Page 1
Page 1
Started By
Message

Failed Apple Rootpipe Fix Leaves Backdoor On All Macs, Researchers Claim

Posted on 4/21/15 at 9:15 am
Posted by colorchangintiger
Dan Carlin
Member since Nov 2005
30979 posts
Posted on 4/21/15 at 9:15 am
LINK

quote:

Patrick Wardle, a former NSA staffer who now heads up research at security firm Synack, said he was on a flight when he discovered he was still able to exploit the Rootpipe vulnerability, which essentially opened up a path to the highest privilege level, known as root access.

Apple put additional access controls to stop attacks, but Wardle’s code was still able to connect to the vulnerable service and start overwriting files on his Mac. “I was tempted to walk into the Apple store this [afternoon] and try it on the display models – but I stuck to testing it on my personal laptop (fully updated/patched) as well as my OS X 10.10.3 [virtual machine]. Both worked like a charm,” Wardle told FORBES over email. In a blog post, he’d said his exploit was “a novel, yet trivial way for any local user to re-abuse Rootpipe”.


nb4 Gamechanger, It just works, and Macs can't get viruses
Posted by CAD703X
Liberty Island
Member since Jul 2008
77927 posts
Posted on 4/21/15 at 9:28 am to
torrent sites will always circumvent efforts of LEO and hackers will always find ways to break into computers.

wasnt there an article recently that the NSA can use radio waves to 'hack' into your PC even if it physically lacks any type of networking card?

and LED lights pulse hundreds of times a second and those pulses can effectively be turned into a microphone so someone nearby can listen to what you're saying?
Posted by colorchangintiger
Dan Carlin
Member since Nov 2005
30979 posts
Posted on 4/21/15 at 9:36 am to
quote:

wasnt there an article recently that the NSA can use radio waves to 'hack' into your PC even if it physically lacks any type of networking card?


I think you're talking about Van Eck Phreaking and that's been around for 30 years now. Just have to be super close. LINK
Posted by CAD703X
Liberty Island
Member since Jul 2008
77927 posts
Posted on 4/21/15 at 9:53 am to
quote:

Security researchers at Ben Gurion University in Israel have found a way to retrieve data from an air-gapped computer using only heat emissions and a computer’s built-in thermal sensors. The method would allow attackers to surreptitiously siphon passwords or security keys from a protected system and transmit the data to an internet-connected system that’s in close proximity and that the attackers control. They could also use the internet-connected system to send malicious commands to the air-gapped system using the same heat and sensor technique.

In a video demonstration produced by the researchers, they show how they were able to send a command from one computer to an adjacent air-gapped machine to re-position a missile-launch toy the air-gapped system controlled.


WIRED
Posted by lsu480
Downtown Scottsdale
Member since Oct 2007
92876 posts
Posted on 4/21/15 at 4:32 pm to
Macs CAN get viruses but they don't get them
Posted by SG_Geaux
1 Post
Member since Aug 2004
77924 posts
Posted on 4/21/15 at 4:43 pm to
This is impossible. Apple products are infallible.
Posted by BlackHelicopterPilot
Top secret lab
Member since Feb 2004
52833 posts
Posted on 4/21/15 at 5:25 pm to
quote:

Rootpipe


quote:

Backdoor



I thought I was on the Poli Board and another Gay Marriage thread was started.

first pageprev pagePage 1 of 1Next pagelast page
refresh

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on Twitter, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookTwitterInstagram