Follow Us

Intego issues OS X security alert

Bluetooth hole grants root access.

Intego has found a "low risk" hole in Mac OS X involving Bluetooth. The exploit, called Inqtana.d, is a proof-of-concept that hasn't been seen "in the wild", the company said.

It is the latest permutation of a malware threat that first came to light earlier in the year and depends on security holes in Macs running Mac OS X v10.3 and 10.4 that haven't been updated all the available security updates, according to Intego.

Inqtana.d can be installed on a Mac through an "rfcomm" security hole in Bluetooth from a computer or PDA running Linux, Intego said. The attacking computer needs to be within Bluetooth range - approximately 30 feet. Unlike previous implementations of Inqtana, it doesn't require any user interaction - a user account called "bluetooth" is created, which grants root access that can then be exploited for malicious use.

Related Articles on Techworld

Intego also said that the Inqtana.d malware installs additional software, and the user account includes a "backdoor" which lets users log in through that account using Ethernet or AirPort. "Users with updated Mac OS X systems will already have installed a security update that protects against this vulnerability," noted Intego.

Apple has already posted a security update for Mac OS X v10.3 and Mac OS X v10.4.7 that closes the exploit - but if you haven't updated your Mac with those, it remains at risk.

"If, however, users' computers have been compromised before applying the updates mentioned above, the damage will be done, and the backdoor will remain installed. The only way to ensure that this backdoor is removed is to run Intego VirusBarrier X4," said Intego.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Desktop modernisation

On the one hand, there is the need to keep the existing desktop environment efficient, secure...

Download Whitepaper

Top 10 myths about virtualising business-critical applications

Even though virtualization has brought positive change to enterprise IT over the last decade,...

Download Whitepaper

Aligning CFO and CIO priorities

Forward-thinking organisations are viewing cloud computing as an investment in business...

Download Whitepaper

The new corporate network

Businesses can’t afford to have employee productivity suffer because they cannot use their...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...
LogMeIn Rescue

Accelerate Your IT Efficiency

View the latest capacity management resources including whitepapers, videos and news.

Find out more...

Site Map

* *