Mac OS X Leopard
The firewall configuration in the Mac OS X Leopard is 'unable to keep out uninvited guests'

Security expert mauls Leopard firewall

Researcher finds glaring holes in new Apple OS

Written by Shaun Nichols in California

The firewall in Apple's new OS X Leopard operating system is unreliable and unable to keep out hackers, according to one security researcher.

Jurgen Schmidt, of Heise Security, issued a report claiming that the Leopard firewall failed every security test performed by the firm.

"The most important task for any firewall is to keep out uninvited guests," wrote Schmidt.

"But a quick look at the firewall configuration in the Mac OS X Leopard shows that it is unable to do this."

Among the shortcomings are a default 'off' state, hidden components that can be accessed by remote users but cannot easily be blocked, and an inability completely to block incoming connections.

"Specifically these results mean that users cannot rely on the firewall," stated Schmidt.

"Even if users select 'block all incoming connections' potential attackers can continue to communicate with system services such as the time server and possibly with the NetBIOS name server."

Schmidt compared the vulnerability of Leopard to that of Microsoft's Windows XP when it first debuted.

"Apple is showing here a casual attitude with regard to security questions which strongly recalls that of Microsoft four years ago," he wrote.

"Although the problems and peculiarities described here are not security vulnerabilities in the sense that they can be exploited to break into a Mac, Apple would be well advised to sort them out pronto."

Tags:

Further reading

Leopard roars to two million sales

Opening weekend best ever for MacOS   More...

Leopard users unable to run Java 1.6

Developers claim Java 6 absent from new Apple OS   More...

Mozilla fixes Firefox flaws and welcomes Leopard

But still some issues running browser on latest Apple Mac OS   More...

OS X declared full Unix

It is not Unix unless it's Unix 03 certified   More...

Related articles

Apple fixes Leopard firewall

New update addresses security issues   More...

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Apple issues major OS X security update

Safari also patched   More...

Apple unleashes Leopard and Tiger updates

Eleven security fixes included   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement