News19,135 Articles

July 19, 2007

Death threats over Mac OS X 'worm'

Hacker threatened in Apple security shocker

Gregg Keizer

The author of a Mac OS X worm has received death threats via his or her blog. The furore started earlier this week, when a researcher responsible for the Information Security Sell Out (InfoSec) blog announced a proof-of-concept worm that exploited a Mac OS X vulnerability which Apple missed in a May round of patches.

The vulnerability exploited by the worm was in mDNSResponder, a component of Apple's Bonjour automatic network configuring service, InfoSec said then.

Criticism from Mac users and other security researchers was almost immediate, with the former focusing on crude insults and the latter concentrating on InfoSec's refusal to identify himself or herself, or prove that the worm existed.

The latter group questioned InfoSec's motives and the veracity of his or her claims. "Let's see this worm deliver a destructive payload in the wild and then we can talk again," said a user identified as Ted Wood. "Until then, you're just hot air."

"If you are a legitimate researcher, you have an obligation to publish your findings so they can be tested," said Stephen, another user on the same comment list. "Any good researcher would do this."

According to InfoSec, some of the comments left earlier included death threats. In a posting - since deleted, more on that below - from Tuesday, InfoSec listed comments he refused to allow to be posted to the blog. Among them:

"You are lucky you are anonymous or I would put a bullet in your head for this!" - Anonymous

"Nice try with the FUD [fear, uncertainty and doubt]. You are full of **** there is no such thing as an Apple Worm." - Jeff

"I dare you to demonstrate this at Defcon you ***** Microsoftie. We will drag you out, put a bullet in you, and bury your body so deep it will take a nuclear blast to find your body." - Anonymous

On Tuesday night, the InfoSec blog's title changed to ‘Security Information...’ and all former postings, which began in January, had been deleted. When asked via email to explain the changes, InfoSec answered: "Blog was hijacked somehow. Also the blog stating I am associated with PHC on another Blog is false and a myth created by Dave Maynor who is involved in the hijacking of the Blog."

InfoSec was likely referring to a posting on a blog dubbed ‘Security Ripcord’ at a site run by a Texas-based security consultancy called Cutaway. In a long entry posted this morning, Don Weber, a.k.a. Cutaway, said an informant had told him that that InfoSec is actually ‘LMH’, a researcher best known for having co-authored January's Month of Apple Bugs (MoAB) campaign. The source also claimed, said Weber, that LMH was part of a group that calls itself ‘Phrack High Council’, or PHC, a self-described group of "black hat" hackers.

No way, said InfoSec.

"The claim that we are LMH or MoAB or PHC are all wrong," InfoSec wrote in a second email yesterday. "These came from Maynor assuming that we are all one and the same because we have all attacked his creditability."

Continued...
1 | 2 | NEXT >

Free whitepaper: Phishing for victims - Truth, myth and cybercrime

<<newer story | back to index | older story>>

Comments received


A Sane Mac User said on Thursday, 19 July 2007

I get the impression that this article is going to fuel the myth that all Mac users are nutters, without exception. There are plenty of perfectly sane Mac users who aren't going to shout at you, who aren't going to preach to you and aren't going to kill you if you write malware for OS X. Try and get the fanboys in proportion - they are a minority, albeit a very vocal one, but nothing more.

What is this?

Subscribe to PC Advisor now and claim your FREE gift

Keep up to date by adding PC Advisor News to your iGoogle home page or Google Reader


Question of the day!

Does your smartphone replace your need for a laptop when on the move?

Question of the day!

Does your smartphone replace your need for a laptop when on the move?

% of PC Advisor readers agree with you

Yes
TBC
No
TBC

What tasks can your smartphone do that would have traditionally been done on a laptop?

119 characters remaining

Follow the conversation at @SmartphoneFocus

web browsing, search facilities, voip, email, word processing everything RT @Graham_D_C

Mainly email but getting better at spreadsheets etc, RT @IDGdan

Google


Recent reviews

Reviews index


Latest reader comments

Latest reader comments


Top news

News index


Latest blog entries

Blogs index


 Our RSS feeds

Sponsored Content

  • Take the internet to new places with the Nokia N800
    Communicate how you want to, where you want to with instant messaging, email and internet calling. View movies, browse the internet wirelessly and watch TV on the high-resolution screen and listen through high-quality stereo speakers with headphone jack.
    Buy now