Showing posts with label OS X. Show all posts
Showing posts with label OS X. Show all posts

Thursday, 22 October 2015

Apple Close Vulnerabilities In OS X, iOS, Safari, iTunes And WatchOS


Apple has released updates to several products, including Mac OS X, iOS and iTunes, which resolve a large number of vulnerabilities together. In Mac OS X El Capitan 10.11.1 and Security Update 2015-007 are 60 vulnerabilities patched allowing an attacker to execute arbitrary code in the worst case.

This could for example by visiting a malicious website to open a malicious audio file or image, extracting a malicious archive file or processing a malicious font file. Also, an attacker with a "privileged" position network, for example, between the user and the Internet, could execute arbitrary code. Updating via the Mac App Store or the Apple website.

For Mac users, Apple has also fixed a vulnerability in the firmware. Researchers demonstrated in August a worm that can infect Mac firmware. There are several possible vulnerabilities were used. One of the leaks is used by Mac EFI Security Update 2015-002 corrected. The update can be downloaded via the Mac App Store.

IOS

For owners of an iPhone, iPad or iPod Touch iOS 1.9 appeared that 49 vulnerabilities were patched. A number of vulnerabilities in Mac OS X are also available in iOS and make it possible for an attacker to execute arbitrary code eg when visiting a website. The Pangu jailbreak will not work in this version. Update via iTunes and the automatic update feature.

There is also a new version of Safari appeared. Via Safari 9.0.1, Apple has patched nine vulnerabilities allowing an attacker could execute arbitrary code. Appeared for owners of an Apple Watch. WatchOS 2.0.1, where 15 vulnerabilities are resolved.

ITunes

Windows users who have installed iTunes be advised to iTunes 12.3.1 upgrade. Via a man-in-the-middle attack when looking around in the iTunes Store via iTunes arbitrary code can be executed on the system. Further, it was also possible for malicious applications to execute arbitrary code via text files.

Tuesday, 14 April 2015

Apple OS X Designed To Help Against Adware


Apple has taken further steps against adware, reinforced free Mac apps settled in Download and changes among other browser settings.

OS X 10.10.3 should also remove unwanted adware, such as Apple tells in a support document . When browsing suddenly pop-up window and graphics appear with advertising or search engine and homepage has been changed unexpectedly, adware has come to the Mac, says the manufacturer. Some download portals insert the advertising software in the offered there free programs - the user installs this then perhaps unintentionally. Even software such as Oracle's Java brings now Adware for OS X with .

What are the steps to initiate the update opposite already installed Adware, Apple does not execute. Apparently the import of 10.10.3 does not always help but long to sudden commercials, as the company continues to point to a longer instructions to remove certain adware manually.

This Apple recommends that you check the Safari Extensions and delete unknown specimens. For removal of other "Ad-injection software" but deeper trip to the library system of OS X are required - specifically, the Group carries it Down Lite, VSearch, Conduit, trovi, MyBrand Search and Protect on.

Specifically, Apple also addresses the adware Genieo respectively InstallMac, the deep hooks into the system and fades among others own promotional items on visited web pages. A Genieo variant blocked the built in OS X anti-malware tool XProtect since February - but the manufacturer should offer more long versions.10.10.3 OS X also includes a long list of vulnerabilities .

Friday, 27 March 2015

Egyptian Company: Google Rogue Certificates Were Mistake


The Egyptian company that had generated rogue SSL certificates for different websites from Google calls it a mistake that Google eventually discovered the certificates and hit alarm . Indeed, it was not intended that the certificates were discovered. This week, Google warned Internet users to rogue Google certificates generated by the Egyptian MCS Holding. Through the certificates could allow an attacker to Man-in-the-middle and phishing attacks on Internet users to intercept passwords and the contents of encrypted traffic.

MCS Holding is an Egyptian security company that delivers business networking. However, it had become a so-called "intermediate" certificate authority (CA), which was linked to the Chinese certificate authority CNNIC. SSL certificates from an intermediate certificate authority originate have the full authority of the CA under which they fall. In particular, Mozilla had great criticism of CNNIC that MCS Holding had given permission to the intermediate CA to generate SSL certificates.

The Egyptian company said in a statement that it had signed an agreement with CNNIC to a two-week period intermediate CA to act. This would be necessary for the testing of a new roll from cloud service. The test took place in a secure lab where the private key of the CA certifcate, to generate SSL certificates, stored in a firewall.

However, the firewall was set to automatically generate certificates for websites that were visited on the Internet. During an unguarded moment at the weekend would be one of the IT engineers decided to use the internet with Google Chrome. Chrome offers certificate pinning, which websites can indicate what their CA SSL certificate has been issued. The browser will then put these certificates on a whitelist.

Is the website for an SSL certificate that is issued by a different CA, then turn the alarm browser. After MCS Holding by CNNIC had informed the certificate was immediately removed from the firewall and warned all parties involved. According to the Egyptian company, it is a human error which inadvertently took place. "We have no evidence of abuse, and we therefore recommend that people will not change their password or other action," said a company spokesman.

Measures

Meanwhile, Google has revoked the intermediate certificate of MCS Holding and also a Microsoft update released under Windows Users. From the description of the software giant appears that certificates for domains *. google.com , *.google.com.eg , *. g.doubleclick.net , *. gstatic.com , www.google.com , www.gmail .com and *. googleapis.com were created. Firefox comes next week with an update to revoke the certificate.

On the mailing list of Mozilla developers after the incident a heated debate erupted or CNNIC is not guilty because it would have violated all sorts of rules. While some want CNNIC is removed from the root store of Firefox. Mozilla could do this then this can have very serious consequences, especially for Chinese Firefox users, thereby HTTPS sites with SSL certificates of CNNIC and suspended beneath intermediate CAs can not visit. The Chinese CA Mozilla has therefore asked not to remove it from the root store CNNIC.

Tuesday, 24 March 2015

Google Sounds Alarm On Rogue Google certificate



Google warns Internet users to rogue Google certificate issued by a company from the United Arab Emirates and could be used to perform man-in-the-middle and phishing attacks on Internet users, so as passwords and the contents of encrypted traffic intercept. SSL certificates are used inter alia for encrypting traffic between websites and visitors and identifying websites.

The company that rogue SSL certificates issued is MCS Holdings , a so-called "intermediate" certificate authority (CA), which is linked to the Chinese CNNIC certificate authority. SSL certificates from an intermediate certificate authority originate have the full authority of the CA under which they fall. CNNIC is in all major "root certificate stores" so the Google unfairly issued certificates would be trusted by most browsers and operating systems.

Chrome on Windows, OS X and Linux, ChromeOS and Firefox 33 and newer would have refused the certificate because certificate-pinning. According to Google, there are probably also issued certificates for other websites that may not be recognized by certificate-pinning. Certificate-pinning sites may indicate by what their CA SSL certificate has been issued. The browser will then put these certificates on a whitelist. Is the website for an SSL certificate that is issued by a different CA, then turn the alarm browser. Browsers like Chrome and Firefox currently support only pinning for some great websites.

Proxy

Following the fraudulent certificates, which were discovered on 20 March, Google CNNIC approached and was told that MCS Holdings only if issued certificates for domains they had registered themselves. That turned the company does not have done. MCS Holdings provides proxy appliances and firewall solutions that enable organizations of workers through the encrypted traffic can intercept self signed certificates. Should normally be set to the office computers to trust the proxy, but in this case it was not required by the wrongly issued certificates.

Google sees similarities with previously unduly certificates issued in 2013 by the French CA ANSSI . The Internet giant also denounces that CNNIC the power to create SSL certificates awarded to a company that was not suitable here. Chrome users do not have to do to be protected from rogue certificates, while Firefox users will have to wait for the arrival of Firefox 37 in which the certificate has been revoked. This version on March 31 appear.

Wednesday, 11 March 2015

Apple Fixes FREAK Vulnerability In Mac OS X And iOS


Apple has released updates for Mac OS X, Apple TV and iOS that it " FREAK leak fixes "in SSL / TLS.Through the vulnerability, an attacker who is between a target and the Internet is in some cases the encryption of the encrypted connection to downgrade to a weak encryption to crack then that and to see the encrypted traffic.

Further resolves Security Update 2015-002 for Mac OS X four other vulnerabilities. It involves leakage and malicious app could execute arbitrary code with system privileges, memory addresses in the kernel were determined and could allow an attacker on the network arbitrary code via iCloud Keychain. iOS 8.2 fixes beside FREAK leak five other vulnerabilities.

Through these vulnerabilities, an attacker could iPods and iPads remote reboots and an attacker with physical access could see the home screen, even though the device was not activated. Furthermore, the same vulnerabilities resolved in Mac OS X, allowing attackers to execute arbitrary code. The same applies to AppleTV 7.1 , where a total of three leaks were patched.Finally, there is also an update for Xcode appeared, the development software from Apple for OS X and iOS. This five leaks were patched.