Jump to content

Drop-dead simple exploit completely bypasses Mac’s malware Gatekeeper

jos
Gatekeeper-bypass-hack-640x360.png
Since its introduction in 2012, an OS X feature known as Gatekeeper has gone a long way to protecting the Macs of security novices and experts alike. Not only does it help neutralize social engineering attacks that trick less experienced users into installing trojans, code-signing requirements ensure even seasoned users that an installer app hasn't been maliciously modified as it was downloaded over an unencrypted connection.
 
Now, a security researcher has found a drop-dead simple technique that completely bypasses Gatekeeper, even when the protection is set to its strictest setting. The hack uses a binary file already trusted by Apple to pass through Gatekeeper. Once the Apple-trusted file is on the other side, it executes one or more malicious files that are included in the same folder. The bundled files can install a variety of nefarious programs, including password loggers, apps that capture audio and video, and botnet software.

 

A Trojan that will attack anti-Trojan software of the mac is just funny.. and it looks like a simple implementation... some one might attack before the patch is released..

 
Link to comment
Share on other sites

Link to post
Share on other sites

But Macs can't get viruses ;)

Archangel (Desktop) CPU: i5 4590 GPU:Asus R9 280  3GB RAM:HyperX Beast 2x4GBPSU:SeaSonic S12G 750W Mobo:GA-H97m-HD3 Case:CM Silencio 650 Storage:1 TB WD Red
Celestial (Laptop 1) CPU:i7 4720HQ GPU:GTX 860M 4GB RAM:2x4GB SK Hynix DDR3Storage: 250GB 850 EVO Model:Lenovo Y50-70
Seraph (Laptop 2) CPU:i7 6700HQ GPU:GTX 970M 3GB RAM:2x8GB DDR4Storage: 256GB Samsung 951 + 1TB Toshiba HDD Model:Asus GL502VT

Windows 10 is now MSX! - http://linustechtips.com/main/topic/440190-can-we-start-calling-windows-10/page-6

Link to comment
Share on other sites

Link to post
Share on other sites

"Macs dont get viruses"

Link to comment
Share on other sites

Link to post
Share on other sites

On the one hand, I want to laugh at the Apple fanboys I knew at my school who thought that Apple devices are perfect and are objectively better than anything else, but on the other hand, I think it's unfortunate that such a simple flaw in a security system has been revealed(it's good that it will be fixed shortly, but still bad that it exists in the first place).

Why is the God of Hyperdeath SO...DARN...CUTE!?

 

Also, if anyone has their mind corrupted by an anthropomorphic black latex bat, please let me know. I would like to join you.

Link to comment
Share on other sites

Link to post
Share on other sites

I am amazed this has not already been exploited

I guess macs are just not targeted as much

Desktop - Corsair 300r i7 4770k H100i MSI 780ti 16GB Vengeance Pro 2400mhz Crucial MX100 512gb Samsung Evo 250gb 2 TB WD Green, AOC Q2770PQU 1440p 27" monitor Laptop Clevo W110er - 11.6" 768p, i5 3230m, 650m GT 2gb, OCZ vertex 4 256gb,  4gb ram, Server: Fractal Define Mini, MSI Z78-G43, Intel G3220, 8GB Corsair Vengeance, 4x 3tb WD Reds in Raid 10, Phone Oppo Reno 10x 256gb , Camera Sony A7iii

Link to comment
Share on other sites

Link to post
Share on other sites

It's actually not that Mac's can't get virus' it's more that Virus' are more commonly written for Windows because if you're going to exploit someone or you're going to trying and get information, why go for the second least used platform. Mac's can get virus' they are just less common. 

Please quote/tag ( Found by typing @DarrenP) In all posts directed at me. I do not check my current content. 


Intel Core i7-4790K - Gigabyte Z97X-UD5H-BK - 16GB Corsair Vengeance Pro 1866Mhz - EVGA GTX 980 - 256GB MX100 - 2TB WD RED - 900D - H100I - Corsair HX1050 - DNS 320L 2x2TB Seagate Barracuda 

Link to comment
Share on other sites

Link to post
Share on other sites

It's actually not that Mac's can't get virus' it's more that Virus' are more commonly written for Windows because if you're going to exploit someone or you're going to trying and get information, why go for the second least used platform. Mac's can get virus' they are just less common. 

Yes, we know, but we're complaining about the fanboys who don't say that Macs get viruses less commonly than Windows machines, but say they don't get viruses altogether. They go around acting all superior because they bought a Mac, and tell everyone how they're objectively better than everything else and how, regardless of what you're using it for, you should get a Mac. You want to do 3D modelling in a laptop? Don't get that $1000 laptop with a quad-core Intel i7 and a dedicated graphics card, get a $1000 Macbook Air or whatever with 4 GB of RAM, a dual-core i5, and integrated graphics. That type of person really gets on my nerves.

Why is the God of Hyperdeath SO...DARN...CUTE!?

 

Also, if anyone has their mind corrupted by an anthropomorphic black latex bat, please let me know. I would like to join you.

Link to comment
Share on other sites

Link to post
Share on other sites

I am amazed this has not already been exploited I guess macs are just not targeted as much

 

I must say, this ^^ always amazes me.  Whenever we do find out about a Mac exploit, its always a relatively easy exploit that gives supreme control of the system.  Yet we never really hear about anyone actually using them.  I think I have only heard of 2 or 3 big issues in the last decade.  With the way Mac security crumbles near instantly at all the hacker contests, I would have expected more news or problems.  I guess the Mac group really is such a small target it isn't worth it, or there is some other factor about Mac users that makes them lesser targets?  I think it has to simply be a numbers issue.

Link to comment
Share on other sites

Link to post
Share on other sites

SNIP

 

less users, most macs are used by creative types with photos and stuff

 

Banks and big companies use windows so you can capture more stuff/hack more things etc

 

Plus OSX is sandboxed so even though you might get into the mac and infect one program it might not actually do much, plus some mac users will run AV making it even less effective

 

 

Probably just not worth the effort when windows is easier to target and more likely to work and pay off

Desktop - Corsair 300r i7 4770k H100i MSI 780ti 16GB Vengeance Pro 2400mhz Crucial MX100 512gb Samsung Evo 250gb 2 TB WD Green, AOC Q2770PQU 1440p 27" monitor Laptop Clevo W110er - 11.6" 768p, i5 3230m, 650m GT 2gb, OCZ vertex 4 256gb,  4gb ram, Server: Fractal Define Mini, MSI Z78-G43, Intel G3220, 8GB Corsair Vengeance, 4x 3tb WD Reds in Raid 10, Phone Oppo Reno 10x 256gb , Camera Sony A7iii

Link to comment
Share on other sites

Link to post
Share on other sites

less users, most macs are used by creative types with photos and stuff

 

Banks and big companies use windows so you can capture more stuff/hack more things etc

 

Plus OSX is sandboxed so even though you might get into the mac and infect one program it might not actually do much, plus some mac users will run AV making it even less effective

 

 

Probably just not worth the effort when windows is easier to target and more likely to work and pay off

And most banks and big companies still use XP, so not much effort needed.

How to create a strong password

Size does not matter; it's how you use it

Link to comment
Share on other sites

Link to post
Share on other sites

And most banks and big companies still use XP, so not much effort needed.

 

Just email them :P

Desktop - Corsair 300r i7 4770k H100i MSI 780ti 16GB Vengeance Pro 2400mhz Crucial MX100 512gb Samsung Evo 250gb 2 TB WD Green, AOC Q2770PQU 1440p 27" monitor Laptop Clevo W110er - 11.6" 768p, i5 3230m, 650m GT 2gb, OCZ vertex 4 256gb,  4gb ram, Server: Fractal Define Mini, MSI Z78-G43, Intel G3220, 8GB Corsair Vengeance, 4x 3tb WD Reds in Raid 10, Phone Oppo Reno 10x 256gb , Camera Sony A7iii

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×