Apple hit by hackers who targeted Facebook last week
reuters.com
reuters.com
I'd be very interested in knowing if myself or coworkers may have been exposed (or in the best case, which waterhole website I've been missing out on)
Even browser updating automatically aren't a panacea: the update itself may be corrupted by an exploit (now that would be a fiasco).
That is precisely the reason people should surf from a separate user account, using very strict firewalling rules.
"iptables -I OUTPUT -p tcp --dport 80 (and 443) -m state --state NEW -m user --user-id 501 -j ACCEPT"
Now it's too bad per-user firewalling cannot be done easily on neither Windows nor OS X.
It's also too bad one user (say the one allowed to surf the Web) cannot display its browser window(s) in another user (say your main account)'s graphical display (neither on Windows nor on OS X).
Or too bad OS X doesn't allow to run two graphical sessions simultaneously (on some version of Windows, if you pay enough, at least you can do that).
All this is trivial to do under Linux.
I'm feeling better and better using Linux as my desktop.
Now it's too bad per-user firewalling cannot be
done easily on neither Windows nor OS X.
I haven't tried this, but pf seems to have the support there, so I'm not sure why you couldn't. It's also too bad one user (say the one allowed
to surf the Web) cannot display its browser window(s)
in another user (say your main account)'s graphical
display (neither on Windows nor on OS X).
$ su testuser$ /Applications/Safari.app/Contents/MacOS/Safari
Seems to work for me.
Or too bad OS X doesn't allow to run two graphical
sessions simultaneously
This is called Fast User Switching on OS X. uid user
Match all TCP or UDP packets sent by or received for a
user. A user may be matched by name or identification
number.
also, since I agree that neither iptables nor ipfw are good enough as UIs, there are a number of graphical firewall apps that allow people to do very very easily filtering per user, per process, per domain, per ip, timed, with different profiles http://www.obdev.at/products/littlesnitch/In the same way a stubborn mathematical proof is trivial, I'm sure.
(Amazing, because look what you've done! Terrible, because almost every other human on this planet could not accomplish your outcome even with guides and training...)
According to the NYTimes, the site is iPhoneDevSDK (not including a clickable link for obvious reasons).
http://bits.blogs.nytimes.com/2013/02/19/apple-computers-hit...
It would be nice if the attack vector were the main focus of the article, but how much publicity would "Java plugin allows Facebook and Apple to be hacked." get.
Here's some perspective: http://www.qualys.com/research/top10/
Also here's their site where you can check your current config: https://browsercheck.qualys.com/
Which browsers are affected? Any browser configured to pass along Java class files or jar archives to Oracle's Java plugin. Chrome, Safari, and Firefox are all potentially affected.
Come on man. Read the Mandiant report on APT1 if you want to get schooled on how to tie groups of hackers together over different campaigns.
> The same software, which infected Macs by exploiting a flaw in a version of Oracle Corp's Java software used as a plug-in on Web browsers, was used to launch attacks against Facebook, which the social network disclosed on Friday.
That being said, even if it is Oracle's "fault", most malware works by exploiting third-party software such as Java or Flash or Acrobat - including most Windows malware. OS X may be "becoming less secure", even though OS X itself hasn't changed, due to the fact that some Java and other exploits are now being used to target OS X machines. This is all covered very fairly in the article.
Write once run anywhere isn't the problem. Write once run anywhere is just a feature that greatly increases the number of machines with a given piece of vulnerable software installed. VMs also tend to be big complicated pieces of software with a huge attack surface, and tend to be written in unsafe languages (C/C++).
If 99% of all browsers used very similar versions of libpng, all with the same vulnerability, we'd see this same problem.
Software monoculture combined with poor incentives to write secure software is the problem.
Edit: since write-once-run-anywhere languages tend to be more safe, it's a shame that more VMs aren't written in (subsets of) their hosted languages. Jikes RVM, PyPy, and Squeak Smalltalk are some notable exceptions.
One of the main reasons I am worried if webkit becomes monolithic, zero day exploits, there will be no running away from it.
This is just a factor of Oracle not paying attention to a product they bought. When Cisco let Linksys (in the consumer market) stagnate, we ended up with lackluster hardware. Not a big deal. When Oracle ignored Java in the consumer market, the damage is quite a bit more extensive due to its sheer ubiquity.
The fact that this is exploitable through a browser plugin makes the risk of infection worse, but doesn't actually make it more cross-platform, per se.
And as you say it certainly doesn't run in the browser on so many disparate systems making watering hole attacks not nearly as damaging if there were to be Python malware in the wild (and I'm sure there are).
Further still, there are attacks through even the most apparently harmless types like maliciously formatted images. If the web was my everyday world, I'd be concerned walking down the street that lines on the street would strangle me.
Aside from that, I believe it is ambiguous as to whether or not publicly traded companies have to disclose incidents that may have adverse effects for investors. In some cases, ambiguous errs on the side of not getting sued or sanctioned.
It's good that companies are coming out. I work in infosec, and it's constantly a battle with clients who take a "it can't happen to a big company like us, we have a professional IT department" mindset. It is happening, constantly, and things only improve when there is awareness.
I also like the forced disclosure to deal with the "they probably won't hack us, and if they do, we will just fix it later and quietly cover it up" companies. There are a fair number of those as well. Doing things right costs money that they think they can get away with not spending. Usually, that translates to externalizing the cost to the customers who get hacked for using their products, or get their data raided.
Every large ( >1000 employees ) organization has DAILY infections on employee computers. That is the reason for IT departments. If any big corp did a press release every time they found malware on a computer, it would just be a never ending stream.
Not everyone who works for apple is a programmer. There are janitors, cooks, secretary's, etc.. Those people use IE and click links in emails.
I cant say as to why apple chose to release this statement. I can just say I am fairly confident they did not have to.
At a previous job, I called Oracle support for one of their enterprise apps (we paid at least 6 figures a year for “support”) asking about IE8 compatibility and was eventually told that they don't test Microsoft's software for them and would wait until it was released to start. This was after IE8 was released and our users had already discovered that Oracle's thicket of JavaScript had an ancient bindows.net library which relied on IE not throwing an exception for a completely erroneous misuse of elem.style; a week or so later, a support manager called me to ask for a copy of the monkey-patch I'd mentioned so they could distribute it to other customers.
Generally the attacks are fuzzy. The attackers are quick to pivot off of the first infected system, because defenses tend to be extremely weak inside the firewall. They look for test systems, code repos, privileged interfaces, etc. For this reason, if they can't reasonably say that the compromise didn't lead anywhere else, they could get in a lot of trouble for failing to disclose.
Remember Sony? They kept quiet and attributed billions in losses to that incident, and had regulators down their backs. Nobody wants to deal with that. If the details of the compromise are not thoroughly understood internally, it could be better to say what happened and note that you don't believe user data was compromised.
Looks like Apple is worried more about leaks of their unreleased products. I would be more worried about data entering Apple, whether any websites were injected with malware or, in a much more unlikely scenario, malicious code being in injected into OS code or apps.