For the moment, you'd better not run Apple's automatic Software
update under OS X (or Mac OS 9 for that matter).
These articles detail that there is no encryption employed by Apple
for the Update system and thus it's trivial for a hacker to spoof
Apple's updates service and install a back-door into your Mac which
allows them root access to everything.
What's more, a hacker has created several programs that take
advantage of this exploit so it's not just an academic question
either. http://www.cunap.com/~hardingr/projects/osx/exploit.html
As such, you'd better stop running Apple's Software Update engine for
the time being until things become clearer....
http://news.zdnet.co.uk/story/0,,t269-s2118730,00.html
http://www.workingmac.com/inetd/164.wm
http://online.securityfocus.com/archive/1/280964
There is no patch available yet, so just don't run any updates for
the time being.
Very, very, very bad of Apple to allow this sort of security breach!
No encryption in the update engine - how could Apple do that?!
(Assuming all of this is verified - it certainly sounds pretty dinkum)
:-(
-Mart
--
-------------------------------------------------------------
Martin Hill mailto:[EMAIL PROTECTED]
Multimedia Consultant Home Page: http://mart.curtin.edu.au
Educational & Online Technologies, Information Systems, Curtin University
Mobile: 0417-967-969 wk: (08)9266-3101 Fax: (08)9266-3826