Hacking Articles Tips Tricks Videos Tutorials
466 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apple Addresses Critical macOS Vulnerability Allowing Undeletable Malware

Apple Addresses Critical macOS Vulnerability Allowing Undeletable MalwarePost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Apple Takes Swift Action to Address Critical macOS Vulnerability Exploiting System Integrity Protection (SIP)In a recent development, Apple has promptly responded to a significant vulnerability discovered by Microsoft security researchers. This flaw, codenamed “Migraine” and tracked as CVE-2023-32369, enables attackers with root privileges to bypass System Integrity Protection (SIP) on macOS. By circumventing Transparency, Consent, and Control (TCC) security checks, attackers could install “undeletable” malware and gain unauthorized access to victims’ private data.

Apple has released security updates for macOS Ventura 13.4, macOS Monterey 12.6.6, and macOS Big Sur 11.7.7, effectively patching the vulnerability. These updates were rolled out on May 18, just two weeks ago, demonstrating Apple’s commitment to addressing security concerns promptly.

System Integrity Protection, commonly known as SIP or “rootless,” plays a critical role in macOS security. It prevents potentially malicious software from altering essential system files and directories. SIP achieves this by imposing restrictions on the root user account, limiting its capabilities within protected areas of the operating system. The primary objective of SIP is to ensure that only Apple-signed processes or those with specific entitlements can modify macOS-protected components.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses
Notably, disabling SIP is not a straightforward task, as it requires a system restart and booting from macOS Recovery—an option only available when physical access to the compromised device is already obtained.

However, Microsoft’s researchers uncovered an avenue for attackers with root permissions to bypass SIP enforcement. They exploited the macOS Migration Assistant utility, leveraging the systemmigrationd daemon’s SIP-bypassing capabilities granted by the com.apple.rootless.install.heritable entitlement. This allowed attackers to automate the migration process using AppleScript, add a malicious payload to SIP’s exclusions list, and execute it without the need for a system restart or macOS Recovery boot. https://wus-streaming-video-rt-microsoft-com.akamaized.net/73e02d08-6769-4514-956b-9490c5fcc132/c39c1947-226e-4f0c-9633-75125a0d_6750.mp4

The Microsoft Threat Intelligence team showcased that by focusing on system processes signed by Apple and possessing the com.apple.rootless.install.heritable entitlement, they could tamper with specific child processes. This manipulation enabled arbitrary code execution, bypassing SIP checks and creating a security context that evades detection.

Bypassing SIP introduces significant risks, particularly when exploited by malware creators. It empowers malicious code to have far-reaching consequences, including the creation of SIP-protected malware that remains resistant to standard deletion methods. Furthermore, it expands the attack surface, allowing attackers to tamper with system integrity through arbitrary kernel code execution. In some cases, attackers could even install rootkits to conceal malicious processes and files from security software.
Trending: Exploit XSS Injections in a one-line powerful Technique Trending: Recon Tool: Sniffer
By bypassing SIP protection, threat actors can completely evade Transparency, Consent, and Control (TCC) policies. This grants them unrestricted access to the v[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Apple Addresses Critical macOS Vulnerability Allowing Undeletable Malware Apple Addresses Critical macOS Vulnerability Allowing Undeletable MalwarePost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/up…
ictim’s private data by replacing TCC databases. The implications of this bypass are severe and demand immediate attention.

This is not the first time Microsoft researchers have discovered vulnerabilities in macOS. In 2021, they reported another SIP bypass known as Shrootless, enabling attackers to execute arbitrary operations, escalate privileges to root, and potentially install rootkits on compromised Macs. More recently, Jonathan Bar Or, a principal security researcher at Microsoft, unearthed a security flaw named Achilles. This flaw allowed attackers to deploy malware through untrusted apps capable of bypassing Gatekeeper execution restrictions. Additionally, Bar Or discovered powerdir, another macOS security bug that permits attackers to bypass TCC technology, accessing users’ protected data.

The proactive steps taken by Apple to address this vulnerability demonstrate the ongoing battle to safeguard macOS from evolving threats. As the cybersecurity landscape continues to evolve, it is imperative for users to stay vigilant, keep their systems updated, and follow recommended security practices to protect their data and privacy.
Trending: BrutePrint Attack: Researchers Unveil New Technique to Bypass Smartphone Fingerprint Authentication
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-18-300x150.png Kali Linux 2023.2 Release (New Tools in Kali, Desktop Updates, New Hyper-V VM Image)May 30, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-17-300x150.png Leaked RaidForums Database Exposes Hacker IdentitiesMay 30, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-16-300x150.png Clever Phishing Toolkit Emerges: Fake WinRAR and Windows File Explorer on ZIP DomainsMay 29, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-15-300x150.png Barracuda’s Email Security Breached: Zero-Day Flaw Puts Users at RiskMay 26, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Apple Addresses Critical macOS Vulnerability Allowing Undeletable Malware first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Is there a way to restrict access to YouTube at certain times of day both on cellular data and WiFi?

So my dad plays annoying music in the morning and it disrupts my sleep. Is there a way to restrict his YouTube access without it looking suspicious?

submitted by /u/ap426
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Best places to get a remote job

Hi everyone! I want to get a remote job in cybersecurity, were i live is too hard to get a job in redteaming or security analysis, i plan to do it after 3 months of work (and obtain CRTP from Altered Security).

I'm not a US citizen, i want a entry job and i have one year of experience in security field + 3 years of software development. At the end of this year i plan to have:

* eCPPT - eLeanSecurity (near to exam)
* CRTP - Altered Security
* CISA - CompTIA

Thanks!

submitted by /u/oppai_silverman
[link] [comments]