reported. Apple's security update 2007-005 included a fix, but the researcher claims that Apple did not attend to the complete code base and that bugs in the [open source] code remain.
Dave Aitel, the CTO at Immunity, Inc. in Miami questioned whether the researcher was able to write the worm only on a few hours, as claimed in the researcher's blog, but admitted that such exploits are still possible in the mDNS code.
The researcher had some harsh words for Apple and said, "I do believe in being responsible and working with vendors, but I also feel that some vendors need to be treated like children and learn lessons the hard way. Apple has a very long way to go when dealing with security issues in their products."
Apple's Anuj Nayer responded in an e-mail. "Apple takes security very seriously and has a great track record of addressing potential vulnerabilities before they can affect users," he said.
There are several factors at play here. Any modern OS will still have deep exploits. Smart and educated researchers, both bad guys and good guys, can still find them in open source code. The real question is not whether Mac OS X is perfectly secure. The question is, can Apple and the community of seasoned and humble technical professionals work together to find and patch the bugs faster than weaponized exploits can do any serious damage. So far, Apple has been successful in achieving that goal.
Observer Comments
Thu Jul 19, 2007 1:52 pm Subject: "Official Response"
Thu Jul 19, 2007 2:10 pm Subject: A long way to go?
Compared to what? Compared to other OS vendors, such as, maybe, you know, Microsoft? No IT professional in his right mind would connect any PC running Windows to the Internet without multiple layers of anti-virus, anti-spam, anti-spyware defenses.
I have four Macs at home, two of which have publicly-addressable static IP addresses. They are protected by nothing other than ipfw. In twelve years of owning Macs, I have never suffered a single virus infection, spyware installation, web page hijacking, etc.
No one with a clue thinks Macs are invulnerable. On the other hand, the number of serious, high-profile attacks on Macintoshes (anyone remember Melissa?) speaks for itself.
If Apple has "a very long way to go" in computer security, what does that say about the rest of the industry?
Ahh this is fun. This is like the Global Warming Theory business. You shoot some shots first, up in the air, like fireworks. No names, no proofs, no nothing. You get the media to eat it, and then harvest the the attention. You'll be famous and the money will follow, soon.
The CLAIM will be on all world-wide-medias front pages, and with some luck this becomes The Fact. It becomes the The Final Truth: Mac's are just as insecure as [ insert your favorite here ]. It's on the media. It must be true.
But who did it ?
TMO is a little late reporting this, and it surprises me a little that they would walk right into this one without mentioning all the doubt that has built up in the time since this was first reported. If it were me, I'd be afraid of reporting this without including a truckload of salt in my headline. From all the nebulous claims and weird happenings to this story, I'm laying my money on a hoax.
Thu Jul 19, 2007 4:03 pm Subject: It sounds like a hoax. . .
Apparently the guy in question has. . .
Disappeared!
Like Kaiser Soze! hmmmm
http://www.tuaw.com/2007/07/19/alleged-os-x-worm-creator-disappears/
If Apple has a long way to go then Microsoft better close shop on Windows. I don't consider it a long way to go when he can only find one exploit compared to the hundred's of thousands that have been found on Windows. So who does he think he's kidding here anyways. Also his is only a theory versus the hundreds of thousands that were reality with Microsoft's Windows. Millions of dollars lost in information and businesses because of Microsoft's LACK OF SECURITY. I think Apple has about an inch compared to Microsoft's 100,000 Light years.
To date, no spyware on OSX, no malware on OSX, and no viruses on OSX.
Windows has it all with more and more coming out everyday. Windows users have to spend there money and time on antivirus software, and anti-spyware software while OSX users just use there Macs for what they want to use them for.
So what were you saying Mr. anonymous?
Sun Jul 22, 2007 12:59 pm Subject: More on the issue
See the ArsTechnica article.
I have owned a mac since 1990. Only once did I have a problem with my computer propagating a virus, because at the time I had no virus protection. Since I started using Norton Antivirus I have had no problems. I will trust a Mac before any other machine on the planet, especially a Windows machine. They are the ones that seem to continually get cracked.
Recent Headlines - Updated January 8th
- Wed, 6:20 PM
- Macworld Expo 2009 - Ecamm Introduces World’s First Bluetooth Webcam
- 6:16 PM
- News - Verbatim Announces Speaker Keyboard, Store ‘n’ Go Micro USB Drive
- 6:09 PM
- Photo Gallery - Photo Gallery: Macworld 2009 Day 2
- 3:24 PM
- Just a Thought - First Time Macworld Impression
- 12:16 PM
- News - EMC Issues Beta of Retrospect 8.0 Backup Software
- 12:04 PM
- News - REAL Server 2009 to Ship Next Month
- 11:40 AM
- News - Livescribe to Bring Pulse Smartpen Software to Mac
- 10:58 AM
- Hot Forum Topic - Reader Reactions: Apple’s Macworld Expo Keynote
- 10:39 AM
- News - Verbatim, Lexar Introduce New Flash Storage Options
- 10:20 AM
- Editorial - Don’t shoot the messenger: Content, Not Delivery Marred Apple’s Last Keynote
- 9:51 AM
- News - LaCie Releases 2big Quadra External Hard Drive Line
- 9:29 AM
- News - Microsoft’s Mac Business Unit Reveals Upcoming Office Improvements
The Mac Observer Reader Specials
- Download Typestyler, still the Ultimate Styling Tool for Internet, Print and Video Graphics. Works great in Classic with a Native OS X Version on the way. Free Tryout: www.typestyler.com
MacPro Memory 667Mhz With Apple Spec Heat Sink - 2GB $62 / 4GB $80 / 8GB $158. Click to Maximize your Macs...
Mac observers can now play Party Poker for Mac as well as Mac casino games by going to MacPokerOnline.com.
RamJet Memory: Upgrade a MacBook to 4GB RAM for $99! Add a 320G MacBook Hard Drive for $73! MacBook Pro 17" 8GB Kits Available Now! Click hereFor the latest Apple products use Ciao a comparison website to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate cell phones.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.

