on 9/7/02 11:02, Martin Hill at [EMAIL PROTECTED] wrote:

> For the moment, you'd better not run Apple's automatic Software
> update under OS X (or Mac OS 9 for that matter).
> 
> These articles detail that there is no encryption employed by Apple
> for the Update system and thus it's trivial for a hacker to spoof
> Apple's updates service and install a back-door into your Mac which
> allows them root access to everything.
> 
> What's more, a hacker has created several programs that take
> advantage of this exploit so it's not just an academic question
> either. http://www.cunap.com/~hardingr/projects/osx/exploit.html
> 
> As such, you'd better stop running Apple's Software Update engine for
> the time being until things become clearer....

Not nearly as dangerous as it sounds. As David Cake said on the Macgeeks
list "Note that they need to compromise another machine on the same
network segment to do the arp spoof, though. So its not that bad an
attack."

There is some danger but it's not nearly as bad as it seems and if you know
what's supposed to be in the software updates and check package versions of
the open source stuff against sourceforge then you can be pretty safe
against installing a compromised package anyway.