| Thread Tools |
3rd June 2015, 07:03 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 153,514
| Macs vulnerable to a new root kit One of the side effects of Apple Macs becoming more popular is that their token security is getting increasingly tested. For years, Apple users smugly claimed that there were was no malware for the Mac because of Jobs’ Mob’s superior technology, while saner types suggested that there were too few macs out there for Malware writers to bother with. There was little point doing all that coding to break into a computer which only had a Coldplay collection and a Safari web browser. That appears to be changing with hackers keener to draft Mac users into botnets on the safe basis that they will never actually believe it has happened to them. A security researcher has discovered a new vulnerability in Apple Mac computers could be used to remotely inject persistent rootkit malware into users’ computers, providing attackers with full-system level control, The zero day appears to be due to a bug in Apple’s sleep-mode energy conservation implementation that can leave areas of memory in the extensible firmware interface (EFI) (which provides low-level hardware control and access) writeable from user accounts on the computer. Putting some late-model Macs to sleep for around 20 seconds and then waking them up unlocks the EFI memory for writing. Pedro Vilaça, said the vulnerability can be used to remotely plant rootkits or persistent malware that is invisible to the operating system in the writeable flash memory, by using Apple’s Safari browser. “A remote exploit could simply deliver a payload that will either wait or test if a previous sleep existed and machine is vulnerable, or force a sleep and wait for a wakeup to resume its work,” Vilaça told iTnews. http://www.techeye.net/uncategorized...a-new-root-kit |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
OS X, iOS, Linux were the most vulnerable OSes in 2014 | Stefan Mileschin | WebNews | 0 | 25th February 2015 07:14 |
Chromecast software vulnerability paves way for another root exploit | Stefan Mileschin | WebNews | 0 | 25th August 2014 10:30 |
Why Android’s OTA Updates Remove Root and How to Keep It | Stefan Mileschin | WebNews | 0 | 3rd July 2014 08:16 |
Chromecast update breaks root-friendly exploit | Stefan Mileschin | WebNews | 0 | 4th August 2013 21:46 |
Developers gain root access on Google Glass, not yet sure what to do with it | Stefan Mileschin | WebNews | 0 | 29th April 2013 10:20 |
Root exploit unearthed for Snapdragon-based Galaxy S 4 | Stefan Mileschin | WebNews | 0 | 29th April 2013 10:17 |
The Case Against Root: Why Android Devices Don’t Come Rooted | Stefan Mileschin | WebNews | 0 | 1st January 2013 16:00 |
PS3 root hacker, GeoHot, busted for $15 weed chocolate | Stefan Mileschin | WebNews | 0 | 16th March 2012 07:33 |
GSM Phones Vulnerable to Hijack Scams | Stefan Mileschin | WebNews | 0 | 29th December 2011 10:53 |
IPv6 added to root DNS | jmke | WebNews | 0 | 22nd July 2004 00:04 |
Thread Tools | |
| |