<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in Matasano Advisory: MacOS X Mach Exception Server Privilege Escalation</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Tue, 03 Oct 2006 00:30:58 -0000</lastBuildDate><item><title>Re: Matasano Advisory: MacOS X Mach Exception Server Privilege Escalation</title><link>http://www.matasano.com/log/530/matasano-advisory-macos-x-mach-exception-server-privilege-escalation/#comment-2320726</link><description>Nemo published some related work in Uninformed back in March. He did a good job of explaining the core fundamentals of the Mach subsystem in OSX and demonstrated various methods of subverting the BSD security features using the Mach subsystem. Definitely a good read.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">rjohnson</dc:creator><pubDate>Tue, 03 Oct 2006 00:30:58 -0000</pubDate></item><item><title>Re: Matasano Advisory: MacOS X Mach Exception Server Privilege Escalation</title><link>http://www.matasano.com/log/530/matasano-advisory-macos-x-mach-exception-server-privilege-escalation/#comment-2320725</link><description>Great work.  Privilege chaining issues are cool.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Steve Christey</dc:creator><pubDate>Mon, 02 Oct 2006 14:59:38 -0000</pubDate></item><item><title>Re: Matasano Advisory: MacOS X Mach Exception Server Privilege Escalation</title><link>http://www.matasano.com/log/530/matasano-advisory-macos-x-mach-exception-server-privilege-escalation/#comment-2320724</link><description>Vendor disclosure's not broken!</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nate</dc:creator><pubDate>Mon, 02 Oct 2006 10:44:39 -0000</pubDate></item><item><title>Re: Matasano Advisory: MacOS X Mach Exception Server Privilege Escalation</title><link>http://www.matasano.com/log/530/matasano-advisory-macos-x-mach-exception-server-privilege-escalation/#comment-2320723</link><description>Hello Ilja,&lt;br&gt;&lt;br&gt;I wouldn't be surprised if there are some way older slightly less-than-public exploits for it also, the bug has been around for a long while.  Once I get NeXTSTEP 3.3 running in a VM, I'll see if they had the bug also :).</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dino</dc:creator><pubDate>Mon, 02 Oct 2006 10:12:44 -0000</pubDate></item><item><title>Re: Matasano Advisory: MacOS X Mach Exception Server Privilege Escalation</title><link>http://www.matasano.com/log/530/matasano-advisory-macos-x-mach-exception-server-privilege-escalation/#comment-2320722</link><description>there's been a public exploit out for this bug for about a year I think. Nice apple finally fixed it :)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ilja</dc:creator><pubDate>Mon, 02 Oct 2006 00:04:00 -0000</pubDate></item></channel></rss>