Orbicule Undercover allows attackers with physical or root access to disable the protection by using the chmod command to change the permissions of the /private/etc/uc.app/Contents/MacOS/uc file, which prevents the service from being started in LaunchDaemon.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/423955/100/0/threaded | mailing list |