Newsletter:

Skip Navigation LinksHome > News > Security > Security expert mauls Leopard firewall

Security expert mauls Leopard firewall

By Shaun Nichols
1 November 2007 07:51AM
Tags: apple | leopard | mac | leopard | security | security | expert

The firewall in Apple's new OS X Leopard operating system is unreliable and unable to keep out hackers, according to one security researcher..

Jurgen Schmidt, of Heise Security, issued a report claiming that the Leopard firewall failed every security test performed by the firm.

"The most important task for any firewall is to keep out uninvited guests," wrote Schmidt.

"But a quick look at the firewall configuration in the Mac OS X Leopard shows that it is unable to do this."

Among the shortcomings are a default 'off' state, hidden components that can be accessed by remote users but cannot easily be blocked, and an inability completely to block incoming connections.

"Specifically these results mean that users cannot rely on the firewall," stated Schmidt.

"Even if users select 'block all incoming connections' potential attackers can continue to communicate with system services such as the time server and possibly with the NetBIOS name server."

Schmidt compared the vulnerability of Leopard to that of Microsoft's Windows XP when it first debuted.

"Apple is showing here a casual attitude with regard to security questions which strongly recalls that of Microsoft four years ago," he wrote.

"Although the problems and peculiarities described here are not security vulnerabilities in the sense that they can be exploited to break into a Mac, Apple would be well advised to sort them out pronto."

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 




Product Reviews

Star Rating
GuardianEdge Device Control is a component of the more robust GuardianEdge Data Protection Platform.
Star Rating
Lumension offers a pair of products, Sanctuary Application Control and Sanctuary Device Control, that work in...
Star Rating
First, it is important to note that unlike previous versions of ZENworks, Novell ZENworks Endpoint Security...
Star Rating
StormShield Security Suite offers integrated system and data protection in a single product.
Star Rating
Panda Security for Enterprise is another suite of products designed to protect the endpoint.
Product Reviews now available on iTnews.com.au

TopTopics
(9139) -  researchers
(6647) -  intel
(6405) -  processor
(6267) -  second
(6193) -  thermodynamics
(5975) -  telstra
(4018) -  network
(3185) -  broadband
(2914) -  microsoft
(2585) -  apple
(2409) -  samsung
(2323) -  wifi
(2311) -  nbn
(1906) -  iphone
(1373) -  security