You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

crsud process with security update 2013-001

I just installed the new security update, 2013-001, and Little Snitch detected a new process at startup, crsud, which wants to connect to Apple.


I would like to know what this does. My guess is that it checks for updates, perhaps to some security software. Anyone know?


It seems to me that when such a process is added, it is appropriate for Apple to explain itself in the update description, but I am old-fashioned about such things.


Greg

MBP 17" 2.33GHz, Mac OS X (10.5.1)

Posted on Mar 15, 2013 2:08 PM

Reply
168 replies

Apr 11, 2013 10:46 AM in response to andyBall_uk

So now I'm back to thinking I'll just let it run and each time after I'll check the install log. If it does something untoward to the system or whatever, I'll restore a clone. How's that for some firm decision making? 😁 We'll probably never know just what a patch was issued for.

andyBall_uk wrote:


don't we know already ?

it downloads certain updates, if apple make them available. Those updates can run regardless of user privilege & w/o notice, except for install.log

Apr 16, 2013 2:47 PM in response to WZZZ

WZZZ wrote:


So now I'm back to thinking I'll just let it run and each time after I'll check the install log.

I thought I should alert the group that there may be a critical update posted for 10.6.8 today:

APPLE-SA-2013-04-16-2 Java for OS X 2013-003 and

Mac OS X v10.6 Update 15

Java for OS X 2013-003 and Mac OS X v10.6 Update 15 are now available

and address the following:


Java

Available for: Mac OS X v10.6.8, Mac OS X Server v10.6.8,

OS X Lion v10.7 or later, OS X Lion Server v10.7 or later,

OS X Mountain Lion 10.8 or later

Impact: Multiple vulnerabilities in Java 1.6.0_43

Description: Multiple vulnerabilities existed in Java 1.6.0_43, the

most serious of which may allow an untrusted Java applet to execute

arbitrary code outside the Java sandbox. Visiting a web page

containing a maliciously crafted untrusted Java applet may lead to

arbitrary code execution with the privileges of the current user.

These issues were addressed by updating to Java version 1.6.0_45.

I jumped on the updates immediately, so I won't know whether this one was critical or not, but thought you might want to watch for it.


I've been watching my install log and noticed the following:

Apr 8 02:55:54 Als-iMac-i7.local Software Update[29068]: SoftwareUpdate: Checking for critical updates only.

Apr 9 22:53:41 Als-iMac-i7.local Software Update[45085]: SoftwareUpdate: Checking for critical updates only.

Apr 10 22:53:41 Als-iMac-i7.local Software Update[83019]: SoftwareUpdate: Checking for critical updates only.

Apr 11 22:53:41 Als-iMac-i7.local Software Update[28744]: SoftwareUpdate: Checking for critical updates only.

Apr 12 22:53:41 Als-iMac-i7.local Software Update[50921]: SoftwareUpdate: Checking for critical updates only.

Apr 14 22:53:42 Als-iMac-i7.local Software Update[90782]: SoftwareUpdate: Checking for critical updates only.

Apr 15 22:53:41 Als-iMac-i7.local Software Update[19924]: SoftwareUpdate: Checking for critical updates only.

So with Mountain Lion (no separate crsud process) I may only be checking for critical updates once a day, even though there is a software update check accomplished every four hours, which seems counterintuitive. I'm also getting a lot of entries with each check as if there is still debug code in this process.

Apr 16, 2013 6:02 PM in response to WZZZ

WZZZ wrote:


SU is only showing me the Java update. Nothing for Safari or anything (like the last security update did) that would update Safari. Where did you see the Safari update?

The DL1569 document hasn't been updated yet, so they may still be rolling it out. I was able to verify it's there by using the "Download" button on http://support.apple.com/downloads/.

Apr 16, 2013 7:29 PM in response to WZZZ

here at least, on 10.6.8,

crsud only actually checks about once a day, despite running more often, as install.log shows. (ds_store's mention of LS warnings seems to bear that out.)

Crsud.plist shows the LastSuccessfulScanDate & even when toggled on/off in sys prefs (which makes crsud run) that isn't necessarily altered. Adding a 'ForceScanAlways (boolean) true' key to the plist seemingly makes it check on each run.


there's also an unused key: 'AllowDevSignedPkgs' .perhaps to allow the possibility of non-apple critical updates ?

Apr 18, 2013 12:58 AM in response to WZZZ

XProtect was bumped up by two numbers Thu, 18 Apr 2013 02:36:12 GMT to add a definition for OSX.adware2.i. I toggled "Automatically update safe downloads list" to get it.


The signature doesn't match anything I can find elsewhere, so my only guess is what Thomas Reed has been working with this week with Boycott Softronic.


Surprisingly (to me) they did not change the minimum versions for either Flash or the Javas, all of which have been updated this week.

Apr 18, 2013 11:32 AM in response to WZZZ

And XProtect was just updated again to cover Java.

APPLE-SA-2013-04-18-1 OS X: Java Web plug-in blocked

Due to multiple security issues in:

Java 6 update 43 and earlier

Java 7 update 17 and earlier

Apple has updated the web plug-in blocking mechanism to disable

versions of Java older than Java 6 update 45 and Java 7 update 21.

ML is at v2037

Lion -- v1047

SL -- v63

Apr 27, 2013 4:15 PM in response to WZZZ

Just like you I feel like I'm put into a bad position by Apple. If I enable "Automatically install important security updates" in Security preferences, I fear I could destabalize my production machine at any random moment and not know why/how it happened.


But if I leave the same option unchecked, I fear that "important" security updates won't come to my machine anymore will now have a more vulnerable system.


The fact that this extensive thread exists should show anyone that Apple screwed up here by not properly documenting what this option does. Really, Apple??


Maybe if we all raise a stink with Apple they'll finally answer what the **** this thing really does?!

crsud process with security update 2013-001

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.