• On TechRepublic: Worst movie of the year?
advertisement
Click Here
October 25, 2004 7:48 AM PDT

The "Opener" scare and keeping malicious scripts off your Mac

by CNET staff
  • Font size
  • Print
  • Post a comment

Over the weekend, MacInTouch and Slashdot posted information regarding a shell script dubbed "opener" that, if installed with proper authentication on a Mac OS X system, can trigger several vulnerabilities including password compromising and activity tracking. Several publications have since sounded the alarm, with headlines like "Mac users face rare virus" and "Destructive Mac virus spies on Apple users".

Fortunately, there is no immediate threat posed by this, or any other malicious shell script currently in circulation -- running the "opener" script and allowing it to do any damage requires root authentication, which must be locally entered by a Mac OS X administrator. There is currently no vector for this or any other malicious Mac OS X script, i.e. no way for the script to autonomously take hold of the system or propagate itself to other systems without express administrator permission. In other words, it is not spreading, and cannot spread without a vector that is capable of gaining root access.

That said, this security scare should remind users to take some precautionary measures that will lessen the chances of another individual gaining the ability to install and run a threatening script.

First of all, make sure to use strong passwords, and never send your administrator password in the clear, without encryption, or to an untrusted third party. Check out the utilities PassGenX or PasswordMaster if you are unfamiliar with generating strong, secure passwords.

Second, make sure to apply all of Apple's security updates up through the most recent revision. These are available through Software Update or Apple's download page. Particularly important are updates that plug secure shell (SSH) protocol vulnerabilities.

Finally, and perhaps most importantly, never provide your administrator password to an untrusted application or install routine. Make sure, when downloading applications from any source, that the author is reputable and (if possible) other users have already tested the release. Unwittingly giving arbitrary code the permission to run is perhaps the greatest current security threat for Mac OS X users.

Feedback? Late-breakers@macfixit.com.

Resources

  • MacInTouch
  • Slashdot
  • "Mac users face rare virus"
  • "Destructive Mac virus spies on Apple users"
  • PassGenX
  • PasswordMaster
  • Apple's download page
  • Late-breakers@macfixit.com
  • More from Late-Breakers
  • Recent posts from MacFixIt
    Pixelated or fuzzy icons in Snow Leopard
    Snow Leopard: iChat restricting minimum chat window width
    Hack enables 10.6.2 on Atom processors
    Weekly Utilities Update: WhatSize, CoolBook, VisualRoute, more...
    Overcoming missing Appletalk printer connectivity in Snow Leopard
    Terminal fun: Options for printing folder and subfolder contents
    Aperture How-To: Add a watermark to your photographs
    Snow Leopard: Finder not opening files when double-clicked

    Navigate MacFixIt

    • Help
    • Archives
    • Utilities
    • Forums
    advertisement
    Click Here

    About MacFixIt

    MacFixIt is CNET's troubleshooting resource for all things Mac. The information here helps you navigate the ins-and-outs of Mac ownership with how-tos, troubleshooting information, news, reviews, and more.

    Add this feed to your online news reader

    MacFixIt topics