Reading some subsequent followups, one poster indicates a hacker would need to know the root password for your Mac to hack into it, which if true means this may not be as major a problem as first publicised.
" you have to have root first folks The very first step in the exploit requires you to use the 'sudo' command which means you have to have an administrator or root account on the machine before you can do this. If you have root access you can already do anything you want to from the machine. The real problem with this is that your update information could be hijacked at someone elses DNS server or web caching server. But you know which machines you're caching through and what your DNS servers are, someone would have to hack them at your ISP or business. (which might not be that hard since most smaller companies are probably using windows for this) You still have to click "install" before anything happens. This is no reason for panic, however Apple should move the connection to an SSL layer at the very least." http://forums.maccentral.com/wwwthreads/showflat.php?Cat=&Board=news020708updatephp&Number=206367&page=&view=expanded&sb=5&o=&part=&returnto=http://maccentral.macworld.com/news/0207/08.update.php You might like to remain cautious until this is verified from reputable sources. -Mart At 11:02 AM +0800 9/7/02, Martin Hill wrote: >For the moment, you'd better not run Apple's automatic Software >update under OS X (or Mac OS 9 for that matter). > >These articles detail that there is no encryption employed by Apple >for the Update system and thus it's trivial for a hacker to spoof >Apple's updates service and install a back-door into your Mac which >allows them root access to everything. > >What's more, a hacker has created several programs that take >advantage of this exploit so it's not just an academic question >either. http://www.cunap.com/~hardingr/projects/osx/exploit.html > >As such, you'd better stop running Apple's Software Update engine for >the time being until things become clearer.... > >http://news.zdnet.co.uk/story/0,,t269-s2118730,00.html >http://www.workingmac.com/inetd/164.wm >http://online.securityfocus.com/archive/1/280964 > >There is no patch available yet, so just don't run any updates for >the time being. > >Very, very, very bad of Apple to allow this sort of security breach! >No encryption in the update engine - how could Apple do that?! > >(Assuming all of this is verified - it certainly sounds pretty dinkum) > >:-( > >-Mart >-- >------------------------------------------------------------- >Martin Hill mailto:[EMAIL PROTECTED] >Multimedia Consultant Home Page: http://mart.curtin.edu.au >Educational & Online Technologies, Information Systems, Curtin University >Mobile: 0417-967-969 wk: (08)9266-3101 Fax: (08)9266-3826 > >-- The WA Macintosh User Group Mailing List -- >Archives - <http://www.wamug.org.au/mailinglist/archives.html> >Guidelines - <http://www.wamug.org.au/mailinglist/guidelines.html> >Unsubscribe - <mailto:[EMAIL PROTECTED]> > >Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/ -- ------------------------------------------------------------- Martin Hill mailto:[EMAIL PROTECTED] Multimedia Consultant Home Page: http://mart.curtin.edu.au Educational & Online Technologies, Information Systems, Curtin University Mobile: 0417-967-969 wk: (08)9266-3101 Fax: (08)9266-3826 [Non-text portions of this message have been removed]

