{"id":129622,"date":"2015-06-18T18:34:01","date_gmt":"2015-06-18T16:34:01","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=129622"},"modified":"2015-06-18T19:09:03","modified_gmt":"2015-06-18T17:09:03","slug":"massive-apple-os-x-ios-security-flaw-revealed","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/129622-massive-apple-os-x-ios-security-flaw-revealed.html","title":{"rendered":"Massive Apple OS X, iOS security flaw revealed"},"content":{"rendered":"<p>Researchers at Indiana University, Peking University, the Georgia Institute of Technology, and Tsinghua University have published a paper detailing a new category of security weaknesses in Apple\u2019s operating system software.<\/p>\n<p>They call this category XARA, short for cross-app resource access, and explained that the keychain and WebSocket on OS X, and URL Scheme on iOS could be exploited to gain access to private data.<\/p>\n<p>According to the researchers, they notified Apple about the vulnerability on 15 October 2014, and were informed that the company needed 6 months to fix the issue.<\/p>\n<p>\u201cWe checked the most recent OS X 10.10.3 and beta version 10.10.4 and found that they attempted to address the iCloud issue using a 9-digit random number as accountName,\u201d the researchers said.<\/p>\n<p>However, the account name attribute for other services remains unobfuscated. Gmail, for example, still uses your email address as the username.<\/p>\n<p>\u201cMost importantly, such protection, based upon a secret attribute name, does not work when the attacker reads the attribute names of an existing item and then deletes it to create a clone under its control.&#8221;<\/p>\n<p>They noted that this is a new problem they discovered after the first keychain vulnerability report, and are helping Apple to fix it.<\/p>\n<h3 class=\"my-4\">Keychain race condition<\/h3>\n<p>In a <strong><a href=\"https:\/\/nakedsecurity.sophos.com\/2015\/06\/18\/apple-os-x-and-ios-in-the-vulnerability-spotlight-meet-cored-also-known-as-xara\/\" target=\"_blank\">blog post<\/a><\/strong> about the vulnerability, security firm Sophos explained that the researchers essentially exploited what is known as a race condition in Keychain on OS X.<\/p>\n<p>Normally when you choose to store your username and password for an application, website, or Wi-Fi hotspot, a login cookie is created in Keychain which only that application or service would have access to.<\/p>\n<p>A race condition is created if a malicious app creates a login cookie and grants another application permission to access that Keychain item.<\/p>\n<p>However, there is one trick: the application being subverted must not have created its own Keychain item yet.<\/p>\n<p>Unfortunately there is a workaround to this, Sophos reported, as it may be possible for the malicious app to delete the login cookie of other applications &#8211; allowing it to trigger the race condition.<\/p>\n<h3 class=\"my-4\">Dire consequences<\/h3>\n<p>Stealing credentials from Keychain is only one possible application of XARA attacks, the researchers wrote.<\/p>\n<p>Not only were they able to get a user\u2019s login for iCloud, e-mail, and bank accounts, they also successfully demonstrated breaking Apple\u2019s App sandbox.<\/p>\n<p>They said that they wrote a proof of concept application that does this, and managed to get it through Apple\u2019s checks and published on the App Store.<\/p>\n<p>These exploits were demonstrated in a series of videos which were published in an article <strong><a href=\"http:\/\/www.theregister.co.uk\/2015\/06\/17\/apple_hosed_boffins_drop_0day_mac_ios_research_blitzkrieg\/\" target=\"_blank\">on The Register<\/a><\/strong>, and are embedded below.<\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/www.youtube.com\/embed\/S1tDqSQDngE\" width=\"640\" height=\"360\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/www.youtube.com\/embed\/IYZkAIIzsIo\" width=\"640\" height=\"360\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/www.youtube.com\/embed\/7NGlmWtw83s\" width=\"640\" height=\"360\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p>\u201cFundamentally, the problem comes from lack of authentication during app-to-app and app-to-system interactions, and further proposes new techniques to detect and mitigate such a threat,\u201d the researchers stated.<\/p>\n<p>\u201cThis preliminary effort contributes to a better understanding of this understudied security problem, an important step for building a more effective app isolation mechanism on future OSes.\u201d<\/p>\n<h3 id=\"related\">More information security news<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/129528-big-samsung-galaxy-s6-s5-s4-security-flaw.html\"><strong>Big Samsung Galaxy S6, S5, S4 security flaw<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/129394-lastpass-hacked-you-need-to-change-your-master-password.html\"><strong>LastPass hacked \u2013 you need to change your master password<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/129392-cape-town-waitress-fined-for-cloning-bank-cards.html\"><strong>Cape Town waitress fined for cloning bank cards<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/127776-how-hackers-steal-your-private-information-on-wi-fi.html\"><strong>How hackers steal your private information on Wi-Fi<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/software\/128168-crash-skype-with-this-simple-message.html\"><strong>Crash Skype with this simple message<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers have disclosed a significant 0-day security vulnerability in Apple\u2019s desktop and mobile operating systems.<\/p>\n","protected":false},"author":23,"featured_media":76174,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[36,605,691,25285,765],"class_list":["post-129622","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-active","tag-apple","tag-ios","tag-os-x","tag-sophos"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/129622"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=129622"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/129622\/revisions"}],"predecessor-version":[{"id":129624,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/129622\/revisions\/129624"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/76174"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=129622"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=129622"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=129622"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}