Ofer For You (1)

Showing posts with label OS X Yosemite. Show all posts
Showing posts with label OS X Yosemite. Show all posts

Tuesday, 4 November 2014

Rootpipe — Critical Mac OS X Yosemite Vulnerability Allows Root Access Without Password



Rootpipe — Critical Mac OS X Yosemite Vulnerability Allows Root Access Without Password
A Swedish Security researcher has discovered a critical vulnerability in Apple’s OS X Yosemite that gives hackers the ability to escalate administrative privileges on a compromised machine, and allows them to gain the highest level of access on a machine, known as root access.

The vulnerability, dubbed as "Rootpipe", was uncovered by Swedish white-hat hacker Emil Kvarnhammar, who is holding on the full details about the privilege escalation bug until January 2015, as Apple needs some time to prepare a security patch.
"Details on the #rootpipe exploit will be presented, but not now. Let's just give Apple some time to roll out a patch to affected users," Emil Kvarnhammar, IT specialist and hacker security company Truesec,tweeted from his twitter account.
By exploiting the vulnerability in the Mac OS X Yosemite, an attacker could bypass the usual safeguard mechanisms which are supposed to stop anyone who tries to root the operating system through a temporary backdoor.

ROOT ACCESS WITHOUT PASSWORD
Once exploited, hackers could install malicious software or make other changes to your computer without any need of a password.

Hackers could steal victims’ sensitive information such as passwords or bank account information, or if required, they could format the entire affected computer, deleting all your important data from the computer.

Kvarnhammar has also provided a video to explain his initial finding.
It all started when I was preparing for two security events, one in Stockholm and one in Malmö,” Kvarnhammar says. “I wanted to show a flaw in Mac OS X, but relatively few have been published. There are a few ‘proof of concepts’ online, but the latest I found affected the older 10.8.5 version of OS X. I couldn’t find anything similar for 10.9 or 10.10.
Kvarnhammar tested the vulnerability on OS X version 10.8, 10.9 and 10.10. He has confirmed that it has existed since at least 2012, but probably is much older than that.

INFORMED APPLE
Kvarnhammar contacted Apple about the issue but he initially didn’t get any response, and Apple silently asked him for more details. When he provided with the details, Apple asked TrueSec not to disclose until next January.
Kvarnhammar said, "The current agreement with Apple is to disclose all details in mid-January 2015. This might sound like a long wait, but hey, time flies. It's important that they have time to patch, and that the patch is available for some time."
HOW TO PROTECT
The full disclosure of the vulnerability would be made public in January, after Apple will provide a fix. Apple Yosemite OS X users are advised to follow the below steps in order to protect yourself from the exploitation of the Rootpipe:
  • Avoid running the system on a daily basis with an admin account. An attacker that will gain control on this account will obtain anyway limited privileges.
  • Use volume encryption Apple’s FileVault tool, which allows encryption and decryption on the fly, protecting your information always.
However, the best way to protect yourself from such security vulnerabilities is to ensure that the operating system running on your system is always up-to-date, and always be careful to the links and documents others send to you.


By "Kunal Vohra", Director@H2K

Still Having Problem..!!! Connect with Admin
BBM: 7F72A48D


 Kunal Vohra
Download Our Official Android App & Get Free Internet



"The Hackers Street"

For Daily Updates 

Tuesday, 21 October 2014

Mac OS X 10.10 Yosemite Sends User Location and Safari Search Data to Apple


Mac OS X 10.10 Yosemite Sends User Location and Safari Searches Data to Apple
Apple's latest desktop operating system, known as Mac OS X 10.10 Yosemite, sends location and search data of users without their knowledge to Apple's remote servers by default whenever a user queries the desktop search tool Spotlight, which questions users' privacy once again.

The technology firm faced criticism on Monday when users came to know about the company's About Spotlight & Privacy which clearly states that anyone who uses the Spotlight feature in either Mac OS X 10.10 Yosemite or its newly launched mobile operating system iOS 8 will have their location and search information passed back to Apple's servers to process.

APPLE COLLECTS USERS' DATA AND FORWARDS IT TO MICROSOFT AS WELL
On one hand, where Apple decided to enable hard drive encryption by default, despite the FBI requests not to do so. But on the other, the company is itself putting its users' privacy on risk. The same data Apple collects from the users' searched term on Spotlight will also be forwarded to Microsoft's Bing search engine as Apple freely admits in its terms of service.

"When you use Spotlight, your search queries, the Spotlight Suggestions you select, and related usage data will be sent to Apple," Apple's "About Spotlight & Privacy" document states. "If you have Location Services on your device turned on, when you make a search query to Spotlight the location of your device at that time will be sent to Apple."

Mac OS X 10.10 Yosemite, which was officially released on Thursday, allows Mac users to upload and organize any file types on their own, meaning users can store any type of file they wish in iCloud drive, as long as it's less than 15 gigabytes in size. With Yosemite, Apple is beginning to unify its desktop and mobile computing platforms.

HOW TO PROTECT YOURSELF
However, the tech giant noted within Mac OS X 10.10 Yosemite's Spotlight preferences that the users' search terms were collected only to improve Spotlight Searches. But, if users don't want their data collected, they can turn off Spotlight Suggestions and Bing Web searches in System Preferences, noted the company.

A developer has also uploaded a Python script to prevent Apple from collecting data, so you can switch off the Spotlight search by going through step-by-step instructions for doing it, according to Fix-MacOSX.com:

Disable "Spotlight Suggestions" and "Bing Web Searches" in System Preferences > Spotlight > Search Results.

Safari also has a "Spotlight Suggestions" setting that is separate from Spotlight's "Spotlight Suggestions." This uses the same mechanism as Spotlight, and if left enabled, Safari will send a copy of all search queries to Apple.

You'd be forgiven for thinking that you'd already disabled "Spotlight Suggestions," but you'll also need to uncheck "Include Spotlight Suggestions" in Safari > Preferences > Search.

APPLE RESPONSE
Apple has issued the following statement saying that the company had build up the Spotlight search feature in order to protect users' privacy and that Spotlight Suggestions minimizes the information that's sent to Apple.
"We are absolutely committed to protecting our users' privacy and have built privacy right into our products. For Spotlight Suggestions we minimize the amount of information sent to Apple," Apple said in statement to iMore. "Apple doesn't retain IP addresses from users' devices. Spotlight blurs the location on the device so it never sends an exact location to Apple. Spotlight doesn't use a persistent identifier, so a user's search history can't be created by Apple or anyone else. Apple devices only use a temporary anonymous session ID for a 15-minute period before the ID is discarded."
"We also worked closely with Microsoft to protect our users' privacy. Apple forwards only commonly searched terms and only city-level location information to Bing. Microsoft does not store search queries or receive users' IP addresses. You can also easily opt out of Spotlight Suggestions, Bing or Location Services for Spotlight."
This is the same approach which is also carried out by Google and other tech companies. So, users just need to understand that nothing in this world is free, neither Google, Facebook nor this new Mac OS X 10.10 Yosemite, because you are paying with your information.

By "Kunal Vohra", Director@H2K

Still Having Problem..!!! Connect with Admin
BBM: 7F72A48D


 Kunal Vohra
Download Our Official Android App & Get Free Internet



"The Hackers Street"

For Daily Updates