<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>VigiMac &#187; issue</title>
	<atom:link href="http://www.vigimac.com/tag/issue/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.vigimac.com</link>
	<description>keep an eye on your Mac</description>
	<lastBuildDate>Sat, 13 Nov 2010 18:27:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>ARDAgent security hole with MacOS X 10.5.4</title>
		<link>http://www.vigimac.com/2008/07/ardagent-security-hole-with-macos-x-1054/</link>
		<comments>http://www.vigimac.com/2008/07/ardagent-security-hole-with-macos-x-1054/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 22:57:18 +0000</pubDate>
		<dc:creator>VigiMac</dc:creator>
				<category><![CDATA[MacOS X]]></category>
		<category><![CDATA[10.5.4]]></category>
		<category><![CDATA[administrator]]></category>
		<category><![CDATA[anti]]></category>
		<category><![CDATA[applescript]]></category>
		<category><![CDATA[ARDAgent]]></category>
		<category><![CDATA[command]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[hole]]></category>
		<category><![CDATA[issue]]></category>
		<category><![CDATA[osascript]]></category>
		<category><![CDATA[protect]]></category>
		<category><![CDATA[Remote Desktop Admin]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[secure]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[slashdot]]></category>
		<category><![CDATA[theft]]></category>
		<category><![CDATA[vigimac]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.vigimac.com/?p=28</guid>
		<description><![CDATA[A security hole has been recently discovered, relayed by all websites of the Mac community. This vulnerability with the ARDAgent program gives access to the root superuser with a simple Applescript command : $ osascript -e &#8216;tell app &#8220;ARDAgent&#8221; to do shell script &#8220;whoami&#8221;&#8216; root If it does not always work with MacOS X 10.5.3 [...]]]></description>
			<content:encoded><![CDATA[<p>A security hole has been recently <a title="ARDAgent security issue on Slashdot" href="http://it.slashdot.org/article.pl?sid=08/06/18/1919224" target="_blank">discovered</a>, relayed by all websites of the Mac community. This vulnerability with the ARDAgent program gives access to the root superuser with a simple Applescript command :</p>
<p><em></em></p>
<p><em>$ osascript -e &#8216;tell app &#8220;ARDAgent&#8221; to do shell script &#8220;whoami&#8221;&#8216;<br />
root</em></p>
<p><em> </em></p>
<p><em><span style="font-style: normal;">If it does not always work with MacOS X 10.5.3 (and previous versions), this security issue is not yet fixed and can appear with the last MacOS X 10.5.4 update.</span></em></p>
<p>You&#8217;ll find different ways to possibly close this ARDAgent security hole on <a title="Faille ARDagent toujours sous MacOS X 10.5.4" href="http://www.macosxhints.com/article.php?story=20080620052233168" target="_blank">macosxhints.com</a>, like this command :</p>
<p><em>$ sudo chmod 755<br />
/System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent</em></p>
<p>If you use Apple Remote Desktop Admin, this command will avoid ARDAgent to launch.<br />
Remote Desktop Admin will work thanks to this second command line and the issue doesn&#8217;t seem to appear anymore.</p>
<p>$ sudo chmod +s<br />
/System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vigimac.com/2008/07/ardagent-security-hole-with-macos-x-1054/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

