<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Mon, 30 Jun 2008 06:43:30 -0000</lastBuildDate><item><title>Re: Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://www.matasano.com/log/1069/apple-ships-suids-with-applescript-dictionaries-hilarity-ensues/#comment-2324000</link><description>Seems like a non-issue on my (Leopard) machine:&lt;br&gt;&lt;br&gt;user@host:/tmp$ osascript -e 'tell app "ARDAgent" to do shell script "whoami"'&lt;br&gt;23:47: execution error: ARDAgent got an error: "whoami" doesn’t understand the do shell script message. (-1708)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matt Schinckel</dc:creator><pubDate>Mon, 30 Jun 2008 06:43:30 -0000</pubDate></item><item><title>Re: Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://www.matasano.com/log/1069/apple-ships-suids-with-applescript-dictionaries-hilarity-ensues/#comment-2324012</link><description>&amp;gt;This single-user system argument is weird. We all use single-user systems,&lt;br&gt;&amp;gt; and none of us want keyloggers installed behind our backs.&lt;br&gt;&lt;br&gt;In the simplest case, in order for this vulnerability to work, the malicious program needs to be already running on your machine, which will most likely be under your user account. Which means that it will already have access to ALL your data and can do ALL the damage to your system that it wants, including installing backdoors/keyloggers etc. Having root will not make the situation that much worse.&lt;br&gt;&lt;br&gt;That is, unless you have many users on your machine, in which case having root access will allow the the trojan to affect other users.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">peter</dc:creator><pubDate>Wed, 25 Jun 2008 07:36:47 -0000</pubDate></item><item><title>Re: Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://www.matasano.com/log/1069/apple-ships-suids-with-applescript-dictionaries-hilarity-ensues/#comment-2324008</link><description>When I run osascript -e 'tell app "ARDAgent" to do shell script "whoami" all I get is "Damn, that was fun"&lt;br&gt;&lt;br&gt;I put my own bin directory before /usr/bin in my PATH&lt;br&gt;&lt;br&gt;cat ~/bin/osascript&lt;br&gt;$ echo "Damn, that was fun"&lt;br&gt;&lt;br&gt;Now if I wanted I could create an application that asked me if I wanted to run the osascript first, if I click Yes it would then forward that request to the real osascript, wherever that now is.&lt;br&gt;&lt;br&gt;Or did I miss something entirely?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ken</dc:creator><pubDate>Wed, 25 Jun 2008 03:39:45 -0000</pubDate></item><item><title>Re: Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://www.matasano.com/log/1069/apple-ships-suids-with-applescript-dictionaries-hilarity-ensues/#comment-2324005</link><description>It's so easy to target. You just need to figure out how to make some internet enabled software execute Applescript, and almost all of them do. If Safari has an exploit where it executes Applescript without asking the user first.. well, that would suck.&lt;br&gt;&lt;br&gt;This single-user system argument is weird. We all use single-user systems, and none of us want keyloggers installed behind our backs.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Max Howell</dc:creator><pubDate>Sat, 21 Jun 2008 08:24:05 -0000</pubDate></item><item><title>Re: Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://www.matasano.com/log/1069/apple-ships-suids-with-applescript-dictionaries-hilarity-ensues/#comment-2324007</link><description>$ id&lt;br&gt;uid=501(jsiren) gid=501(jsiren) groups=501(jsiren), 81(appserveradm), 79(appserverusr), 80(admin)&lt;br&gt;$ uname -a&lt;br&gt;Darwin (redacted) 8.11.1 Darwin Kernel Version 8.11.1: Wed Oct 10 18:23:28 PDT 2007; root:xnu-792.25.20~1/RELEASE_I386 i386 i386&lt;br&gt;$ osascript -e 'tell app "ARDAgent" to do shell script "whoami"'&lt;br&gt;23:47: execution error: ARDAgent got an error: Connection is invalid. (-609)&lt;br&gt;&lt;br&gt;What am I doing wrong, or does this not work in Tiger? (10.4.11)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">js</dc:creator><pubDate>Sat, 21 Jun 2008 04:05:47 -0000</pubDate></item><item><title>Re: Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://www.matasano.com/log/1069/apple-ships-suids-with-applescript-dictionaries-hilarity-ensues/#comment-2324006</link><description>@tom:&lt;br&gt;&lt;br&gt;&amp;gt; Who cares if someone busts root on your Mac?&lt;br&gt;&lt;br&gt;&amp;gt; It’s a single-user system. I let you in on a &lt;br&gt;&amp;gt; Matasano state secret: if you break the “tqbf” &lt;br&gt;&amp;gt; account on my laptop, I’m in trouble. If you’re &lt;br&gt;&amp;gt; malware and just trying to spread, or redirect my &lt;br&gt;&amp;gt; browser to phishing pages, you’re wasting your&lt;br&gt;&amp;gt; time with this “root” silliness.&lt;br&gt;&lt;br&gt;That raises this point then eh?&lt;br&gt;&lt;br&gt;sh-3.2$ id&lt;br&gt;uid=4294967294(nobody) gid=4294967294(nobody) groups=4294967294(nobody)&lt;br&gt;sh-3.2$ osascript -e 'tell app "Finder" to do shell script "whoami"'&lt;br&gt;emonti</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Eric Monti</dc:creator><pubDate>Fri, 20 Jun 2008 18:42:48 -0000</pubDate></item><item><title>Re: Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://www.matasano.com/log/1069/apple-ships-suids-with-applescript-dictionaries-hilarity-ensues/#comment-2324004</link><description>Well if you turn ARD on and have any local users that are standard, then those standard users can run root commands with ARD if Allow All Users (the default) radio button is selected... I noticed that a while back, didn't seem quite right: &lt;a href="http://www.brunerd.com/blog/2008/03/08/ard-security-awareness-standard-user-can-run-root-commands/" rel="nofollow"&gt;http://www.brunerd.com/blog/2008/03/08/ard-secu...&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">brunerd</dc:creator><pubDate>Fri, 20 Jun 2008 13:30:01 -0000</pubDate></item><item><title>Re: Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://www.matasano.com/log/1069/apple-ships-suids-with-applescript-dictionaries-hilarity-ensues/#comment-2324009</link><description>First, Having ARD on is NOT an effective workaround for this issue.&lt;br&gt;&lt;br&gt;Second, I think there's a difference between "having an AppleScript dictionary" (which means handling some custom AppleScript commands) and just handling system AppleScript commands (like "do shell script").  ARDAgent falls into the latter, as do any "normal" applications without having to do anything special related to AppleScript.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bill</dc:creator><pubDate>Fri, 20 Jun 2008 10:28:39 -0000</pubDate></item><item><title>Re: Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://www.matasano.com/log/1069/apple-ships-suids-with-applescript-dictionaries-hilarity-ensues/#comment-2324011</link><description>Nothing personal, but you haven't understood it. ARDAgent doesn't have an AppleScript dictionary. But it does have the ability to pass AppleScripts on to the OS as Root. So you can look for dictionaries all you like, and that won't change anything.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kirk</dc:creator><pubDate>Fri, 20 Jun 2008 09:35:17 -0000</pubDate></item><item><title>Re: Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://www.matasano.com/log/1069/apple-ships-suids-with-applescript-dictionaries-hilarity-ensues/#comment-2324010</link><description>Yeah, nice going.&lt;br&gt;&lt;br&gt;I used another workaround for the matter tho.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">André Medeiros</dc:creator><pubDate>Fri, 20 Jun 2008 04:03:46 -0000</pubDate></item><item><title>Re: Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://www.matasano.com/log/1069/apple-ships-suids-with-applescript-dictionaries-hilarity-ensues/#comment-2324003</link><description>You can work around this issue (should you want to), by enabling ARD. Perversely.&lt;br&gt;&lt;br&gt;I guess when ARD is turned on, ARDAgent acts as smartly as it should be all of the time. Quite why you're able to script it at *all* when ARD's switched off is beyond me.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mo</dc:creator><pubDate>Fri, 20 Jun 2008 02:47:43 -0000</pubDate></item><item><title>Re: Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://www.matasano.com/log/1069/apple-ships-suids-with-applescript-dictionaries-hilarity-ensues/#comment-2324002</link><description>On Leopard, in which directory is the plist for ARDAgent?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">john</dc:creator><pubDate>Thu, 19 Jun 2008 19:55:37 -0000</pubDate></item><item><title>Re: Apple Ships SUIDs With AppleScript Dictionaries. Hilarity Ensues.</title><link>http://www.matasano.com/log/1069/apple-ships-suids-with-applescript-dictionaries-hilarity-ensues/#comment-2324001</link><description>thats pretty funny. The bug itself isn't too worrisome, but it is indicative of some serious oversights in design that I am sure will get released and discovered in the very near future....very near....like around February '09 ;-)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">stephen</dc:creator><pubDate>Thu, 19 Jun 2008 15:25:31 -0000</pubDate></item></channel></rss>