[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label iTunes. Tampilkan semua postingan
Tampilkan postingan dengan label iTunes. Tampilkan semua postingan

12/11/11

Apple's iOS 5.0.1 is out - should you upgrade?

Apple's latest iOS update is out.

The new version bumps iOS5 up to 5.0.1, and is Apple's first OTA update.

OTA stands for "over-the-air", and means that you can download and apply the update directly from your iDevice.
You no longer need to download the entire firmware file to your computer - including yet another copy of everything which hasn't changed in iOS - and push it to your device.
(OTA updating isn't yet mandatory. If you prefer to keep full copies of each iOS firmware distro, you can still use the download-and-install-with-iTunes method.)

According to Apple, the highlights of the 5.0.1 update are that it:
* fixes bugs affecting battery life,
* adds Multitasking Gestures for the original iPad,
* resolves bugs with Documents in the Cloud, and
* improves voice recognition for Australian users using dictation.

Strewth! That last one's a bonzer boost for blokes and sheilas everywhere! Gives an Aussie something worth lifting a tinnie to after the Baggy Green got such a big hiding from the South Africans in the cricket!

Importantly, 5.0.1 also fixes a number of security flaws, including a remote code execution (RCE) vulnerability involving font handling, found by Erling Ellingsen of Facebook. RCE means that a cybercriminal might be able to trick your device into running software without asking you, even if you're just browsing the internet.

Interestingly, Charlie Miller's recent and controversial App Store hole has also been patched. Miller showed how to write an innocent-looking App which, once approved by Apple, could fetch and run unapproved software.

Miller was unceremoniously banned from the Apple Developer scene for at least a year; there's no word from Apple, however, on whether he'll be readmitted now the hole is fixed.

Jailbreakers will be pleased to note that devices suitable for running a jailbroken iOS5 - a list which sadly still excludes the iPhone 4GS and the iPad 2 - can happily run a jailbroken iOS5.0.1.

If you are a jailbreaker, however, note that there is not yet any way to go back to iOS5.0 once you've moved on to 5.0.1.
That means that you'll never be able to use Charlie Miller's code-signing vulnerability for jailbreaking purposes in the future, for example if an iPad 2 jailbreak appears which relies on it.

And that leaves us with one question: should you update?
Some reports suggest that 5.0.1 brings with it a raft of new problems, and that the update might not, after all, fix your battery issues.

But these complaints are still anecdotal and unscientific, so if you trust Apple and you're not into jailbreaking, I'd suggest updating to 5.0.1 as soon as you conveniently can.

Ellingsen's and Miller's vulnerabilities may not have made it to Apple's highlights list, but each of these bugs on its own can be considered sufficiently important to warrant a prompt update.
Read More...

12/10/11

iTunes 10.5 released to fix 79 vulnerabilties on Windows, OS X to follow

iTunes 10.5Apple released a mammoth update to iTunes for Windows today bumping the version number to 10.5. The update fixes 79 vulnerabilities in iTunes, although not for Mac OS X users.

The largest number of fixes, 73, affect WebKit and could cause remote code execution. WebKit is used to render HTML content from the iTunes store.
Fortunately these vulnerabilities can only be exploited through a man-in-the-middle attack while using iTunes.

Other fixes resolve remote code execution flaws in CoreFoundation, ColorSync, CoreAudio, CoreMedia and ImageIO.

According to SANS Internet Storm Center, Apple will be releasing fixes for OS X users as part of the yet unreleased updates for 10.6 (Snow Leopard) and 10.7 (Lion). Users of OS X 10.5 and earlier will be left unprotected.
iCloud logoiTunes 10.5 for OS X is available as well, but only includes new features, not security fixes. iTunes 10.5 introduces iCloud support, wireless syncing and support for iOS 5.

One piece of good news is that iTunes no longer requires QuickTime on Windows machines. If you don't need/want QuickTime this might be a great opportunity to remove it, reducing the number of applications you need to keep patched.

I hope we see an update for Mac OS X soon as Apple still have not fixed the six week old directory services vulnerability and the three week old password change vulnerability.

If you are a Mac user interested in protecting your computer consider downloading our Sophos Anti-Virus for Mac Home Edition for free protection from viruses, Trojans and other malware.
Read More...

Apple slaps another security band-aid on iTunes

Summary: Apple patches 79 gaping security holes in the iTunes for Windows software.


Apple has shipped iTunes 10.5 to fix mountains of security problems that expose Windows users to dangerous hacker attacks.

The security patch, available for Windows 7, Windows Vista and Windows XP SP2, fixes a total of 79 documented vulnerabilities.  The most serious of these flaws could allow remote code execution attacks via booby-trapped image or movie files.

The bulk of the vulnerabilities affect the open-source WebKit rendering engine that powers the iTunes Store and iTunes LP.

Details on the vulnerabilities can be found in this Apple security advisory.
iTunes 10.5 is being distributed via the Windows software update utility.
 Alternatively, it can be downloaded directly from the iTunes web page.
Read More...

06/10/11

ExploitHub Offering Bounties - And Residuals - for Exploits

NSS Labs’ announced today that their penetration-testing site, Exploithub, will be offering bounties to researchers for developing exploits for12 high-value vulnerabilities.

Exploithub is putting up $4,400 for working exploits against what the company describes as a “dirty dozen” of client-side vulnerabilities. And, in what may be a first in the vulnerability research field, the company is offering the authors the chance to earn residual payments for subsequent use of the vulnerabilities.

Launched in October of 2010, Exploithub is described as an "iTunes for exploits" - an easy to use market for penetration testers and IT staff to obtain high quality exploits to use against software they are evaluating.

But every iTunes needs its music, so NSS has opted to put money on the table to attract talented vulnerability researchers and prime the pump. NSS has identified 12 known vulnerabilities by their Common Vulnerabitiles and Exposures (CVE) numbers. They are: CVE-2011-1256, CVE-2011-1266, CVE-2011-1261, CVE-2011-1262, CVE-2011-1963, CVE-2011-1964, CVE-2011-0094, CVE-2011-0038, CVE-2011-0035, CVE-2010-3346, CVE-2011-2110, and CVE-2011-0628. Each exploit will be worth somewhere between $100 and $500. Ten of the eligible vulnerabilities are in Microsoft's Internet Explorer browser, with the remaining two being in Adobe Flash.

Submitted bounty candidates must be client-side remote exploits resulting in code execution, PoC and denial of service does not count, and the exploits under the bounty program cannot currently be available in the Metasploit framework community or other exploit toolkits. The first participant to submit a working exploit wins.

“Client-side exploits are the weapons of choice for modern attacks, including spear phishing and so-called APTs. Security professionals need to catch up,” said Rick Moy, NSS Labs CEO in a statement. “This program is designed to accelerate the development of testing tools, as well as help researchers do well by doing good.” Read More...

23/09/11

Massachusetts Attorney General to investigate iTunes fraud

iTunes logoMassachusetts Attorney General Martha Coakley announced Tuesday that her office will be investigating Apple Computers to determine if they are in compliance with her state's data breach notification laws.

Coakley spoke at a business luncheon at the Massachusetts' Advanced Cyber Security Center (ACSC), where she was reaching out to business leaders to assure them that compliance with the regulations would not be burdensome if they simply complied with the notification requirements.

Coakley herself was a victim of identity theft recently and her stolen credit card details were used to successfully make fraudulent iTunes purchases.

Has Apple's luck run out in denying there might be an issue with iTunes security?
Perhaps Coakley should contact Apple's friends at the San Francisco Police Department to help track down the thieves?

It will be interesting to see the results of the investigation, but I think Coakley is barking up the wrong tree.

While there are many creative criminals trying to leverage iTunes to launder their money and steal content, none have been the result of a data breach at Apple (to my knowledge).

Does Apple have some responsibility in all of this? Sure. They have not put in technical measures to better secure iTunes accounts or purchases made from iOS devices.

Many users choose poor passwords for iTunes and the App Store because they must enter this password from their mobile device. Entering a complex 20 character passphrase with punctuation isn't something most of us choose to do from our phones.

The other common problem is password re-use. Many friends of mine have had their iTunes accounts compromised after other major data loss events at other organizations.

Attackers will frequently use purloined emails and passwords to attempt authentication at Facebook, Twitter, Gmail and iTunes. If you aren't using unique passwords for sensitive accounts you may have your account used for a scam as well.

While it might be a pain to have a secure password for your iTunes purchases, it's your credit card and reputation that's at risk. Choose a passphrase wisely.
If the Attorney General's office finds Apple in breach of the Massachusetts law it could have far reaching implications for businesses with customers in the state. Follow Naked Security for further developments to this story.

nb : nakedsecurity.sophos
Read More...