By John Gruber
Stop political robocalls & texts with Nomorobo!
24% off with code DARINGFIREBALL24.
Leopard’s ARDagent — the background process that handles Apple Remote Desktop access — has a security hole, where it allows arbitrary AppleScripts to run as root, and, since AppleScript can execute shell scripts, arbitrary shell code to run as root too. Brian Krebs has uncovered proof-of-concept code that takes advantage of the hole.
★ Tuesday, 24 June 2008