MacSecure.com
A Mac Security Blog

Archive for December, 2007

Apple Security Update 2007-009

Tuesday, December 18th, 2007

Fixing some of the known issues with cups, tar, Safari, samba, etc.   Lots of updates in this one.
Apple has more info with CVE’s listed here.    SANS also has a blurb about it here.   I’ll install tonight and take some notes.   Also, coming soon — more tool discussions.

Leopard Crash “Risk”

Tuesday, December 11th, 2007

I’d say it’s less ‘risk’ and more ‘real’ at this point — but I’m traveling and I haven’t had much time to look into it yet.    Heise has more info available here.

Firewall Rules for Quicktime RTSP Vulnerability

Thursday, December 6th, 2007

See here.   Just a quick note:  if you read the Symantec advisory regarding the Quicktime RTSP Header Vunerability, they mention blocking certain traffic if you’re worried about the exploit — which appears to be Windows specific at this point. In the interest of being safe though, here is a set of ipfw rules for blocking […]

Product Review: FileDefense

Wednesday, December 5th, 2007

At the end of November, SubRosaSoft released “FileDefense” - a new application for securing Mac OS X computers. SubRosaSoft makes and sells a number of utilities as well as some freeware for Macs; I primarily know of them for their MacForensicsLab and MacLockPick programs. From their website:
“FileDefense is a program that forms the first line […]

Quicktime Vulnerability - RTSP Headers

Tuesday, December 4th, 2007

Symantec is reporting details of a vulnerability in Quicktime 7.2 and 7.3 that is currently unpatched by Apple.   Right now the exploits in the wild for this vulnerability appear to only be loading Windows executables, but the suggestion is that OS X systems could potentially be vulnerable as well.  Recommended steps until there is […]