OS X Vulnerability Can Allow Superuser Access to Unauthorized Users

FilevaultUsers looking to exploit a vulnerability in the Sudo Unix command, originally reported back in March, have received some assistance, reports Ars Technica.

The developers of Metasploit, software that makes it easier to misuse vulnerabilities in operating systems and applications, have added the Sudo vulnerability to their software suite. All versions of OS X from OS X Lion 10.7 through the current Mountain Lion 10.8.4 remain vulnerable.

Mac users should realize that an attacker must satisfy a variety of conditions before being able to exploit this vulnerability. For one, the end-user who is logged in must already have administrator privileges. And for another, the user must have successfully run sudo at least once in the past. And of course, the attacker must already have either physical or remote shell access to the target machine. In other words: this exploit can't be used in the kind of drive-by webpage attacks that last year infected some 650,000 Macs with the Flashback malware. This doesn't mean it's a non-issue though, since the exploit can be used in concert with other attacks to magnify the damage they can do.

Most of the recent exploits in Mac OS X have been related to Java, which Apple completely blocked earlier this year over security vulnerabilities, though Apple did release a standalone malware removal tool to help clean machines that were affected by a number of Java vulnerabilities.

OS X has been targeted more in recent years as it has gained in popularity. The Janicab.A malware was discovered last month, while another program called macs.app was discovered in May. That app captured and stored screenshots.

Top Rated Comments

batchtaster Avatar
101 months ago
Since this is a "flaw" (to the extent it has been described) in sudo, it's not Mac-specific. Other flavors of UNIX are also affected. But it's more fun and gets more hits and attention when you call it an "OS X Vulnerability", as if it's Apple's mistake or fault and not due to an issue (if that's what it is) in one of several hundred non-Apple projects (http://www.sudo.ws).
Score: 10 Votes (Like | Disagree)
sjinsjca Avatar
101 months ago
"I'm not too sure why a user who already has admin access would bother using an exploit to gain admin privilege - an access level he already has.

Admin != root
Score: 8 Votes (Like | Disagree)
pdjudd Avatar
101 months ago
I'm not too sure why a user who already has admin access would bother using an exploit to gain admin privilege - an access level he already has.
Admin and root are two different levels of access. You can do some things with root that you cannot do with admin. Root is the deepest access one can have - but it's not really the goal of most hackers. An administrator account is probably the most that an attacker really needs since they can pretty much do anything they need with that account.

So an exploit that needs admin rights access and one that rehires you to have used sudo isn't one that is high priority. The number of users that run sudo at all is really small, and from a security standpoint, if you have admin rights, all security goes out the window. In other words, you don't have security.
Score: 8 Votes (Like | Disagree)
mikethebigo Avatar
101 months ago
Sudo make me a sandwich.
Score: 6 Votes (Like | Disagree)
RabidMacFan Avatar
101 months ago
You don't need to run metasploit to exploit this bug.

The following command should give you root if you are logged in to OS X as an Administrator and have used the "sudo" command at least once in the past. It will also set your system clock to 01/01/1970.

sudo -k
systemsetup -setusingnetworktime Off -settimezone GMT -setdate 01:01:1970 -settime 00:00
sudo su

To set your system clock back to normal, go into the System Preferences and set the time and time zone back to the way it was.

To prevent somebody from abusing this attack, you will need to run the following command after every time you use the sudo command, until it gets patched.
sudo -K
Score: 6 Votes (Like | Disagree)
Dalton63841 Avatar
101 months ago
"For one, the end-user who is logged in must already have administrator privileges. And for another, the user must have successfully run sudo at least once in the past."

I'm not too sure why a user who already has admin access would bother using an exploit to gain admin privilege - an access level he already has.
What it is saying is that if an attacker already has access to your machine, AND you are on an administrator account, AND you have opened Terminal and used sudo, THEN they could maybe gain root access to your account.
Score: 6 Votes (Like | Disagree)

Top Stories

13 inch macbook pro m1

Apple to Announce Redesigned 14-Inch and 16-Inch MacBook Pro at WWDC, Says Wedbush Analyst

Wednesday June 2, 2021 10:44 pm PDT by
Apple plans to announce its long-rumored 14-inch and 16-inch MacBook Pro with Apple silicon at WWDC, taking place in less than five days, according to Wedbush analyst Daniel Ives. In a note to investors seen by MacRumors, Ives says alongside the normally expected announcement of new versions of iOS, iPadOS, macOS, watchOS, and tvOS, Apple is planning a "few surprises," including the...
16 inch macbook pro m2 render

Next-Generation 16-Inch MacBook Pro Seemingly Filed in Regulatory Database Ahead of WWDC

Thursday June 3, 2021 8:30 am PDT by
Apple is widely rumored to be planning new 14-inch and 16-inch MacBook Pro models, each with a mini-LED display and an improved iteration of the M1 chip. The notebooks are expected to feature a new design with a flatter top and bottom and more ports, including the return of an HDMI port, SD card slot, and a magnetic power cable. Rumors also suggest the Touch Bar will be retired in favor of...
imessage wwdc 2021

Apple's iMessage to Finally Get Major Update at WWDC?

Thursday June 3, 2021 10:50 am PDT by
Apple has put iMessage at the center of its promotional materials for WWDC next week, hinting that the company's popular messaging service could be seeing substantial upgrades. iMessage appears to be a central theme in the marketing for this year's WWDC. For example, the placeholder for WWDC's live stream on YouTube, which is already live, features iMessage bubbles, Tapback, and iMessage's...
maxresdefault

2021 Apple TV 4K vs. 2017 Apple TV 4K: Is It Worth Upgrading?

Wednesday June 2, 2021 10:30 am PDT by
Apple in April unveiled a new version of the 4K Apple TV, but on the surface, it's hard to tell it apart from its predecessor because it looks the same as the 2017 model. There are, however, a few internal changes, but are those changes worth upgrading for? That's what we're aiming to find out in our Apple TV 4K hands-on video. Subscribe to the MacRumors YouTube channel for more videos. ...
appleparkempty

Apple Staff Complain About Plans for Return to Office Work in Letter to Tim Cook

Saturday June 5, 2021 1:11 am PDT by
A large group of Apple employees are opposing the company's plans to require three days of in-person work a week from September, according to a internal letter seen by The Verge. In the detailed letter sent yesterday afternoon, addressed to CEO Tim Cook and the company's executive leadership, the Apple employees said that they want a more flexible approach where those who want to work...
16 inch macbook pro m2 render

At Least One New MacBook With Apple Silicon 'Likely' at WWDC, Says Morgan Stanley Analyst

Friday June 4, 2021 7:50 am PDT by
We're just three days away from Apple's annual developers conference, WWDC, but rumors are still divided as to whether new MacBook Pro models with Apple silicon will be announced at Apple's opening keynote on Monday. Morgan Stanley analyst Katy Huberty weighed in on the matter in a research note shared with MacRumors today, claiming it's "likely" that Apple will announce at least one new...
16 inch macbook pro m2 render

Redesigned MacBook Pro Models May Not Ship to Customers Until Late 2021

Friday June 4, 2021 3:45 am PDT by
The long-rumored and highly anticipated redesigned 16-inch MacBook Pro with Apple silicon will enter its phase of mass production in the first quarter of next year, according to industry sources cited in a paywalled DigiTimes report. According to the report, the smaller 14-inch MacBook Pro will enter "volume production" in the fourth quarter of this year, while the larger 16-inch model is...
apple park drone june 2018 2

Apple Employees Asked to Return to Offices for Three Days a Week Starting in September

Wednesday June 2, 2021 3:58 pm PDT by
Apple corporate employees will be returning to the office for three days a week starting in early September, Apple CEO Tim Cook told workers today in a memo that was seen by The Verge. "For all that we've been able to achieve while many of us have been separated, the truth is that there has been something essential missing from this past year: each other," Cook said in the memo. "Video...
iOS 15 icon mock in article

Bloomberg: iPadOS 15 to Feature Improved Multitasking, Redesigned Notification Banner for iOS 15

Saturday June 5, 2021 6:38 am PDT by
iPadOS 15 will include improvements to the way users manage multiple apps open at once, in addition to a redesigned incoming notification banner that will also debut in iOS 15, according to Bloomberg's Mark Gurman. In an overview report of what to expect from Apple at its Worldwide Developers Conference on Monday, Gurman reiterates his previous reporting while also providing a few additional ...
iPad mini pro feature

iPad Mini With Slimmer Bezels and No Home Button Coming Later This Year

Thursday June 3, 2021 9:50 pm PDT by
Apple is working on a revamped version of the iPad mini that will feature the first design update the smaller-sized tablet has seen in six years, according to a new report from Bloomberg. The updated iPad mini will feature narrower screen bezels, with Apple also testing a design that does away with the Home button. We've heard several prior rumors about Apple's work on a new version of the...