<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mac Sage &#187; Security</title>
	<atom:link href="http://www.macsage.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.macsage.com</link>
	<description>Consulting. Design. Solutions.</description>
	<lastBuildDate>Fri, 29 Jan 2010 03:44:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>OS X Trojan In The Wild</title>
		<link>http://www.macsage.com/os-x-trojan-in-the-wild/</link>
		<comments>http://www.macsage.com/os-x-trojan-in-the-wild/#comments</comments>
		<pubDate>Fri, 20 Jun 2008 18:17:12 +0000</pubDate>
		<dc:creator>patrick</dc:creator>
				<category><![CDATA[Alert]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[rojan]]></category>

		<guid isPermaLink="false">http://www.mac-sage.com/wordpress/?p=181</guid>
		<description><![CDATA[I usually refrain from posting &#8220;theoretical&#8221; OS X exploits since they rarely pose any real threat to Mac users. However, several sources are now reporting multiple Mac Trojan horses in the wild. These Trojans exploit a root vulnerability in Apple Remote Desktop Agent in Mac OS X 10.4 and 10.5.
This exploit has been rated as [...]]]></description>
			<content:encoded><![CDATA[<p>I usually refrain from posting &#8220;theoretical&#8221; OS X exploits since they rarely pose any real threat to Mac users. However, several sources are now reporting multiple Mac Trojan horses in the wild. These Trojans exploit a root vulnerability in Apple Remote Desktop Agent in Mac OS X 10.4 and 10.5.</p>
<p>This exploit has been rated as &#8220;critical&#8221;, but it does require that a user download and open the Trojan file.</p>
<p>Pay attention, folks. We knew that Macs would come more and more into hackers focus as market-share grew.</p>
<p>See more information at the <a title="Mac Trojan Information" href="http://www.securemac.com/applescript-tht-trojan-horse.php" target="_blank">SecureMac site</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.macsage.com/os-x-trojan-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mac OS X Snow Leopard</title>
		<link>http://www.macsage.com/mac-os-x-snow-leopard/</link>
		<comments>http://www.macsage.com/mac-os-x-snow-leopard/#comments</comments>
		<pubDate>Thu, 19 Jun 2008 21:48:56 +0000</pubDate>
		<dc:creator>patrick</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[OS X]]></category>

		<guid isPermaLink="false">http://www.mac-sage.com/wordpress/?p=177</guid>
		<description><![CDATA[Apple announced OS X 10.6 named Snow Leopard as more of a performance release rather than a feature release.
Some of the announced changes include a smaller footprint (giving back some hard drive space), Microsoft Exchange support, extended 64-bit support to allow a theoretical 16TB of RAM, faster clock speeds with the multicore &#8220;Grand Central&#8221; technology, [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft alignnone size-full wp-image-178" style="float: left;" title="snow_leopard" src="http://www.mac-sage.com/wp-content/uploads/2008/06/snowleopard.jpg" alt="Snow Leopard" width="374" height="143" />Apple announced OS X 10.6 named Snow Leopard as more of a performance release rather than a feature release.</p>
<p>Some of the announced changes include a smaller footprint (giving back some hard drive space), Microsoft Exchange support, extended 64-bit support to allow a theoretical 16TB of RAM, faster clock speeds with the multicore &#8220;Grand Central&#8221; technology, and QuickTime X which includes optimized support for the latest codecs.</p>
<p>It&#8217;s not known yet whether Snow Leopard is the beginning of dropped support for PowerPC by Apple. Several developers are reporting that their developer preview copy runs only on Intel machines.</p>
<p>The rumors are that this will be a free upgrade, but that hasn&#8217;t been announced yet.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.macsage.com/mac-os-x-snow-leopard/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Pile of Patches for Leopard and Tiger</title>
		<link>http://www.macsage.com/pile-of-patches-for-leopard/</link>
		<comments>http://www.macsage.com/pile-of-patches-for-leopard/#comments</comments>
		<pubDate>Mon, 17 Dec 2007 23:40:49 +0000</pubDate>
		<dc:creator>patrick</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[10]]></category>
		<category><![CDATA[22]]></category>
		<category><![CDATA[23]]></category>
		<category><![CDATA[30]]></category>

		<guid isPermaLink="false">http://mac-sage.com/wordpress/?p=141</guid>
		<description><![CDATA[Apple just released a big old pile of patches for the security-burdened Leopard and Tiger operating systems. Among the addressed problems:
&#160;

 Address Book
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
       CFNetwork
Impact: Visiting a malicious website could allow the automatic download [...]]]></description>
			<content:encoded><![CDATA[<p>Apple just released a big old pile of patches for the security-burdened Leopard and Tiger operating systems. Among the addressed problems:</p>
<p align="left">&nbsp;</p>
<ul class="q2">
<li><em> Address Book<br />
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution</em></li>
<li><em>       CFNetwork<br />
Impact: Visiting a malicious website could allow the automatic download of files to arbitrary folders to which the user has write permission</em></li>
<li><em>       Core Foundation<br />
Impact: Usage of CFURLWriteDataAndPropertiesToResource API may lead to the disclosure of sensitive information</em></li>
<li><em>       Desktop Services<br />
Impact: Opening a directory containing a maliciously-crafted .DS_Store file in Finder may lead to arbitrary code execution</em></li>
<li>
<p align="left"><em>       Flash Player Plug-in<br />
Description: Adobe Flash Player is updated to version 9.0.115.0 to address CVE-2007-5476.<br />
Further information is available via the Adobe site at <a href="http://www.adobe.com/support/security/advisories/apsa07-05.html">http://www.adobe.com/support/security/advisories/apsa07-05.html</a><br />
Credit to Opera</em></li>
<li><em>       GNU Tar<br />
Impact: Extracting a maliciously crafted tar archive could overwrite arbitrary files</em></li>
<li><em>       iChat<br />
Impact: A person on the local network may initiate a video connection without the user&#8217;s approval</em></li>
<li><em>       IO Storage Family<br />
Impact: Opening a maliciously crafted disk image may lead to an unexpected system shutdown or arbitrary code execution</em></li>
<li><em>       Launch Services<br />
Impact: Opening a maliciously crafted HTML file may lead to information disclosure or cross-site scripting<br />
Impact: Opening an executable mail attachment may lead to arbitrary code execution with no warning</em></li>
<li><em>       Mail<br />
Impact: SMTP accounts set up through Account Assistant may use plaintext authentication even when MD5 Challenge-Response authentication is available</em></li>
<li><em>       Quick Look<br />
Impact: Previewing a file with QuickLook enabled may lead to the disclosure of sensitive information<br />
Impact: Previewing a movie file may access URLs contained in the movie</em></li>
<li><em>       Safari<br />
Impact: Visiting a malicious website may result in the disclosure of sensitive information</em></li>
<li><em>       Safari RSS<br />
Impact: Accessing a maliciously crafted feed: URL may lead to an application termination or arbitrary code execution</em></li>
<li><em>       Samba<br />
Impact: Multiple vulnerabilities in Samba</em></li>
<li><em>       Shockwave Plug-in<br />
Impact: Opening maliciously crafted Shockwave content may lead to arbitrary code execution</em></li>
<li><em>       SMB<br />
Impact: A local user may be able to execute arbitrary code with system privileges</em></li>
<li><em>       Software Update<br />
Impact: A man-in-the-middle attack could cause Software Update to execute arbitrary commands</em></li>
<li><em>       Spin Tracer<br />
Impact: A local user may be able to execute arbitrary code with system privileges</em></li>
<li><em>       Spotlight<br />
Impact: Downloading a maliciously crafted .xls file may lead to an unexpected application termination or arbitrary code execution</em></li>
</ul>
<p align="left">Get a look at Apple&#8217;s full descriptions of issues and fixes at their site: <a href="http://docs.info.apple.com/article.html?artnum=307179" target="_blank">Security Update 2007-009</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.macsage.com/pile-of-patches-for-leopard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Leopard Security &#8211; Still An Issue</title>
		<link>http://www.macsage.com/leopard-security-still-an-issue/</link>
		<comments>http://www.macsage.com/leopard-security-still-an-issue/#comments</comments>
		<pubDate>Tue, 04 Dec 2007 04:23:01 +0000</pubDate>
		<dc:creator>patrick</dc:creator>
				<category><![CDATA[Alert]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[10]]></category>
		<category><![CDATA[16]]></category>
		<category><![CDATA[22]]></category>
		<category><![CDATA[23]]></category>
		<category><![CDATA[32]]></category>

		<guid isPermaLink="false">http://mac-sage.com/wordpress/?p=139</guid>
		<description><![CDATA[The QuickTime vulnerability originally reported on November 15 seems to have been spotted in the wild. This is not good news.
Apple made a decision to change the firewall settings in Leopard, provoking some serious questions about the security of this new OS. This latest security issue puts a spotlight on what may become a real [...]]]></description>
			<content:encoded><![CDATA[<p>The QuickTime vulnerability originally reported on November 15 seems to have been spotted in the wild. This is not good news.</p>
<p>Apple made a decision to change the firewall settings in Leopard, provoking some serious questions about the security of this new OS. This latest security issue puts a spotlight on what may become a real thorn in Apple&#8217;s side.</p>
<p>This from Symantec:</p>
<p><em>Originally, the flaw was disclosed on November 23, 2007 by Polish security researcher Krystian Kloskowski and since then we have seen number of exploits targeting the vulnerability being released to the public. But now the exploit is active and in the wild, meaning web surfers are in danger of being attacked. Our current analysis is also leading us to believe that there may be multiple attacks in existence. Further investigation is currently under way to confirm this.</em></p>
<p><em>Let me briefly explain what we have seen. The attack we have confirmed today begins with the popular IFRAME. An IFRAME code that causes the browser to make an additional request to another URL, is embedded in a porn site. Without knowledge, users visiting this site are redirected to the malicious site serving the exploit. Currently, the malware that is downloaded by the exploit is detected by Symantec as Downloader. We are still studying the attack in depth, so look out for more information at a later time.</em></p>
<p><em>Since a patch to correct the issue has yet to be released, we advise users to be cautious when browsing the web. For those of you seeking extra protection, we also recommend the following options:</em></p>
<p><em>- Run web browsers at the highest security settings possible<br />
- Disable Apple QuickTime as a registered RTSP protocol handler.<br />
- Filter outgoing activity over common RTSP ports, including TCP port 554 and UDP ports 6970-6999.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.macsage.com/leopard-security-still-an-issue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Leopard Firewall Off By Default</title>
		<link>http://www.macsage.com/leopard-firewall-off-by-default/</link>
		<comments>http://www.macsage.com/leopard-firewall-off-by-default/#comments</comments>
		<pubDate>Tue, 06 Nov 2007 22:55:01 +0000</pubDate>
		<dc:creator>patrick</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[19]]></category>
		<category><![CDATA[22]]></category>
		<category><![CDATA[23]]></category>

		<guid isPermaLink="false">http://mac-sage.com/wordpress/?p=136</guid>
		<description><![CDATA[The casual user of Apple&#8217;s new operating system, Leopard, may not be aware that unlike in Tiger, the firewall is off by default. To turn it on, you&#8217;ll need to go to System Preferences/Security/Firewall tab.

This is a new interface which lets you specify firewall blocking by application rather than ports or services (unlike Tiger). There [...]]]></description>
			<content:encoded><![CDATA[<p>The casual user of Apple&#8217;s new operating system, Leopard, may not be aware that unlike in Tiger, the firewall is off by default. To turn it on, you&#8217;ll need to go to System Preferences/Security/Firewall tab.</p>
<p align="center"><img src="http://www.mac-sage.com/wp-content/uploads/2007/11/firewall.png" alt="firewall.png" /></p>
<p>This is a new interface which lets you specify firewall blocking by application rather than ports or services (unlike Tiger). There have been several reports that Leopard&#8217;s firewall does not behave like Tiger&#8217;s. In some cases,  it appears that it is not blocking certain services indicated by the settings.</p>
<p>Stay tuned for ongoing information regarding Leopard&#8217;s firewall issues, including some other security issues arising from Leopard&#8217;s Screen Sharing capabilities.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.macsage.com/leopard-firewall-off-by-default/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
