Reading some subsequent followups, one poster indicates a hacker 
would need to know the root password for your Mac to hack into it, 
which if true means this may not be as major a problem as first 
publicised.

" you have to have root first folks     

The very first step in the exploit requires you to use the 'sudo' 
command which means you have to have an administrator or root account 
on the machine before you can do this. If you have root access you 
can already do anything you want to from the machine.

The real problem with this is that your update information could be 
hijacked at someone elses DNS server or web caching server. But you 
know which machines you're caching through and what your DNS servers 
are, someone would have to hack them at your ISP or business. (which 
might not be that hard since most smaller companies are probably 
using windows for this)

You still have to click "install" before anything happens.

This is no reason for panic, however Apple should move the connection 
to an SSL layer at the very least."
http://forums.maccentral.com/wwwthreads/showflat.php?Cat=&Board=news020708updatephp&Number=206367&page=&view=expanded&sb=5&o=&part=&returnto=http://maccentral.macworld.com/news/0207/08.update.php

You might like to remain cautious until this is verified from 
reputable sources.

-Mart

At 11:02 AM +0800 9/7/02, Martin Hill wrote:
>For the moment, you'd better not run Apple's automatic Software
>update under OS X (or Mac OS 9 for that matter).
>
>These articles detail that there is no encryption employed by Apple
>for the Update system and thus it's trivial for a hacker to spoof
>Apple's updates service and install a back-door into your Mac which
>allows them root access to everything.
>
>What's more, a hacker has created several programs that take
>advantage of this exploit so it's not just an academic question
>either. http://www.cunap.com/~hardingr/projects/osx/exploit.html
>
>As such, you'd better stop running Apple's Software Update engine for
>the time being until things become clearer....
>
>http://news.zdnet.co.uk/story/0,,t269-s2118730,00.html
>http://www.workingmac.com/inetd/164.wm
>http://online.securityfocus.com/archive/1/280964
>
>There is no patch available yet, so just don't run any updates for
>the time being.
>
>Very, very, very bad of Apple to allow this sort of security breach!
>No encryption in the update engine - how could Apple do that?!
>
>(Assuming all of this is verified - it certainly sounds pretty dinkum)
>
>:-(
>
>-Mart
>--
>-------------------------------------------------------------
>Martin Hill mailto:[EMAIL PROTECTED]
>Multimedia Consultant Home Page: http://mart.curtin.edu.au
>Educational & Online Technologies, Information Systems, Curtin University
>Mobile: 0417-967-969 wk: (08)9266-3101 Fax: (08)9266-3826
>
>-- The WA Macintosh User Group Mailing List --
>Archives - <http://www.wamug.org.au/mailinglist/archives.html>
>Guidelines - <http://www.wamug.org.au/mailinglist/guidelines.html>
>Unsubscribe - <mailto:[EMAIL PROTECTED]>
>
>Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/


-- 
-------------------------------------------------------------
Martin Hill mailto:[EMAIL PROTECTED]
Multimedia Consultant Home Page: http://mart.curtin.edu.au
Educational & Online Technologies, Information Systems, Curtin University 
Mobile: 0417-967-969 wk: (08)9266-3101 Fax: (08)9266-3826

[Non-text portions of this message have been removed]