<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>hard-mac.com</title>
	<link>http://www.hard-mac.com/blog</link>
	<description>- -  a passion for apple security...</description>
	<lastBuildDate>Tue, 17 Aug 2010 16:55:10 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/abc" -->

	<item>
		<title>APPLE QuickTime 7.6.7 Security Update for Windows</title>
		<description><![CDATA[Apple has released a security update their Windows version of QuickTime 7.6.7 fixing one vulnerability. According to Apple this issue does not affect Mac OS X systems. QuickTime 7.6.7 may be obtained from the Software Update application, or from the QuickTime Downloads site: http://www.apple.com/quicktime/download/]]></description>
		<link>http://www.hard-mac.com/blog/?p=450</link>
			</item>
	<item>
		<title>APPLE iOS 4.0.2 Update for iPhone and iPod touch &amp; 3.2.2 Update for iPad</title>
		<description><![CDATA[Apple has released an update to fix comex&#8217;s recent .pdf exploit used by jailbreakme.com to jailbreak iDevices. You must use iTunes to update your device. This update is not available through Apple Software Update For more information on the security update Apple Security Updates web site: http://support.apple.com/kb/HT1222]]></description>
		<link>http://www.hard-mac.com/blog/?p=442</link>
			</item>
	<item>
		<title>APPLE-SA-2009-11-09-1 Security Update 2009-006 &#8211; Mac OS X v10.6.2 &amp; 10.5.8</title>
		<description><![CDATA[Along with this Snow Leopard update to 10.6.2, Apple also released a security update for OS X 10.5.8 client and server. The update includes numerous security updates and some feature enhancements, Apple also pulled support for Intel Atom processor which breaks Hackintosh Netbooks. The update is available via Software Update and Apple’s support downloads site.]]></description>
		<link>http://www.hard-mac.com/blog/?p=434</link>
			</item>
	<item>
		<title>iPhone SSH worms making the rounds</title>
		<description><![CDATA[updated 9.11.09 More variants of iPhone malware are showing up, some claiming to gather personal data from phones. Don&#8217;t be surprised with the source code for ikee circulating that more nefarious malware will be coming soon. JailBroken phone w/ alpine default pswd = pwned phone or a honeypot In the past week or so at [...]]]></description>
		<link>http://www.hard-mac.com/blog/?p=415</link>
			</item>
	<item>
		<title>Apple Issues Java for Mac OS X 10.5 Update 5 &#8211; Patching several vulnerabilities</title>
		<description><![CDATA[Apple issued a Java update Thursday patching several known vulnerabilities. The 161.35MB update is only applicable to Mac OS X Leopard version 10.5.8 or later (not Snow Leopard). Java SE 6 is updated to version 1.6.0_15, J2SE 5.0 is updated to version 1.5.0_20, and J2SE 1.4.2 is updated to version 1.4.2_22. While J2SE 5.0 and [...]]]></description>
		<link>http://www.hard-mac.com/blog/?p=408</link>
			</item>
	<item>
		<title>Apple ships vulnerable Flash with Snow Leopard</title>
		<description><![CDATA[For those of you that have recently updated to OS X 10.6 Snow Leopard time to u[pgrade Flash Player. Apple downgraded your installation of Flash to an earlier version (version 10.0.23.1), which is known not to be secure and is not patched against various security vulnerabilities. The version you should be running is the latest [...]]]></description>
		<link>http://www.hard-mac.com/blog/?p=399</link>
			</item>
	<item>
		<title>New Snow Leopard got Anti-Virus?</title>
		<description><![CDATA[No not really, but it does check for a couple of the more common trojans. The last Developer seed of Snow Leopard Snow 10a421A and what we expect Apple to release on Friday contains a file XProtect.plist that checks for possible trojans. /System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/XProtect.plist It contains five signatures for the two most active trojans, OSX.RSPlug that [...]]]></description>
		<link>http://www.hard-mac.com/blog/?p=389</link>
			</item>
	<item>
		<title>Security Update 2009-004 &#8211; Bind Vulnerability Fix</title>
		<description><![CDATA[Apple issued a fix for the recent bind vulnerability. Good to see Apple releasing fixes fairly fast for known vulnerabilities. Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.8, Mac OS X Server v10.5.8 Impact: A remote attacker may be able to cause the DNS server to unexpectedly terminate [...]]]></description>
		<link>http://www.hard-mac.com/blog/?p=383</link>
			</item>
	<item>
		<title>Hijacking Safari 4 Top Sites with Phish Bombs</title>
		<description><![CDATA[It is possible for a malicious website to place arbitrary sites into your Top Sites view through automated actions. The attack technique makes use of javascript windows where in a small window is used to repeatedly browse to different sites that the attacker wants to add in your Top Sites list. This window is completely [...]]]></description>
		<link>http://www.hard-mac.com/blog/?p=375</link>
			</item>
	<item>
		<title>APPLE-SA-2009-08-11-1 Safari 4.0.3 Update</title>
		<description><![CDATA[Safari 4.0.3 is now available and addresses the following: CoreGraphics CVE-ID: CVE-2009-2468 Available for: Windows XP and Vista Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution Description: A heap buffer overflow exists in the drawing of long text strings. Visiting a maliciously crafted website may lead [...]]]></description>
		<link>http://www.hard-mac.com/blog/?p=373</link>
			</item>
	<item>
		<title>CrashWrangler &#8211; Apple&#8217;s !exploitable</title>
		<description><![CDATA[Apple recently released the new CrashWrangler tools to anyone with a free ADC account, and is available at: https://connect.apple.com/cgi-bin/WebObjects/MemberSite.woa/wa/getSoftware?bundleID=20390 CrashWrangler is a set of developer tools that help in creating and debugging secure Mac OS X applications. The tools work by inspecting the application&#8217;s state at the time of the crash, as well as the [...]]]></description>
		<link>http://www.hard-mac.com/blog/?p=326</link>
			</item>
	<item>
		<title>Apple keyboard firmware based keylogger hack</title>
		<description><![CDATA[Apple&#8217;s keyboards are no have 8Kb of flash memory, and 256 bytes of RAM. K. Chen has found a way to very easily install keyloggers, rootkits or other malicious code right inside of an Apple keyboard. K. Chen presented his findings at this year&#8217;s Black Hat conference. It&#8217;s actually quite easy to abuse the memory [...]]]></description>
		<link>http://www.hard-mac.com/blog/?p=334</link>
			</item>
	<item>
		<title>APPLE-SA-2009-08-05-1 Security Update 2009-003 / Mac OS X v10.5.8</title>
		<description><![CDATA[Security Update 2009-003 / Mac OS X v10.5.8 is now available and addresses the following: bzip2 CVE-ID: CVE-2008-1372 Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 through v10.5.7, Mac OS X Server v10.5 through v10.5.7 Impact: Decompressing maliciously crafted data may lead to an unexpected application termination Description: [...]]]></description>
		<link>http://www.hard-mac.com/blog/?p=338</link>
			</item>
	<item>
		<title>Apple iPhone SMS hack</title>
		<description><![CDATA[iPhone security expert Charlie Miller of Independent Security Evaluators (ISE) , along with colleague Collin Mulliner, demonstrated a vulnerability in the SMS messaging system which can ultimately lead to hacking of an iPhone. Miller and Mullinet released their paper &#8220;Fuzzing the Phone in your Phone&#8221; at Black Hat last week. Other hackers identified similar flaws [...]]]></description>
		<link>http://www.hard-mac.com/blog/?p=333</link>
			</item>
	<item>
		<title>Dino Dai Zovi presents Machiavelli &#8211; Another POC rootkit for Mac OS X</title>
		<description><![CDATA[At the Black Hat security conference on last week, security researcher Dino Dai Zovi presented a proof-of-concept rootkit that runs on Apple&#8217;s Mac OS X operating system, underscoring the fact that all software has flaws. Dai Zovi&#8217;s proof-of-concept rootkit is called Machiavelli, a reference to the Mach kernel that underpins Mac OS X. &#8220;Machiavelli consists [...]]]></description>
		<link>http://www.hard-mac.com/blog/?p=335</link>
			</item>
</channel>
</rss>
