<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MacSecure.com &#187; Vulnerabilities</title>
	<atom:link href="http://macsecure.com/category/vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://macsecure.com</link>
	<description>A Mac Security Blog</description>
	<lastBuildDate>Tue, 18 Nov 2008 00:46:01 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Apple Security Update 2007-009</title>
		<link>http://macsecure.com/2007/12/18/apple-security-update-2007-009/</link>
		<comments>http://macsecure.com/2007/12/18/apple-security-update-2007-009/#comments</comments>
		<pubDate>Tue, 18 Dec 2007 16:32:10 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[leopard]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[tiger]]></category>

		<guid isPermaLink="false">http://macsecure.com/2007/12/18/apple-security-update-2007-009/</guid>
		<description><![CDATA[Fixing some of the known issues with cups, tar, Safari, samba, etc.   Lots of updates in this one.
Apple has more info with CVE&#8217;s listed here.    SANS also has a blurb about it here.   I&#8217;ll install tonight and take some notes.   Also, coming soon &#8212; more tool discussions.
]]></description>
			<content:encoded><![CDATA[<p>Fixing some of the known issues with cups, tar, Safari, samba, etc.   Lots of updates in this one.</p>
<p>Apple has more info with CVE&#8217;s listed <a href="http://docs.info.apple.com/article.html?artnum=307179" target="_blank">here</a>.    SANS also has a blurb about it <a href="http://isc.sans.org/diary.html?storyid=3760&amp;rss" target="_blank">here</a>.   I&#8217;ll install tonight and take some notes.   Also, coming soon &#8212; more tool discussions.</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2007/12/18/apple-security-update-2007-009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Leopard Crash &#8220;Risk&#8221;</title>
		<link>http://macsecure.com/2007/12/11/leopard-crash-risk/</link>
		<comments>http://macsecure.com/2007/12/11/leopard-crash-risk/#comments</comments>
		<pubDate>Tue, 11 Dec 2007 18:06:33 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[heise]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://macsecure.com/2007/12/11/leopard-crash-risk/</guid>
		<description><![CDATA[I&#8217;d say it&#8217;s less &#8216;risk&#8217; and more &#8216;real&#8217; at this point &#8212; but I&#8217;m traveling and I haven&#8217;t had much time to look into it yet.    Heise has more info available here.
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;d say it&#8217;s less &#8216;risk&#8217; and more &#8216;real&#8217; at this point &#8212; but I&#8217;m traveling and I haven&#8217;t had much time to look into it yet.    Heise has more info <a href="http://www.heise-security.co.uk/news/100336" target="_blank">available here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2007/12/11/leopard-crash-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firewall Rules for Quicktime RTSP Vulnerability</title>
		<link>http://macsecure.com/2007/12/06/firewall-rules-for-quicktime-rtsp-vulnerability/</link>
		<comments>http://macsecure.com/2007/12/06/firewall-rules-for-quicktime-rtsp-vulnerability/#comments</comments>
		<pubDate>Thu, 06 Dec 2007 05:20:15 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[ipfw]]></category>
		<category><![CDATA[quicktime]]></category>
		<category><![CDATA[rtsp]]></category>

		<guid isPermaLink="false">http://macsecure.com/2007/12/06/firewall-rules-for-quicktime-rtsp-vulnerability/</guid>
		<description><![CDATA[See here.   Just a quick note:  if you read the Symantec advisory regarding the Quicktime RTSP Header Vunerability, they mention blocking certain traffic if you&#8217;re worried about the exploit &#8212; which appears to be Windows specific at this point. In the interest of being safe though, here is a set of ipfw rules for blocking [...]]]></description>
			<content:encoded><![CDATA[<p>See <a href="http://macsecure.com/2007/12/04/quicktime-vulnerability-rtsp-headers/" target="_blank">here</a>.   Just a quick note:  if you read the Symantec advisory regarding the Quicktime RTSP Header Vunerability, they mention blocking certain traffic if you&#8217;re worried about the exploit &#8212; which appears to be Windows specific at this point. In the interest of being safe though, here is a set of ipfw rules for blocking access as suggested:</p>
<p>01000   0     0 deny tcp from me to not me dst-port 554 out<br />
01100   0     0 deny tcp from me to 85.255.117.212 out<br />
01200   0     0 deny tcp from me to 85.255.117.213 out<br />
01300   0     0 deny tcp from me to 216.255.183.59 out<br />
01400   0     0 deny tcp from me to 69.50.190.135 out<br />
01500   0     0 deny tcp from me to 58.65.238.116 out<br />
01600   0     0 deny tcp from me to 208.113.154.34 out</p>
<p>You can put these in on a command line (via Terminal or iTerm) using &#8216;ipfw&#8217; or using WaterRoof.</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2007/12/06/firewall-rules-for-quicktime-rtsp-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quicktime Vulnerability &#8211; RTSP Headers</title>
		<link>http://macsecure.com/2007/12/04/quicktime-vulnerability-rtsp-headers/</link>
		<comments>http://macsecure.com/2007/12/04/quicktime-vulnerability-rtsp-headers/#comments</comments>
		<pubDate>Tue, 04 Dec 2007 15:16:22 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[cert]]></category>
		<category><![CDATA[quicktime]]></category>
		<category><![CDATA[rtsp]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://macsecure.com/2007/12/04/quicktime-vulnerability-rtsp-headers/</guid>
		<description><![CDATA[Symantec is reporting details of a vulnerability in Quicktime 7.2 and 7.3 that is currently unpatched by Apple.   Right now the exploits in the wild for this vulnerability appear to only be loading Windows executables, but the suggestion is that OS X systems could potentially be vulnerable as well.  Recommended steps until there is [...]]]></description>
			<content:encoded><![CDATA[<p>Symantec is <a href="http://www.symantec.com/business/security_response/vulnerability.jsp?bid=26560" target="_blank">reporting details</a> of a vulnerability in Quicktime 7.2 and 7.3 that is currently unpatched by Apple.   Right now the exploits in the wild for this vulnerability appear to only be loading Windows executables, but the <a href="http://www.macworld.com/news/2007/12/03/quicktimeflaw/index.php" target="_blank">suggestion is</a> that OS X systems could potentially be vulnerable as well.  Recommended steps until there is a patch include blocking outbound TCP traffic on port 554, or even blocking certain IP blocks that the Windows exploit is known to be sending data back to.    The CERT page for this vulnerability is <a href="http://www.kb.cert.org/vuls/id/659761" target="_blank">here</a> with tons of details.  As a note for anyone running OS X in a corporate environment &#8212; SourceFire&#8217;s SEU 118 has the Snort signatures for this vulnerability.</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2007/12/04/quicktime-vulnerability-rtsp-headers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Quicktime Vulnerabilities</title>
		<link>http://macsecure.com/2007/11/06/quicktime-vulnerabilities/</link>
		<comments>http://macsecure.com/2007/11/06/quicktime-vulnerabilities/#comments</comments>
		<pubDate>Tue, 06 Nov 2007 15:35:51 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://macsecure.com/?p=8</guid>
		<description><![CDATA[The Tipping Point / 3com funded Zero Day Initiative posted a whole batch of Quicktime vulnerabilities yesterday:

ZDI-07-065
ZDI-07-066
ZDI-07-067
ZDI-07-068

While all of them are interesting, the 65 and 68 items stand out to me as the less important ones, as exploitation of the issue requires that a user open a specific file.  The more nefarious items in [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.tippingpoint.com/" target="_blank">Tipping Point</a> / 3com funded <a href="http://www.zerodayinitiative.com/index.html" target="_blank">Zero Day Initiative</a> posted a whole batch of Quicktime vulnerabilities yesterday:</p>
<ul>
<li><a href="http://www.zerodayinitiative.com/advisories/ZDI-07-065.html" target="_blank">ZDI-07-065</a></li>
<li><a href="http://www.zerodayinitiative.com/advisories/ZDI-07-066.html" target="_blank">ZDI-07-066</a></li>
<li><a href="http://www.zerodayinitiative.com/advisories/ZDI-07-067.html" target="_blank">ZDI-07-067</a></li>
<li><a href="http://www.zerodayinitiative.com/advisories/ZDI-07-068.html" target="_blank">ZDI-07-068</a></li>
</ul>
<p>While all of them are interesting, the 65 and 68 items stand out to me as the less important ones, as exploitation of the issue requires that a user open a specific file.  The more nefarious items in 66 and 67 can be exploited by simply visiting a malicious website that has specially crafted images.</p>
<p>These vulnerabilities are part of what prompted the upgrade to the new Quicktime 7.3 that was released on Monday, and Apple has an updated page with <a href="http://docs.info.apple.com/article.html?artnum=306896" target="_blank">notes about each vulnerability</a> as well as a number of other CVE&#8217;s that were outstanding.    As of today, Apple doesn&#8217;t have any outstanding issues on the ZDI <a href="http://www.zerodayinitiative.com/upcoming_advisories.html" target="_blank">Upcoming Advisories list</a>.</p>
<p>This fall has largely been about image rendering flaws &#8212; from iPhone jailbreaks to this, it&#8217;s been almost non-stop.  &#8216;Tis the season!</p>
]]></content:encoded>
			<wfw:commentRss>http://macsecure.com/2007/11/06/quicktime-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
