[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label Apple iOS. Tampilkan semua postingan
Tampilkan postingan dengan label Apple iOS. Tampilkan semua postingan

12/11/11

Apple's iOS 5.0.1 is out - should you upgrade?

Apple's latest iOS update is out.

The new version bumps iOS5 up to 5.0.1, and is Apple's first OTA update.

OTA stands for "over-the-air", and means that you can download and apply the update directly from your iDevice.
You no longer need to download the entire firmware file to your computer - including yet another copy of everything which hasn't changed in iOS - and push it to your device.
(OTA updating isn't yet mandatory. If you prefer to keep full copies of each iOS firmware distro, you can still use the download-and-install-with-iTunes method.)

According to Apple, the highlights of the 5.0.1 update are that it:
* fixes bugs affecting battery life,
* adds Multitasking Gestures for the original iPad,
* resolves bugs with Documents in the Cloud, and
* improves voice recognition for Australian users using dictation.

Strewth! That last one's a bonzer boost for blokes and sheilas everywhere! Gives an Aussie something worth lifting a tinnie to after the Baggy Green got such a big hiding from the South Africans in the cricket!

Importantly, 5.0.1 also fixes a number of security flaws, including a remote code execution (RCE) vulnerability involving font handling, found by Erling Ellingsen of Facebook. RCE means that a cybercriminal might be able to trick your device into running software without asking you, even if you're just browsing the internet.

Interestingly, Charlie Miller's recent and controversial App Store hole has also been patched. Miller showed how to write an innocent-looking App which, once approved by Apple, could fetch and run unapproved software.

Miller was unceremoniously banned from the Apple Developer scene for at least a year; there's no word from Apple, however, on whether he'll be readmitted now the hole is fixed.

Jailbreakers will be pleased to note that devices suitable for running a jailbroken iOS5 - a list which sadly still excludes the iPhone 4GS and the iPad 2 - can happily run a jailbroken iOS5.0.1.

If you are a jailbreaker, however, note that there is not yet any way to go back to iOS5.0 once you've moved on to 5.0.1.
That means that you'll never be able to use Charlie Miller's code-signing vulnerability for jailbreaking purposes in the future, for example if an iPad 2 jailbreak appears which relies on it.

And that leaves us with one question: should you update?
Some reports suggest that 5.0.1 brings with it a raft of new problems, and that the update might not, after all, fix your battery issues.

But these complaints are still anecdotal and unscientific, so if you trust Apple and you're not into jailbreaking, I'd suggest updating to 5.0.1 as soon as you conveniently can.

Ellingsen's and Miller's vulnerabilities may not have made it to Apple's highlights list, but each of these bugs on its own can be considered sufficiently important to warrant a prompt update.
Read More...

10/11/11

Adobe, Apple, Microsoft & Mozilla Issue Critical Patches

Adobe, Apple, Microsoft and Mozilla all released updates on Tuesday to fix critical security flaws in their products. Adobe issued a patch that corrects four vulnerabilities in Shockwave Player, while Redmond pushed updates to address four Windows flaws. Apple slipped out an update that mends at least 17 security holes in its version of Java, and Mozilla issued yet another major Firefox release, Firefox 8.

The only “critical” patch from Microsoft this month is a dangerous Windows flaw that could be triggered remotely to install malicious software just by sending the target system specially crafted packets of data. Microsoft says this vulnerability may be difficult to reliably exploit, but it should be patched immediately. Information on the other three flaws fixed this week is here. The fixes are available via Windows Updates for most supported versions of the operating system, including XP, Vista and Windows 7.


Adobe’s Shockwave update also fixes critical flaws, but users should check to see if they have this program installed before trying to update it. To test whether you have Shockwave installed, visit this page; if you see an animation, it’s time to update. If you see a prompt to install Shockwave, there is no need to install it. Mozilla Firefox users without Shockwave Player installed may still see “Shockwave Flash” listed in the “Plugins” directory of the browser; this merely indicates that the user has Adobe’s Flash Player installed.

The vulnerabilities fixed by this update exist in versions of Shockwave 11.6.1.629 and earlier. The latest version, v. 11.6.3.633, is available here.  As I noted earlier this year, I haven’t had Shockwave on my system for some time now and don’t seem to have missed it. I’m sure it has its uses, but to me Shockwave is just another Adobe program that requires constant care and feeding. What’s more, like Adobe’s Flash Player, Shockwave demands two separate installation procedures for IE and non-IE browsers.

Hat tip to the SANS Internet Storm Center for the heads up on the Java fix from Apple. This update, available via Software Update or Apple Downloads, essentially brings Snow Leopard and Lion up to date with the Oracle patches released last month in Java 6 Update 29 (Apple maintains its own version of Java).

If you use Mozilla Firefox or Thunderbird, you may have noticed that Mozilla is pushing out another major upgrade that includes critical fixes to these programs; both have now been updated to version 8. If you’re still running Firefox version 3.6.x, Mozilla has updated that to 3.6.24 (if anyone can help decipher Mozilla’s timeline for exactly how long it will continue to support this workhorse version of Firefox, please drop a line in the comments below). Perhaps I’m becoming a curmudgeon, but I’m growing weary of the incessant update prompts from Firefox. It seems that almost every time I start it up it’s asking to restart the browser or to remove plugins that no longer work with the latest version. I’ve been gradually transitioning more of my work over to Google Chrome, which seems faster and updates the browser and any installed plugins silently (and frequently patches oft-targeted plugins like Flash Player even before Adobe officially releases the update).
Read More...

Apple Bans Security Researcher Charlie Miller For Exposing iOS Exploit

The latest wave in the infosec world is that Apple has banned the well known security researcher – Charlie Miller – from it’s developer program for exposing a new iOS exploit.

It’s not really the smartest move as I’m pretty sure anyone as smart as Charlie Miller still has plenty of options – use another person’s account, sign up another account with a different identity, hack the phone without the developer program access and so on..

Really it’s quite a harsh move from Apple and it’s not going to make them any friends in the security industry.

Apple has banned well-known security researcher Charlie Miller from its developer program, for creating an apparently benign iOS app that was actually designed to exploit a security flaw he had uncovered in the firmware.

Within hours of talking about the exploit with Forbes’ security reporter Andy Greenberg, who published the details, Miller received an email from Apple: “This letter serves as notice of termination of the iOS Developer Program License Agreement … between you and Apple. Effective immediately.”

Based on Greenberg’s follow-up story, Apple was clearly within its rights to do so. Miller created a proof-of-concept application to demonstrate the security flaw and how it could be exploited by malicious code. He then hid it inside an apparently legitimate stock ticker program, an action that, according to Apple, “violated the developer agreement that forbid[s] him to ‘hide, misrepresent or obscure’ any part of his app,” Greenberg wrote.

He quoted Miller, who works for security consultancy Acuvant, “I’m mad. I report bugs to them all the time. Being part of the developer program helps me do that. They’re hurting themselves, and making my life harder.”

In a way though, you have to agree that Miller did violate the very specific developer program agreement by hiding the PoC inside a legitimate application. That probably wasn’t his smartest idea, but then again it’s helping Apple and he’s not doing it in a malicious way to infect people – he’s doing it as a security researcher.

Apple should be more proactive on working with people like this, people who are actually fixing bugs in their products for free and improving the user experience.

It’s the way Apple operates though, secretive, exclusive, domineering etc. If you don’t do things their way, screw you.


Miller, a former National Security Agency staffer, is a well-known “white hat” hacker (he made Network World’s recent list of “Security All Stars”), with expertise in Apple’s Mac OS X and iOS platforms, including the Safari browser, and in Android. Miller “has found and reported dozens of bugs to Apple in the last few years,” Greenberg noted. Miller reported the latest one barely three weeks ago, and it was Greenberg’s public account of it yesterday, in advance of a planned public presentation by Miller next week, that got the researcher kicked out of the developer program.

The vulnerability is a fascinating exercise in information security sleuthing. Miller uncovered a flaw introduced in Apple’s restrictions on code signing on iOS devices. Code signing is a process by which only Apple-approved commands run in device memory, according to Greenberg’s account.

Miller began to suspect a flaw when Apple released iOS 4.3 in March. He realized that to boost the speed of the mobile Safari browser, Apple for the first time had allowed javascript code from a website to run at a deeper level in memory. This entailed creating a security exception, allowing the browser to run unapproved code. According to Greenberg’s story, Apple created other security restrictions to block untrusted websites from exploiting this exception, so that only the browser could make use of it.

Miller wasn’t the only one to notice that Apple had done something different with Safari in iOS 4.3, but many didn’t understand what was actually happening. Various news sites and bloggers claimed that Web apps running outside of Safari, and its new Nitro javascript engine, were slower. Some suggested that Apple was deliberately slowing them down to make Web apps less attractive than native ones.

The way in which Miller uncovered the flaw once again shows his technical brilliance – something which Apple really should be harnessing rather than turning away.

A lot of people noticed changes with iOS 4.3, but couldn’t actually figure out what was going on. Well that’s what we know in the public realm anyway, no doubt the bad guys had their eyes on it and were digging in with much more malicious exploits.

It basically seems like a way to bypass any kind of code validation by Apple and execute arbitrary code from an attack server – dangerous indeed.
Read More...

06/11/11

Apple Security Chief Reportedly Leaves Company

Apple’s vice president of global security has reportedly stepped down roughly two months after the surface of news reports that an iPhone prototype had gone missing for the second time in less than two years.

According to reports, John Theriault, who came to Apple from Pfizer and was a former FBI agent, has retired in the wake of controversy regarding the device's disappearance and the subsequent efforts to track it down. Apple did not return a request for comment.

Nevertheless, Theriault’s departure follows a public relations dustup that began when an Apple employee left the prototype at a bar in San Francisco. The company's attempts to find the device led it to 22-year-old Sergio Calderon, who has said members of Apple's security team showed up at his home in San Francisco with police to search for the phone. According to Calderon, he only let the Apple investigators in because he thought they were police. However, the San Francisco Police Department - which initially denied involvement - has said that while there were officers at the scene, the search itself was conducted by the Apple employees.

The device, believed to have been a prototype of an iPhone 4S, was not found during the search. A lawyer for Calderon has reportedly threatened a lawsuit against Apple.

The latest case of the missing prototype echoes the disappearance of an iPhone 4 prototype in 2010. In that incident, an Apple employee left the phone at a bar called Gourmet Haus Staudt in Redwood City, Calif. When the phone was discovered, it was sold to the tech blog Gizmodo, which dissected the device and published pictures. This ultimately led investigators to raid the home of a Gizmodo editor. Two men were charged with selling the phone to Gizmodo and were sentenced to probation earlier this year. No one from Gizmodo was charged.

In the aftermath of the most recent incident, Apple was found to have posted job listings for a “product security manager” who would be responsible for “overseeing the protection of, and managing risks to, Apple’s unreleased products and related intellectual property.”
Read More...

30/10/11

DevilRobber Mac OS X Trojan horse spies on you, uses GPU for Bitcoin mining

GraphicConverterYesterday, users of Sophos's security products (including our free anti-virus for Mac home users) had their protection automatically updated to protect against a new Mac OS X Trojan horse that has been distributed via torrent sites such as PirateBay.

Copies of the legitimate Mac OS X image editing app GraphicConverter version 7.4 were uploaded to file-sharing networks. However, they came with an unexpected addition.

Hidden inside the download was a copy of the OSX/Miner-D (also known as 'DevilRobber') Trojan horse.

If your Mac computer was infected by the malware, the first thing you might notice is performance becoming sluggish.

BitcoinThat's because OSX/Miner-D tries to generate Bitcoins, the currency of the anonymous digital cash system, by stealing lots of GPU (Graphics Processing Unit) time.
GPUs are much better than regular CPUs at performing the mathematical calculations required for Bitcoin mining.
Yes, this Mac malware is stealing computing time as well as data.

In addition to Bitcoin mining, OSX/Miner-D also spies on you by taking screen captures and stealing your usernames and passwords. In addition, it runs a script that copies information to a file called dump.txt regarding truecrypt data, Vidalia (TOR plugin for Firefox), your Safari browsing history, and .bash_history.

Curiously, the Trojan also hunts for any files that match "pthc". It's unclear whether this is intended to uncover child abuse material or not (the phrase "pthc" is sometimes used on the internet to refer to pre-teen hardcore pornography).
To complete the assault - if the malware finds the user's Bitcoin wallet it will also steal that.

OSX/Miner-D
Of course, the producers of GraphicConverter have done nothing wrong themselves - they are victims of the criminals who are using their popular software as a trap to infect Mac users who download software from unofficial sources.

It's possible that other apps have also been distributed via torrent sites infected by the malware, or that the cybercriminals will use other methods to distribute their Trojan horse.

Clearly, Mac users - like their Windows cousins - should practice safe computing and only download software from official websites and legitimate download services. But, in addition to that, it's becoming clearer every week that Mac users need to take malware protection more seriously by running anti-virus software.
There may be a lot less malware for Mac OS X than there is for Windows, but many Mac users are making themselves an unnecessarily soft target by imagining that they are somehow magically protected from threats.

There are a number of anti-virus products available for Mac, including Sophos's free version for home users, so there's really no excuse.
Read More...

28/10/11

More Mac malware - new Tsunami backdoor variants discovered

WavesAs our friends at ESET have mentioned on their blog, new variants of the latest Mac malware - the Tsunami backdoor Trojan - have been discovered.

SophosLabs has received a few new samples of the malware - which can be used both to launch denial-of-service attacks and by remote hackers to gain access to your computer.

The new versions, which Sophos is adding detection for as OSX/Tsunami-Gen, are builds for 32-bit Intel x86 and PowerPC Mac computers, whereas the original version was 64-bit only. In addition, the new samples use a different IRC domain for their command & control server.

Some folks have questioned why the computer security industry has dubbed this threat "Tsunami", and I must admit that I find myself feeling somewhat uncomfortable with the name because of the devastating natural disasters that have struck in some parts of the world.

The truth is, however, that the name derives from one of the commands that can be sent to computers running the malicious code, to flood a target with internet traffic.

Tsunami command

It's actually the same command that was built into the Linux version of the attack tool (which Sophos calls Troj/Kaiten) first seen some years ago.

Because we see considerably less malware for Mac OS X than we do for Windows, new Mac threats tend to make the news headlines. It's important to note that the sky is not falling, and we believe the threat posed by OSX/Tsunami is currently quite low. Indeed, we have not received any reports from customers yet of infections by this Mac malware.

Nevertheless, it's clear that someone is working on developing new versions of this code for the Mac platform and you have to presume they are not doing it purely for the intellectual challenge. (If they are, Lord help them.. it's not much of a challenge)

Mac users would be wise to take preventative steps against this, and the other malware which we see for the Mac OS X platform. Free anti-virus software is available for Mac home users - so there's really no excuse.
Read More...

26/10/11

Tsunami backdoor for Mac OS X discovered

TsunamiOSX/Tsunami-A, a new backdoor Trojan horse for Mac OS X, has been discovered.

What makes Tsunami particularly interesting is that it appears to be a port of Troj/Kaiten, a Linux backdoor Trojan horse that once it has embedded itself on a computer system listens to an IRC channel for further instructions.

Typically code like this is used to rally compromised computers into a DDoS (distributed denial-of-service) attack, flooding a website with traffic.

If you were wondering where the name "Tsunami" comes from, that should probably help explain things.

It's not just a DDoS tool though. As you can see by the portion of OSX/Tsunami's source code that I have reproduced below, the bash script can be given a variety of different instructions and can be used to remotely access an affected computer.

Tsunami source code

Sophos's Mac anti-virus products (including our free anti-virus for Mac home users) are being updated to detect OSX/Tsunami-A.

The big question, of course, is how would this code find itself on your Mac in the first place? It could be that a malicious hacker plants it there, to access your computer remotely and launch DDoS attacks, or it may even be that you have volunteered your Mac to participate in an organised attack on a website.

But remember this - not only is participating in a DDoS attack illegal, it also means that you have effectively put control of your Mac into someone else's hands. If that doesn't instantly raise the hairs on the back of your neck, it certainly should.

Tsunami snapshot
Mac users are reminded that even though there is far less malware in existence for Mac OS X than for Windows, that doesn't mean the problem is non-existent. You only need to read our short history of Mac malware to realise that.

We fully expect to see cybercriminals continuing to target poorly protected Mac computers in the future. If the bad guys think they can make money out of infecting and compromising Macs, they will keep trying.

My advice to Mac users is simple: don't be a soft target, protect yourself.
Read More...

14/10/11

Apple Ships Mammoth Security Update for OS X

Apple released OS X Lion v10.7.2 yesterday along with an absolutely enormous security update that patches some 80 bugs in the various iterations of Apple’s operating system. One of the patches fixes a highly critical vulnerability that enables an attacker to run code on a remote machine with a simple exploit.

The vulnerability, CVE-2011-3230, which was discovered by researcher Aaron Sigel, lies in the way that Safari handles certain URLs.

"This allows you to send any "file:" url to LaunchServices, which will run binaries, launch applications, or open content in the default application, all from a web page. The only caveat is that since LaunchServices will check for the quarantine bit, you cannot directly push a binary to the browser and launch it," Sigel said in his advisory. The other bugs fixed in the OS X update could lead to denials of service, escalation of privileges, and arbitrary code execution to name a few. In addition, the patch fixes various password authentication problems ranging from password interception to log-ins occurring without passwords.

The update resolves one or more vulnerabilities in all of the following programs: Apache, Application Firewall, ATS, BIND, Certificate Trust Policy, CFNetwork, CoreFoundation, CoreMedia, CoreProcesses, CoreStorage, File Systems, IOGraphics, iChat Server, Kernel, libsecurity, Mailman, MediaKit, Open Directory, PHP, postfix, python, QuickTime, SMB File Server, Tomcat, User Documentation, Web Server, andX11.

Among the most noteworthy fixes are, Multiple DoS vulnerabilities in BIND, the resolution of a cookie storage and configuration bug in Safari, the addition of a number of trusted certificates to Apple’s list of system roots, a number of open directory password issues that could allow users to log-in without passwords, easily change or read other’s passwords, and a bug in the file systems that could allow an attacker in a privileged network position the ability to manipulate HTTPS server certificates, leading to the disclosure of sensitive data.

This latest update caps off a busy week for the world’s largest technology company, who released iOS 5 yesterday and another enormous patch for their music player, iTunes on Tuesday.

Again, this is an enormous patch, so please read the ‘About the security content of OS X Lion v10.7.2 and Security Update 2011-006’ for all the specific details. You can also download the update there.
Read More...

Mac OS X security update causes crashes, say experts

Apple's massive security update addresses more than 70 vulnerabilities, but installing the patches could render computers unbootable

Apple has released a massive security update for Mac OS X along with a new version of its OS, however, according to several reports, installing the patches could render computers unbootable.

The Mac OS X Security Update 2011-006 addresses more than 70 vulnerabilities in core components, as well as third-party products bundled by default with the OS.

[ iOS 5 upgrade error reports have flooded Apple's support forum. | Check out InfoWorld's quick guide to what's new in iOS 5. | Discover the key Mac, iOS, and Apple tech trends for business users. Read InfoWorld's Technology: Apple newsletter. ]

Many of the flaws have the highest severity rating assigned to them and can result in arbitrary code execution through a remote attack vector. Two security issues were patched in the Mac OS X kernel, one in CoreStorage, two in CoreMedia, while others were in CoreProcesses, CoreFoundation, CFNetwork, and even the application firewall.

With this update Apple also played security catch-up with many third-party software packages that provide important functionality, such as Apache HTTPD, BIND, PHP, Tomcat, Mailmain, Python, or libpng.

QuickTime, a central application in Apple's ecosystem, was also updated in this release to address 11 different vulnerabilities. However, some of them only affect OS X Snow Leopard.

Despite the benefits of the security update, users should carefully weigh whether to install it. That's because, according to some reports, the update can result in serious issues.

"Apple OSX Security Update makes macbook kernel panic at boot," warned security researcher Dragos Ruiu Thursday on Twitter. He later confirmed that other users have experienced similar problems, particularly on systems with Lion/Snow dual-boot configurations. "If you have two or more os partition on mbp [MacBook Pro] it breaks," the security expert said.

Meanwhile, Graham Cluley, a senior technology consultant at Mac OS antivirus provider Sophos, reported installation errors for the newly released iOS 5 mobile OS. He couldn't confirm the Mac OS X boot issues, but advised users to postpone updating if they believe they might be affected.

"My advice would be to contact Apple technical support - and see if they have a resolution for the problem. If you suspect you may be impacted by the issue it may be wise to hold off installing the security update until Apple has confirmed if it has fixed it," Cluley said.

Apple's new Mac OS X Lion v10.7.2 contains most of the security patches from Security Update 2011-006, and there are reports that it too is causing issues for adopters. Reports like "After updating to Lion 10.7.2 System now hangs on boot" or "Mac forced me to restart after updating to 10.7.2" started appearing on the Apple support forums.

One user suggests that resetting the PRAM after the update might solve the problem. Apple did not immediately respond to a request for comment.
Read More...

Error 3200: Apple iOS 5 stumbles on launch

Apple has launched the much anticipated iOS 5.0 - the new version of its operating system for iPhones and iPads, complete with revolutionary new features such as the iCloud.

It should have been a great moment for the company, and something to put some cheer back in Apple fans' hearts following the death of founder Steve Jobs last week.

iOS 5

However, things aren't going as smoothly and catch-free as the notoriously detailed-orientated company would perhaps like.

Error 3200 trending on TwitterMany users are finding that their attempts to update their iOS devices to the latest and greatest version of the mobile operating system are floundering, with users faced with error messages such as

"An internal error occurred." (3200)
during the install process.
Others are seeing messages related to internal errors 3002 or Error 3004.

Whatever the number, the problem has got so big that the phrase "Error 3200" is currently trending on Twitter.

Theories are bouncing around the net that Apple is simply a victim of its own success, and its servers have not been able to cope with demand for the new version of iOS, meaning that devices are failing to properly register themselves with the mothership. If that's true, you might be wise to wait a day or two.

Error message

Unfortunately, Apple's website isn't being terribly helpful for any users searching for information about what the error may mean:

No results found

Come on Apple, surely you can do better than that?
Me? I have chosen to hold off upgrading my wife's iPhone and iPad to iOS 5.0 - just as we haven't updated our iMac at home to Mac OS X Lion yet.

Call me antediluvian if you wish, but I can't really see the attraction in being an early-adopter. Security patches are one thing, but if something is working for me just fine, I don't feel the need to install the shiny new version as soon as it rolls off the software vendor's conveyor belt.

The risk is always going to be that there are still some wrinkles to iron out. I'd much rather wait until the teething problems have been sorted out, and then consider whether the new features built into Apple's operating system are what I'm after.

This is hardly the most auspicious launch for iOS 5.0 and the much vaunted iCloud. And let's not forget, if there's an error 3200 you have to assume that there's at least another 3199 error messages waiting to show their face to some poor users at some point in the future. :) Read More...

12/10/11

iTunes 10.5 released to fix 79 vulnerabilties on Windows, OS X to follow

iTunes 10.5Apple released a mammoth update to iTunes for Windows today bumping the version number to 10.5. The update fixes 79 vulnerabilities in iTunes, although not for Mac OS X users.

The largest number of fixes, 73, affect WebKit and could cause remote code execution. WebKit is used to render HTML content from the iTunes store.
Fortunately these vulnerabilities can only be exploited through a man-in-the-middle attack while using iTunes.

Other fixes resolve remote code execution flaws in CoreFoundation, ColorSync, CoreAudio, CoreMedia and ImageIO.

According to SANS Internet Storm Center, Apple will be releasing fixes for OS X users as part of the yet unreleased updates for 10.6 (Snow Leopard) and 10.7 (Lion). Users of OS X 10.5 and earlier will be left unprotected.
iCloud logoiTunes 10.5 for OS X is available as well, but only includes new features, not security fixes. iTunes 10.5 introduces iCloud support, wireless syncing and support for iOS 5.

One piece of good news is that iTunes no longer requires QuickTime on Windows machines. If you don't need/want QuickTime this might be a great opportunity to remove it, reducing the number of applications you need to keep patched.

I hope we see an update for Mac OS X soon as Apple still have not fixed the six week old directory services vulnerability and the three week old password change vulnerability.

If you are a Mac user interested in protecting your computer consider downloading our Sophos Anti-Virus for Mac Home Edition for free protection from viruses, Trojans and other malware.
Read More...

Apple slaps another security band-aid on iTunes

Summary: Apple patches 79 gaping security holes in the iTunes for Windows software.


Apple has shipped iTunes 10.5 to fix mountains of security problems that expose Windows users to dangerous hacker attacks.

The security patch, available for Windows 7, Windows Vista and Windows XP SP2, fixes a total of 79 documented vulnerabilities.  The most serious of these flaws could allow remote code execution attacks via booby-trapped image or movie files.

The bulk of the vulnerabilities affect the open-source WebKit rendering engine that powers the iTunes Store and iTunes LP.

Details on the vulnerabilities can be found in this Apple security advisory.
iTunes 10.5 is being distributed via the Windows software update utility.
 Alternatively, it can be downloaded directly from the iTunes web page.
Read More...

06/10/11

Steve Jobs death exploited by Facebook scammers

It's impossible to express how sad many people in the technology world feel at the news of the death of Steve Jobs.

Sickeningly, as with the deaths of other figures in the public eye, there are scammers waiting to take advantage of bad news.

Here's a scam we have seen on Facebook, claiming that free iPads are being given away "in memory of Steve Jobs".


In memory of Steve, a company is giving out 50 ipads tonight. R.I.P. Steve Jobs [LINK]

The cool-sounding link sucks you in, tricking you into believing that you may get a free iPad but then goes on to get you to complete online surveys to "qualify".

The link goes through the bit.ly short url service (we have asked our friends at bit.ly to shut the link down) and we can see that over 15,000 people have already clicked on the link which was set up within hours of Steve Jobs's death first being announced.



Of course, if you were one of those people who clicked on the link you may be wondering what the chances are that you will receive a free iPad. I hate to disappoint you, but it's pretty unlikely.

The webpage you are taken to is very similar to ones we have seen pointed to by other scammers. Here's what I saw:



I am writing this article from the Virus Bulletin conference in Barcelona, and you can see that the page has automagically determined where I am in the world and adjusted its language and wording as appropriate.

Below you'll see how the survey pages look if you visit them from Sydney, Australia, for instance.

Survey site visited from Australia
If you don't click through within a few seconds, it plays an audio message urging you to do so:

You'll notice that the audio message spectacularly fails to mention the 50 free iPads, which have by this time been reduced to the promise of "an exclusive reward", whatever that might be.

My colleague Paul Ducklin captured the audio and - being a fountain of interesting but not always entirely relevant information - tells me that the speaker is an Australian who grew up in South Africa.

When Duck visited the page a second time from Sydney, this is what he saw:
Casino website
How do the scammers make money? Well, they are earning affiliate cash - in a nutshell, they make more money the more traffic they can direct to websites, driving more people to become customers, or take online surveys and competitions.

Cynically, they exploited the death of Steve Jobs in the hope of driving large numbers of internet users to websites offering content such as contests, surveys and online gambling. The fact is, of course, that they could just as easily have taken those users to a webpage containing malicious code or a phishing page designed to steal credentials.

Chances are that this won't be the only scam we see regarding the untimely death of Steve Jobs. It wouldn't be a surprise, for instance, to see scams which might try to take advantage of those moved by the loss of Apple's founder with lures like "Donate to Steve's favourite charities as a tribute".

If you do want to pay tribute to Steve Jobs, the most appropriate place it seems to me would be Apple's website itself.

The truth is that the scammers are not geniuses like Jobs, and they don't contribute anything to the world of technology or wider society as Steve Jobs did. It's a shame that they can't be inspired by speeches like the one Jobs gave at Stanford University in 2005, and make something better of their lives.



I think that's how we should remember Steve Jobs today.

Please folks - always think carefully about the links that you click on. Time and time again scammers and cybercriminals have proven themselves to have no qualms about exploiting news stories - whether it be the personal tragedy of a teenage girl committing suicide, bizarre escapades, a natural disaster or the latest salacious celebrity gossip.


Read More...

Cybercriminals Remember Steve Jobs Through Facebook Scam

In an inevitable turn of events, cybercriminals were found leveraging the death of Apple co-founder Steve Jobs through Facebook scams within hours after it was announced.

The particular scam we found involves a website which claims that Apple has decided to give away 1000 iPads, in memory of Steve Jobs. The said site displays the following:

The site asks users to share the page in order to be eligible. After the user follows the instructions, he is directed to an ad site, while in the background, the link is posted on their Facebook wall.


And as dubious as the offer sounds, it seems like some users are falling for the scheme, as we are seeing an increasing number of posts bearing the website’s URL.

The catch behind this scam is that there is no such offer from Apple, and that only ones who will get anything from this are the scammers, who will earn money from the displayed ads every time a user is tricked into following the instructions. Also, as more users share the link, the number of potential victims also increases, as well as the profit for the scammers behind it.

The death of known persons have become staple topics of social engineering schemes for the past years. Just a couple of months ago we saw scams that took advantage of the death of singer Amy Winehouse, as well as rumors about the death of Lady Gaga.

Users are advised not to click on posts like these if they see them on their Facebook newsfeeds. We also suggest users to educate those who have been tricked to stop the spreading of such scams.

For more information on threats leveraging social networking sites, check our infographic, The Geography of Social Media Threats.

Access to the mentioned website is now blocked through the Web Reputation Service. Users of the latest Trend Micro™ Titanium™ Maximum Security are also protected from this through the Social Networking Security feature.

Read More...

Steve Jobs Dead At 56

Outpourings of grief came from all corners of the technology world on Wednesday after Apple Computer announced that its co-founder and former CEO Steve Jobs had died of cancer at the age of 56.

Apple's Web page paid tribute to Jobs on Wednesday, as tributes poured in from across the world. Of note: Bill Gates, Chairman and former CEO of Microsoft - and Jobs longtime rival - issued a statement expressing his condolences to Jobs family and friends.

Steve Jobs Dead at 56: Apple Tribute Page 
Steve Jobs Dead at 56: Apple Tribute Page

"Steve and I first met nearly 30 years ago, and have been colleagues, competitors and friends over the course of more than half our lives. The world rarely sees someone who has had the profound impact Steve has had, the effects of which will be felt for many generations to come," Gates wrote.

Sergey Brin, cofounder of Google, expressed condolences on behalf of Google. "From the earliest days of Google, whenever Larry and I sought inspiration for vision and leadership, we needed to look no farther than Cupertino. Steve, your passion for excellence is felt by anyone who has ever touched an Apple product (including the macbook I am writing this on right now). And I have witnessed it in person the few times we have met," he wrote.

Jobs, who has been battling cancer since 2003, stepped down as CEO in August, citing the difficulty of continuing in that position as he struggled with illness. Read More...

29/09/11

Apple blocks malware-as-PDF threat but new attack emerges

Summary: Even as Apple adds detection to block a Mac OS X malware threat, researchers find new Mac malware posing as a legitimate Flash Player installation package.


Apple has quietly added detection for the recent malware attack that used PDF files as lures to trick Mac OS X users into downloading a malicious Trojan dropper. 

The detection was added into the rudimentary XProtect.plist malware blocker built into Mac OS X.

The malware, flagged as a trojan dropper, installs downloader component that downloads a backdoor program onto the system, while camouflaging its activity by opening a PDF file to distract the user.

However, in what has become a classic cat-and-mouse game, researchers have spotted a new Mac malware threat posing as a legitimate Flash Player installation package.

Researchers find Mac OS X malware posing as PDF file ]

Intego explains the characteristics of the new threat:

Users visiting certain malicious websites may see a link or an icon to download and install Flash Player. Since Mac OS X Lion does not include Flash Player, some users may be fooled and think this is a real installation link. When they click the link, an installation package downloads, and, if the user is using Safari as their web browser, the Mac OS X Installer will launch. (Safari considers installer packages, with .pkg or .mpkg extensions, to be “safe” files and will launch them after download, if default settings are used.)

If the user proceeds with the installation procedure, the installer for this Trojan horse will deactivate some network security software, Intego said.

After installation, [it] will delete the installation package itself. The malware installs a dyld (dynamic loader) library and auto-launch code, allowing it to inject code into applications the user launches. This code, installed in a file at ~/Library/Preferences/Preferences.dylib, connects to a remote server, and sends information about the infected Mac to this server: this includes the computer’s MAC address, a unique identifier. This will allow the malware to detect if a Mac is infected.

The company said it has spotted this new malware in the wild but notes that it is not widely distributed.
Read More...

24/09/11

New Mac malware poses as PDF doc

The Trojan code is crude and can't yet connect to control server, say security firms

Security firms today warned Mac users of a new Trojan horse that masquerades as a PDF document.

The malware, which was spotted by U.K.-based Sophos and Finnish antivirus vendor F-Secure, uses a technique long practiced by Windows attackers.

[ Discover the key Mac, iOS, and Apple tech trends for business users. Read InfoWorld's Technology: Apple newsletter. ]

"This malware may be attempting to copy the technique implemented by Windows malware, which opens a PDF file containing a '.pdf.exe' extension and an accompanying PDF icon," said F-Secure today.

That practice relies on what is called the "double extension" trick: adding the characters ".pdf" to the filename to disguise an executable file.

The Mac malware uses a two-step process, composed of a Trojan "dropper" utility that downloads a second element, a Trojan "backdoor" that then connects to a remote server controlled by the attacker, using that communications channel to send information gleaned from the infected Mac and receiving additional instructions from the hacker.

Because it doesn't exploit a vulnerability in Mac OS X -- or any other software -- the malware instead must dupe users into downloading and opening the seemingly-innocuous PDF document, which is actually an executable.

Once run, the dropper downloads the second-stage backdoor and opens a Chinese-language PDF. F-Secure said that the PDF was another sleight-of-hand trick: "[The dropper component] drops a PDF file in the /tmp folder, then opens it to distract the user from noticing any other activity occurring," the company said in a description of the attack.

Both Sophos and F-Secure noted that the malware doesn't work reliably, and currently can't connect to the C&C (command-and-control) server because the latter isn't fully functional.

Mac malware is typically crude in comparison with what targets Windows PCs.
Because the C&C server is not yet operational and since it found samples of the Trojans on VirusTotal -- a free service that runs malware against a host of antivirus engines -- F-Secure speculated that the malware is still in the testing phase.

Although Apple's Mac OS X includes a bare-bones antivirus detector, it has not been updated to detect the just-noticed Trojan dropper or backdoor. Checks of several Computerworld Macs running Lion, for instance, found that Apple last updated its detector on Aug. 9.

Mac users had their biggest malware scare earlier this year, when a series of fake security programs, dubbed "scareware," were aimed at them.

Several antivirus companies, including Sophos, F-Secure and Intego, offer security software for the Mac.

nb : infoworld Read More...

23/09/11

Researchers find Mac OS X malware posing as PDF file

Summary: The malware installs a backdoor that contacts a remote server for instructions and can be used to steal files or capture a screenshot of the infected computer system.


Researchers at F-Secure have discovered a Mac OS X malware file masquerading as a PDF file to lure users into installing a backdoor trojan.

The malware, flagged as a trojan dropper, installs downloader component that downloads a backdoor program onto the system, while camouflaging its activity by opening a PDF file to distract the user.

According to F-Secure, the PDF file contains Chinese-language text related to political issues, which some users may find offensive.

The use of a PDF file as a social engineering gimmick is widely used by malicious hackers on the Windows platform and F-Secure’s research team believes this is an attempt to copy the trick of opening a PDF file containing a “.pdf.exe” extension and an accompanying PDF icon.
 
“”The sample on our hand does not have an extension or an icon yet. However, there is another possibility. It is slightly different in Mac, where the icon is stored in a separate fork that is not readily visible in the OS. The extension and icon could have been lost when the sample was submitted to us. If this is the case, this malware might be even stealthier than in Windows because the sample can use any extension it desires,” the company said.


Once installed, the trojan dropper installs a backdoor program that gives a hacker full control of the infected Mac OS X machine.

The backdoor typically contacts a remote server for instructions and can be used to steal files or capture a screenshot of the infected computer system, which is then forwarded to the remote server.

F-Secure reports that the command-and-control of the malware is just a bare Apache installation that is not yet capable of communicating with the backdoor.

nb : zdnet
Read More...

Massachusetts Attorney General to investigate iTunes fraud

iTunes logoMassachusetts Attorney General Martha Coakley announced Tuesday that her office will be investigating Apple Computers to determine if they are in compliance with her state's data breach notification laws.

Coakley spoke at a business luncheon at the Massachusetts' Advanced Cyber Security Center (ACSC), where she was reaching out to business leaders to assure them that compliance with the regulations would not be burdensome if they simply complied with the notification requirements.

Coakley herself was a victim of identity theft recently and her stolen credit card details were used to successfully make fraudulent iTunes purchases.

Has Apple's luck run out in denying there might be an issue with iTunes security?
Perhaps Coakley should contact Apple's friends at the San Francisco Police Department to help track down the thieves?

It will be interesting to see the results of the investigation, but I think Coakley is barking up the wrong tree.

While there are many creative criminals trying to leverage iTunes to launder their money and steal content, none have been the result of a data breach at Apple (to my knowledge).

Does Apple have some responsibility in all of this? Sure. They have not put in technical measures to better secure iTunes accounts or purchases made from iOS devices.

Many users choose poor passwords for iTunes and the App Store because they must enter this password from their mobile device. Entering a complex 20 character passphrase with punctuation isn't something most of us choose to do from our phones.

The other common problem is password re-use. Many friends of mine have had their iTunes accounts compromised after other major data loss events at other organizations.

Attackers will frequently use purloined emails and passwords to attempt authentication at Facebook, Twitter, Gmail and iTunes. If you aren't using unique passwords for sensitive accounts you may have your account used for a scam as well.

While it might be a pain to have a secure password for your iTunes purchases, it's your credit card and reputation that's at risk. Choose a passphrase wisely.
If the Attorney General's office finds Apple in breach of the Massachusetts law it could have far reaching implications for businesses with customers in the state. Follow Naked Security for further developments to this story.

nb : nakedsecurity.sophos
Read More...

22/09/11

Massachusetts Attorney General, Victim of an iTunes Scam, Says She'll Demand Answers

Massachusetts Attorney General Martha Coakley said on Tuesday that her office would be inquiring into long-standing complaints about fraudulent purchases that leverage Apple's popular online music store.

In a lunchtime address to business and technology leaders in Massachusetts, Coakley said she was a victim of identity theft in recent months, and that her stolen credit card information was used to make fraudulent iTunes purchases. When asked (by Threatpost) about whether such fraud constitutes a reportable event under the Bay State's strict data breach notification law, Coakley said that her office would be looking into that question and demanding answers from Cupertino, California based Apple, which has steadfastly refused to comment, or report the breaches to Massachusetts regulators.

Coakley was speaking before an audience of technology and business leaders at an inaugural lunch for Massachusetts' Advanced Cyber Security Center (ACSC). Coakley said that her investment in protecting consumers from identity theft was personal, acknowledging that her bank account was emptied after cyber criminals stole her debit card information during a ski trip to New Hampshire. It was not the first time Coakley had mentioned the incident in public. After skimming the card info, Coakley said the thieves attempted to use it to purchase a laptop from Dell Computer, which detected the fraudulent transaction and contacted Coakley. Not so Apple, whose iTunes media store was used to make a slew of transactions that emptied the Attorney General's account.

Informed of the well documented pattern of fraud through iTunes, in which stolen credit cards or bogus iTunes gift cards are matched with compromised iTunes accounts and used to purchase merchandise, Coakley said she wasn't aware of the larger pattern, but that it could be a reportable offense under the State's data privacy law. She promised her office would be contacting Apple for more information that very afternoon - a statement that received hearty applause from the audience.

Despite the tough tone, Coakley's speech was tailored more to a business audience wary of burdensome enforcement of State data privacy laws, including the State's data breach notification law and 201 CMR 17, the Massachusetts Data Protection Law. That law took effect in March, 2010 but the first fine under the law was issued in March of 2011 to Briar Group, a Boston-area restaurant chain that showed gross negligence in securing its networks and handling customers' credit card numbers.

Coakley said that companies that attempt, in good faith, to adhere to the State's privacy laws have little to fear in the way of fines or prosecution. However, organizations that flaunt the law or ignore the need for data security should count themselves warned.

Describing her office as the first line of defense for consumers, Coakley said her office was pursuing a "common sense" approach to enforcement and notification. Large breaches, such as the hack of Massachusetts retailer TJX, warrant an all out effort to notify the public. In the case of smaller breaches, Coakley said her office wanted to work with victim organizations to make sure that holes in their defenses and IT security practice are addressed.

The Attorney General said her office has received around 480 data breach notifications so far in 2011, and 1,166 since the law took effect in March, 2010 - suggesting that the incidence of data breaches is holding steady, despite a tough economy. The vast majority of those breaches are small in nature. Eighty two percent of disclosed breaches affected fewer than 100 people, and just 4% affected between 1,000 and 10,000 people. Similarly, hacking incidents only made up a quarter of the reported breaches, with another quarter due to inadvertent human error, Coakley said.

The State's breach notification law, dubbed 201 CMR 17, sets clear guidelines for the types of incidents that constitute reportable breaches. Any incident resulting in "the unauthorized acquisition or unauthorized use of unencrypted data or, encrypted electronic data" that creates a "substantial risk of identity theft or fraud against a resident of the commonwealth" need to be disclosed, as well as combinations of personal information, such as a name and credit card number, must be reported. That would seem to describe the use of Coakley's credit card information on iTunes. However, its is unclear whether Apple actually holds the data used to process the transaction on iTunes, or whether the purchases are merely "pass through" transactions about which Apple has no knowledge or visibility, according to a source within the Attorney General's Office.

nb : threatpost Read More...