New exploit devised for the Mac

Share this article:
Most exploits posted on the web that make use of Mac viruses or malware are largely theoretical. But a researcher in Italy claims he has found a valid way to run hostile code on the Mac OS X.

The technique involves what the researcher, Vincenzo Iozzo, a reverse engineer at Zynamics GmbH, calls in-memory injection. The approach can put code into running processes and leave no trace of having ever been there.

According to The Register, Iozzo devised the exploit by discovering a way to bypass traditional means of loading binaries into the operating system.

Attacking the Apple Mac is notoriously difficult. Because Macs are based on Linux-like coding approach, it's one of the most secure systems, said Justin Esgar, president of Virtua Computers, an Apple system administrator.

“Anything that runs on the machine has to be installed by the user, unlike Windows which has ActiveX that can install something in the background," he told SCMagazineUS.com. “There is no way to install unauthorized software on the Mac. There are no processes running in the background that would allow for such a thing.”

An Apple spokesperson did not respond Wednesday for comment.

This new exploit relies on Mach-O, short for Mach object file format, which is used in Mac OS X for native executables.

“The people subjected to this are coders," Esgar said. "Typically users do not compile random source code on their computer."
Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

More in News

CryptoWall surpasses CryptoLocker in infection rates

CryptoWall surpasses CryptoLocker in infection rates

A threat analysis from Dell SecureWorks CTU says that CryptoWall has picked up where its famous sibling left off.

Professor says Google search, not hacking, yielded medical info

Professor says Google search, not hacking, yielded medical ...

A professor of ethical hacking at City College San Francisco came forward to clarify that he did not demonstrate hacking a medical center's server in a class.

Syrian Malware Team makes use of enhanced BlackWorm RAT

Syrian Malware Team makes use of enhanced BlackWorm ...

FireEye analyzed the hacking group's use of the malware, dubbed the "Dark Edition" of BlackWorm.