Crack Mac OS X Security Externally in 30 mins? No way!

Yesterday, CNet published an article first posted on ZDNet Australia with the original attention-getting headline claiming Mac OS X hacked under 30 minutes by a hacker responding to a challenge. The CNet headline has now been changed to Winner mocks OS X hacking contest but the story has not changed in any significant way that we could find. It still reports the hacker broke through Mac OS X's security on a Mac mini acting as a server and gained root control in 20-30 minutes. The article reports that the hacker calls the Mac "easy pickings." The implication is that this Mac mini was sitting on the internet and the hacker broke into it from the outside and gained complete control through an unpublished vulnerability.

Not so, wrote Dave Schroeder of the University of Wisconsin's Department of Information Technology. Readers will remember that Dave Schroeder is also the source of the Mac-compatible Citrix server solution with guide, Grants.gov for Mac OS X, that allows Mac users to access Grants.gov to file grant applications. He pointed out that the ZDNet/CNet article leaves out the fact that potential hackers in the contest were given user accounts and those accounts were given access by ssh. So, the hacker gained root access as a user on the system through privilege escalation rather than first breaking in from the outside which is Mac OS X's strength.

Dave Schroeder is so confident of the difficulty to break into a Mac from the outside that he set up his own challenge with the prize being recognition that it was done. He set up a Mac mini on the internet and posted its IP address. He even made it easier by opening ssh and http ports which few Mac users would do. To win, someone has to break in from the outside (not through being given a user account), modify the Web page that the Mac mini is displaying and then notify Schroeder including a description of the mechanism used. He also plans to provide the mechanism to Apple and others responsible for the compromised parts of Mac OS X so that they may be fixed.

Schroeder's Mac OS X Security Challenge began yesterday at 10:00 am CT and 12 hours later, as of 10:05 pm CT, no break-ins have occurred. We think individual Mac users and their families on small home networks behind routers or individual firewalls are pretty safe from direct external attacks.

That Mac OS X has perhaps been proved vulnerable through privilege escalation, on the other hand, should be of concern to those who run large networks with many users, some of whom may for some reason decide to become destructive. It's also possible for Trojan horses to use such vulnerabilities to do damage so the problem is not completely insignificant. Hopefully, Apple is working to better armor Mac OS X against attacks from within, a much more difficult job for any OS. [Bill Fox]



Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Mac OS · This month in the archive