Apple Developer Center Outage Fixed 'Remote Code Execution' Flaw

xcodelogoApple has released new details (via @cabel) on the security flaw that caused the Developer Center to be down for more than a week, noting via its Apple Web Server notifications page that a "remote code execution issue" was fixed.

On the site, Apple credits 7dscan.com and SCANV of www.knownsec.com for reporting the bug on July 18, which is the same day the Developer Center was taken offline. During the downtime, Apple reported that the Developer Center website had been hacked, with an intruder attempting "to secure personal information" from registered developers. The company noted that while sensitive information was encrypted, some developer names, mailing addresses, and/or email addresses may have been acquired.

The eight-day outage required a complete overhaul of Apple's developer systems and a restoration plan that slowly brought services back online.

While security researcher Ibrahim Balic speculated that he might have been behind the security breach, it is now clear that the issue he reported was unrelated to the major flaw that caused the downtime. Apple credits Ibrahim with reporting a separate iAd Workbench vulnerability on July 22. The vulnerability allowed Balic to obtain both names and Apple IDs of users.

applesecuritysite
On August 10, Apple reported that all of its developer services were back online, a full 23 days after the outage first occurred. As a result of the downtime, Apple gave all developers a one month extension on their developer memberships.

Top Rated Comments

bbeagle Avatar
140 months ago
Glad its finally all resolved. I'm sure someone is trying to find the next venerability.
ven·er·a·ble (vnr--bl)
adj.
1. Commanding respect by virtue of age, dignity, character, or position.
2. Worthy of reverence, especially by religious or historical association: venerable relics.
3. Venerable Abbr. Ven. or V.
a. Roman Catholic Church Used as a form of address for a person who has reached the first stage of canonization.
b. Used as a form of address for an archdeacon in the Anglican Church or the Episcopal Church.

vener·a·ble·ness, vener·a·bili·ty n.
vener·a·bly adv.
Score: 3 Votes (Like | Disagree)
macsrcool1234 Avatar
140 months ago
And you know this.... how exactly?



Key word, reported, but not confirmed. So, until that time I'll assume it is also a bug in OS X Server that needs addressing. However, I'll give the benefit of doubt and also throw in that it might be the software running on top of OS X.


Because he knows what he's talking about, unlike you. OSX Server is not designed for that kind of use and would crumble under the load.
Score: 2 Votes (Like | Disagree)
mdnz Avatar
140 months ago
And you know this.... how exactly?



Key word, reported, but not confirmed. So, until that time I'll assume it is also a bug in OS X Server that needs addressing. However, I'll give the benefit of doubt and also throw in that it might be the software running on top of OS X.
OS X server has tons of memory overhead (like the GUI) and is not as scalable as some other solutions. Servers at enterprise level need to be as optimised for one job (granted, depends on the server) as much as possible to reduce overhead and costs.

Bottom line: If you need to host a website which has millions of viewers a day, it's just not efficient nor costfriendly do to it purely on OS X. Also one thing to add is if you look at their job applications for System administrator it's mostly for Solaris/Linux.
Score: 2 Votes (Like | Disagree)
jav6454 Avatar
140 months ago
If they used OS X, I hope they released a patch for the system.
Score: 2 Votes (Like | Disagree)
Terrin Avatar
140 months ago
Think of readers whose first language isn't English. When you use unusual words with spelling that is not found in any dictionary, they can have a hard time finding out what you mean. Ibrahim Balic is quite possibly one of them.

Now whatever was said about him, he deserved it. He took actions that he shouldn't have taken and openly boasted about it. If you want to appear as the tough guy who brought Apple's developer site down, then you deserve anything that comes as a reaction.

I am confused. He did what all security researchers do. Namely try to find bugs. He then quietly reported the bugs to Apple. The site then went down the same day. The guy freaked thinking he was the cause. To try and cover himself he posted a video outlining what happened. He was clearly worried about Apple coming after him. Turns out Apple credited him with discovering another unrelated bug. The guy acted properly and never boasted.
Score: 1 Votes (Like | Disagree)
rdlink Avatar
140 months ago
Queue the, "Apple owes us more free time." rants.
Score: 1 Votes (Like | Disagree)

Popular Stories

apple crush ad

Apple Apologizes for 'Crush' iPad Pro Ad, Won't Put It on TV

Friday May 10, 2024 8:32 am PDT by
When introducing the new M4 iPad Pro models, Apple showed a video of a hydraulic press crushing all manner of creative tools, including musical instruments, electronic equipment, arcade games, paint and brushes, computers, cameras, and more, with the aim of demonstrating how the iPad represents all of the tools condensed into a single device. The ad was a play on the popular hydraulic press...
ChatGPT for Mac

OpenAI Announces ChatGPT App for Mac, GPT-4 for Free, and More

Monday May 13, 2024 10:43 am PDT by
At its Spring Update event, OpenAI announced that it will be releasing a desktop app for the Mac, as seen in the screenshot below. The app will be rolling out to ChatGPT Plus subscribers starting today, ahead of a wider launch "in the coming weeks." "With a simple keyboard shortcut (Option + Space), you can instantly ask ChatGPT a question," OpenAI's press release says. In addition, Voice...
Beyond iPhone 13 Better Blue Face ID Single Camera Hole

10 Reasons to Wait for Next Year's iPhone 17

Thursday May 9, 2024 9:00 am PDT by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models concurrently, which is why we sometimes get rumored feature leaks so far ahead of launch. The iPhone 17 series is no different, and already we have some idea of what to expect from Apple's 2025 smartphone lineup. If you plan to skip...
iOS 17

Apple Releases iOS 17.5 With Cross-Platform Tracking Detection, EU App Downloads From Websites and More

Monday May 13, 2024 10:04 am PDT by
Apple today released iOS 17.5 and iPadOS 17.5, major updates to the iOS 17 and iPadOS 17 operating system updates that came out last September. The 17.5 updates come more than two months after the launch of iOS 17.4 and iPadOS 17.4. iOS 17.5 and iPadOS 17.5 can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. In the European Union, ...
apple tv 4k red image

Apple Releases tvOS 17.5

Monday May 13, 2024 10:01 am PDT by
Apple today released tvOS 17.5, the fifth update update to the tvOS 17 operating system that came out last September. tvOS 17.5 comes two months after the release of tvOS 17.4. tvOS 17.5 can be downloaded using the Settings app on the ‌Apple TV‌. Go to System > Software Update to get the new software. ‌Apple TV‌ owners who have automatic software updates activated will be upgraded to ...
macos sonoma 4

Apple Releases macOS Sonoma 14.5 With Apple News+ Improvements

Monday May 13, 2024 10:04 am PDT by
Apple today released macOS Sonoma 14.5, the fifth update to the macOS Sonoma operating system that launched last September. macOS Sonoma 14.5 comes more than two months after the launch of macOS Sonoma 14.4. The ‌‌‌‌‌macOS Sonoma‌‌‌ 14.5 update can be downloaded for free on all eligible Macs using the Software Update section of System Settings. There's also a macOS 13.6.7...