<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; Apple</title>
	<atom:link href="http://www.darknet.org.uk/category/apple-hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Apple Bans Security Researcher Charlie Miller For Exposing iOS Exploit</title>
		<link>http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/</link>
		<comments>http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/#comments</comments>
		<pubDate>Wed, 09 Nov 2011 12:44:32 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[apple-security]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[hacking apple]]></category>
		<category><![CDATA[hacking ios]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[ios code signing]]></category>
		<category><![CDATA[ios exploit]]></category>
		<category><![CDATA[ios flaw]]></category>
		<category><![CDATA[ios security]]></category>
		<category><![CDATA[ios vulnerability]]></category>
		<category><![CDATA[security researcher]]></category>
		<category><![CDATA[white hat]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3223</guid>
		<description><![CDATA[The latest wave in the infosec world is that Apple has banned the well known security researcher &#8211; Charlie Miller &#8211; from it&#8217;s developer program for exposing a new iOS exploit. It&#8217;s not really the smartest move as I&#8217;m pretty sure anyone as smart as Charlie Miller still has plenty of options &#8211; use another [...]]]></description>
			<content:encoded><![CDATA[<p>The latest wave in the infosec world is that <a href="http://www.darknet.org.uk/category/apple-hacking/">Apple</a> has banned the well known security researcher &#8211; <a href="http://www.darknet.org.uk/tag/charlie-miller/">Charlie Miller</a> &#8211; from it&#8217;s developer program for exposing a new iOS exploit.</p>
<p>It&#8217;s not really the smartest move as I&#8217;m pretty sure anyone as smart as Charlie Miller still has plenty of options &#8211; use another person&#8217;s account, sign up another account with a different identity, hack the phone without the developer program access and so on..</p>
<p>Really it&#8217;s quite a harsh move from Apple and it&#8217;s not going to make them any friends in the security industry.</p>
<blockquote><p>Apple has banned well-known security researcher Charlie Miller from its developer program, for creating an apparently benign iOS app that was actually designed to exploit a security flaw he had uncovered in the firmware.</p>
<p>Within hours of talking about the exploit with Forbes&#8217; security reporter Andy Greenberg, who published the details, Miller received an email from Apple: &#8220;This letter serves as notice of termination of the iOS Developer Program License Agreement &#8230; between you and Apple. Effective immediately.&#8221;</p>
<p>Based on Greenberg&#8217;s follow-up story, Apple was clearly within its rights to do so. Miller created a proof-of-concept application to demonstrate the security flaw and how it could be exploited by malicious code. He then hid it inside an apparently legitimate stock ticker program, an action that, according to Apple, &#8220;violated the developer agreement that forbid[s] him to &#8216;hide, misrepresent or obscure&#8217; any part of his app,&#8221; Greenberg wrote.</p>
<p>He quoted Miller, who works for security consultancy Acuvant, &#8220;I&#8217;m mad. I report bugs to them all the time. Being part of the developer program helps me do that. They&#8217;re hurting themselves, and making my life harder.&#8221; </p></blockquote>
<p>In a way though, you have to agree that Miller did violate the very specific developer program agreement by hiding the PoC inside a legitimate application. That probably wasn&#8217;t his smartest idea, but then again it&#8217;s helping Apple and he&#8217;s not doing it in a malicious way to infect people &#8211; he&#8217;s doing it as a security researcher.</p>
<p><a href="http://www.darknet.org.uk/category/apple-hacking/">Apple</a> should be more proactive on working with people like this, people who are actually fixing bugs in their products for free and improving the user experience.</p>
<p>It&#8217;s the way Apple operates though, secretive, exclusive, domineering etc. If you don&#8217;t do things their way, screw you.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Miller, a former National Security Agency staffer, is a well-known &#8220;white hat&#8221; hacker (he made Network World&#8217;s recent list of &#8220;Security All Stars&#8221;), with expertise in Apple&#8217;s Mac OS X and iOS platforms, including the Safari browser, and in Android. Miller &#8220;has found and reported dozens of bugs to Apple in the last few years,&#8221; Greenberg noted. Miller reported the latest one barely three weeks ago, and it was Greenberg&#8217;s public account of it yesterday, in advance of a planned public presentation by Miller next week, that got the researcher kicked out of the developer program.</p>
<p>The vulnerability is a fascinating exercise in information security sleuthing. Miller uncovered a flaw introduced in Apple&#8217;s restrictions on code signing on iOS devices. Code signing is a process by which only Apple-approved commands run in device memory, according to Greenberg&#8217;s account.</p>
<p>Miller began to suspect a flaw when Apple released iOS 4.3 in March. He realized that to boost the speed of the mobile Safari browser, Apple for the first time had allowed javascript code from a website to run at a deeper level in memory. This entailed creating a security exception, allowing the browser to run unapproved code. According to Greenberg&#8217;s story, Apple created other security restrictions to block untrusted websites from exploiting this exception, so that only the browser could make use of it.</p>
<p>Miller wasn&#8217;t the only one to notice that Apple had done something different with Safari in iOS 4.3, but many didn&#8217;t understand what was actually happening. Various news sites and bloggers claimed that Web apps running outside of Safari, and its new Nitro javascript engine, were slower. Some suggested that Apple was deliberately slowing them down to make Web apps less attractive than native ones. </p></blockquote>
<p>The way in which Miller uncovered the flaw once again shows his technical brilliance &#8211; something which Apple really should be harnessing rather than turning away.</p>
<p>A lot of people noticed changes with iOS 4.3, but couldn&#8217;t actually figure out what was going on. Well that&#8217;s what we know in the public realm anyway, no doubt the bad guys had their eyes on it and were digging in with much more malicious exploits.</p>
<p>It basically seems like a way to bypass any kind of code validation by Apple and execute arbitrary code from an attack server &#8211; dangerous indeed.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/110811-miller-ios-bug-252886.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Apple+Bans+Security+Researcher+Charlie+Miller+For+Exposing+iOS+Exploit+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3223+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/&amp;t=Apple+Bans+Security+Researcher+Charlie+Miller+For+Exposing+iOS+Exploit" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/&amp;title=Apple+Bans+Security+Researcher+Charlie+Miller+For+Exposing+iOS+Exploit" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/&amp;title=Apple+Bans+Security+Researcher+Charlie+Miller+For+Exposing+iOS+Exploit" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/&amp;title=Apple+Bans+Security+Researcher+Charlie+Miller+For+Exposing+iOS+Exploit" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/&amp;title=Apple+Bans+Security+Researcher+Charlie+Miller+For+Exposing+iOS+Exploit" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Fapple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OS X Lion Brings Major Security Overhaul To Apple Users</title>
		<link>http://www.darknet.org.uk/2011/07/os-x-lion-brings-major-security-overhaul-to-apple-users/</link>
		<comments>http://www.darknet.org.uk/2011/07/os-x-lion-brings-major-security-overhaul-to-apple-users/#comments</comments>
		<pubDate>Thu, 21 Jul 2011 08:23:02 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[apple lion]]></category>
		<category><![CDATA[apple lion security]]></category>
		<category><![CDATA[apple lion update]]></category>
		<category><![CDATA[apple-security]]></category>
		<category><![CDATA[aslr]]></category>
		<category><![CDATA[lion os]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[os x lion]]></category>
		<category><![CDATA[OS X Lion security]]></category>
		<category><![CDATA[os x security]]></category>
		<category><![CDATA[osx]]></category>
		<category><![CDATA[osx security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3153</guid>
		<description><![CDATA[It&#8217;s been a long time coming but with the latest release of Max OS X Lion &#8211; Apple has really stepped it up in terms of security and pro-active protection. Just a few months back in May we reported that &#8211; Mac Malware is Becoming a Serious Threat and back in march Day One At [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a long time coming but with the latest release of Max OS X Lion &#8211; <a href="http://www.darknet.org.uk/category/apple-hacking/" title="Apple Hacking">Apple</a> has really stepped it up in terms of security and pro-active protection.</p>
<p>Just a few months back in May we reported that &#8211; <a href="http://www.darknet.org.uk/2011/05/mac-malware-becoming-a-serious-threat/" title="Mac Malware Becoming a Serious Threat">Mac Malware is Becoming a Serious Threat</a> and back in march <a href="http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/" title="Day One At Pwn2Own Takes Out Microsoft Internet Explorer and Apple Safari">Day One At Pwn2Own Takes Out Microsoft Internet Explorer and Apple Safari</a>.</p>
<p>With this latest update they have really integrated some very modern security techniques with many claiming this puts them ahead of <a href="http://www.darknet.org.uk/tag/windows-7/">Windows 7</a> and Ubuntu in terms of security.</p>
<blockquote><p>With Wednesday&#8217;s release of Mac OS X Lion, Apple has definitively leapfrogged its rivals by offering an operating system with state-of-the-art security protections that make it more resistant to malware exploits and other hack attacks, two researchers say.</p>
<p>Unlike the introduction of Snow Leopard in 2009, which offered mostly incremental security enhancements, OS X 10.7 represents a major overhaul, said the researchers, who spent the past few months analyzing the OS.</p>
<p>The most important addition is full ASLR. Short for address space layout randomization, the protection makes it much harder for attackers to exploit bugs by regularly changing the memory location where shell code and other system components are loaded. Other improvements include security sandboxes that tightly restrict the way applications can interact with other parts of the operating system and full disk encryption that doesn&#8217;t interfere with other OS features.</p>
<p>“It&#8217;s a significant improvement, and the best way that I&#8217;ve described the level of security in Lion is that it&#8217;s Windows 7, plus, plus,” said Dino Dai Zovi, principal of security consultancy Trail of Bits and the coauthor of The Mac Hacker&#8217;s Handbook. “I generally tell Mac users that if they care about security, they should upgrade to Lion sooner rather than later, and the same goes for Windows users, too.”</p></blockquote>
<p>There were a couple of blunders back in 2009 when Snow Leopard (commonly known as SL) was released, and of course &#8211; <a href="http://www.darknet.org.uk/2009/08/mac-os-x-snow-leopard-bundled-with-malware-detector/" title="Mac OS X Snow Leopard Bundled With Malware Detector">Mac OS X Snow Leopard Bundled With Malware Detector</a>.</p>
<p>Back then the security tech bundled with Snow Leopard was incremental at best, there was nothing really new or anything that inspired confidence in us security chaps.</p>
<p>With the latest version of Lion however Apple has put in some really good stuff like full address space layout randomization (ASLR) and even more sandboxing (always a good idea to trap <a href="http://www.darknet.org.uk/category/virustrojanswormsrootkits/" title="Malware">malware</a> in userspace).</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Although ASLR made its OS X debut in Leopard, the predecessor to Snow Leopard, its implementation was woefully inadequate because it failed to randomize core parts of the OS, including the heap, stack, and dynamic linker. That meant entire classes of exploits were automatically immune to the protection.</p>
<p>It also prompted many to wonder why Apple engineers bothered to put it into the OS in the first place, or didn&#8217;t properly implement it with the introduction of Snow Leopard. Windows Vista and Ubuntu, by contrast, added much more robust implementations of ASLR years earlier.</p>
<p>“When they went from Leopard to Snow Leopard, as far as I&#8217;m concerned, there really wasn&#8217;t any change,” said Charlie Miller, principal research consultant at security firm Accuvant and the other coauthor of The Mac Hacker&#8217;s Handbook. “They might have said there was more security and it was better, but at a low functionality level there really wasn&#8217;t any difference. Now, they&#8217;ve made significant changes and it&#8217;s going to be harder to exploit.”</p>
<p>What&#8217;s more, Lion&#8217;s refurbished ASLR has been augmented, so that even if hackers clear that hurdle, they&#8217;ll still have to bypass other new protections. Among them is a sandbox design that shields the most vulnerable and vital parts of the computer from attack. Safari, for example, has now been divided into two processes that separate the browser&#8217;s user interface and other functions from the part that parses JavaScript, images, and other web content.</p></blockquote>
<p>Now these changes won&#8217;t stop Apple software from being vulnerable to <a href="http://www.darknet.org.uk/category/exploitsvulnerabilities/" title="Exploits">exploits</a> &#8211; but it will make it a hell of a lot harder to pull of code execution after getting in.</p>
<p>There are some smart changes to <a href="http://www.darknet.org.uk/tag/safari/" title="Safari">Safari</a> too, which makes surfing a lot safer as one of the biggest attack vectors right now is through browser based exploits (Flash/JavaScript etc).</p>
<p>Even with all of that though, there will still be ways around it (just look at the <a href="http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/" title="Malicious PDF Files To Exploit iPhone &#038; iPad Zero Day In The Wild">latest JailBreak</a>) &#8211; so as always &#8211; be careful Mac users!</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/07/21/mac_os_x_lion_security/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=OS+X+Lion+Brings+Major+Security+Overhaul+To+Apple+Users+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3153+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/07/os-x-lion-brings-major-security-overhaul-to-apple-users/&amp;t=OS+X+Lion+Brings+Major+Security+Overhaul+To+Apple+Users" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/07/os-x-lion-brings-major-security-overhaul-to-apple-users/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/07/os-x-lion-brings-major-security-overhaul-to-apple-users/&amp;title=OS+X+Lion+Brings+Major+Security+Overhaul+To+Apple+Users" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/07/os-x-lion-brings-major-security-overhaul-to-apple-users/&amp;title=OS+X+Lion+Brings+Major+Security+Overhaul+To+Apple+Users" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/07/os-x-lion-brings-major-security-overhaul-to-apple-users/&amp;title=OS+X+Lion+Brings+Major+Security+Overhaul+To+Apple+Users" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/07/os-x-lion-brings-major-security-overhaul-to-apple-users/&amp;title=OS+X+Lion+Brings+Major+Security+Overhaul+To+Apple+Users" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F07%2Fos-x-lion-brings-major-security-overhaul-to-apple-users%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/07/os-x-lion-brings-major-security-overhaul-to-apple-users/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>French Company Intego Release First iPhone Malware Scanner</title>
		<link>http://www.darknet.org.uk/2011/07/french-company-intego-release-first-iphone-malware-scanner/</link>
		<comments>http://www.darknet.org.uk/2011/07/french-company-intego-release-first-iphone-malware-scanner/#comments</comments>
		<pubDate>Wed, 13 Jul 2011 10:46:38 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[ios antivirus]]></category>
		<category><![CDATA[ios malware]]></category>
		<category><![CDATA[ios malware scanner]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[iphone antivirus app]]></category>
		<category><![CDATA[iphone malware]]></category>
		<category><![CDATA[malware scanning iphone app]]></category>
		<category><![CDATA[virusbarrier]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3147</guid>
		<description><![CDATA[This is quite an interesting story as it&#8217;s very closely related to the story we published earlier this week &#8211; Malicious PDF Files To Exploit iPhone &#038; iPad Zero Day In The Wild. Hot on the tail of that news is the first-ever malware scanning app for iOS devices (iPhone/iPad etc) from a French security [...]]]></description>
			<content:encoded><![CDATA[<p>This is quite an interesting story as it&#8217;s very closely related to the story we published earlier this week &#8211; <a href="http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/">Malicious PDF Files To Exploit iPhone &#038; iPad Zero Day In The Wild</a>. Hot on the tail of that news is the first-ever malware scanning app for iOS devices (iPhone/iPad etc) from a French security company called Intego.</p>
<p>The odd thing is the app can&#8217;t scan the filesystem of the device due to the <a href="http://www.darknet.org.uk/tag/ios/">iOS</a> sandbox &#8211; but it can scan remotely hosted files (e-mail attachments, files in your Dropbox account and on on).</p>
<p>It&#8217;ll be interesting to see what kind of response this app gets and if people will be interested in purchasing it.</p>
<blockquote><p>A French security company known for its Mac OS X antivirus software today released the first malware-scanning app for the iPhone and iPad and iPod Touch. Intego&#8217;s VirusBarrier for iOS has been approved by Apple, and debuted on the App Store Tuesday for $2.99.</p>
<p>Because iOS prevents the program from accessing the file system or conducting automatic or scheduled scans &#8212; as do virtually all Mac and Windows antivirus software &#8212; VirusBarrier must be manually engaged, and then scans only file attachments and files on remote servers, said Peter James, a spokesman for Intego.</p>
<p>&#8220;Because of the sandbox, you can&#8217;t scan the file system,&#8221; said James. &#8220;Since you don&#8217;t see the iOS file system, the only things you can scan are attachments sent by email or files in, say, your Dropbox folder.&#8221;</p>
<p>Unlike software written for Android &#8212; such as Lookout, from the San Francisco-based company by the same name &#8212; VirusBarrier cannot scan apps for possible infection. When an email attachment is received by the iPhone, iPad or iPod Touch, the user can intercede by calling on VirusBarrier, which then scans the file for possible infection before the file is opened or forwarded to others.</p>
<p>&#8220;We&#8217;ve had enterprise customers say that although they know you can&#8217;t do a full system scan of an iPhone, they don&#8217;t like the fact that files go through these devices and end up on a Mac or Windows PC,&#8221; said James. &#8220;They want their users to be able to check that an attachment is safe.&#8221; </p></blockquote>
<p>It also can&#8217;t scan apps for possible infection, which is kind of weak &#8211; but I guess it&#8217;s supportive of the walled garden approach implemented by <a href="http://www.darknet.org.uk/category/apple-hacking/" title="Apple">Apple</a>. Seen as though all official apps are vetted by Apple there shouldn&#8217;t be any infections anyway (unless the user executed a <a href="http://www.darknet.org.uk/tag/jailbreak/" title="Jailbreak">JailBreak</a> their device).</p>
<p>Symantec did make some kind of push into the iOS market in October 2010, but I&#8217;m not sure what came of it &#8211; <a href="http://www.darknet.org.uk/2010/10/symantec-expands-security-products-to-cover-android-ios/" title="Symantec Expands Security Products To Cover Android &#038; iOS">Symantec Expands Security Products To Cover Android &#038; iOS</a>.</p>
<p>With the whole model Apple is running on the iOS platform &#8211; there honestly isn&#8217;t that many vectors for attack.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>He characterized VirusBarrier for iOS as a way for iPhone and iPad users to prevent their hardware from spreading malware. &#8220;You don&#8217;t want your iPhone becoming a &#8216;Typhoid Mary,&#8217;&#8221; James said.</p>
<p>VirusBarrier for iOS can scan email attachments in a variety of formats, including Microsoft&#8217;s Word, Excel and PowerPoint; PDF documents; JavaScript files; and Windows executables, those files tagged with the .exe extension. It can also scan files in a Dropbox folder, those stored on MobileMe&#8217;s iDisk, or files downloaded via the iOS version of Safari. The scanning engine and signatures &#8212; the digital &#8220;fingerprints&#8221; used to detect malware &#8212; in VirusBarrier for iOS are identical to those used by Intego&#8217;s Mac OS X product line.</p>
<p>VirusBarrier for iOS lets iPhone and iPad users run on-demand scans of email attachments before those files are opened or forwarded. </p>
<p>&#8220;It&#8217;s important that people understand what [VirusBarrier] can and cannot do,&#8221; said James, pointing to the malware scanner&#8217;s limitations. &#8220;Although there is no malware written for iOS today, if attackers do try to exploit the [recent] PDF vulnerability, this is something we can scan for.&#8221;</p>
<p>James was referring to the still-unpatched vulnerability in iOS that can be exploited through a malicious PDF document, one of two bugs used last week to &#8220;jailbreak&#8221; an iPhone , iPad or iPod Touch. VirusBarrier for iOS can be downloaded to an iPhone, iPad or iPod Touch from Apple&#8217;s App Store. It requires iOS 4.0 or later.</p></blockquote>
<p>You can check out the app on Apple&#8217;s App Store here:</p>
<p><a href="http://itunes.apple.com/us/app/virusbarrier/id436111378?mt=8&#038;ign-mpt=uo%3D4">VirusBarrier By Intego</a></p>
<p>Basically the purpose of the app seems to more towards halting malware application on the iPhone &#8211; rather than preventing the device itself getting infected. You can read a lot more about it on the App Store description.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/071211-mac-security-firm-ships-first-ever.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=French+Company+Intego+Release+First+iPhone+Malware+Scanner+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3147+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/07/french-company-intego-release-first-iphone-malware-scanner/&amp;t=French+Company+Intego+Release+First+iPhone+Malware+Scanner" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/07/french-company-intego-release-first-iphone-malware-scanner/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/07/french-company-intego-release-first-iphone-malware-scanner/&amp;title=French+Company+Intego+Release+First+iPhone+Malware+Scanner" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/07/french-company-intego-release-first-iphone-malware-scanner/&amp;title=French+Company+Intego+Release+First+iPhone+Malware+Scanner" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/07/french-company-intego-release-first-iphone-malware-scanner/&amp;title=French+Company+Intego+Release+First+iPhone+Malware+Scanner" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/07/french-company-intego-release-first-iphone-malware-scanner/&amp;title=French+Company+Intego+Release+First+iPhone+Malware+Scanner" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F07%2Ffrench-company-intego-release-first-iphone-malware-scanner%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/07/french-company-intego-release-first-iphone-malware-scanner/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Malicious PDF Files To Exploit iPhone &amp; iPad Zero Day In The Wild</title>
		<link>http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/</link>
		<comments>http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/#comments</comments>
		<pubDate>Mon, 11 Jul 2011 09:39:43 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[apple-security]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hacking apple]]></category>
		<category><![CDATA[hacking ipad]]></category>
		<category><![CDATA[hacking iphone]]></category>
		<category><![CDATA[ipad hacking]]></category>
		<category><![CDATA[ipad jailbreak]]></category>
		<category><![CDATA[ipad2 jailbreak]]></category>
		<category><![CDATA[iphone jailbreak]]></category>
		<category><![CDATA[iphone pdf]]></category>
		<category><![CDATA[jailbreakme]]></category>
		<category><![CDATA[pdf jailbreak]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3144</guid>
		<description><![CDATA[Well everyone has been waiting for a Jailbreak for the iPad 2 with the latest version of iOS &#8211; it happened and only hours later the malformed PDF files that were used in the exploit were circulating the Internet. It&#8217;s not the first time this has happened, last time jailbreakme did the same thing back [...]]]></description>
			<content:encoded><![CDATA[<p>Well everyone has been waiting for a <a href="http://www.darknet.org.uk/tag/jailbreak/" title="Jailbreak">Jailbreak</a> for the iPad 2 with the latest version of iOS &#8211; it happened and only hours later the malformed PDF files that were used in the exploit were circulating the Internet.</p>
<p>It&#8217;s not the first time this has happened, last time <a href="http://www.darknet.org.uk/tag/jailbreakme/" title="jailbreakme">jailbreakme</a> did the same thing back in August 2010 &#8211; <a href="http://www.darknet.org.uk/2010/08/dangerous-iphone-ios-jailbreak-exploit-goes-public/" title="Dangerous iPhone iOS JailBreak Exploit Goes Public">Dangerous iPhone iOS JailBreak Exploit Goes Public</a>.</p>
<p>The exploit is quite a nasty one, and the irony is this time &#8211; only users that have applied the Jailbreak then the additional &#8216;PDF Patcher 2&#8242; software (from Cydia) are safe from this. Users running the vanilla version of iOS are actually at risk.</p>
<blockquote><p>Hours after developers revealed they had exploited bugs in Apple&#8217;s iOS to &#8220;jailbreak&#8221; iPhones and iPads, German government security authorities warned that one of the flaws could be put to malicious use.</p>
<p>Malformed files that exploit the vulnerability have been publicly posted on the Internet. Late Wednesday, Germany&#8217;s Federal Office for Information Security, known by its German-language initials of BSI for &#8220;Bundesamt fuer Sicherheit in der Informationstechnik,&#8221; warned citizens that the iOS bug could be used by criminals to hijack iPhones, iPads and iPod Touches.</p>
<p>&#8220;Even clicking a crafted PDF document or surfing to a website with the PDF documents are sufficient to infect the mobile device with malicious software,&#8221; the BSI said in a translation of the German-language alert .</p>
<p>PDF files that successfully exploit the vulnerability are available on the Web, according to Mikko Hypponen, chief research officer of Helsinki-based antivirus company F-Secure. And those PDFs could be used by miscreants to hack iOS devices simply by luring users to malicious sites, said Andrew Storms, director of security operations at nCircle Security.</p>
<p>iPhone and iPad users steered to a malicious PDF &#8212; via a link embedded in an email, for instance &#8212; would not receive any warning or be required to take additional action. </p></blockquote>
<p>I hope <a href="http://www.darknet.org.uk/category/apple-hacking/" title="Apple">Apple</a> gets their act together and pushes out the patch for this ASAP as I foresee some kind of iPhone/iPad targeted worm coming out of this fairly shortly.</p>
<p>It took them 10 days to patch a similar pair of exploits back in August 2010 so we should be expecting a patch by the end of this week (mid-July sometime).</p>
<p>The worrying part when it comes to business/agencies/government etc &#8211; is that these exploits could be used to target specific individuals of importance. All you need to know is the e-mail address they access on their iPhone/iPad and do a bit of <a href="http://www.darknet.org.uk/category/social-engineering/" title="Social Engineering">social engineering</a> and you&#8217;re in.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>The BSI warning came just hours after a group of developers released an updated version of JailbreakMe, a tool that hacks iOS so iPhone and iPad users can install software not sanctioned by Apple.</p>
<p>Those developers exploited a pair of vulnerabilities, including one in the font parsing of the PDF viewer integrated with the iOS version of Safari, and another that bypassed anti-malware defenses such as ASLR (address space layout randomization). Wednesday, security experts said that the same vulnerabilities, particularly the one exploitable through malicious PDF files, could be used by criminals to hijack Apple&#8217;s popular iPhone and iPad.</p>
<p>&#8220;They&#8217;re certainly a threat, and would be easy to make malicious,&#8221; said Charlie Miller, a noted Mac OS X and iOS vulnerability researcher who works for Denver-based Accuvant.</p>
<p>Miller also speculated that Apple would quickly patch the vulnerabilities, perhaps even faster than last year when it faced a similar situation. In August 2010, Apple patched a pair of bugs used by JailbreakMe 2.0 just 10 days after the tool&#8217;s release. News of JailbreakMe 3.0&#8242;s impending release had leaked several days before Wednesday&#8217;s official launch, noted Miller, and should have given Apple even more warning.</p>
<p>Yesterday&#8217;s BSI alert was similar to one it issued last August after JailbreakMe 2.0 appeared.On Thursday, Apple said it would fix the flaws.</p></blockquote>
<p>Of course the &#8216;developer&#8217; version of iOS 5.0 is already out and I guess someone people are using this, most iPhone/iPad users have been waiting for that major update &#8211; but I&#8217;m guessing Apple will have to push a patch out for this before the 5.x major release.</p>
<p>There&#8217;s another interesting and relevant article on this topic here:</p>
<p><a href="http://www.networkworld.com/news/2011/070811-the-problem-with-doing-and.html?source=nww_rss">The problem with doing &#8211; and not doing &#8211; an iPhone jailbreak</a></p>
<p>It&#8217;ll be interesting to see what comes of this and if any kind of iPhone/iPad chaos is going to occur due to these exploits.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/070711-pdfs-that-exploit-iphone-ipad.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3144+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;t=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;title=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;title=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;title=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;title=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F07%2Fmalicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mac Malware Becoming a Serious Threat</title>
		<link>http://www.darknet.org.uk/2011/05/mac-malware-becoming-a-serious-threat/</link>
		<comments>http://www.darknet.org.uk/2011/05/mac-malware-becoming-a-serious-threat/#comments</comments>
		<pubDate>Fri, 13 May 2011 10:03:49 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[apple malware]]></category>
		<category><![CDATA[apple virus]]></category>
		<category><![CDATA[apple-security]]></category>
		<category><![CDATA[mac malware]]></category>
		<category><![CDATA[mac malware kit]]></category>
		<category><![CDATA[mac osx bot]]></category>
		<category><![CDATA[mac osx trojan]]></category>
		<category><![CDATA[mac-security]]></category>
		<category><![CDATA[malware kit]]></category>
		<category><![CDATA[osc malware kit]]></category>
		<category><![CDATA[osx malware]]></category>
		<category><![CDATA[osx security]]></category>
		<category><![CDATA[weyland-yutani bot]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3108</guid>
		<description><![CDATA[Malware on the ubiquitous Apple platform has always been scoffed at by Mac users, and it was fair enough really. There weren&#8217;t a whole lot of Mac users so the effort to develop malware for the Mac platform really wasn&#8217;t worth it. The platform has exploded though with Macs being the weapon of choice for [...]]]></description>
			<content:encoded><![CDATA[<p>Malware on the ubiquitous <a href="http://www.darknet.org.uk/category/apple-hacking/">Apple</a> platform has always been scoffed at by Mac users, and it was fair enough really. There weren&#8217;t a whole lot of Mac users so the effort to develop <a href="http://www.darknet.org.uk/category/virustrojanswormsrootkits/">malware</a> for the Mac platform really wasn&#8217;t worth it.</p>
<p>The platform has exploded though with Macs being the weapon of choice for all the hipsters and yuppies out there, we wrote about <a href="http://www.darknet.org.uk/2009/06/apple-struggling-with-security-malware/">Apple Struggling With Security &#038; Malware</a> back in 2009.</p>
<p>In 2010 we saw <a href="http://www.darknet.org.uk/2010/11/sophos-launches-free-anti-virus-software-for-mac/">Sophos Launch a FREE Anti-Virus Software For Mac</a> and in 2011 we saw a <a href="http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/">JAVA based cross platform trojan that also effected Mac machines</a>.</p>
<blockquote><p>Apple &#8212; and many Mac users &#8212; argue that Mac OS X has a special recipe for security that makes it less likely to be infected with malware. Many security researchers counter that the Mac&#8217;s seeming immunity stems not from its security, but from its lack of market share.</p>
<p>The debate may finally be settled. The emergence of a serious malware construction kit for the Mac OS X seems to mimic a 2008 prediction by a security researcher. The prediction comes from a paper written in IEEE Security &#038; Privacy, which used game theory to predict that Macs would become a focus for attackers as soon as Apple hit 16 percent market share.</p>
<p>Last week, security researchers pointed to a construction kit for creating Trojans for the Mac OS X as a major issue for Mac users. Currently, three countries &#8212; Switzerland, Luxembourg and the United States &#8212; have Mac market share around that level.</p>
<p>&#8220;The kit is being sold under the name Weyland-Yutani Bot and it is the first of its kind to hit the Mac OS platform,&#8221; Peter Kruse, partner and security specialist at security firm CSIS, writes in a blog post. &#8220;CSIS finds this crimekit to be quite disturbing news since Mac OS previously to some degree has been spared from the increasing amount of malware which has haunted Windows-based systems for years.&#8221; </p></blockquote>
<p>The prediction in the paper was that Mac would start being targeted when they reached a 16% market share, which has happened recently in 3 countries. There is not a trojan creation kit targeting Mac OSX &#8211; this makes threats on the platform a reality.</p>
<p>The original paper can be found here &#8211; <a href="http://www.securitymetrics.org/content/attach/Metricon3.0/j3attAO.pdf">j3attAO.pdf</a></p>
<p>The fact is that Mac users probably still don&#8217;t run anti-virus software because they don&#8217;t believe they need to, these threats could spread fast.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Weyland-Yutani Bot, named for the corporation in the 1979 movie Alien, is currently being sold by its developers. While it is not the first attack on the Mac OS X, crimeware has enabled criminals in the past to scale up attacks quickly.</p>
<p>&#8220;What is happening is that people are testing the waters,&#8221; says Adam O&#8217;Donnell, chief architect of the cloud technology group at SourceFire and the author of the 2008 paper. &#8220;It just becomes economically viable to do it, so you start seeing these attacks becoming more common.&#8221;</p>
<p>The 2008 paper used game theory to calculate when attackers would start seeing a payoff in focusing on the Mac OS X over Windows. It simplified the problem by assuming that all PC users ran antivirus software and that no Mac users did. The assumptions helped reduce the problem down to two factors: the effectiveness of the defenses and the marketshare of the dominant platform.</p>
<p>With detection rates for antivirus in the 80 percent range, the Mac OS X becomes an attractive target around 16 percent marketshare. If PC defenses are better than 80 percent, then the Mac market share at which attackers become interested drops. For example, if antivirus programs detect attack 90 percent of the time, then attackers will focus on the Mac OS X at approximately 6 percent marketshare, says O&#8217;Donnell.</p>
<p>&#8220;It is much more of an argument that at the low rates of penetration of the Mac in the market is why there is no malware,&#8221; he says. &#8220;You get a few points up, and like we are seeing now, you will start seeing malware.&#8221; </p></blockquote>
<p>But even still, with AV software installed doesn&#8217;t make your computer the bastion of security. AV software still works on a reactive basis, there still is no real proactive security. AV heuristics are crap, they don&#8217;t detect anything.</p>
<p>Signatures still need to be updated and pushed out, and can be avoided. Especially by morphing software, the new generations of trojan and bot software are much more advanced than any AV system.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/051211-mac-malware-goes-from-game.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Mac+Malware+Becoming+a+Serious+Threat+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3108+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/05/mac-malware-becoming-a-serious-threat/&amp;t=Mac+Malware+Becoming+a+Serious+Threat" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/05/mac-malware-becoming-a-serious-threat/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/05/mac-malware-becoming-a-serious-threat/&amp;title=Mac+Malware+Becoming+a+Serious+Threat" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/05/mac-malware-becoming-a-serious-threat/&amp;title=Mac+Malware+Becoming+a+Serious+Threat" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/05/mac-malware-becoming-a-serious-threat/&amp;title=Mac+Malware+Becoming+a+Serious+Threat" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/05/mac-malware-becoming-a-serious-threat/&amp;title=Mac+Malware+Becoming+a+Serious+Threat" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F05%2Fmac-malware-becoming-a-serious-threat%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/05/mac-malware-becoming-a-serious-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Day One At Pwn2Own Takes Out Microsoft Internet Explorer and Apple Safari</title>
		<link>http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/</link>
		<comments>http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/#comments</comments>
		<pubDate>Thu, 10 Mar 2011 09:39:01 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[chaouki bekrar]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[hacking apple]]></category>
		<category><![CDATA[hacking macbook]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[internet explorer hack]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[pwn2own]]></category>
		<category><![CDATA[return oriented programming]]></category>
		<category><![CDATA[safari]]></category>
		<category><![CDATA[safari-exploit]]></category>
		<category><![CDATA[safari-security]]></category>
		<category><![CDATA[use-after-free flaw]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3063</guid>
		<description><![CDATA[Well it&#8217;s March again and well we love March because it&#8217;s Pwn2Own time! Every year around this time we get some goodies to discuss way back since: 2008 &#8211; Mac owned on 2nd day of Pwn2Own hack contest 2009 &#8211; Charlie Miller Does It Again At PWN2OWN 2010 &#8211; Mozilla Beats Apple &#038; Microsoft to [...]]]></description>
			<content:encoded><![CDATA[<p>Well it&#8217;s March again and well we love March because it&#8217;s <a href="http://www.darknet.org.uk/tag/pwn2own/">Pwn2Own</a> time! Every year around this time we get some goodies to discuss way back since:</p>
<ul>
<li>2008 &#8211; <a href="http://www.darknet.org.uk/2008/03/mac-owned-on-2nd-day-of-pwn2own-hack-contest/">Mac owned on 2nd day of Pwn2Own hack contest</a></li>
<li>2009 &#8211; <a href="http://www.darknet.org.uk/2009/03/charlie-miller-does-it-again-at-pwn2own/">Charlie Miller Does It Again At PWN2OWN</a></li>
<li>2010 &#8211; <a href="http://www.darknet.org.uk/2010/04/mozilla-beats-apple-microsoft-to-pwn2own-patch-for-firefox/">Mozilla Beats Apple &#038; Microsoft to Pwn2Own Patch For Firefox</a></li>
</ul>
<p>It took Microsoft till June last year to fix the Pwn2Own bug &#8211; <a href="http://www.darknet.org.uk/2010/06/microsoft-patches-at-least-34-bugs-including-pwn2own-vulnerability/">Microsoft Patches At Least 34 Bugs Including Pwn2Own Vulnerability</a>.</p>
<p>This time both <a href="http://www.darknet.org.uk/tag/internet-explorer/">Internet Explorer</a> and <a href="http://www.darknet.org.uk/tag/safari/">Safari</a> fell on the first day! </p>
<blockquote><p>Contestants in a high-stakes hacking contest had no trouble toppling the Apple Safari and Microsoft Internet Explorer browsers, proving for a fifth year in a row that no software or application is safe from people with the expertise and motivation to exploit them.</p>
<p>The attacks came on Day One of the Pwn2Own contest, which pays more than $15,000 apiece for exploits that successfully give the attacker full remote access of the targeted machine. Wednesday&#8217;s event saw hackers take complete control of a fully patched Sony Vaio and MacBook Air by compromising IE and Safari respectively. Google&#8217;s Chrome browser was also up for grabs, but no one stepped forward to try hacking it.</p>
<p>“Every browser, every operating system, has its own vulnerabilities,” said Chaouki Bekrar, CEO of Vupen Security and the contestant who successfully hacked Safari. “This is what we wanted to demonstrate – that we can create a very reliable exploit for Apple Mac OS and Safari without even crashing the browser.”</p>
<p>Contest rules forbid him from disclosing most technical details behind the vulnerability, but he was permitted to say that it involved what&#8217;s known as a use-after-free flaw in the Apple browser. He said the exploit used a technique known as return-oriented programming to bypass a security protection known as data execution prevention that is built into many Apple programs.</p></blockquote>
<p>There have been a barrage of patches recently too with Microsoft patching some very serious bugs in the <a href="http://isc.sans.edu/diary.html?storyid=10510&#038;rss">March 2011 Black Tuesday</a>, <a href="http://www.networkworld.com/news/2011/030911-apple-patches-critical-mac-bugs.html?source=nww_rss">Apple patches critical Mac bugs with Java updates</a>, <a href="http://lists.apple.com/archives/security-announce/2011/Mar/msg00004.html">Apple patching 62 bugs in Safari</a> and Jon Oberheide killing his own <a href="http://www.darknet.org.uk/tag/internet-explorer/">Android</a> bug by <a href="http://www.theregister.co.uk/2011/03/07/android_pwn2own_bug_killed/">reporting it to Google</a>.</p>
<p>Also sadly one of the Pwn2Own champions <a href="http://www.darknet.org.uk/tag/geohot/">Geohot</a> wasn&#8217;t present most likely to to the <a href="http://www.darknet.org.uk/2011/01/happy-new-year-geohot-court-orders-seizure-of-ps3-hackers-computers/">shit storm Sony is throwing at him</a>.</p>
<p>It&#8217;ll be interesting to what else comes out of Pwn2Own this year.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>After building the tools from scratch, it took him about two weeks to find the bug and set out to exploit it. The result was an attack that reliably commandeers a Mac when Safari visits a website that hosts the malicious code.</p>
<p>“Just after visiting the webpage with the affected version of Safari, we can, for example, launch the calculator or open a shell or do anything else we want,” he said a minute or two after demonstrating the exploit at the contest, which was attended by members of Apple&#8217;s security team. “We have the same privileges as the user who visited the webpage.”</p>
<p>He said users would have no way of knowing their machines have been compromised. There is no prompt asking for a password. The only way to thwart the attack is to run Safari from an account that has been configured to have limited privileges.</p>
<p>Under competition rules, contestants drew a lottery to determine who was the first to attempt hacking a particular browser. Once a browser was compromised, it was eliminated from the running. Both IE and Safari were hacked on the first try.</p>
<p>“I have an exploit all ready to go, and now it&#8217;s just sitting in my bag,” said Charlie Miller, a three-time Pwn2Own winner, shortly after Bekrar took this year&#8217;s prize. “You&#8217;d think Apple would be concerned about it.”</p>
<p>Miller said he&#8217;s had the working attack for more than nine months now. Even after Apple patched a whopping 62 Safari security bugs just hours before the contest started, Miller&#8217;s exploit still worked, he said.</p></blockquote>
<p><a href="http://www.darknet.org.uk/tag/charlie-miller/">Charlie Miller</a> has a working exploit sitting in his back too after Bekrar already took the prize. It seems like it&#8217;s really quite worth developing a reliable, working 0-day exploit for $15,000!</p>
<p>The new sandbox in IE got pwned pretty easily too, which shows..slapping on some tonka toy security controls isn&#8217;t ever going to stop a dedicated attacker. There was one contestant who stepped up to the plate to take down <a href="http://www.darknet.org.uk/tag/chrome/">Google&#8217;s Chrome</a>, but perhaps the exploit didn&#8217;t work as there&#8217;s no reports on that.</p>
<p>Day two of Pwn2Own will see attacks on Smart-phone platforms &#8211; Windows 7 Mobile, an iPhone 4, a BlackBerry Torch 9800, and a Nexus S running Google&#8217;s Android. There are multiple contestants signed up for each platform!</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/03/10/apple_safari_ie_stomped/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3063+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;t=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;title=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;title=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;title=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;title=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F03%2Fday-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Java Based Cross Platform Malware Trojan (Mac/Linux/Windows)</title>
		<link>http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/</link>
		<comments>http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/#comments</comments>
		<pubDate>Thu, 20 Jan 2011 07:45:43 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[cross platform malware]]></category>
		<category><![CDATA[cross platform trojan]]></category>
		<category><![CDATA[cross platform virus]]></category>
		<category><![CDATA[java based malware]]></category>
		<category><![CDATA[java based trojan]]></category>
		<category><![CDATA[jnanabot]]></category>
		<category><![CDATA[koobface]]></category>
		<category><![CDATA[linux malware]]></category>
		<category><![CDATA[linux trojan]]></category>
		<category><![CDATA[mac malware]]></category>
		<category><![CDATA[mac trojan]]></category>
		<category><![CDATA[mac-virus]]></category>
		<category><![CDATA[macbook-pro]]></category>
		<category><![CDATA[osx trojan]]></category>
		<category><![CDATA[osx.koobface]]></category>
		<category><![CDATA[trojan.jnanabot]]></category>
		<category><![CDATA[windows-virus]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3031</guid>
		<description><![CDATA[It&#8217;s pretty rare to read about malware on the Linux or Mac OSX platforms and even more rare to read about cross-platform malware which targets both AND Windows by using Java. A neat piece of coding indeed, it targets vulnerabilities in all 3 operating systems &#8211; the sad thing? The malware itself is vulnerable to [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s pretty rare to read about malware on the <a href="http://www.darknet.org.uk/category/linux-hacking/">Linux</a> or <a href="http://www.darknet.org.uk/category/apple-hacking/">Mac OSX</a> platforms and even more rare to read about cross-platform malware which targets both AND Windows by using Java.</p>
<p>A neat piece of coding indeed, it targets vulnerabilities in all 3 operating systems &#8211; the sad thing? The malware itself is vulnerable to a basic <a href="http://www.darknet.org.uk/tag/directory-traversal/">directory traversal</a> exploit, which means rival gangs can actually commandeer the infected targets.</p>
<p>They went to lengths to keep it secure and unseen (encrypted communications etc) &#8211; but didn&#8217;t program the malware itself securely&#8230;</p>
<blockquote><p>From the department of cosmic justice comes this gem, spotted by researchers from Symantec: a trojan that targets Windows, Mac, and Linux computers contains gaping security vulnerabilities that allow rival criminal gangs to commandeer the infected machines.</p>
<p>Known as Trojan.Jnanabot, or alternately as OSX/Koobface.A or trojan.osx.boonana.a, the bot made waves in October when researchers discovered its Java-based makeup allowed it to attack Mac and Linux machines, not just Windows PCs as is the case with most malware. Once installed, the trojan components are stored in an invisible folder and use strong encryption to keep communications private.</p>
<p>The bot can force its host to take instructions through internet relay chat, perform DDoS attacks, and post fraudulent messages to the victim&#8217;s Facebook account, among other things.</p>
<p>Now, Symantec researchers have uncovered weaknesses in the bot&#8217;s peer-to-peer functionality that allow rival criminals to remotely steal or plant files on the victim&#8217;s hard drive. That means the unknown gang that took the trouble to spread the infection in the first place risks having their botnet stolen from under their noses.</p>
<p>“Even though it&#8217;s encrypted and even though it was written in Java to make it cross-platform, it was still vulnerable to basically a directory transversal exploit,” Dean Turner, director of Symantec&#8217;s Global Intelligence Network, told The Reg. “From a technical perspective, it goes to show that even if you have all those things where you&#8217;re building in a secure platform, if you&#8217;re not building application security into your malware, other bad guys will probably take advantage of it.”</p></blockquote>
<p>It&#8217;s somewhat of an odd decision though, in terms of numbers obviously Windows machines far outnumber Linux and OSX desktop installations. On the web-server front perhaps Linux is a valuable target &#8211; but on consumer desktops? Is it really worth the effort for malware creators to make cross-platform trojans? Personally I don&#8217;t think it is, maybe it was just an experiment.</p>
<p>The number of Apple machines is certainly growing, the next big market we are going to see is tablets and smartphones I believe. I&#8217;d be on the lookout for more <a href="http://www.darknet.org.uk/tag/ios/">iOS</a> and <a href="http://www.darknet.org.uk/tag/android/">Android</a> worms/trojans in coming months.</p>
<p>A self-replicating stealthy Android trojan with a previously unpatched zero-day remote root exploit could be devastating.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Jnanabot&#8217;s P2P feature is designed to make botnets harder to take down by providing multiple channels of communication. After sending an infected machine a single GET request, a website can discover all the information needed to upload any file to any location on the host&#8217;s file system. Attackers can then install a simple backdoor on a user&#8217;s machine by, for instance, writing a malicious program to a computer&#8217;s startup directory.</p>
<p>Attackers can use the same vulnerability to steal files on infected machines.</p>
<p>Turner said the number of Jnanabot infections so far is “measured in the thousands,” rather than the hundreds of thousands for some of the better-known trojans. Still, infection statistics gathered by Symantec in December are surprising. They show that about 16 per cent of infections hit Macs. They didn&#8217;t show any infections on Linux machines. Turner said that Jnanabot attacks on the open source platform weren&#8217;t able to survive a reboot.</p>
<p>The bot was discovered spreading over Facebook posts that planted the following message on infected users&#8217; Facebook pages: “As you are on my friends list I thought I would let you know I have decided to end my life.” An included link leads recipients to a cross-platform JAR, or Java Archive file that can run on Windows, Mac, or Linux. Once the recipient is infected, his Facebook page carries the same dire warning.</p></blockquote>
<p>It seems like the trojan theoretically can attack Linux, but so far hasn&#8217;t been seen in the wild and it can&#8217;t survive a reboot. Not that it really matters as from my experience most Linux users never reboot anyway except for kernel upgrades (which isn&#8217;t that often).</p>
<p>Perhaps it just doesn&#8217;t work that well on Linux, or Linux users don&#8217;t believe in installing JVM &#8211; it doesn&#8217;t usually come standard with OS installs as it&#8217;s considered non-free software.</p>
<p>The chosen vector for replication seems to be <a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> and a rather dramatic faux-suicide note &#8211; which sadly I think will be very effective.</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/01/19/mac_linux_bot_vulnerabilities/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3031+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;t=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;title=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;title=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;title=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;title=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F01%2Fjava-based-cross-platform-malware-trojan-maclinuxwindows%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>PGP Users Locked Out With Latest OS X Update</title>
		<link>http://www.darknet.org.uk/2010/11/pgp-users-locked-out-with-latest-os-x-update/</link>
		<comments>http://www.darknet.org.uk/2010/11/pgp-users-locked-out-with-latest-os-x-update/#comments</comments>
		<pubDate>Fri, 12 Nov 2010 10:26:50 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[apple osx]]></category>
		<category><![CDATA[apple osx pgp]]></category>
		<category><![CDATA[boot guard]]></category>
		<category><![CDATA[disc encryption]]></category>
		<category><![CDATA[efi booter]]></category>
		<category><![CDATA[pgp]]></category>
		<category><![CDATA[pgp disc encryption]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[wde]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2993</guid>
		<description><![CDATA[For the past day or so I&#8217;ve been seeing endless people tweeting about how the latest Mac OS X update b0rks your Mac if you are using PGP full disc encryption. It&#8217;s a pretty nasty bug, but thankfully it can be recovered from fairly easily. If you are just looking for a quick solution, you [...]]]></description>
			<content:encoded><![CDATA[<p>For the past day or so I&#8217;ve been seeing endless people tweeting about how the latest Mac OS X update b0rks your Mac if you are using PGP full disc encryption. It&#8217;s a pretty nasty bug, but thankfully it can be recovered from fairly easily.</p>
<p>If you are just looking for a quick solution, you can:</p>
<p>a) Not apply the update (<a href="http://forum.pgp.com/t5/PGP-Announcements/Update-ALERT-PGP-MAC-WDE-Compatibil-ity-Problem-with-MAC-OS-X-10/td-p/40584">as recommended by PGP</a>)<br />
b) Decypt your volumes, apply the update, then re-encrypt</p>
<blockquote><p>Users of PGP&#8217;s Whole Disk Encryption for Macs got a nasty surprise when they upgraded to the latest OS X update once they discovered their systems were no longer able to reboot.</p>
<p>It seems that Apple and the Symantec-owned PGP suffered a near-fatal failure to communicate that 10.6.5 ships with a new EFI booter that was incompatible with the encryption software&#8217;s boot guard. As a result, the update rendered Macs using WDE as little more than expensive paperweights.</p>
<p>“PGP you DO HAVE A FREAKING DEVELOPERS LICENCE FOR APPLE RIGHT???” one outraged user vented here. “YOU CANNOT TEST SYSTEM RELEASES IN ADVANCE???”</p></blockquote>
<p>It&#8217;s caused a massive backlash from the user-base with people hurling insults left, right and center. For the non-tech savvy user it&#8217;s pretty worrying when their system can&#8217;t even boot up and in most cases they probably have absolutely no idea what to do.</p>
<p>It seems like a lack of communication between PGP devs and <a href="http://www.darknet.org.uk/category/apple-hacking/">Apple</a> with regards to the new boot loader.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Test versions of the update have been available to developers for a while now, but it&#8217;s not clear if they included the new EFI booter. If not, the fault could lie with Apple. The world will probably never know.</p>
<p>Fortunately, a fix was provided Thursday morning that&#8217;s relatively painless. It involves booting off the PGP recovery CD and then logging in to OS X. An automatic self-repair process that&#8217;s part of the Mac bootup sequence will straighten out things from there. A variation on that theme is to put the bricked machine in target mode and boot from another Mac running PGP.</p>
<p>WDE users who have yet to install the update may safely do so by decrypting their systems before running the update, PGP said.</p></blockquote>
<p>A fix was provided yesterday morning by PGP, the details are here:</p>
<p><a href="https://pgp.custhelp.com/app/answers/detail/a_id/2288">Mac PGP WDE customers should not apply the recent Mac OS X 10.6.5 update</a></p>
<p>Source: <a href="http://www.theregister.co.uk/2010/11/12/mac_update_bricks_pgp/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=PGP+Users+Locked+Out+With+Latest+OS+X+Update+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2993+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/11/pgp-users-locked-out-with-latest-os-x-update/&amp;t=PGP+Users+Locked+Out+With+Latest+OS+X+Update" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/11/pgp-users-locked-out-with-latest-os-x-update/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/11/pgp-users-locked-out-with-latest-os-x-update/&amp;title=PGP+Users+Locked+Out+With+Latest+OS+X+Update" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/11/pgp-users-locked-out-with-latest-os-x-update/&amp;title=PGP+Users+Locked+Out+With+Latest+OS+X+Update" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/11/pgp-users-locked-out-with-latest-os-x-update/&amp;title=PGP+Users+Locked+Out+With+Latest+OS+X+Update" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/11/pgp-users-locked-out-with-latest-os-x-update/&amp;title=PGP+Users+Locked+Out+With+Latest+OS+X+Update" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F11%2Fpgp-users-locked-out-with-latest-os-x-update%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/11/pgp-users-locked-out-with-latest-os-x-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sophos Launches FREE Anti-Virus Software For Mac</title>
		<link>http://www.darknet.org.uk/2010/11/sophos-launches-free-anti-virus-software-for-mac/</link>
		<comments>http://www.darknet.org.uk/2010/11/sophos-launches-free-anti-virus-software-for-mac/#comments</comments>
		<pubDate>Tue, 02 Nov 2010 13:59:15 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[apple-mac]]></category>
		<category><![CDATA[mac anti-virus]]></category>
		<category><![CDATA[mac antivirus]]></category>
		<category><![CDATA[mac av]]></category>
		<category><![CDATA[mac-osx]]></category>
		<category><![CDATA[mac-security]]></category>
		<category><![CDATA[osx anti-virus]]></category>
		<category><![CDATA[osx antivirus]]></category>
		<category><![CDATA[sophos]]></category>
		<category><![CDATA[sophos antivirus]]></category>
		<category><![CDATA[sophos mac antivirus]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2986</guid>
		<description><![CDATA[Well most Apple users would tell you they don&#8217;t need anti-virus anyway, viruses and malware are a Windows problem &#8211; not something the hi-tech hipsters need to worry about. And let&#8217;s face it, even if you run Windows you don&#8217;t really need to run anti-virus either if you practice good web-habits. But with the amount [...]]]></description>
			<content:encoded><![CDATA[<p>Well most <a href="http://www.darknet.org.uk/tag/apple/">Apple</a> users would tell you they don&#8217;t need anti-virus anyway, viruses and malware are a <a href="http://www.darknet.org.uk/tag/windows/">Windows</a> problem &#8211; not something the hi-tech hipsters need to worry about.</p>
<p>And let&#8217;s face it, even if you run Windows you don&#8217;t really need to run anti-virus either if you practice good web-habits. But with the amount of idiots running OSX on their shiny Macbooks &#8211; malware may well become a problem for the platform.</p>
<p>It&#8217;s not a problem right now, the stats for malicious software on Apple platforms are still minuscule compared to the threats on Windows and even on Linux.</p>
<blockquote><p>Sophos released a free of charge Mac anti-virus product for consumers on Tuesday in a bid to highlight the growing security risk against the platform and to shake fanbois out of their complacency.</p>
<p>The business-focused internet security firm is making Sophos Anti-Virus Home Edition for Mac available for download at no charge &#8211; with no time limit, and requiring no registration. The technology is a cut-down version of Sophos&#8217;s pre-existing anti-virus software for Macs and will ship with detection of thousands of malware strains including Trojans and rootkits. Sophos has no plans to release an equivalent free of charge Windows anti-malware scanner.</p>
<p>Three well-established freebie security scanners (AVG, Avast, Avira) already exist even without considering Microsoft&#8217;s own Security Essentials software. Although commercial anti-virus packages for Macs have been sold for some time by the likes of Intego and Symantec &#8211; and more recently by Kaspersky and Panda &#8211; Sophos&#8217;s software one of very few freebie scanners for Macs available to date.</p></blockquote>
<p>It&#8217;s a pretty interesting move from <a href="http://www.darknet.org.uk/tag/sophos/">Sophos</a> tho, business wise, as they have no plans into strong-arming users into paying for a commercial version by releasing a crappy crippled version under the guise of &#8216;free&#8217; software.</p>
<p>Sophos has always been a company with strong technology, so even as freeware I&#8217;d expect this to be fairly capable software. There are other commercial AV systems out their for Mac &#8211; but this is the first one from a reputable vendor that is free. I mean there&#8217;s <a href="http://www.darknet.org.uk/2007/12/wabisabilabi-pimping-clamav-vulnerability-exploit/">ClamAV</a> &#8211; but in all honestly who would want to rely on that?</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>It&#8217;s not the first freebie scanner for Macs currently available, contrary to claims in the first version of this article. Others including, most notable, ClamAV exist.</p>
<p>Past threats to Mac users have included malware disguised as pirated software and uploaded onto P2P file-sharing networks, supposed video codecs that actually contain a Mac-specific Trojan horse and strains of Windows malware capable of infecting virtual installations of Windows running on a Mac.</p>
<p>Apple acknowledged the malware problem by integrating rudimentary protection against a handful of Mac Trojans in Snow Leopard, Sophos notes, arguing that users running its software are provided with more comprehensive protection against potential threats.</p>
<p>Carole Theriault, senior security consultant at Sophos, explained that while the picture is different in enterprise environments, &#8220;home Mac users aren&#8217;t protecting themselves from malware&#8221;.</p>
<p>Theriault admitted that Windows threats counted in their millions dwarf the number of strains of Mac malware, which can be counted in their thousands, but maintained there was a need for protection, whatever sales people in Apple Stores might say to the contrary. &#8220;We want to raise awareness,&#8221; she explained.</p></blockquote>
<p>Either way it&#8217;s an interesting move from Sophos and we&#8217;ll have to see where it goes from here. They claim they won&#8217;t charge for it, but who knows? And will this pressure other AV vendors that have paid versions for Mac to release free versions for Home users. Much like the Windows vendors do (Avira, Avast!, AVG etc).</p>
<p>More on the software, together with hardware compatibility information, can be found out from a download micro-site here:</p>
<p><a href="http://www.sophos.com/products/free-tools/free-mac-anti-virus/">Sophos Anti-Virus for Mac Home Edition</a></p>
<p>Source: <a href="http://www.theregister.co.uk/2010/11/02/sophos_mac_anti_virus/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Sophos+Launches+FREE+Anti-Virus+Software+For+Mac+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2986+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/11/sophos-launches-free-anti-virus-software-for-mac/&amp;t=Sophos+Launches+FREE+Anti-Virus+Software+For+Mac" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/11/sophos-launches-free-anti-virus-software-for-mac/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/11/sophos-launches-free-anti-virus-software-for-mac/&amp;title=Sophos+Launches+FREE+Anti-Virus+Software+For+Mac" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/11/sophos-launches-free-anti-virus-software-for-mac/&amp;title=Sophos+Launches+FREE+Anti-Virus+Software+For+Mac" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/11/sophos-launches-free-anti-virus-software-for-mac/&amp;title=Sophos+Launches+FREE+Anti-Virus+Software+For+Mac" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/11/sophos-launches-free-anti-virus-software-for-mac/&amp;title=Sophos+Launches+FREE+Anti-Virus+Software+For+Mac" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F11%2Fsophos-launches-free-anti-virus-software-for-mac%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/11/sophos-launches-free-anti-virus-software-for-mac/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>JailBreaking AppleTV Running on iOS 4.1 &#8211; iPad/iPhone 4 Jailbreak Soon?</title>
		<link>http://www.darknet.org.uk/2010/09/jailbreaking-appletv-running-on-ios-4-1-ipadiphone-4-jailbreak-soon/</link>
		<comments>http://www.darknet.org.uk/2010/09/jailbreaking-appletv-running-on-ios-4-1-ipadiphone-4-jailbreak-soon/#comments</comments>
		<pubDate>Wed, 29 Sep 2010 07:55:59 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hardware Hacking]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[apple jailbreak]]></category>
		<category><![CDATA[apple tv jailbreak]]></category>
		<category><![CDATA[appletv appletv jailbreak]]></category>
		<category><![CDATA[ios 4.1 jailbreak]]></category>
		<category><![CDATA[ios 4.1 jb]]></category>
		<category><![CDATA[iphone4 jailbreak]]></category>
		<category><![CDATA[jail break]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[jailbreaking apple tv]]></category>
		<category><![CDATA[jailbreaking appletv]]></category>
		<category><![CDATA[jailbreaking iphone 4]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2958</guid>
		<description><![CDATA[Posts about the latest Jailbreak exploit/software for the new Apple devices are always pretty popular and this looks like it might turn out to be pretty interesting. It seems like at the moment the latest iOS update has been cracked for iPod Touch and earlier iPhones (3GS) but there&#8217;s no working Jailbreak at the moment [...]]]></description>
			<content:encoded><![CDATA[<p>Posts about the latest <a href="http://www.darknet.org.uk/tag/jailbreak/">Jailbreak</a> exploit/software for the new <a href="http://www.darknet.org.uk/category/apple-hacking/">Apple</a> devices are always pretty popular and this looks like it might turn out to be pretty interesting.</p>
<p>It seems like at the moment the latest iOS update has been cracked for iPod Touch and earlier iPhones (3GS) but there&#8217;s no working Jailbreak at the moment for the newly released iPhone 4 &#8211; something to do with the baseband I think. I&#8217;m not super familiar with Apple stuff though so do correct me if I&#8217;m wrong.</p>
<p>The note about this exploit comes at the bottom of this post:</p>
<p><a href="http://blog.iphone-dev.org/post/1197198297/shattered-ipod-touch-4g">SHAttered iPod touch 4G</a></p>
<blockquote><p>The latest Apple TV isn&#8217;t even in people&#8217;s hands and its already close to being jailbroken, according to members of a hacker group that has a track record of successfully freeing iDevices from the artificial shackles of Steve Jobs &#038; Co.</p>
<p>According to a post on Monday on the iPhone Dev Team Blog, members were able to crack the customized iOS firmware shortly after its release on Monday on an Apple download site. The release came the same day Apple began shipping the $99 device.</p>
<p>The download, which allows users to restore Apple TVs to their original factory settings, confirms rumors that Jobs&#8217;s “hobby” does in fact run iOS. More importantly, it gave iPhone Dev Team members an opportunity to run it through an in-development iOS 4.1 hacking tool they developed called SHAtter. They quickly extracted the cryptographic key used to lock down the Apple TV firmware, which is the first step in finding a reliable jailbreak.</p></blockquote>
<p>The funny thing is AppleTV device hasn&#8217;t even shipped out yet and it&#8217;s already been jailbroken, they have also confirmed that it&#8217;s running on a version of iOS. This might be interesting for development of an iPhone 4 jailbreak.</p>
<p>Jailbreaks are a pretty hot topic at the moment with the iPhone 4 slowly releasing around the World after having been out commercially in the US for a couple of months now. It could set things up for a whole new slew of applications to come out too, imagine a hacked AppleTV with a custom iOS firmware or something else running on it (Android/MeeGo) hooked up via HDMI to your LCD/Plasma TV &#8211; now that&#8217;d be sweet!</p>
<blockquote><p>It&#8217;s unclear exactly what could be done with a jailbroken Apple TV. Compared with other iDevices, it has a paltry amount of storage space. And, of course, there&#8217;s still the prospect that Apple will make last-minute changes to Apple TVs that patch the vulnerability SHatter exploits.</p>
<p>But as we&#8217;ve reckoned before, the mini USB port included with the Apple TV opens the door to running unauthorized code loaded on a patchstick. That in turn might allow users to run iPhone and iPad apps or add amenities such as SSH access, a USB-supported hard drive or even the ability to stream shows from Hulu.</p>
<p>All of that is in the future. With Monday&#8217;s commencement of Apple TV shipments, it won&#8217;t take long for us to find out.</p></blockquote>
<p>The shipping starts next week and I&#8217;m pretty sure Apple is going to be doing something about this, so we&#8217;ll find out about the future of this neat hack pretty soon. We&#8217;ll also see if a spin-off iPhone 4 jailbreak comes out of this.</p>
<p>You can find direct download links for the AppleTV firmware files here:</p>
<p><a href="http://iclarified.com/entry/index.php?enid=970">AppleTV Firmware Download Locations</a></p>
<p>Source: <a href="http://www.theregister.co.uk/2010/09/29/apple_tv_jailbreaking/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=JailBreaking+AppleTV+Running+on+iOS+4.1+%E2%80%93+iPad%2FiPhone+4+Jailbreak+Soon%3F+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2958+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/09/jailbreaking-appletv-running-on-ios-4-1-ipadiphone-4-jailbreak-soon/&amp;t=JailBreaking+AppleTV+Running+on+iOS+4.1+%E2%80%93+iPad%2FiPhone+4+Jailbreak+Soon%3F" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/09/jailbreaking-appletv-running-on-ios-4-1-ipadiphone-4-jailbreak-soon/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/09/jailbreaking-appletv-running-on-ios-4-1-ipadiphone-4-jailbreak-soon/&amp;title=JailBreaking+AppleTV+Running+on+iOS+4.1+%E2%80%93+iPad%2FiPhone+4+Jailbreak+Soon%3F" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/09/jailbreaking-appletv-running-on-ios-4-1-ipadiphone-4-jailbreak-soon/&amp;title=JailBreaking+AppleTV+Running+on+iOS+4.1+%E2%80%93+iPad%2FiPhone+4+Jailbreak+Soon%3F" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/09/jailbreaking-appletv-running-on-ios-4-1-ipadiphone-4-jailbreak-soon/&amp;title=JailBreaking+AppleTV+Running+on+iOS+4.1+%E2%80%93+iPad%2FiPhone+4+Jailbreak+Soon%3F" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/09/jailbreaking-appletv-running-on-ios-4-1-ipadiphone-4-jailbreak-soon/&amp;title=JailBreaking+AppleTV+Running+on+iOS+4.1+%E2%80%93+iPad%2FiPhone+4+Jailbreak+Soon%3F" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F09%2Fjailbreaking-appletv-running-on-ios-4-1-ipadiphone-4-jailbreak-soon%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/09/jailbreaking-appletv-running-on-ios-4-1-ipadiphone-4-jailbreak-soon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

