May 5, 2024

Charlie Miller to Disclose How He Found 20 Zero Day Holes in Mac OS X

Posted March 19, 2010 at 12:59pm by iClarified · 4006 views
Security expert Charlie Miller is planning to disclose how he found 20 zero day security holes in Mac OS X at the CanSecWest security conference next week, according to H-Online.

The zero-day holes are present in closed source Apple products, said Miller. "OS X has a large attack surface consisting of open source components (i.e. webkit, libz, etc), closed source 3rd party components (Flash), and closed source Apple components (Preview, mdnsresponder, etc). Bugs in any of these types of components can lead to remote compromise"

Miller discovered the vulnerabilities by fuzzing, a process which bombards application input channels with as much corrupted data as possible. His presentation subtitled, "An analysis of fuzzing 4 products with 5 lines of Python" will discuss "what you really find when you fuzz and it tries to draw conclusions about what to expect in the future when you fuzz a mature product."

Miller says Apple users are currently "safer, but less secure."

"Mac OS X is like living in a farmhouse in the country with no locks, and Windows is living in a house with bars on the windows in the bad part of town."

Read More [via Jacqui]