MacSecure.com
A Mac Security Blog

Archive for the 'News' Category

TrueCrypt for Mac - Version Update !

Wednesday, March 5th, 2008

The new revision of TrueCrypt - Version 5.0(a) — has now been released for Mac.   Downloads are available here.  I haven’t had a change to work with it since I’m traveling, but initial word from some colleagues is that it works as expected.

TrueCrypt Notes

Friday, February 8th, 2008

Got to do some testing with TrueCrypt on the Mac - and immediately hit a wall.  One of the unique features of TrueCrypt is the ability to create a hidden TrueCrypt volume inside of another TrueCrypt volume.  The idea is that if you were forced to reveal a passphrase, you give up the passphrase to […]

TrueCrypt for Mac - Released

Wednesday, February 6th, 2008

A staple on the Windows OS for quite a while, TrueCrypt has finally been ported to OS X. While it doesn’t have a lot of polish yet, it does indeed seem to work like the Windows version does. TrueCrypt has the ability to create an encrypted volume — which can […]

Apple Security Update 2007-009

Tuesday, December 18th, 2007

Fixing some of the known issues with cups, tar, Safari, samba, etc.   Lots of updates in this one.
Apple has more info with CVE’s listed here.    SANS also has a blurb about it here.   I’ll install tonight and take some notes.   Also, coming soon — more tool discussions.

Leopard Crash “Risk”

Tuesday, December 11th, 2007

I’d say it’s less ‘risk’ and more ‘real’ at this point — but I’m traveling and I haven’t had much time to look into it yet.    Heise has more info available here.

Firewall Rules for Quicktime RTSP Vulnerability

Thursday, December 6th, 2007

See here.   Just a quick note:  if you read the Symantec advisory regarding the Quicktime RTSP Header Vunerability, they mention blocking certain traffic if you’re worried about the exploit — which appears to be Windows specific at this point. In the interest of being safe though, here is a set of ipfw rules for blocking […]

Quicktime Vulnerability - RTSP Headers

Tuesday, December 4th, 2007

Symantec is reporting details of a vulnerability in Quicktime 7.2 and 7.3 that is currently unpatched by Apple.   Right now the exploits in the wild for this vulnerability appear to only be loading Windows executables, but the suggestion is that OS X systems could potentially be vulnerable as well.  Recommended steps until there is […]

“Ultimate” Leopard Firewall Ruleset

Tuesday, November 20th, 2007

Rich over at Securosis and some other folks have been working on a set of rules for the Leopard firewall (ipfw) that would be restrictive without breaking everything completely.  The ruleset has been tweaked extensively now and takes a lot of things into account.   I’ll be testing it out tonight, but it looks great so […]

Mac OS 10.5.1 Update - Security Changes

Thursday, November 15th, 2007

I’m sure the 10.5.1 update (which just rolled out to Software Update today) will be dissected on all of the Mac forums and blogs, but in the Security section of the release notes, there are a few highlights that were noteworthy:

The “Block All Incoming Connections” setting I talked about here has now been changed to […]

Leopard Firewall: Why it’s acting the way it’s acting.

Wednesday, November 7th, 2007

Apple posted documentation about the Application Firewall today which explains a lot of what many folks have been seeing.
I haven’t had much time to analyze it yet, but here’s the kicker:
Anything running as UID 0 will not be blocked, even when the Application Firewall is set to Block All Incoming Connections.     This explains why the […]