Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > macOS > New Security Update out today (Mar. 1)

New Security Update out today (Mar. 1)
Thread Tools
CharlesS
Posting Junkie
Join Date: Dec 2000
Status: Offline
Reply With Quote
Mar 1, 2006, 07:46 PM
 
Seems to fix the infamous shell script exploit, as well as a bunch of other nasty-looking bugs. Therefore, everyone should download it.

http://docs.info.apple.com/article.html?artnum=303382

Ticking sound coming from a .pkg package? Don't let the .bom go off! Inspect it first with Pacifist. Macworld - five mice!
     
rickey939
Addicted to MacNN
Join Date: Jul 2005
Location: Cooperstown '09
Status: Offline
Reply With Quote
Mar 1, 2006, 07:49 PM
 
Installed just fine here.
     
moodymonster
Mac Elite
Join Date: Sep 2003
Location: London
Status: Offline
Reply With Quote
Mar 1, 2006, 07:51 PM
 
downloaded, restarted tried oompa loompa demo file:

http://www.heise.de/security/dienste.../Heise.jpg.zip

file contents:

Code:
/bin/ls -al echo echo echo "heise Security: Sie sind verwundbar." echo echo
lists your home directory. that's all, drag the file over a text editor and it'll show you the text.

The new update now tells me this file isn't what it's supposed to be.

Everything else (OS wise) seems to run fine.
( Last edited by moodymonster; Mar 1, 2006 at 09:02 PM. )
     
Chris Grande
Senior User
Join Date: Mar 2002
Location: CT
Status: Offline
Reply With Quote
Mar 1, 2006, 07:55 PM
 
It does warn you but it still leaves a safe looking Heise.jpg file on your desktop. All this update does is stop all of this from happening automatically, however it doesn't stop code from hiding inside a file that looks just like a jpg. The system should really warn you if a .jpg .mov, etc try to open using Terminal. There is no reason for that. It shouldn't just warn you it should completely block it, and tell you to go to File -> Open in Terminal if you wish to open this file.

Also if you have Virex running with 'active scanning' enabled downloading this file will cause Safari to crash.
     
rickey939
Addicted to MacNN
Join Date: Jul 2005
Location: Cooperstown '09
Status: Offline
Reply With Quote
Mar 1, 2006, 07:59 PM
 
Originally Posted by moodymonster
downloaded, restarted tried oompa loompa demo file:

http://www.heise.de/security/dienste.../Heise.jpg.zip

tells me it's dodgy.

Everything else seems to run fine.
What does the code in that file do exactly?
     
Orion27
Mac Elite
Join Date: Aug 2002
Location: Safe House
Status: Offline
Reply With Quote
Mar 1, 2006, 08:05 PM
 
Open safe files after download is still checked!
     
rickey939
Addicted to MacNN
Join Date: Jul 2005
Location: Cooperstown '09
Status: Offline
Reply With Quote
Mar 1, 2006, 08:06 PM
 
Originally Posted by Orion27
Open safe files after download is still checked!
Umm, why do you think it would have been unchecked? Nowhere does Apple state this update is supposed to change that setting.
     
rickey939
Addicted to MacNN
Join Date: Jul 2005
Location: Cooperstown '09
Status: Offline
Reply With Quote
Mar 1, 2006, 08:14 PM
 
Originally Posted by Chris Grande
It does warn you but it still leaves a safe looking Heise.jpg file on your desktop. All this update does is stop all of this from happening automatically, however it doesn't stop code from hiding inside a file that looks just like a jpg. The system should really warn you if a .jpg .mov, etc try to open using Terminal. There is no reason for that. It shouldn't just warn you it should completely block it, and tell you to go to File -> Open in Terminal if you wish to open this file.
I totally 100% agree with you. Apple has only partially addressed this issue.
     
JKT
Professional Poster
Join Date: Jan 2002
Location: London, UK
Status: Offline
Reply With Quote
Mar 1, 2006, 08:18 PM
 
The code in the test file causes Terminal to open and it runs a script to show you the contents of the top level of your home directory. That is all.

This is a band aid fix for this hole, but at least it is doing something - one suspects it is going to take a lot longer to fix the underlying flaw that means the file still looks innocuous in the Finder.
     
baw
Mac Elite
Join Date: Jun 2005
Status: Offline
Reply With Quote
Mar 1, 2006, 08:39 PM
 
Everything feels snappier®.
     
TETENAL
Addicted to MacNN
Join Date: Aug 2004
Location: FFM
Status: Offline
Reply With Quote
Mar 1, 2006, 09:14 PM
 
Originally Posted by moodymonster
downloaded, restarted tried oompa loompa demo file.
This has nothing to with the oompa/loompa Leap-A thing.
     
slugslugslug
Mac Elite
Join Date: Jan 2002
Location: Durham, NC
Status: Offline
Reply With Quote
Mar 1, 2006, 09:58 PM
 
It doesn't seem worth starting a new thread in Applications for this, so:

What's Safari's build number after the update?
     
moodymonster
Mac Elite
Join Date: Sep 2003
Location: London
Status: Offline
Reply With Quote
Mar 1, 2006, 10:00 PM
 
Originally Posted by slugslugslug
It doesn't seem worth starting a new thread in Applications for this, so:

What's Safari's build number after the update?
Version 2.0.3 (417.8)
     
slugslugslug
Mac Elite
Join Date: Jan 2002
Location: Durham, NC
Status: Offline
Reply With Quote
Mar 1, 2006, 10:03 PM
 
Originally Posted by moodymonster
Version 2.0.3 (417.8)
Oh, good, then I don't have to go editing Saft's .plist. Thanks.
     
allblue
Forum Regular
Join Date: May 2005
Location: Somewhere they can't find me
Status: Offline
Reply With Quote
Mar 1, 2006, 11:02 PM
 
Not quite sure what forum etiquette is here, but I just picked up this posting from VL-Tone at MacRumours:


"Well the security fix is more deep than what you think. With the update, the Heise.jpg file won't open in the terminal even when double-clicked .
Do a get info on the file, and you'll see a difference from before the update. The get info box shows "Kind: JPEG Image" instead of "Kind: Terminal Document". If you double-click it, Preview tries to open it and report a "corrupted file" error.
Sure the actual data inside the file can be a malicious script, but there is now no way to make it execute unless you manually remove the extension after downloading and force the terminal to open it.
If you do a get info after removing the extension, you see that it shows: "Kind: Unix Executable File".
So you say "Someone can still put a custom icon on these and make people click on it!" without doing get info. Wrong! Double click this Unix Executable and what happens? It opens in TextEdit!!
It means that also squashes the Leap.A trojan to pieces. Try to download Leap.A, double click on it and it opens in TextEdit, showing you the malicious terminal code!
Apple took these issues seriously and it shows.
From now on, with this update, there is no known way to make a trojan on OS X that doesn't have the .app extension, which is forced to appear even with "show extensions" off. And each of those .app will warn you the first time you run them. And Safari will warn you if it finds .app files or a compressed file it cannot check before completing the download."


This is excellent from Apple! Nothing can run as a trojan unless it has a .app file name, and any new application being opened for the first time will ask you if you want to run it! Only seven days since Leap-A - very impressive Steve and co.!
"Believe nothing, no matter where you heard it, or who has said it, not even if I have said it, unless it agrees with your own reason and your own common sense."

Buddha
     
CharlesS  (op)
Posting Junkie
Join Date: Dec 2000
Status: Offline
Reply With Quote
Mar 1, 2006, 11:08 PM
 
^ This is just not true. The Heise example still opens in the Terminal when double-clicked on my iMac.

Ticking sound coming from a .pkg package? Don't let the .bom go off! Inspect it first with Pacifist. Macworld - five mice!
     
rickey939
Addicted to MacNN
Join Date: Jul 2005
Location: Cooperstown '09
Status: Offline
Reply With Quote
Mar 1, 2006, 11:11 PM
 
Originally Posted by CharlesS
^ This is just not true. The Heise example still opens in the Terminal when double-clicked on my iMac.
Exactly.

     
allblue
Forum Regular
Join Date: May 2005
Location: Somewhere they can't find me
Status: Offline
Reply With Quote
Mar 1, 2006, 11:35 PM
 
Sorry! I'm just following it over there and so I'd better keep it going a bit! And it's 3;30 am here! Bugger! If 'Open Safe Files after downloading' is ON in Safari it will open in the application related to the file name. So Leap-A with it's .jpg would give you a Preview error message saying 'corrupt file' - so the concealed .app cannot run.
"Believe nothing, no matter where you heard it, or who has said it, not even if I have said it, unless it agrees with your own reason and your own common sense."

Buddha
     
allblue
Forum Regular
Join Date: May 2005
Location: Somewhere they can't find me
Status: Offline
Reply With Quote
Mar 1, 2006, 11:38 PM
 
...or you could go to MacRumours yourself and let me go to bed!
"Believe nothing, no matter where you heard it, or who has said it, not even if I have said it, unless it agrees with your own reason and your own common sense."

Buddha
     
allblue
Forum Regular
Join Date: May 2005
Location: Somewhere they can't find me
Status: Offline
Reply With Quote
Mar 1, 2006, 11:44 PM
 
Thank you, good night
"Believe nothing, no matter where you heard it, or who has said it, not even if I have said it, unless it agrees with your own reason and your own common sense."

Buddha
     
rickey939
Addicted to MacNN
Join Date: Jul 2005
Location: Cooperstown '09
Status: Offline
Reply With Quote
Mar 2, 2006, 12:42 AM
 
Originally Posted by allblue
Sorry! I'm just following it over there and so I'd better keep it going a bit! And it's 3;30 am here! Bugger! If 'Open Safe Files after downloading' is ON in Safari it will open in the application related to the file name. So Leap-A with it's .jpg would give you a Preview error message saying 'corrupt file' - so the concealed .app cannot run.
But if the option is OFF within Safari it doesn't follow that behavior? Hmm, that doesn't make any sense.
     
Chris Grande
Senior User
Join Date: Mar 2002
Location: CT
Status: Offline
Reply With Quote
Mar 2, 2006, 01:29 AM
 
Originally Posted by rickey939
But if the option is OFF within Safari it doesn't follow that behavior? Hmm, that doesn't make any sense.
And its not true, if Open Safe files is on it gives you the warning but doesn't try to open the file. The file is just on your Desktop. If you double click it Terminal still opens. Apple didn't fix the larger issue. I'm not sure what the person over at MacRumors is doing.
     
CharlesS  (op)
Posting Junkie
Join Date: Dec 2000
Status: Offline
Reply With Quote
Mar 2, 2006, 02:43 AM
 
Yeah, it's actually safer to have the "safe" files thing on now, since that's the only way you'll get warned...

Ticking sound coming from a .pkg package? Don't let the .bom go off! Inspect it first with Pacifist. Macworld - five mice!
     
moodymonster
Mac Elite
Join Date: Sep 2003
Location: London
Status: Offline
Reply With Quote
Mar 2, 2006, 06:02 AM
 
there's PA that does offers some protection:

http://www.unsanity.com/haxies/pa/

Paranoid Android can now notify you when a file is launched with a custom application (one other than the default one for the document's file type). This does not affect opening documents from within applications.
Updated to mitigate the recent Safari/LaunchServices exploit described in detail here.
Last time something like this happened, Apple's solution was basically what unsanity did.
     
rickey939
Addicted to MacNN
Join Date: Jul 2005
Location: Cooperstown '09
Status: Offline
Reply With Quote
Mar 2, 2006, 08:52 AM
 
Originally Posted by moodymonster
there's PA that does offers some protection:

http://www.unsanity.com/haxies/pa/



Last time something like this happened, Apple's solution was basically what unsanity did.
Wow, that works beautifully...just what Apple should have done. Thank you!
     
iKevin
Grizzled Veteran
Join Date: Nov 2000
Location: USA
Status: Offline
Reply With Quote
Mar 2, 2006, 03:30 PM
 
After installing the update my Mail.app is pretty much gone. ? for the doc icon and an applescript icon in the applications folder that doesn't do anything.
     
iKevin
Grizzled Veteran
Join Date: Nov 2000
Location: USA
Status: Offline
Reply With Quote
Mar 2, 2006, 03:46 PM
 
Disregard post about new widgets. Figured out I hadn't booted up the iMac since the last update added them :-)
( Last edited by iKevin; Mar 3, 2006 at 04:13 PM. )
     
Thinine
Mac Elite
Join Date: Jul 2002
Status: Offline
Reply With Quote
Mar 2, 2006, 03:57 PM
 
Those were in a previous update.
     
mdc
Addicted to MacNN
Join Date: Feb 2003
Location: NY²
Status: Offline
Reply With Quote
Mar 2, 2006, 04:28 PM
 
@iKevin, those came with 10.4.5. Pretty sure it was .5. I'll be corrected if I'm wrong.
     
rickey939
Addicted to MacNN
Join Date: Jul 2005
Location: Cooperstown '09
Status: Offline
Reply With Quote
Mar 2, 2006, 04:42 PM
 
Originally Posted by mdc
@iKevin, those came with 10.4.5. Pretty sure it was .5. I'll be corrected if I'm wrong.
v10.4.4 brought the new and updated widgets.

     
iKevin
Grizzled Veteran
Join Date: Nov 2000
Location: USA
Status: Offline
Reply With Quote
Mar 3, 2006, 04:15 PM
 
Yeah, i'm an idiot and hadn't booted the iMac in a while. . . . Thanks for the info though
     
Webscreamer
Mac Elite
Join Date: Dec 2002
Location: Silicon Valley
Status: Offline
Reply With Quote
Mar 3, 2006, 11:48 PM
 
I downloaded that file and it ran in my terminal.... Ummmmm did this just mess my system up?!?!

I was expecting a message like you guys said!!!

help!
Anyone who would letterspace blackletter would steal sheep. - Frederic Goudy
     
rickey939
Addicted to MacNN
Join Date: Jul 2005
Location: Cooperstown '09
Status: Offline
Reply With Quote
Mar 4, 2006, 11:27 AM
 
Originally Posted by Webscreamer
I downloaded that file and it ran in my terminal.... Ummmmm did this just mess my system up?!?!

I was expecting a message like you guys said!!!

help!
The code in the test file causes Terminal to open and it runs a script to show you the contents of the top level of your home directory. That is all. Your system is not messed up.
     
alphasubzero949
Mac Elite
Join Date: Jan 2003
Location: 127.0.0.1
Status: Offline
Reply With Quote
Mar 4, 2006, 04:18 PM
 
Another half-baked "security" update from Apple.

This fix only takes care of the symptoms but avoids the real problems going back to resource forks, but that's for another discussion.

If you insist on using Safari, first quit it and open the Terminal. Enter the following command all in one shot:

sudo defaults write com.apple.Safari AutoOpenSafeDownloads -bool NO;defaults write /Library/Preferences/com.apple.Safari AutoOpenSafeDownloads -bool NO

This effectively places a Safari preference file at the root Library level that will prevent "safe" files from automatically downloading for any new user. It's the equivalent of unchecking the box in the General prefs. If you were to edit com.apple.Safari.plist and remove AutoOpenSafeDownloads, the default of "Open Safe Files" will be checked once again. You have to tell it NO (either by unchecking the box) or performing the command to make it a system-wide setting.

As far as the PithHelmets and Safts breaking with every Safari update, I recommend using Privoxy. I found it a lot easier to configure and even though it has very strict filtering out of the box, you can freely customize it however you want. And it won't break.


One last caution: Fink and Darwin Ports users will find that rsync is broken by this update. Simply install rsync via Fink and/or Darwin Ports and you'll be back in business.
     
   
 
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Top
Privacy Policy
All times are GMT -4. The time now is 01:47 PM.
All contents of these forums © 1995-2017 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2017, Jelsoft Enterprises Ltd.,