<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Unpatched Flaw In Apple Remote Desktop Brings About Trojans &amp; Community Fixes</title>
	<atom:link href="http://gigaom.com/2008/06/24/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/feed/" rel="self" type="application/rss+xml" />
	<link>http://gigaom.com/2008/06/24/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/</link>
	<description></description>
	<lastBuildDate>Sat, 25 May 2013 11:50:09 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Manzzana &#187; Blog Archive &#187; Nuevo troyano en Mac OS X</title>
		<link>http://gigaom.com/2008/06/24/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/#comment-328777</link>
		<dc:creator><![CDATA[Manzzana &#187; Blog Archive &#187; Nuevo troyano en Mac OS X]]></dc:creator>
		<pubDate>Thu, 26 Jun 2008 13:54:58 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/?p=3553#comment-328777</guid>
		<description><![CDATA[[...] Vía &#124; The Apple Blog [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Vía | The Apple Blog [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Descubierta vulnerabilidad importante en Apple Remote Desktop &#124; macevangelismo.com</title>
		<link>http://gigaom.com/2008/06/24/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/#comment-328776</link>
		<dc:creator><![CDATA[Descubierta vulnerabilidad importante en Apple Remote Desktop &#124; macevangelismo.com]]></dc:creator>
		<pubDate>Thu, 26 Jun 2008 13:31:49 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/?p=3553#comment-328776</guid>
		<description><![CDATA[[...] &#124; The Apple Blog Imagen &#124; Flickr de The Trojan [...]]]></description>
		<content:encoded><![CDATA[<p>[...] | The Apple Blog Imagen | Flickr de The Trojan [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Descubierta vulnerabilidad importante en Apple Remote Desktop &#124; Desinformado.com en Espanol</title>
		<link>http://gigaom.com/2008/06/24/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/#comment-328767</link>
		<dc:creator><![CDATA[Descubierta vulnerabilidad importante en Apple Remote Desktop &#124; Desinformado.com en Espanol]]></dc:creator>
		<pubDate>Thu, 26 Jun 2008 13:30:17 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/?p=3553#comment-328767</guid>
		<description><![CDATA[[...] &#124; The Apple Blog Imagen &#124; Flickr de The Trojan [...]]]></description>
		<content:encoded><![CDATA[<p>[...] | The Apple Blog Imagen | Flickr de The Trojan [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Descubierta vulnerabilidad importante en Apple Remote Desktop</title>
		<link>http://gigaom.com/2008/06/24/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/#comment-328768</link>
		<dc:creator><![CDATA[Descubierta vulnerabilidad importante en Apple Remote Desktop]]></dc:creator>
		<pubDate>Thu, 26 Jun 2008 13:22:52 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/?p=3553#comment-328768</guid>
		<description><![CDATA[[...] &#124; The Apple Blog Imagen &#124; Flickr de The Trojan Project      trackback    ¿Recomendarías este post?      Más [...]]]></description>
		<content:encoded><![CDATA[<p>[...] | The Apple Blog Imagen | Flickr de The Trojan Project      trackback    ¿Recomendarías este post?      Más [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pete</title>
		<link>http://gigaom.com/2008/06/24/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/#comment-328775</link>
		<dc:creator><![CDATA[pete]]></dc:creator>
		<pubDate>Wed, 25 Jun 2008 09:36:17 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/?p=3553#comment-328775</guid>
		<description><![CDATA[Hi,

vasya: I think the point in the blog post was to disable the flaw using the flaw, the shell script will be run as root anyways so sudo is not needed.

for some reason this flaw doesn&#039;t exist on my mac, I get:

execution error: ARDAgent got an error: &quot;whoami&quot; doesn’t understand the do shell script message. (-1708)

However even without this flaw in the OS you should always be careful what you run even with just your use rights. All bets are off when you run malicious code, this just makes it easier to do nasty stuff.

pete]]></description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>vasya: I think the point in the blog post was to disable the flaw using the flaw, the shell script will be run as root anyways so sudo is not needed.</p>
<p>for some reason this flaw doesn&#8217;t exist on my mac, I get:</p>
<p>execution error: ARDAgent got an error: &#8220;whoami&#8221; doesn’t understand the do shell script message. (-1708)</p>
<p>However even without this flaw in the OS you should always be careful what you run even with just your use rights. All bets are off when you run malicious code, this just makes it easier to do nasty stuff.</p>
<p>pete</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WinExtra &#187; From the Pipeline &#8211; 6.24.08</title>
		<link>http://gigaom.com/2008/06/24/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/#comment-328774</link>
		<dc:creator><![CDATA[WinExtra &#187; From the Pipeline &#8211; 6.24.08]]></dc:creator>
		<pubDate>Wed, 25 Jun 2008 07:51:27 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/?p=3553#comment-328774</guid>
		<description><![CDATA[[...] Unpatched Flaw In Apple Remote Desktop Brings About Trojans &amp; Community Fixes :: The Apple Blog – as Apple becomes more popular it is only a matter of time before things like this will become more commonplace. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Unpatched Flaw In Apple Remote Desktop Brings About Trojans &amp; Community Fixes :: The Apple Blog – as Apple becomes more popular it is only a matter of time before things like this will become more commonplace. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GroovyBrent</title>
		<link>http://gigaom.com/2008/06/24/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/#comment-328770</link>
		<dc:creator><![CDATA[GroovyBrent]]></dc:creator>
		<pubDate>Wed, 25 Jun 2008 05:26:00 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/?p=3553#comment-328770</guid>
		<description><![CDATA[Just a possible warning on this fix; After executing it, Remote Desktop no longer opens for me (&quot;The Remote Desktop Administrator software failed to start due to an unexpected error&quot;).

It&#039;s late, and I&#039;m tired, so I could have possibly done something wrong, or the 2 events (running the command and Remote Desktop failing) may be totally unrelated.  Just wanted to get it out there as a possible &quot;gotcha.&quot;  Will explore more when I have some time.]]></description>
		<content:encoded><![CDATA[<p>Just a possible warning on this fix; After executing it, Remote Desktop no longer opens for me (&#8220;The Remote Desktop Administrator software failed to start due to an unexpected error&#8221;).</p>
<p>It&#8217;s late, and I&#8217;m tired, so I could have possibly done something wrong, or the 2 events (running the command and Remote Desktop failing) may be totally unrelated.  Just wanted to get it out there as a possible &#8220;gotcha.&#8221;  Will explore more when I have some time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://gigaom.com/2008/06/24/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/#comment-328773</link>
		<dc:creator><![CDATA[Mike]]></dc:creator>
		<pubDate>Wed, 25 Jun 2008 00:05:17 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/?p=3553#comment-328773</guid>
		<description><![CDATA[Instead of 0555, just chmod it u-s:

sudo chmod u-s /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent

Which removes the setuid bit from the file.

The setuid (literally set uid, or set user id) bit instructs the system that when the command is executed (here, ARDAgent) it should be run as the owner of the file (in this case root, the administrator) instead of the person executing the command as would be normal.]]></description>
		<content:encoded><![CDATA[<p>Instead of 0555, just chmod it u-s:</p>
<p>sudo chmod u-s /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent</p>
<p>Which removes the setuid bit from the file.</p>
<p>The setuid (literally set uid, or set user id) bit instructs the system that when the command is executed (here, ARDAgent) it should be run as the owner of the file (in this case root, the administrator) instead of the person executing the command as would be normal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vasya</title>
		<link>http://gigaom.com/2008/06/24/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/#comment-328772</link>
		<dc:creator><![CDATA[vasya]]></dc:creator>
		<pubDate>Tue, 24 Jun 2008 23:33:29 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/?p=3553#comment-328772</guid>
		<description><![CDATA[Don&#039;t get it, but most people think that regular admin user can change attributes of file which belongs to root. it&#039;s wrong. you need to use sudo command, as Ken suggested. So correct script will be:
osascript -e &#039;tell app &quot;ARDAgent&quot; to do shell script &quot;sudo chmod 0555 /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent&quot;&#039;;

But this is wrong anyway. Ken is correct - just do sudo chmod 555 blah-blah-blah]]></description>
		<content:encoded><![CDATA[<p>Don&#8217;t get it, but most people think that regular admin user can change attributes of file which belongs to root. it&#8217;s wrong. you need to use sudo command, as Ken suggested. So correct script will be:<br />
osascript -e &#8216;tell app &#8220;ARDAgent&#8221; to do shell script &#8220;sudo chmod 0555 /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent&#8221;&#8216;;</p>
<p>But this is wrong anyway. Ken is correct &#8211; just do sudo chmod 555 blah-blah-blah</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ken</title>
		<link>http://gigaom.com/2008/06/24/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/#comment-328769</link>
		<dc:creator><![CDATA[Ken]]></dc:creator>
		<pubDate>Tue, 24 Jun 2008 23:00:56 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/?p=3553#comment-328769</guid>
		<description><![CDATA[For a simple command that avoids all the quotes, do the following from an account that is allowed to administer the system:

&lt;code&gt;
sudo chmod 0555 /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent
&lt;/code&gt;

Enter your password when prompted.  All that extra stuff in the article example is just using the backdoor to close the backdoor.]]></description>
		<content:encoded><![CDATA[<p>For a simple command that avoids all the quotes, do the following from an account that is allowed to administer the system:</p>
<p><code><br />
sudo chmod 0555 /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent<br />
</code></p>
<p>Enter your password when prompted.  All that extra stuff in the article example is just using the backdoor to close the backdoor.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
