Apple, Mac, MacOS, iOS4, iPad, iPhone and (in)security...
16.1K views | +1 today
Follow
Apple, Mac, MacOS, iOS4, iPad, iPhone and (in)security...
Everything related to the (in)security of Apple products
Curated by Gust MEES
Your new post is loading...
Your new post is loading...
Scooped by Gust MEES
Scoop.it!

Every Mac is still at risk from this "backdoor" bug | Apple failed to fix "rootpipe" backdoor flaw

Every Mac is still at risk from this "backdoor" bug | Apple failed to fix "rootpipe" backdoor flaw | Apple, Mac, MacOS, iOS4, iPad, iPhone and (in)security... | Scoop.it
The bug should've been squashed in the latest update of OS X 10.10.3, but researchers say it persists. Every Mac is at risk from this "backdoor" bug.


Learn more:


http://www.scoop.it/t/apple-mac-ios4-ipad-iphone-and-in-security/?tag=RootPipe


Gust MEES's insight:

The bug should've been squashed in the latest update of OS X 10.10.3, but researchers say it persists. Every Mac is at risk from this "backdoor" bug.


Learn more:


http://www.scoop.it/t/apple-mac-ios4-ipad-iphone-and-in-security/?tag=RootPipe



No comment yet.
Scooped by Gust MEES
Scoop.it!

OS X Yosemite sports serious privilege escalation bug

OS X Yosemite sports serious privilege escalation bug | Apple, Mac, MacOS, iOS4, iPad, iPhone and (in)security... | Scoop.it
A Swedish researcher has unearthed a serious bug that affects the newest version of OS X - version 10.10, or Yosemite - and which could allow attackers to gain complete control of the target's Mac machine.

It's a privilege escalation bug he dubbed Rootpipe, but declined to explain why, as the explanation could reveal details that would help attackers find it and create an exploit.

The existence of the flaw has been indirectly confirmed by Apple when they asked the researcher to delay publishing details about it until January 2015, after a fix for the bug is released and pushed out to users


Rootpipe is a privilege escalation from admin to root so switching to a non-admin account would clearly be a good thing," Kvarnhammar said.



Learn more:


http://www.scoop.it/t/apple-mac-ios4-ipad-iphone-and-in-security


http://www.scoop.it/t/apple-mac-ios4-ipad-iphone-and-in-security?q=Rootpipe

Gust MEES's insight:

Rootpipe is a privilege escalation from admin to root so switching to a non-admin account would clearly be a good thing," Kvarnhammar said.



Learn more:


http://www.scoop.it/t/apple-mac-ios4-ipad-iphone-and-in-security


http://www.scoop.it/t/apple-mac-ios4-ipad-iphone-and-in-security?q=Rootpipe


No comment yet.
Scooped by Gust MEES
Scoop.it!

Rootpipe : la version 10.10.3 de Mac OS X apporte un correctif

Rootpipe : la version 10.10.3 de Mac OS X apporte un correctif | Apple, Mac, MacOS, iOS4, iPad, iPhone and (in)security... | Scoop.it
Vous vous souvenez de Rootpipe ? Cette vulnérabilité avait été signalée en fin d’année 2014 par un chercheur suédois qui avait découvert un moyen d’élever ses privilèges au niveau root depuis une session utilisateur. Rootpipe était restée une énigme jusqu’alors : Apple avait en effet annoncé que corriger cette vulnérabilité prendrait du temps et Emil Kvarnammar, le chercheur à l’origine de cette découverte, avait accepté d’attendre un patch avant de donner plus de détails. Le correctif était annoncé pour le début de l'année 2015, mais il aura fallu attendre encore un peu, Apple invoquant d'importants changements nécessaires afin de rectifier le tir.


En savoir plus / Learn more:


http://www.scoop.it/t/apple-mac-ios4-ipad-iphone-and-in-security/?tag=RootPipe


Gust MEES's insight:

Vous vous souvenez de Rootpipe ? Cette vulnérabilité avait été signalée en fin d’année 2014 par un chercheur suédois qui avait découvert un moyen d’élever ses privilèges au niveau root depuis une session utilisateur. Rootpipe était restée une énigme jusqu’alors : Apple avait en effet annoncé que corriger cette vulnérabilité prendrait du temps et Emil Kvarnammar, le chercheur à l’origine de cette découverte, avait accepté d’attendre un patch avant de donner plus de détails. Le correctif était annoncé pour le début de l'année 2015, mais il aura fallu attendre encore un peu, Apple invoquant d'importants changements nécessaires afin de rectifier le tir.



En savoir plus / Learn more:


http://www.scoop.it/t/apple-mac-ios4-ipad-iphone-and-in-security/?tag=RootPipe


No comment yet.
Scooped by Gust MEES
Scoop.it!

Serious security flaw in OS X Yosemite 'Rootpipe' | Cyber Security

Serious security flaw in OS X Yosemite 'Rootpipe' | Cyber Security | Apple, Mac, MacOS, iOS4, iPad, iPhone and (in)security... | Scoop.it

Details are finally emerging about a serious vulnerability in Apple's OS X Yosemite, called "Rootpipe" which allows root access by attackers.


The privilege escalation vulnerability was discovered by Swedish hacker Emil Kvarnhammar, who has been asked by Apple to withhold details until January 2015 -- since Apple likely wouldn't allow details until they have a fix, this is probably when users can expect a patch.


Rootpipe is a privilege escalation from admin to root so switching to a non-admin account would clearly be a good thing," Kvarnhammar said.


Learn more:


http://www.scoop.it/t/apple-mac-ios4-ipad-iphone-and-in-security



Gust MEES's insight:

Details are finally emerging about a serious vulnerability in Apple's OS X Yosemite, called "Rootpipe" which allows root access by attackers.


The privilege escalation vulnerability was discovered by Swedish hacker Emil Kvarnhammar, who has been asked by Apple to withhold details until January 2015 -- since Apple likely wouldn't allow details until they have a fix, this is probably when users can expect a patch.


Rootpipe is a privilege escalation from admin to root so switching to a non-admin account would clearly be a good thing," Kvarnhammar said.


Learn more:


http://www.scoop.it/t/apple-mac-ios4-ipad-iphone-and-in-security



No comment yet.