<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MacSecure.com &#187; News</title>
	<atom:link href="http://macsecure.com/category/news/feed/" rel="self" type="application/rss+xml" />
	<link>http://macsecure.com</link>
	<description>A Mac Security Blog</description>
	<lastBuildDate>Tue, 18 Nov 2008 00:46:01 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>MacSecure &#8211; Missing in Action</title>
		<link>http://macsecure.com/2008/11/17/macsecure-missing-in-action/</link>
		<comments>http://macsecure.com/2008/11/17/macsecure-missing-in-action/#comments</comments>
		<pubDate>Tue, 18 Nov 2008 00:46:01 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://macsecure.com/?p=33</guid>
		<description><![CDATA[This blog has been neglected for a bit, but it&#8217;s coming back soon.
]]></description>
			<content:encoded><![CDATA[<p>This blog has been neglected for a bit, but it&#8217;s coming back soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2008/11/17/macsecure-missing-in-action/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TrueCrypt for Mac &#8211; Version Update !</title>
		<link>http://macsecure.com/2008/03/05/truecrypt-for-mac-version-update/</link>
		<comments>http://macsecure.com/2008/03/05/truecrypt-for-mac-version-update/#comments</comments>
		<pubDate>Wed, 05 Mar 2008 05:56:24 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[truecrypt]]></category>

		<guid isPermaLink="false">http://macsecure.com/2008/03/05/truecrypt-for-mac-version-update/</guid>
		<description><![CDATA[The new revision of TrueCrypt &#8211; Version 5.0(a) &#8212; has now been released for Mac.   Downloads are available here.  I haven&#8217;t had a change to work with it since I&#8217;m traveling, but initial word from some colleagues is that it works as expected.
]]></description>
			<content:encoded><![CDATA[<p>The new revision of TrueCrypt &#8211; Version 5.0(a) &#8212; has now been released for Mac.   Downloads are available <a href="http://www.truecrypt.org/downloads.php" target="_blank">here</a>.  I haven&#8217;t had a change to work with it since I&#8217;m traveling, but initial word from some colleagues is that it works as expected.</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2008/03/05/truecrypt-for-mac-version-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TrueCrypt Notes</title>
		<link>http://macsecure.com/2008/02/08/truecrypt-notes/</link>
		<comments>http://macsecure.com/2008/02/08/truecrypt-notes/#comments</comments>
		<pubDate>Sat, 09 Feb 2008 02:56:16 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[truecrypt]]></category>

		<guid isPermaLink="false">http://macsecure.com/2008/02/08/truecrypt-notes/</guid>
		<description><![CDATA[Got to do some testing with TrueCrypt on the Mac &#8211; and immediately hit a wall.  One of the unique features of TrueCrypt is the ability to create a hidden TrueCrypt volume inside of another TrueCrypt volume.  The idea is that if you were forced to reveal a passphrase, you give up the passphrase to [...]]]></description>
			<content:encoded><![CDATA[<p>Got to do some testing with TrueCrypt on the Mac &#8211; and immediately hit a wall.  One of the unique features of TrueCrypt is the ability to create a hidden TrueCrypt volume inside of another TrueCrypt volume.  The idea is that if you were forced to reveal a passphrase, you give up the passphrase to the &#8216;outer&#8217; volume, and nobody would know that another volume exists inside of the main one.</p>
<p>This isn&#8217;t a requirement for many folks, but the ability to do it is going to be missed for the time being.  Regular TrueCrypt volumes are working great though.</p>
<p>More info about TrueCrypt Hidden volumes is available <a href="http://www.truecrypt.org/docs/?s=hidden-volume" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2008/02/08/truecrypt-notes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TrueCrypt for Mac &#8211; Released</title>
		<link>http://macsecure.com/2008/02/06/truecrypt-for-mac-released/</link>
		<comments>http://macsecure.com/2008/02/06/truecrypt-for-mac-released/#comments</comments>
		<pubDate>Wed, 06 Feb 2008 17:10:22 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[truecrypt security]]></category>

		<guid isPermaLink="false">http://macsecure.com/2008/02/06/truecrypt-for-mac-released/</guid>
		<description><![CDATA[A staple on the Windows OS for quite a while, TrueCrypt has finally been ported to OS X.    While it doesn&#8217;t have a lot of polish yet, it does indeed seem to work like the Windows version does.   TrueCrypt has the ability to create an encrypted volume &#8212; which can [...]]]></description>
			<content:encoded><![CDATA[<p>A staple on the Windows OS for quite a while, TrueCrypt has finally been ported to OS X.    While it doesn&#8217;t have a lot of polish yet, it does indeed seem to work like the Windows version does.   TrueCrypt has the ability to create an encrypted volume &#8212; which can be stored as random data on your disk &#8212; essentially hiding the fact that you have any hidden data.   If nobody knows you have something encrypted, how would they know to even ask for your passphrase?        As a note, TrueCrypt on Windows has been used by folks doing various illegal things over the years, and using it to hide data;  real Dateline kinds of stuff.      It&#8217;s good at what it does, but having it around could make someone think you have something to hide.</p>
<p>Try it out here:  <a href="http://www.truecrypt.org/downloads.php" target="_blank">http://www.truecrypt.org/downloads.php</a></p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2008/02/06/truecrypt-for-mac-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple Security Update 2007-009</title>
		<link>http://macsecure.com/2007/12/18/apple-security-update-2007-009/</link>
		<comments>http://macsecure.com/2007/12/18/apple-security-update-2007-009/#comments</comments>
		<pubDate>Tue, 18 Dec 2007 16:32:10 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[leopard]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[tiger]]></category>

		<guid isPermaLink="false">http://macsecure.com/2007/12/18/apple-security-update-2007-009/</guid>
		<description><![CDATA[Fixing some of the known issues with cups, tar, Safari, samba, etc.   Lots of updates in this one.
Apple has more info with CVE&#8217;s listed here.    SANS also has a blurb about it here.   I&#8217;ll install tonight and take some notes.   Also, coming soon &#8212; more tool discussions.
]]></description>
			<content:encoded><![CDATA[<p>Fixing some of the known issues with cups, tar, Safari, samba, etc.   Lots of updates in this one.</p>
<p>Apple has more info with CVE&#8217;s listed <a href="http://docs.info.apple.com/article.html?artnum=307179" target="_blank">here</a>.    SANS also has a blurb about it <a href="http://isc.sans.org/diary.html?storyid=3760&amp;rss" target="_blank">here</a>.   I&#8217;ll install tonight and take some notes.   Also, coming soon &#8212; more tool discussions.</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2007/12/18/apple-security-update-2007-009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Leopard Crash &#8220;Risk&#8221;</title>
		<link>http://macsecure.com/2007/12/11/leopard-crash-risk/</link>
		<comments>http://macsecure.com/2007/12/11/leopard-crash-risk/#comments</comments>
		<pubDate>Tue, 11 Dec 2007 18:06:33 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[heise]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://macsecure.com/2007/12/11/leopard-crash-risk/</guid>
		<description><![CDATA[I&#8217;d say it&#8217;s less &#8216;risk&#8217; and more &#8216;real&#8217; at this point &#8212; but I&#8217;m traveling and I haven&#8217;t had much time to look into it yet.    Heise has more info available here.
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;d say it&#8217;s less &#8216;risk&#8217; and more &#8216;real&#8217; at this point &#8212; but I&#8217;m traveling and I haven&#8217;t had much time to look into it yet.    Heise has more info <a href="http://www.heise-security.co.uk/news/100336" target="_blank">available here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2007/12/11/leopard-crash-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firewall Rules for Quicktime RTSP Vulnerability</title>
		<link>http://macsecure.com/2007/12/06/firewall-rules-for-quicktime-rtsp-vulnerability/</link>
		<comments>http://macsecure.com/2007/12/06/firewall-rules-for-quicktime-rtsp-vulnerability/#comments</comments>
		<pubDate>Thu, 06 Dec 2007 05:20:15 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[ipfw]]></category>
		<category><![CDATA[quicktime]]></category>
		<category><![CDATA[rtsp]]></category>

		<guid isPermaLink="false">http://macsecure.com/2007/12/06/firewall-rules-for-quicktime-rtsp-vulnerability/</guid>
		<description><![CDATA[See here.   Just a quick note:  if you read the Symantec advisory regarding the Quicktime RTSP Header Vunerability, they mention blocking certain traffic if you&#8217;re worried about the exploit &#8212; which appears to be Windows specific at this point. In the interest of being safe though, here is a set of ipfw rules for blocking [...]]]></description>
			<content:encoded><![CDATA[<p>See <a href="http://macsecure.com/2007/12/04/quicktime-vulnerability-rtsp-headers/" target="_blank">here</a>.   Just a quick note:  if you read the Symantec advisory regarding the Quicktime RTSP Header Vunerability, they mention blocking certain traffic if you&#8217;re worried about the exploit &#8212; which appears to be Windows specific at this point. In the interest of being safe though, here is a set of ipfw rules for blocking access as suggested:</p>
<p>01000   0     0 deny tcp from me to not me dst-port 554 out<br />
01100   0     0 deny tcp from me to 85.255.117.212 out<br />
01200   0     0 deny tcp from me to 85.255.117.213 out<br />
01300   0     0 deny tcp from me to 216.255.183.59 out<br />
01400   0     0 deny tcp from me to 69.50.190.135 out<br />
01500   0     0 deny tcp from me to 58.65.238.116 out<br />
01600   0     0 deny tcp from me to 208.113.154.34 out</p>
<p>You can put these in on a command line (via Terminal or iTerm) using &#8216;ipfw&#8217; or using WaterRoof.</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2007/12/06/firewall-rules-for-quicktime-rtsp-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quicktime Vulnerability &#8211; RTSP Headers</title>
		<link>http://macsecure.com/2007/12/04/quicktime-vulnerability-rtsp-headers/</link>
		<comments>http://macsecure.com/2007/12/04/quicktime-vulnerability-rtsp-headers/#comments</comments>
		<pubDate>Tue, 04 Dec 2007 15:16:22 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[cert]]></category>
		<category><![CDATA[quicktime]]></category>
		<category><![CDATA[rtsp]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://macsecure.com/2007/12/04/quicktime-vulnerability-rtsp-headers/</guid>
		<description><![CDATA[Symantec is reporting details of a vulnerability in Quicktime 7.2 and 7.3 that is currently unpatched by Apple.   Right now the exploits in the wild for this vulnerability appear to only be loading Windows executables, but the suggestion is that OS X systems could potentially be vulnerable as well.  Recommended steps until there is [...]]]></description>
			<content:encoded><![CDATA[<p>Symantec is <a href="http://www.symantec.com/business/security_response/vulnerability.jsp?bid=26560" target="_blank">reporting details</a> of a vulnerability in Quicktime 7.2 and 7.3 that is currently unpatched by Apple.   Right now the exploits in the wild for this vulnerability appear to only be loading Windows executables, but the <a href="http://www.macworld.com/news/2007/12/03/quicktimeflaw/index.php" target="_blank">suggestion is</a> that OS X systems could potentially be vulnerable as well.  Recommended steps until there is a patch include blocking outbound TCP traffic on port 554, or even blocking certain IP blocks that the Windows exploit is known to be sending data back to.    The CERT page for this vulnerability is <a href="http://www.kb.cert.org/vuls/id/659761" target="_blank">here</a> with tons of details.  As a note for anyone running OS X in a corporate environment &#8212; SourceFire&#8217;s SEU 118 has the Snort signatures for this vulnerability.</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2007/12/04/quicktime-vulnerability-rtsp-headers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>&#8220;Ultimate&#8221; Leopard Firewall Ruleset</title>
		<link>http://macsecure.com/2007/11/20/ultimate-leopard-firewall-ruleset/</link>
		<comments>http://macsecure.com/2007/11/20/ultimate-leopard-firewall-ruleset/#comments</comments>
		<pubDate>Tue, 20 Nov 2007 18:45:43 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[ipfw]]></category>
		<category><![CDATA[leopard]]></category>

		<guid isPermaLink="false">http://macsecure.com/2007/11/20/ultimate-leopard-firewall-ruleset/</guid>
		<description><![CDATA[Rich over at Securosis and some other folks have been working on a set of rules for the Leopard firewall (ipfw) that would be restrictive without breaking everything completely.  The ruleset has been tweaked extensively now and takes a lot of things into account.   I&#8217;ll be testing it out tonight, but it looks great so [...]]]></description>
			<content:encoded><![CDATA[<p>Rich over at <a href="http://securosis.com" target="_blank">Securosis</a> and some other folks have been <a href="http://securosis.com/2007/11/16/ipfw-rules-20071116-revision/" target="_blank">working on a set of rules</a> for the Leopard firewall (ipfw) that would be restrictive without breaking everything completely.  The <a href="https://securosis.com/wp-content/uploads/2007/11/ipfw-securosis.txt" target="_blank">ruleset</a> has been tweaked extensively now and takes a lot of things into account.   I&#8217;ll be testing it out tonight, but it looks great so far.     I&#8217;ll see if I can import these rules via Waterroof &#8212; or if not, just drop them in by hand.   <strong>Note:</strong>  Certain values need to be customized to your own environment!  Don&#8217;t just drop these in and expect it to work 100% !</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2007/11/20/ultimate-leopard-firewall-ruleset/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mac OS 10.5.1 Update &#8211; Security Changes</title>
		<link>http://macsecure.com/2007/11/15/mac-os-1051-update-security-changes/</link>
		<comments>http://macsecure.com/2007/11/15/mac-os-1051-update-security-changes/#comments</comments>
		<pubDate>Thu, 15 Nov 2007 19:05:31 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[10.5.1]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[leopard]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://macsecure.com/2007/11/15/mac-os-1051-update-security-changes/</guid>
		<description><![CDATA[I&#8217;m sure the 10.5.1 update (which just rolled out to Software Update today) will be dissected on all of the Mac forums and blogs, but in the Security section of the release notes, there are a few highlights that were noteworthy:

The &#8220;Block All Incoming Connections&#8221; setting I talked about here has now been changed to [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m sure the 10.5.1 update (which just rolled out to Software Update today) will be dissected on all of the Mac forums and blogs, but in the Security section of the release notes, there are a few highlights that were noteworthy:</p>
<ul>
<li>The &#8220;Block All Incoming Connections&#8221; setting I talked about <a href="http://macsecure.com/2007/11/07/leopard-firewall-why-its-acting-the-way-its-acting/" target="_blank">here</a> has now been changed to read &#8220;Allow only essential services.&#8221;   Without having installed it yet, I <strong>believe </strong>that&#8217;s still going to mean &#8216;anything running as root, plus the MDNS and a few other things.&#8217;</li>
<li>Another change to the Application Firewall related to code-signing and parental controls</li>
<li>Patches for all of the <a href="http://docs.info.apple.com/article.html?artnum=61798" target="_blank">recent security issues</a>.</li>
</ul>
<p>There are a few other things I&#8217;ll need to look at later tonight, but this is a start.   I&#8217;ll do some of the <a href="http://macsecure.com/2007/11/07/proving-the-leopard-firewall-issue-in-four-easy-steps/" target="_blank">netcat testing</a> again to verify the firewall change item.</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2007/11/15/mac-os-1051-update-security-changes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
