<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; mac os x</title>
	<atom:link href="http://www.darknet.org.uk/tag/mac-os-x/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Apple Fixes &#8216;Misleading&#8217; Leopard Firewall Settings</title>
		<link>http://www.darknet.org.uk/2007/11/apple-fixes-misleading-leopard-firewall-settings/</link>
		<comments>http://www.darknet.org.uk/2007/11/apple-fixes-misleading-leopard-firewall-settings/#comments</comments>
		<pubDate>Wed, 21 Nov 2007 12:46:32 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[apple firewall]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking apple]]></category>
		<category><![CDATA[leopard]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[mac os x]]></category>
		<category><![CDATA[mac-osx]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[osx]]></category>
		<category><![CDATA[safari]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/11/apple-fixes-misleading-leopard-firewall-settings/</guid>
		<description><![CDATA[Apple has admitted that is has at LEAST three serious design weaknesses in it&#8217;s new application based firewall being rolled out with Mac OS X &#8216;Leopard&#8217;. It comes (somewhat oddly) only 24 hours after a Mac OS X security update that fixed 41 OS X and Safari security vulnerabilities. Previously independent researchers proved that Apple&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Apple has admitted that is has at LEAST three serious design weaknesses in it&#8217;s new application based firewall being rolled out with Mac OS X &#8216;Leopard&#8217;.</p>
<p>It comes (<em>somewhat oddly</em>) only 24 hours after a <a href="http://blogs.zdnet.com/security/?p=666">Mac OS X security update</a> that fixed <a href="http://docs.info.apple.com/article.html?artnum=307041">41 OS X and Safari security vulnerabilities</a>.</p>
<p>Previously <a href="http://www.heise-security.co.uk/articles/98120">independent researchers proved</a> that Apple&#8217;s claim that the Leopard firewall could block all incoming connections was false.</p>
<blockquote><p>In an advisory accompanying the Mac OS X v10.5.1 update, Apple admitted that the “Block all incoming connections” setting for the firewall is misleading.</p>
<p>“The ‘Block all incoming connections’ setting for the Application Firewall allows any process running as user “root” (UID 0) to receive incoming connections, and also allows mDNSResponder to receive connections. This could result in the unexpected exposure of network services,” Apple said.</p>
<p>With the fix, the firewall will more accurately describe the option as “Allow only essential services”, and by limiting the processes permitted to receive incoming connections under this setting to a small fixed set of system services, Apple said</p></blockquote>
<p>Sounds like they are back-pedaling rather fast. They also addressed two other issues with the application based firewall.</p>
<blockquote><p><strong>CVE-2007-4703:</strong>  The “Set access for specific services and applications” setting for the Application Firewall allows any process running as user “root” (UID 0) to receive incoming connections, even if its executable is specifically added to the list of programs and its entry in the list is marked as “Block incoming connections”. This could result in the unexpected exposure of network services.</p>
<p><strong>CVE-2007-4704:</strong> When the Application Firewall settings are changed, a running process started by launchd will not be affected until it is restarted. A user might expect changes to take effect immediately and so leave their system exposed to network access.</p></blockquote>
<p>So watch out, Apple is not the panacea of security as some people claim it to be.</p>
<p></p>
<p>Source: <a href="http://blogs.zdnet.com/security/?p=673">ZDNet</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Apple+Fixes+%E2%80%98Misleading%E2%80%99+Leopard+Firewall+Settings+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D745+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/11/apple-fixes-misleading-leopard-firewall-settings/&amp;t=Apple+Fixes+%E2%80%98Misleading%E2%80%99+Leopard+Firewall+Settings" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/11/apple-fixes-misleading-leopard-firewall-settings/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/11/apple-fixes-misleading-leopard-firewall-settings/&amp;title=Apple+Fixes+%E2%80%98Misleading%E2%80%99+Leopard+Firewall+Settings" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/11/apple-fixes-misleading-leopard-firewall-settings/&amp;title=Apple+Fixes+%E2%80%98Misleading%E2%80%99+Leopard+Firewall+Settings" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/11/apple-fixes-misleading-leopard-firewall-settings/&amp;title=Apple+Fixes+%E2%80%98Misleading%E2%80%99+Leopard+Firewall+Settings" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/11/apple-fixes-misleading-leopard-firewall-settings/&amp;title=Apple+Fixes+%E2%80%98Misleading%E2%80%99+Leopard+Firewall+Settings" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F11%2Fapple-fixes-misleading-leopard-firewall-settings%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/11/apple-fixes-misleading-leopard-firewall-settings/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>

