Magmatic Security Squawk Box: Recent Episodes

Sean OConnel

Security Alerts, Facts and News Specific to Apple Products

View Details

This Weeks Topics

This week I discuss Mavricks and iOS 7, the rumor mill of badBIOS, hoax, bad day or something else.

Finally, you can expect to hear more regular podcast in the future. A project that was a game changer for Magmatic has now been completed. We expect 2014 to be a real game changer for us. We have lots of tools and ideas we are really excited about. 

iTunes Preview

View Details

This Weeks Topics

This week I discuss Oracle's Java 1.7.0_09 for Mac OSX. While the System Preference Pane is a welcome addition it would be nice if it actually worked. 

After several months of using Gatekeeper it is official, I love it and you should too. Gatekeeper provides a host of protection against rouge developers. Best of all it stops rouge Java APPS in their tracks. 

Sandy reminds us all of what is important, that includes having a backup of critical data and the capability to keep your customer facing resources up and running. 

iTunes Preview 

View Details

This Weeks Topics

Adobe Flash, Reader, Acrobat and Shockwave Updates
iOS SMS Spoofing and Phishing

This week we discuss the recent Adobe updates. While no specific threat in the wild currently targets Mac OSX there are zero days targeting unpatched versions on the Windows platform. Criminals have regularly used the Adobe update cycle as cover to fool Mac users into installing malicious software, usually in the form as a Flash Player.

SMS protocol is vulnerable to spoofing, this includes all version of iOS. A recent release of a tool to make this process easier can allow a criminal to create SMS Phishing messages, what is called SMiShing. The pattern is similar to email phishing as are the defenses, do not visit links sent via unsecure comminication. There are a host of tools that this proof of concept was built off of. Some that requirer your iPhone to be Jail Broken, something you should never do. (See Reference Links) I consider this really low risk. Using iMessage prevents this form of attack, so for clients or users that are Mac/iOS based use iMessage.

Lastly I have some thoughts on Cloud based services. It is important that businesses and users realize that while the data is in the cloud, the responsibility for compliance and security is completely their responsibility.

iTunes Preview

View Details

This Weeks Topics

Social Engineering iCloud, The Curious Case of Mat Honan.
Gatekeeper Code Signing.

Summary

This week I give my take on the Apple ID account compromise of Former Journalist for Gizmodo, Mat Honan. I address some of the issues companies have to consider when working with Free-lancers who bring their own devices or their own eco-systems into your security umbrella. There are various Risk that need to be considered from a host of perspectives. I explain why it is important to have control over your backups.

Next I touch on the issue of code signing in Mountain Lion. User can override and set exceptions but the only way to manage these exceptions from the administrator perspective is via a command line tool called spctl. I argue that for most users and organizations, code signing make security sense and eliminates RISK, especially if code review is outside the scope of your business. 

Finally, my commentary on why now is the day to turn off Java on your Mac, eliminate the RISK of crime ware using Java. 

iTunes Preview

View Details

This Weeks Topics

Drop Box Spam
Icon Decoys
Java RISK and Updates

Summary

This week I address something old and something new. What do we need to consider after the recent revolation by Dropbox that an employee was compromised resulting in malicious actors gaining access to  the email addresses of account holders. 

I then discuss the social engineering method of Icon Decoying. A method that has been used over the last several months by criminals with mixed success.

Last we discuss Java and touch on how to manage RISK using the Java Preferences.app.  

iTunes Preview

View Details

Imuler.c, reported by Intego, is a low risk icon decoy social engineering attack. In MacOSX the user you can simply copy an icon to another file by using "File>Get Info (Comand-I)" in the Finder.

Summary Within a zip file the criminals hide an Application with an icon that looks like an image along with other image files. The decoy is an attempt to get the user to click on the Application and run the malicious file.

FACTS * This is a social engineering attack based on an attack method dating back to Mac OS 7 (Pre-OSX). * The stratergy of the attacker is Icon Decoying. * Users can turn on view extensions or use detail list to see the file type. (This is not really needed.) * MacOSX will prompt the user if they try to open a file for the first time downloaded from the internet. * You need to be the administrator to install or run the malicious application. Enterprise managers should manage these options in Mac OSX.

Figure 1: Warning Dialog for downloaded Application from Internet

RISK Imuler.C as all of it's previous versions are VERY LOW RISK. The attack method is similar to the PDF decoy in September 2011. The Application with the Icon Decoy is an attempt to use tactics decades old.

MITIGATION * Do all your computing as a general user, not the administrator. This stops most malicious installers in there tracks. * Do not open files from un-trusted sources. * Make sure that if you open an Application that you downloaded that you confirm the (HASH). * When you first open a file downloaded from the internet you will recieve the dialog in Figure 1, make sure that you trust that application. * Optional : Turn on "Show all applications extensions" in Finder>Preferences>Advance. * Enterprise administrator can manage what applications user can and cannot run. * Enterprise adminstrators should rely on the priciple of least privileged for application exectuion for users.

View Details

Apple has announced today a new System Preference Pane and Core Service called Gatekeeper along with other features of OX Mountain Lion. Gatekeeper will allow the user or Mac Systems Administrator to control the installation of software allowing them to ensure that only software signed by an Apple developer from the Mac APP store can be installed.

The iPhone ecosystem has been making it's way on to the desktop of Mac OSX users and developers for sometime. Mobile operating systems are influencing what we can expect in the coming years on our laptops, desk tops, servers, PaaS and computing devices. (For my PC friends, wait until you see Metro.) Gatekeeper will be a game changer because Apple has the capability to implement it effectively. It is my thinking that this adds a layer of protection and control that is long over due. Basically, this control will, at the user's/admin's discretion, result in the Mac OSX platform to truely mimic the iOS application code signing ecosystem. (Only code signed by a Mac developer can be installed with additional options.) Clearly as has been demonstrated by iOS sand-boxing approach, what once was thought of as restrictions now are considered an excellent balance of protection verse features. But why stop there?

I have long been an avocate for administrators creating their own seat-belt profile files(.sb) to enhance the settings already used in MacOSX. I expect additional controls including seat-belt in a very user friendly control pane as well in the not to distant future. Many applications and users do not need access to the file system, particular frameworks or networking. (Yes, there are other way to control this and Apple has added these controls to XCode for developers to implement. Figure 1) Allowing users and administrators a simple manner in which to manage these very complicated controls over applications and their privileges seems a logical next step in porting some of the security features from iOS to the desktop.

Currently XCode 4.2.1 build 4D502 allows developers various sandboxing controls as of Lion.

Of course, Gatekeeper is not a perfect solution, nothing is, once you create a system there are flaws. Gatekeeper provides the user/administrator with an additional technical tool to enhance Mac OSX's security robustness. The technology is not new and various technical aspects have been discussed for some time by many researchers. Apple's controls at various levels including development, distribution, installation and administrator has lots of potential. However as with any security schema the devil is in the implementation. What makes this a game changer is that Apple, largely due to the success of the iOS ecosystem, is extremely capable of implementing Gatekeeper along with these other security controls in a way that will matter.

View Details

Ade Barkah has posted on his site Peekay.com details about his discovery of a bug in iOS which allows access to the camera roll when the device is locked. Rolling back theDate & Timewill allow unauthorized access to any photos that were already taken on any future Date & Time.

Summary If the Date & Time IS ROLLED BACK on an iOS device running 5.x a malicious actor will have unauthorized access to the photos with future dates and times in the camera roll.

FACTS * Rolling back the Date & Time on a device running iOS 5.x will allow access to the camera roll on a locked device to images with only with future dates and times.

RISK There is a RISK that if you travel across time zones and your Date & Time is rolled back a malicious actor with physical access to your device can access your camera roll without the need for a Passcode and access photos taken between the two times.

Overall RISK: LOW RISK

Mitigation General Users

Make sure that Set Automatically is enabled in General>Date&Time to ensure that your device has the current Date & Time for your current Time Zone.

Set Automatically Date & Time

This will ensure correction by your location's temporal condition until Apple's update.

Result-ResidualRISK: Extremely Low RISK (Pending Update.)

High Value Users

Restricting the Camera ensures that this bug will not be triggered. High value users should considered this option when traveling. This can further be managed by using Configuration and Provisioning Profiles which includes the capability to configure Restrictions on iOS devices. Enterprise managers can manage restrictions using the iPhone Configuration Utility.

View Details

The site blog.chpwn.com has reported that there is a version of Carrier IQ within Apple's iOS 5.x.x. I am sure that by now you have read the reports about Carrier IQ being discovered on mobile devices by Trevor Eckhart. The analysis on blog.chpwn.com is missing some key details as it relates to iOS 5.x.x that are useful in managing any RISK. To help users make informed decisions and understand the risk involved we will provide full details related to Apple's "Diagnostic & Usage Data."

Summary In iOS 5.x.x you do not need to Jail Break the Phone and finding the information collected does not require technical expertise. (Just have to know where to look.) What is most important to note is that the data is anonymous and users have complete control. Turning off "Diagnostics and Usage" along with System Services Location will prevent any reporting. Users can view and disable the sharing of data on their iOS device running 5.x.x at anytime. What is collected, transmitted and how a user manages the collection of data is clearly stated in Apple's "About Diagnostics and Privacy" statement.

The improvements in the management of the data can be traced back to April 2011, when it was discovered that Apple was in fact tracking users location data. The result of that discovery has resulted in Apple providing a clear and concise way in which users can manage "Diagnostic & Usage Data." So after all there is something to be said for a company being scared straight.

Checking Your Diagnostic & Usage Files and Settings Apple iOS 5.x.x during the inital setup phase will ask the user if they would like to share "Diagnostic & Usage Data." (This is disabled by default.) If a user enables this option data about the phone including location data related to cell service will be anonymously collected and sent to Apple. It is really easy to turn this option on and off and to review the data that has been collected and transmitted if the option is enabled.

If you go into Setting>General>About>Diagnostic & Usage you are presented with the following screen. On this device below automatically send diagnostic and usage data is turned on.

Diagnostics & UsageIf you select "Diagnostic & Usage Data" you will see a list of files the collected data if the phone had "Automatically Send" enabled at some point. The file format is awdd_

aawd File ListIn addition to crash logs and calibration information the files contain information about the iOS 5.x.x device but all device information remains anonymous. Apple clearly explains what data is collected and how a user can manage it, more on that in a moment.

awdd Example one

Notice that the isAnonymous key <value is set to TRUE. You can also view all of the other key pairs within the file. Cell service information at your location is collected if that option is enabled in Location Services. This data is includes cellularXXXCellInfo, channels, band, hybrid_active_channel, etc. The deviceId value is the SysInfoCrashReporterKey which does not contain information that is device specific such as the MAC address, serial number, IMEI/MEID or the ICCID. Physical access to the device or to an un-encrypted backup allows an individual access to the deviceId (theSysInfoCrashReporterKey.)

awdd Example Two

This awdd data files also contain diagnostic information related to applications and hardware, the example below is specific to the camera.

com.apple.camera Example

Turning Off Reporting of Diagnostic & Usage

Turning off the collection of "Diagnostic and Usage Files" is very easy to do, you simply select "Don't Send" in Settings>General>About>Diagnostic and Usage.

Turning Off Diagnostic and Usage DataNo data or crash logs will be shared or sent but the files created will remain on the device for a undetermined period of time (Update Pending). They also remain in any backups of any iOS device backup. If you want to achieve a zero impact foresic foot print as it relates to these files you must setup the device initially with "Don't Send" selected.

Turning Off Location Services As stated above a major issue back in April 2011 was the discovery that Apple was collecting location data of users. Location data is a double edge sword no matter the device in question. (When it comes to mobile devices device=user.) The profile of the user predetermines all specific location settings for Applications and System Services. (For example a high value user would have a different location settings profile as compared to a low value.) At the enterprise level these can be managed with iPhone Configuration Utility.app.

If you have "Diagnostics & Usage" set to "Automatically Send" and enabled the location based services for the system service "Diagnostics & Usage" in the Settings>Location>Services>System Services window, cellular data related to your location is shared anonymously. You can turn this off in Settings>Location>Services>System Services and toggle "Diagnostocs & Usage" to off.

Location Services System Services

Apple's Diagnostics and Privacy Apple has a plain language privacy policy when it comes to diagnostic data collection along with clear instructions on how to turn it off. That infomation can be found on every iOS device running 5.x.x at Settings>General>About>Diagnostics & Usage. If you click the "About Diagnostics and Privacy" on the bottom of the view the following will appear.

Apple Diagnostics and Privacy

Facts * iOS 5.x.x Diagnostics & Usage data is anonymous. * iOS 5.x.x Diagnostics & Usage data reporting can be turned off. * iOS 5.x.x is Diagnostics & Usage data uses SysInfoCrashReporterKey as a key for the deviceId flag, thus with physical access to the device you can obtain this number.

RISK Poor management, limited knowledge and misleading information represent the Highest Degree of RISK related to iOS 5.x.x "Diagnostic & Usage" reporting.

iOS 5.x.x "Diagnostic & Usage" RISK can be mitigated with management of your iOS settings.

The RISK to user privacy is LOW in iOS 5.x.x as it relates to "Diagnostic & Usage" reporting.

Mitigation Individual user or system profile must determine all Applications and System Services specific location and "Diagnostic & Usage" reporting settings.

It is not recommended to provide any "Diagnostic & Usage" data or location data for any high value system or user.

General users should consider disabling "Diagnostic & Usage" reporting and turn off location services for this system service. Residual risk remains such as interception and physical access compromise thus consider additional mitigation.

Addition Mitigation

  • Encrypt all Backups of iOS devices on your Computer.
  • Use a Passcode of Significant strength.
  • Enable Find My iPhone if appropriate.
  • Ensure that Mobile Wipe is available.

Additional Notes

Test done on iPad 2 and iPhone 4s running iOS 5.0 and 5.0.1. Due to our specific privacy policiy some information has been removed. To contact us please use the following form here.

View Details

Apple has released iOS 5.0.1 to address an array of concerns including the battery life issue reported by some users.

This update also fixes the unsigned code access to Standard Data Management and Frameworks demonstrated by @0xCharlie (Charlie Miller). His discovery exposed a weakness in Apple's code approval process. There is NO THREAT to the general user population.

The logic error discovered by @0xCharlie  took advantage of failures in mmap system calls checking of flags. This allowed any application to execute code at a level similar to Mobile Safari. Malicious Applications could use objects/classes such as NSURL, NSURLRequest, NSURLConnection and NSXMLParser to fetch additional code to execute in memory from a remote source. 

This opened a possible pathway in which a malicious actor can execute unsigned code or possibly launch a more complex exploit. Charlie Miller's application represents no threat to any user. However malicious actors have the capability and technical knowledge to duplicate his findings very easily. 

Users should update their version of iOS immediately on compatible devices.

View Details

Apple will be rolling out iCloud over the next couple of days. Apple has released iTunes 10.5 as a first step today. 

What's new in iTunes 10.5 (From Software Update.)

  • iTunes in the Cloud. iTunes now stores your music and TV purchases in iCloud and makes them available on your devices anywhere, any time, at no additional cost.

    • Automatic Downloads. Purchase music from any device or computer and automatically download a copy to your Mac and iOS devices.
    • Download Previous Purchases. Download your past music, TV, app, and book purchases again, at no additional cost. Previous purchases may be unavailable if they are no longer on the iTunes Store.
    • Sync with your iPhone, iPad, or iPod touch with iOS 5.
    • Wi-Fi Syncing. Automatically sync your iPhone, iPad, or iPod touch with iTunes any time they're both on the same Wi-Fi network.

View Details

Reuse of code in crimeware kits and tools targeting Windows infrastructure via Java has been building momentum. Java is a cross platform environment which can allow criminals to take advantage of systems regardless of operating system. For example, much of the crime ware kit call BlackHole RAT is still written in Java and Real Basic. We still consider this kit Low Risk.

It is our thinking that in the case of JAVA, due to the cross OS nature and Apple's custom update cycle, it continues to be the attack vector platform of choice.

Ways to Eliminate any Threat from malicious JAVA Applets If you do not need or use Java than disable it in Safari.

  1. In Safari goto Safari>Preferences>Security and disable Java.
  2. In Chrome visit Chrome://plugins and disable Java.
  3. In Firefox Tools>Add-ons and disable Firefox.

Suggested Setting in the Java Preferences.app to Protect Your Mac * In /Applications/Utilities/Java Preferences.app disable "Allow User to grant permissions to content from an untrusted authority." * In /Applications/Utilities/Java Preferences.app disable "Use certificates and keys in browser keystore" * In /Applications/Utilities/Java Preferences.app disable "Use personal certificate automatically if only one matches server request." * In /Applications/Utilities/Java Preferences.app enable "Enable blacklist revocation check." * In /Applications/Utilities/Java Preferences.app enable "Check certificates for revocation using CRL" * In /Applications/Utilities/Java Preferences.app enable "Enable online certificate validation" * In /Applications/Utilities/Java Preferences.app enable Verify mix security code. "Enable-don't run untrusted code, no warning." **This should be reviewed based on business needs. * Review Trusted Publishers in Security pane.

Java Preferences.app also allows the user control over the cache and storage space used.

Consider each option based on your specific business needs. For example, if you are developing jar/applets internally consider reviewing of the signing process to insure that all internal app/jar used for production systems and properly signed by your organization. You may also want to disable Java or create a custom seat-belt file.

View Details

Recently F-Secure has reported they may have come across a Mac Trojan. The operative word being "may" from their original post which was not picked up by additional press accounts. (F-Secure is a five start organization, not that they cannot make errors but they are a gold standard when it comes to accurate disclosure.)

This PDF Decoy Malicious Installer is actually an attempt to use tactics found on the Windows platform by sending rouge documents that an unsuspecting user will open up. The taxidermy of the Windows attack attempts to execute a malicious application, open a malicious site or exploit a vulnerability in the Adobe Product line or Microsoft's Product line. In this particular case targeting Mac OSX there are very important key differences.

This is not a TROJAN running from a PDF taking advantage of an exploit or vulnerability. It is NOT EXPLOITING ANY KNOW FLAW at all, it is however using a host of deceptive tactics. It is a rouge Package Installer that installs and opens a PDF DECOY to cover up the installation of an additional services (Apache) without getting the user suspicious. In it's current form it is the technical equivalent of putting a square peg into a round hole.

How it Works The PDF Decoy Rouge Installer PACKAGE runs additional scripts after the decoy is installed and opened up on screen. Using combinations of Preinstall scripts, Post Install scripts and/or Actions within the Package the scripts will attempt to install and/or download additional services. (We have encountered a version which installs apache.) The developer of this malicious package has attempted to use an application which cleans itself up, similar to the one used in latter version of MacDefender, AVRunner. (Class Diagram) The good news is that a properly configured Mac will mitigate this PDF Decoy Installer. This represent a LOW RISK threat in its current form.

Reports of Changing Extensions to Execute PKG Files are WRONG! If you change the extension of a file in Mac OSX to one that it is not compatible with it will not execute or open. For example, a DMG, MPKG or PKG file that has had its extension changed to .PDF it WILL NOT open or execute. What will happen is that an error will be generated.

Fig. 1.1 Firefox DMG file extension changed to .PDF

Primary Mitigation Currently XProtect has been updated and will recognize this installer. In Apple Menu>System Preferences>Security & Privacy Make sure to have "Automatically update safe downloads list" Enabled for automatic updates of XProtect. (If you toggle this option it will update but make sure to do a "Show All" to save your settings. Advanced users can update XProtect manually** by doing the following:

  • Open /Applications/Utilities/Terminal.app
  • Type sudo /usr/libexec/XProtectUpdater
  • Enter the Adminstrator Password
  • Quit out of Terminal.app

It is important to realize that a developer can bypass the need for the user to enter the Administrator Password when creating an installer Package. The best defense is not to perform general computing as an administrator. This will limit what and where files can be installed. The administrator account type in Mac OSX is the equivalent of root and has full rights to install and write to a host of directories. You must use a standard user account for all your computing.

Fig. 2.1 Installer Failing Standard User Account

In larger deployments of Mac OSX systems protect the administrator account as you would root using layered administrative permissions and sudo to execute system altering commands. (Administrator's should never have full access to root privileges and all activities should be audited.)

Mac OSX System

  • In Apple Menu>System Preferences>Security & Privacy Make sure to have "Automatically update safe downloads list" Enabled thus setting up automatic updates of XProtect.

Safari

  • Do not install any program from an installer opened directly from the Web.
  • Make sure "Open Safe Files" is de-selected in Safari Preferences.
  • Download files only to the Download folder that is in each users home directory.
  • Set Remove Downloads to "When Safari Quits." Manually clear this folder for other Browsers.
  • Make sure that "Block Pop-Up Windows" is on.
  • Never do Web Surfing as the Administrator, carry out daily task as a user that does not have administrator privileges.

For Chrome

  • Select "Clear Auto-Opening" settings in chrome://settings/advanced.
  • *Never do Web Surfing as the Administrator, carry out daily task as a user that does not have administrator privileges.*

Secondary Mitigation * We also recommend that you only install Applications that come from trusted sources or from the Mac App Store. These are digitally signed so their is trace back to the developer. * Consider installing an Anti-Virus product. We love F-Secure and Intego.

RISK The RISK related to this PDF Decoy Malicious Installer is LOW.

We continue to monitor how this evolves since the tactics are similar to larger scale Phishing attacks designed to create a beach front into an sensitive internal systems of high profile organizations. Due to recent system updgrades at previously targeted companies of users in certain departments and groups to Mac OSX systems, these actors are attempting to discover how to use their old tactics to create new jump off points to internal compromises.

**Apple does not recommend doing this from the command line and users should consider the risk. For the general user setting the system preferences should suffice. This solution is ideal in larger managed environments.

View Details

Directory Services Command Line (dscl) allows authenticated users to change various settings including their password. We wanted to provide some clarity to the RISK and avoid headlines, little detail or poor analysis. Below we provide all the facts along with mitigation technics to limit the effectiveness of a this type of physical access attack. It is our desire to clear up misconceptions so that users and administrators have a clear understanding of the Risk and mitigation methods to take.

Background

This issue reported by the blog Defence in Depth and than picked up by various news outlets states exactly what dscl does. (See man dscl) We think that this issue was reported without proper quantification of risk. dscl allows users to alter their setting in directory nodes they are authenticated to. (See man dscl) If you are a root user or administrator you can alter every user.

Facts -A user authenticated in Mac OSX Lion can from the terminal use the Directory Service Command Line Utility to set various options to the directory node the user is authenticated to.

-Using the dsl command with the -passwd option a user that is already authenticated can change their password without having to provide the old password.

Last login: Tue Sep 20 07:18:30 on console
Box23Lion:~ joeuser$ dscl localhost -passwd /Search/Users/joeuser
New Password:

-This is clearly stated in the man page for dscl -passwd option:

passwd

Usage: passwd user_path [new_pasword | old_password new_pasword]

Changes a password for a user. The user must be specified by full path, not just a username. If you are authenticated to the node (either by specifying the -u and -P flags or by using the auth command when in interactive node) then you can simply specify a new password. If you are not authenticated then the user's old password must be specified. If passwords are not specified while in interactive mode, you will be prompted for them. Passing these passwords on the command line is inher-ently insecure and can cause password exposure. For better security do not provide the password as part of the command and you will be securely prompted.

-As an account with Mac OSX Administrator or as root privileges you will be able to change any user's password. This is why you should never do general computing as the root user.

-The original Key Chain cannot be accessed without the old password, thus your saved passwords are protected.

-The File Vault Recovery Key and Password will continue to work.

Myths Myth-You can change any users password and lock them out of the system.

If the malicious actor has physical access to a logged in account with Administrative privileges they can make it difficult for a user to gain access. Any password change will not affect the users keychain which stores saved passwords and developer certificates, the old password is required to access that key chain. They will not have access to chainging FileVault Settings.

Using an Administrator account for computing is extremely bad idea, MacOSX is Unix thus privileges come with responsibilities. Create a general account that for doing your daily computing task. If the Administrator password is changed resetting it is an easy task.

Myth-A general user can change any password they want.

One hundred percent false, as a non-administrative user cannot change the password of any user other than themselves. Read the man page above.

Box23Lion:~ joeuser$ dscl localhost -passwd /Search/Users/aliceuser
New Password:
Permission denied. Please enter user's old password:
passwd: DS error: eDSAuthFailed
DS Error: -14090 (eDSAuthFailed)

Myth-I can be locked out of my system.

If a malicious actor gains physical access to a command prompt with root or Administrative privileges and changes the user or root account all is not lost. You can use your Lion Emergency Disk or Lion Recovery Disk Assistant.

Primary Mitigation Never do computing as the Administrator, set up an Administrator account and a user account. Do all your computing as the user. Mac OSX has various layers of protection, use them. Shame on any organization or user who continues to operate in this manner or falsely confuse users instead of educate.

Secondary Mitigation In System Prefences>Security & Privacy ensure that "Require Password immediately after sleep.." is selected.

In System Prefences>Security & Privacy ensure that "Log out after 2 minutes of inactivity" is selected.

For organizations with multiple administrators, never give your administrators the keys to the castle. Have specific administrative accounts that are logged and audited.

Make sure to setup File Vault and to store your recovery key in a safe place.

RISK The risk of this type of attack is LOW due to the need for the attacker to have physical access and administrative privileges.

We believe that already poorly configure MacOSX machines will be vulnerable to this and a host of physical attacks.

Disappointment We are disappointed that there continues to be an issue with dscl, which has been reported to Apple in the past. The user should be prompted again to enter their password even if they are already authenticate to the node. At that same time there is no weakness or true flaw, just bad implementation. We also think that the combined layers of protections in Mac OSX mitigate this risk, similar to all physical threats. So the real Risk we rate as LOW.

There is nothing to discover or new here except that someone read the man page for dscl who may have not done before. Due to the limited understanding about how best to secure MacOSX a LOW RISK flaw has become poorly reported on and explained.

We expect better and have done so here.

View Details

There have been inaccurate reports that the MacGuard installer bypasses the administrator account. This is false, what it does is take advantage of users who are doing general computing task such as Web Surfing, Email and Word Processing as the Administrator account. On MacOSX, this account has access to write to the application folder. MacGuard is taking advantage of poor deployment, not a complex circumvention of the Administrator Privileges.

The Facts Fact- YOU MUST BE THE ADMINISTRATOR ACCOUNT ON THE MAC TO INSTALL MACGUARD.
Fact- If you are not the administrator account or an account that is in the administrative group the installer WILL NOT INSTALL MacGUARD.

Trying to install MacGuard not as the Administrator

Fact-When you visit a page hosting MacGuard, the new variant of MacDefender, after the common fake scan in the browser window the user is promoted to download MacProtector.mpkg.zip
Fact-The Zip file contains avSetup.pkg which installs /Applications/avRunner.app.
Fact- avSetup.pkg has two postinstall scripts called postinstall and avSetup.post_install which run /Applications/avRunner.app
Fact-acRunner.app connects to a nginx server as the User Agent: avRunner/1 CFNetwork/454.11.12 Darwin/10.7.0 (0000) DDDDDDDDDDDDDD
Fact-acRunner.app downloads MacGuard.app.zip
Fact-acRunner.app unzips the file, removes the zip and places MacGuard.app into Applications.
Fact-This can only happen if you are the Administrator or an account with Administrative Privileges.
Fact-MacGuard can be removed using the manual method and our script.

View Details

We have created a script to help you remove MacProtector and MacDefender which you can download below. Please note that this is not Anti-Virus product, this is only a script which removes these particular malware applications. Users should backup their computer and confirm the hash below the file download. We have used it successfully and will have an improved on by Sunday.

The instructions are as follows after unzipping and mounting the Disk Image File.

  • Close MacProtector's or MacDefender's annoying window and stop any scans it is performing, THEY ARE FAKE!.

  • Double click on RemoveMacDefenderProtector.

  • You will be in the Applications folder, scroll down and find either MacDefender or MacProtector, MacSecurity.

  • Choose the one you wish to remove and eventually the MacProtector/defender indicator will close.

  • The application will be moved into the trash. Confirm this by opening the trash.
  • Your browser will direct you back to our site which includes some tips for settings in Safari.

If you have any questions please use the contact form on our site. For more information about our investigation please see our draft report page. Please note, our site has no ads and we do not wish to track your. This script we have used with our clients and have determined that we can release it publicly.

System requirements- MacOSX 10.6

MagmaticMalwareRemove5_02v.dmg.zip

SHA(MagmaticMalwareRemove5_02v.dmg.zip)= dc795ac2fcc92a284802090048a20e38e147918e

http://magmatic.com/storage/publicscript/MagmaticMalwareRemove5_02v.dmg.zip

View Details

That recent malware that targeted Mac OSX systems, MacDefender and MacProtector, are fake anti-virus products designed to steal users personal information including credit card accounts. We think version OSX/MAcDefender.F tries to steal two credit card numbers by bouncing one and directing the user to another site. Below is our pending draft analysis for OSX/MacDefender.A , OSX/MacDefender.D and OSX/MacDefender.F.

Our analysis includes takeaway’s of the evolution of key inherited traits within each rouge application followed by an detailed technical breakdown or the woking three variants we have. Our format is broken into stakeholder sections for executives, users, researchers and experienced MacOSX administrators. This report is a draft and may change without notification.

Excerpts From Our Analysis

Files

/Contents/MacOS/MacDefender (OSX/MacDefender.A)

MD5(MacDefender)= 2f357b6037a957be9fbd35a49fb3ab72

SHA(MacDefender)= 470e1c99d7b5ec6d00b26715f4fa37bc70984fb4

/Contents/MacOS/MacProtector (OSX/MacDefender.D)

MD5(MacProtector)= 1f8e9cd3f0717a85b96f350e4f4a539a

SHA(MacProtector)= 361ba7b420e1a9ec0af5f7811e84dc95d04624a9

Added 05_21_2011

/Contents/MacOS/MacProtector (OSX/MacDefender.F)

SHA(MacProtector)= a94bd6a52bcb275a8ff1cd15977167f709b7ab04

UPADTE PENDING MacProtector (OSX/MacDefender.F) It is our theory that this version of MacProtector will trick the user into to providing two credit card numbers by directing them to two separate sites. It also can ensure that if one site is down the other will continue to steal credit cards. // @interface URLMaster : NSObject { } + (id)getBuyPageIP; // IMP=0x000000010000f1f7 + (id)getBackupBuyPageIP; // IMP=0x000000010000f1e8 + (id)getSoftInstallLink; // IMP=0x000000010000f391 + (id)getBuyPagLink; // IMP=0x000000010000f30d + (id)getBackupBuyPageLink; // IMP=0x000000010000f289 + (id)getSendTicketLink; // IMP=0x000000010000f0a8 @end @interface URLMaster : NSObject{}
+ (id)getBuyPageIP; // IMP=0x000000010000f1f7+ (id)getBackupBuyPageIP; // IMP=0x000000010000f1e8+ (id)getSoftInstallLink; // IMP=0x000000010000f391+ (id)getBuyPagLink; // IMP=0x000000010000f30d+ (id)getBackupBuyPageLink; // IMP=0x000000010000f289+ (id)getSendTicketLink; // IMP=0x000000010000f0a8
@end

  • Both installers have the "ru.lproj" indicating the developer spoke Russian.
  • Localizations for .nib files set to English.
  • Localizations for application set to English.
  • Xcode build for both was 10M2518, Xcode 3.2.6 / iOS SDK 4.3 gm which include Russian and English.
  • The build machine which created both was running OSX seed 10J869, 10.6.7.
  • Minimum system version is 10.5.
  • Both use “df -lg|awk” to get disk space information.
  • Both create and then write the output to a file named dmem.txt in the users ~/home folder
  • Both use “ps -e|awk” to get process information.
  • Both create and then write the output to a file named proc.txt in the users ~/home folder.
  • Both use random number to seed timers, determine time to indicate infected file. (int)GetRndNum:(int)arg1:(int)arg2;
  • Both use a method (void)setTimeIntervalForFirstVirAppearing to set the random time for first fake indication of virus to appear.
  • MacProtector has a superior coding operating structure as compared to MacDefender.
  • MacDefender opened the default browser to make a purchase, MacProtector has the Webkit framework opening a WebKit container to a site all built into the application
  • MacDenfender link is dead, MacProtector link is still active remains active.
  • MacDefender connect to 69 50 214 53 using default browser. (Site offline.)
  • MacProtector connect to a nginx server 91 213 217 30. (Web and Reverse proxy)
  • MacProtector manages and obfuscates the IP address but the serial numbers are still stored in plain text, MacDefender does not obfuscate the site IP address.
  • MacProtector @Interface RegWindow handles the registration process, for example http : //91 213 217 30 / js / payform3 .js (Do not visit this link.)
  • MacProtect uses token and cookies in the false activate product process.
  • MacProtector uses various class methods to get ip address and confirm cookie from site.
  • MacProtector sends data to 91 213 217 30.
  • MacProtector receives cookies from 91 213 217 30.
  • MacProtector uses methods (void)createURLForSerialNumberCookieSearch; and (void)OnCheckCookieForRegkey; to handle checking for registration cookie.
  • MacProtector has a text file in resources called ksms.txt which contains the number “4”.
  • MacProtector’s post flight script does not “reveal” the application in the Finder and does not use AppleScript.

Downloads-DRAFT Update-Draft report v2.

Magmatic_Analysis_MacDefender_MacProtectorv2Draft.pdf (MAJOR UPDATE PENDING)

SHA(Magmatic_Analysis_MacDefender_MacProtectorv2Draft.pdf)= 72b17c4250da23ae3c744fb26508d2b1889ae49e

Draft report v1

Magmatic_Analysis_MacDefender_MacProtector(DRAFT)

sha=5a708a3751c3ddd7bf38fcf240d8abc676514452

Magmatic_Analysis_MacDefender_MacProtector(DRAFT)

sha=c20f74b6eef02667033ddf50ff8a4ef1a10c7f13

Class Diagrams MacProtector (OSX/MacDefender.A)

OSX_MacDefender.A_ClassDiagramDraft2.pdf

SHA(OSX_MacDefender.A_ClassDiagramDraft2.pdf)=d4b9902967f842773a563b215cae49ac5d3bde40

MacProtector (OSX/MacDefender.D)

OSX_MacDefender.D_ClassDiagramDraft2.pdf

SHA(OSX_MacDefender.D_ClassDiagramDraft2.pdf)= 2a92c951b9378d2370d559cbcbce873660fcc12d

MacProtector (OSX/MacDefender.F)

OSX_MacDefender.F_ClassDiagramDraft2.pdf

SHA(OSX_MacDefender.F_ClassDiagramDraft2.pdf)= 2b80717c46157cd2606dcbe6a7817e5993fb7ace

Class Dumps MacDefenderOSX_MacDefender_A_ClasssDump (OSX/MacDefender.A)

SHA(MacDefenderOSX_MacDefender_A_ClasssDump.txt)= 5087f008da46bdd3cfacaf1be9d3729f19916f65

MacDefenderOSX_MacDefender_D_ClasssDump (OSX/macDefender.D)

SHA(MacProtector_OSX_MacDefender_D_ClassDump.txt)= a53cc5a8c9cd2f19726e56beed8b07a097d7b8e2

MacDefenderOSX_MacDefender_F_ClasssDump (OSX/MacDefender.F)

SHA(MacProtector_OSX_MacDefender_F_ClassDump.txt)= f26c0091ab26b1ca998d8f58e9ee133d967c5bd8

**Note-This is draft data and contains raw information, final release of the document and addition updates will be located at here. All information is provided as is and falls under the copyright located on this site and within the draft report. Any questions use the Contact Us Link and put "MacDefenderProtector Report" in subject line.

View Details

Background * MacDefender, MacProtector, MacSecurity and MacGuard are all rouge mac Anti Virus products. * They are crime-ware designed to steal your Credit Card information. * Created by Criminals out of Russia.

What if I purchased it? Call your Credit Card company and report the card compromised. Review all charges on all your accounts. Remember they also have you address and phone number so exercise caution to phone solicitations.

How to remove MacDefender, MacProtector and MacSecurity if I installed it? 1. Open the Activity Monitor in the Applications/Utilities/ directory.

When the Activity Monitor opens up find the rouge application based on its name from the process list. Once you find either MacDefender, MacProtector or MacSecurity select it in the list.

  1. Quit the Process.

  2. Trash MacDefender, MacProtector or MacSecurity

Move the application to the

thrash and then select

Finder>Secure Empty Trash.

  1. Remove it Login Items.

Go into your Apple Menu>System Preferences and open accounts. Select you account and tab to the Login Items Pane.

Make sure that once you are done to change your password and all other passwords on the Mac. Close System Preferences and then restart your Mac to ensure removal.

  1. Check Safari and Chrome consider the following settings.

  2. Do not install any program that installer open directly from the Web.

  3. Make sure "Open Safe Files" is de-selected in Safari Preferences.
  4. Select "Clear Auto-Opening" settings in chrome://settings/advanced.
  5. Download files only to the Download folder that is in each users home directory.
  6. Set Remove Downloads to "When Safari Quits." Manually clear this folder for other Browsers.
  7. Make sure that "Block Pop-Up Windows" is on.
  8. Never do Web Surfing as the Administrator, carry out daily task as a user that does not have administrator privileges.
  9. Never use Safari on a Mac OSX Server.
  10. Make sure "Auto Fill" is de-selected for all.
  11. Download and confirm the hash before installing any files on assets in your control. (Recommended for enterprise customers.)

If you still are having problems removing MacDefender, MacSecurity and MacProtector and your computer is within the United States we can help. Go to the Contact Page and put Remove into the Subject and we will contact you to see if we can help. We are only asking for suggested payment of $19.99 + NYS Sales Tax for remote repair service which covers our cost. We only expect you to pay if we remove it and your happy with the results. This about the cost in lost time and transportation of going to the Genius Bar.

View Details

Adobe has added a new Preference Pane for Flash for Mac OSX, which allows you to control Flash Privacy and Update Notification via a standard MacOSX Preference Pane. While this is a good step, the problems which existed with the Setting Manager still exist in the Preference Pane when it comes to the handling of Local Shared Objects (LSO) otherwise know as Flash Cookies. Below we expose the various issues with the Preference Pane, mainly when you select Storage>Delete All and Advance>Delete All site data remains.

The Flash Player Preference Pane

The Flash Player Preference Pane replaces the clumsy Setting Manager for Flash which ran directly from the Browser. One great feature of the pane is the management of Flash updates which was horrible in the Setting Manager. The Advanced tab enables you to determine the version installed and provides a direct link to the About Flash Player page. You also have the capability to set storage and privacy controls for the camera and microphone. "Private Browsing" is supported in Safari 5.0.5, thus private browser session information including Flash content is not stored in the usual directories ~/Library/Preferences/Macromedia/Flash Player/macromedia.com or ~/Library/Preferences/Macromedia/Flash Player/#SharedObjects.

Sounds Good, So What is the Problem

We have discovered that if you visit a site with "Allow sites to save information on this computer" enabled in the Preference Pane or had previous sites that stored information the "Delete All" button does not provide the protection describe here on Adobe's site and below.

After reading this you would expect buttons labeled "Delete All" to perform as advertised and remove all content saved from sites. This is not always the case, and some data remains, similar to the failures in the Setting Manager, thus the "Delete All" does not perform as expected. In our demo we will clearly show that the Flash Player Preference Pane does not work properly resulting in Flash Cookie (LSO) data remaining on the system.

Note : (For our demo we will be using Philipp Kostin Flash Site Demo titled "Flash Cookies: Local Shared Objects" to create the data and Flash Cookie (LSO).)

Follow these steps to duplicate our results in the video that follows:

  • Go to ~/Library/Preferences/Macromedia/Flash Player/macromedia.com and leave open.
  • Go to ~/Library/Preferences/Macromedia/Flash Player/#SharedObjects and leave open.
  • Select System Preferences>Flash Player>Storage and enable "Allow Sites to save information on this computer"
  • Visit a site that writes some date via a Flash Cookie (LSO), in our example we used Philipp Kostin Flash Demo.
  • Write some information using the demo or from any other Flash Site of your choice.
  • Change your settings in System Preferences>Flash Player>Storage to "Block all sites from storing information on this computer."
  • Click on "Local Storage Settings by site" and view any site information. Did a site show up?
  • Try "Delete All" in System Preferences>Flash Player>Storage and System Preferences>Flash Player>Advanced.
  • Notice that the data in the Flash Cookie (LSO) remains.

Wasn't This Always a Problem?

In previous versions of Flash Player for Mac OSXdeleting site storage did not remove all the Flash Cookies (LSO) including the .sol file and a folder with the site name. This was one of the many issues which made using the Setting Manager very frustrating. Flash Cookies (LSO) have raised all kinds of privacy issues since they were first used, and that continues to be the case even if Adobe has introduced a Preference Pane.

In the Flash Player Preference Pane the language is clear so we expect that "Delete All" would do exactly as expected. In our demo this was not the case. The only solution that worked one hundred percent of the time was to manually remove Flash Cookies (LSO) and then enable "Block all sites from storing information on this computer."

Conclusion

In the current state the Flash Player Preference Pane for Mac OSX does not work as advertised, thus it continues to be a work in progress. The Flash Player Preference Pane clearly does not improve the management of Flash content privacy. In fact, the Flash Player Preference Pane will result in users having a false sense of privacy. It is our hope that Adobe was making an attempt at making Flash privacy easy to manage and not trying to layer the issue of privacy in a veil of confused user interaction. Take a chance Adobe, your business goals can be met while providing users and developers with clear dependable controls over Flash Cookies (LSO) and their privacy. The other option is to agree with Steve Jobs and move away from the Flash Platform.

View Details

Intego has reported a new rouge Anti-Malware program targeting Mac OSX and Mac products. There are several things that can be done to mitigate the risk of this rouge product. Do not attempt to purchase this application via PayPal or Credit Card. If you have purchased it then report your credit card or PayPal account compromised immediately.

Currently the risk from this product is low but users in various discussion forums are reporting that they already have downloaded and installed it.

To remove the rouge Anti-Malware software if you downloaded it:

  • If you have purchased this product call your credit card company or contact PayPal and report your account compromised immediately.
  • Boot your Mac into "Safe Mode" by holding the shift key at startup.
  • Clear out your "Downloads" folder or the folder you download files to. (Do this for all users.)
  • Clear out you "Web History." (Do this for all users.)
  • Go into System Preferences>Accounts>Login Items and remove MacDefender from the Startup list for any users. (Check every user including the local administrator account.)
  • In Finder>File> Select search "This Mac." Enter Filename Contains "MacDefend."
  • Select the "+" button and scroll down to Other and add "System files."

  • Select "System Files are Included"

  • Delete the Application by moving to the trash along with items in the Startup folder or files associated with MACDefender. This includes web pages in the cache /Library/StartupItems or ~/Library/StartupItems.

  • Securely Empty Trash.
  • Change all passwords for administrators and users on your Mac.
  • Change your keyChain Password, make it different from the login password.
  • As a precaution we also higly recommend that you change your passwords saved in browsers from Web Sites, especially iTunes and mail providers. (This is a good monthly or bi-monthly practice depending on your organization.)

How to Protect yourself:

  • Do not install any program called MacDefender.
  • Make sure "Open Safe Files" is deselected in Safari.
  • Select "Clear Auto-Opening" settings in chrome://settings/advanced.
  • Download files only to the Download folder that is in each users home directory.
  • Set Remove Downloads to "When Safari Quits." Manually clear this folder for other Browsers.
  • Make sure that "Block Pop-Up Windows" is on.
  • Never do Web Surfing as the Administrator, carry out daily task as a user that does not have administrator privileges.
  • Never use Safari on a Mac OSX Server.
  • Download and confirm the hash before installing any files on assets in your control. (Recommended for enterprise customers.)
  • Make sure "Auto Fill" is de-selected for all.
  • Install a full featured anti-virus software, XProtect does not scan Meta Package File (.MPKG). (See references below.)

We continue to evaluate the risk created by rouge installers and malware related to Apple products. The "Human Interface Guidelines" which are key for any successful Apple developer to follow also creates risk skewed by users expectations of the Apple experience. We expect this to only increase in the future.

In our independent testing, using XCode and very little effort, we created various rouge installers which successfully convinced many Mac OSX users and Administrators they were safe to install. Far more Mac users were convinced by the Malware's ability to conform with the Apple operating system experience and never considered the source.

In our view the most threatening form of malware for Apple Productions is one that focuses on the MacOSX or iOS experience for the user. (This is very true for all GUI based computing devices, just more so on a platform that is experience driven.) Windows administrators and users have had to deal with this threat for sometime, whose experiences can beneficial as this threat continues to grow.

If you have not done so already we recommend installation of a complete Anti-Virus and Internet security package. Our favorite in Intego's Internet Barrier and we are very excited about F-Secure's beta offering. (Beta is not recommended for production critical systems.)

View Details

Google has released Chrome update 11.0.696.57 to the stable channel. The update address various security fixes. This is directly taken from the reference link attached.

  • [61502] High CVE-2011-1303: Stale pointer in floating object handling. Credit to Scott Hess of the Chromium development community and Martin Barbella.
  • [70538] Low CVE-2011-1304: Pop-up block bypass via plug-ins. Credit to Chamal De Silva.
  • [Linux / Mac only] [70589] Medium CVE-2011-1305: Linked-list race in database handling. Credit to Kostya Serebryany of the Chromium development community.
  • [$500] [71586] Medium CVE-2011-1434: Lack of thread safety in MIME handling. Credit to Aki Helin.
  • [72523] Medium CVE-2011-1435: Bad extension with ‘tabs’ permission can capture local files. Credit to Cole Snodgrass.
  • [Linux only] [72910] Low CVE-2011-1436: Possible browser crash due to bad interaction with X. Credit to miaubiz.
  • [$1000] [73526] High CVE-2011-1437: Integer overflows in float rendering. Credit to miaubiz.
  • [$1000] [74653] High CVE-2011-1438: Same origin policy violation with blobs. Credit to kuzzcc.
  • [Linux only] [74763] High CVE-2011-1439: Prevent interference between renderer processes. Credit to Julien Tinnes of the Google Security Team.
  • [$1000] [75186] High CVE-2011-1440: Use-after-free with tag and CSS. Credit to Jose A. Vazquez.
  • [$500] [75347] High CVE-2011-1441: Bad cast with floating select lists. Credit to Michael Griffiths.
  • [$1000] [75801] High CVE-2011-1442: Corrupt node trees with mutation events. Credit to Sergey Glazunov and wushi of team 509.
  • [$1000] [76001] High CVE-2011-1443: Stale pointers in layering code. Credit to Martin Barbella.
  • [$500] [Linux only] [76542] High CVE-2011-1444: Race condition in sandbox launcher. Credit to Dan Rosenberg.
  • [76646] Medium CVE-2011-1445: Out-of-bounds read in SVG. Credit to wushi of team509.
  • [$3000] [76666] [77507] [78031] High CVE-2011-1446: Possible URL bar spoofs with navigation errors and interrupted loads. Credit to kuzzcc.
  • [$1000] [76966] High CVE-2011-1447: Stale pointer in drop-down list handling. Credit to miaubiz.
  • [$1000] [77130] High CVE-2011-1448: Stale pointer in height calculations. Credit to wushi of team509.
  • [$1000] [77346] High CVE-2011-1449: Use-after-free in WebSockets. Credit to Marek Majkowski.
  • [77349] Low CVE-2011-1450: Dangling pointers in file dialogs. Credit to kuzzcc.
  • [$2000] [77463] High CVE-2011-1451: Dangling pointers in DOM id map. Credit to Sergey Glazunov.
  • [$500] [77786] Medium CVE-2011-1452: URL bar spoof with redirect and manual reload. Credit to Jordi Chancel.
  • [$1500] [79199] High CVE-2011-1454: Use-after-free in DOM id handling. Credit to Sergey Glazunov.
  • [79361] Medium CVE-2011-1455: Out-of-bounds read with multipart-encoded PDF. Credit to Eric Roman of the Chromium development community.
  • [79364] High CVE-2011-1456: Stale pointers with PDF forms. Credit to Eric Roman of the Chromium development community.

View Details

Apple has released iTunes 10.2.2 for Windows and Mac OSX. The Mac OSX update includes the following fixes. 

  • Addresses an issue where iTunes may become unresponsive when syncing an iPad.
  • Resolves an issue which may cause syncing photos with iPhone, iPad, or iPod touch to take longer than necessary.
  • Fixes a problem where video previews on the iTunes Store may skip while playing.
  • Addresses other issues that improve stability and performance.
  • Sync with your iPhone, iPad, or iPod touch with iOS 4.3.
  • Improved Home Sharing. Browse and play from your iTunes libraries with Home Sharing on any iPhone, iPad, or iPod touch with iOS 4.3.

View Details

Google has released Chrome 10.0.648.205 to the stable channel which fixes the Flash Zero day along with the listing below. (Mac Only)

  • [75629] Critical CVE-2011-1301: Use-after-free in the GPU process. Credit to Google Chrome Security Team (Inferno).
  • [$1000] [78524] Critical CVE-2011-1302: Heap overflow in the GPU process. Credit to Christoph Diehl.

View Details

Apple has released Safari version 5.0.5. to address two issues within WebKit. Users should apply this update promptly. 

View Details

Apple has released Apple-SA-2011-04-14-4 Security Update 2011-002 for Mac OSX and Mac OSX Server to address the Certificate of Trust Policy issue related to the Comodo CA compromise. This update is critical, a reboot is required after the update.