Talk With an Expert

Covering the Tracks on Mac OS X Leopard

Covering the Tracks on Mac OS X Leopard (PDF, 2.49MB)Published: 09 Jan, 2009
Created by:
Charlie Scott

Many systems administrators are not aware of the subtle differences between Mac OS X and its Unix operating system brethren (Jepson, Rothman, and Rosen, 2008). Hackers can exploit this ignorance when hiding their presence on compromised systems (Skoudis, 2007). In this paper, I apply the Covering the Tracks techniques described in the SANS SEC 504 course to Mac OS X. Doing so highlights the ways in which Mac OS X and Unix diverge, increasing awareness of how an attacker might conceal himself in Mac OS X. The goal is to improve vigilance among systems administrators so they can better prepare for and identify intrusions on Mac OS X systems.