It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Macs vulnerable to a new root kit Macs vulnerable to a new root kit
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Macs vulnerable to a new root kit
Reply
 
Thread Tools
Old 3rd June 2015, 07:03   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 153,514
Stefan Mileschin Freshly Registered
Default Macs vulnerable to a new root kit

One of the side effects of Apple Macs becoming more popular is that their token security is getting increasingly tested.

For years, Apple users smugly claimed that there were was no malware for the Mac because of Jobs’ Mob’s superior technology, while saner types suggested that there were too few macs out there for Malware writers to bother with.

There was little point doing all that coding to break into a computer which only had a Coldplay collection and a Safari web browser. That appears to be changing with hackers keener to draft Mac users into botnets on the safe basis that they will never actually believe it has happened to them.

A security researcher has discovered a new vulnerability in Apple Mac computers could be used to remotely inject persistent rootkit malware into users’ computers, providing attackers with full-system level control,

The zero day appears to be due to a bug in Apple’s sleep-mode energy conservation implementation that can leave areas of memory in the extensible firmware interface (EFI) (which provides low-level hardware control and access) writeable from user accounts on the computer.

Putting some late-model Macs to sleep for around 20 seconds and then waking them up unlocks the EFI memory for writing.

Pedro Vilaça, said the vulnerability can be used to remotely plant rootkits or persistent malware that is invisible to the operating system in the writeable flash memory, by using Apple’s Safari browser.

“A remote exploit could simply deliver a payload that will either wait or test if a previous sleep existed and machine is vulnerable, or force a sleep and wait for a wakeup to resume its work,” Vilaça told iTnews.

http://www.techeye.net/uncategorized...a-new-root-kit
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
OS X, iOS, Linux were the most vulnerable OSes in 2014 Stefan Mileschin WebNews 0 25th February 2015 07:14
Chromecast software vulnerability paves way for another root exploit Stefan Mileschin WebNews 0 25th August 2014 10:30
Why Android’s OTA Updates Remove Root and How to Keep It Stefan Mileschin WebNews 0 3rd July 2014 08:16
Chromecast update breaks root-friendly exploit Stefan Mileschin WebNews 0 4th August 2013 21:46
Developers gain root access on Google Glass, not yet sure what to do with it Stefan Mileschin WebNews 0 29th April 2013 10:20
Root exploit unearthed for Snapdragon-based Galaxy S 4 Stefan Mileschin WebNews 0 29th April 2013 10:17
The Case Against Root: Why Android Devices Don’t Come Rooted Stefan Mileschin WebNews 0 1st January 2013 16:00
PS3 root hacker, GeoHot, busted for $15 weed chocolate Stefan Mileschin WebNews 0 16th March 2012 07:33
GSM Phones Vulnerable to Hijack Scams Stefan Mileschin WebNews 0 29th December 2011 10:53
IPv6 added to root DNS jmke WebNews 0 22nd July 2004 00:04

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 20:29.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO