I find it rather interesting that a blog entry was used to reply to my blog entry on Adware on the Mac. Whilst I appreciate the reply, I just hope that JTanium gets to register an account so it’d be easier for me to keep track of your suggestions and comments.
Anyway, if you have read what I wrote – I said and you quoted:
“I am curious as to how this is achieved specially when you are not running as administrator and all applications that you use are saved at the default /Applications, which require admin privileges for write access.”
Normally, the first user that is created by Mac OS X is the administrator. Unfortunately, most Mac users stick with this account to make it convenient for them to add/remove applications. Try creating another user without admin privileges and you will see what I mean.
To test it, I did try to drag and drop files into /Applications using the Finder. No matter what application I add, it prompts me to enter the username and password of an account with admin privileges. Even dragging and dropping a PDF file into /Applications will ask you to authenticate.
I urge you to test it using an account with no admin privileges and you will know what I mean.
Technorati Tags: mac os x, vulnerability