search technology reviews, news, features, group tests
Popular Searches:   video , dell , dvd
 |  Register
 |  Newsletters  | 
Sitemap  |  RSS
RSS
Tuesday November 24, 2009 5:49 PM AEST
Skip Navigation LinksPC Authority > News > Security expert mauls Leopard firewall
NEWS

Security expert mauls Leopard firewall

by Shaun Nichols  on Nov 1, 2007
Researcher finds glaring holes in new Apple OS.
The firewall in Apple's new OS X Leopard operating system is unreliable and unable to keep out hackers, according to one security researcher.

Jurgen Schmidt, of Heise Security, issued a report claiming that the Leopard firewall failed every security test performed by the firm.

"The most important task for any firewall is to keep out uninvited guests," wrote Schmidt.

"But a quick look at the firewall configuration in the Mac OS X Leopard shows that it is unable to do this."

Among the shortcomings are a default 'off' state, hidden components that can be accessed by remote users but cannot easily be blocked, and an inability completely to block incoming connections.

"Specifically these results mean that users cannot rely on the firewall," stated Schmidt.

"Even if users select 'block all incoming connections' potential attackers can continue to communicate with system services such as the time server and possibly with the NetBIOS name server."

Schmidt compared the vulnerability of Leopard to that of Microsoft's Windows XP when it first debuted.

"Apple is showing here a casual attitude with regard to security questions which strongly recalls that of Microsoft four years ago," he wrote.

"Although the problems and peculiarities described here are not security vulnerabilities in the sense that they can be exploited to break into a Mac, Apple would be well advised to sort them out pronto."

Copyright © 2009 v3.co.uk
Email a Friend Email this
Print Page Print this
Tweet This Tweet this
Feedback Send us your tips


Ads by Google

Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Login or register to submit a comment.
 

Top Stories

Verified by Visa phishing attack spotted
Security experts warned today that the Verified by Visa online authentication scheme has become the latest lure used by phishers hoping to harvest personal information from unsuspecting shoppers..
 
Intel and AMD: Videos explain how grains of sand are used to create a silicon CPU
Intel has released a short animated video illustrating the process by which sand is turned into silicon and a CPU. But the over-simplicity has us leaning towards AMD's older and more interesting video
 
Need to know: Google's Chrome OS
Google is bringing out an operating system - Chrome OS. But how will it fare against the likes of Windows?
 


 
Intel
 
 
LogMeIn
 
 
Amazing Dell Coupons now available
 
Discover Apple