For the moment, you'd better not run Apple's automatic Software update under OS X (or Mac OS 9 for that matter).

These articles detail that there is no encryption employed by Apple for the Update system and thus it's trivial for a hacker to spoof Apple's updates service and install a back-door into your Mac which allows them root access to everything.

What's more, a hacker has created several programs that take advantage of this exploit so it's not just an academic question either. http://www.cunap.com/~hardingr/projects/osx/exploit.html

As such, you'd better stop running Apple's Software Update engine for the time being until things become clearer....

http://news.zdnet.co.uk/story/0,,t269-s2118730,00.html
http://www.workingmac.com/inetd/164.wm
http://online.securityfocus.com/archive/1/280964

There is no patch available yet, so just don't run any updates for the time being.

Very, very, very bad of Apple to allow this sort of security breach! No encryption in the update engine - how could Apple do that?!

(Assuming all of this is verified - it certainly sounds pretty dinkum)

:-(

-Mart
--
-------------------------------------------------------------
Martin Hill mailto:[EMAIL PROTECTED]
Multimedia Consultant Home Page: http://mart.curtin.edu.au
Educational & Online Technologies, Information Systems, Curtin University
Mobile: 0417-967-969 wk: (08)9266-3101 Fax: (08)9266-3826