Wednesday, May 28, 2008

Mac OS X 10.5.3 IS HERE! So is Security Update 003 with 27 Security Patches! And, And, And...


At last, at last!
10.5.3 is HERE AT LAST!

I gave up counting bugs in 10.5.2 when I hit #35. I am crossing my fingers they are all stamped out with this ENORMOUS update. If you use Software Update from within Leopard, the client version of Mac OS X 10.5.3 Update is 420 MB! The server version is 496 MB! If you want the Combo versions, the client version is 536 MB! The Combo server version is 632 MB!

But just as eye-opening are the 27+ security patches (Twenty Seven +!) included in Security Update 2008-003. The PPC client version is 72 MB (Seventy Two!). The Intel client version is 111 MB (One Hundred And Eleven!). The PPC server version is 88.9 MB (Eighty Eight Point Nine Megabytes!). The Universal Binary server version is 118 MB (One Hundred And Eighteen!).

And I'm not finished yet! Pay attention!

Also new is the Digital Camera RAW Compatibility Update 2.1 at 2.4 MB.

AND the Logic Express Update version 8.0.2 at 73.5 MB.

AND Server Admin Tools 10.5.3 at 64.5 MB.

IOW: Get ready for a snoozer of a download marathon.

Now for the boring but useful part. Here are all the URLs where you can read about and download the update disk images, followed by a list of security patches. I dare you to read them all! Will you survive?

Mac OS X 10.5.3 Update
Mac OS X Server 10.5.3 Update

Mac OS X 10.5.3 Combo Update
Mac OS X Server 10.5.3 Combo Update

Security Update 2008-003 (PPC)
Security Update 2008-003 (Intel)

Security Update 2008-003 Server (PPC)
Security Update 2008-003 Server (Universal)

Server Admin Tools 10.5.3

Digital Camera RAW Compatibility Update 2.1

Logic Express Update 8.0.2

Here is a summary of the new Mac OS X security updates, published in the Secunia Weekly Summary - Issue: 2008-22, which you can read at the most excellent Secunia website.

Quoting:
___________

Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.

The vulnerabilities include:

- An error in AFP server

- Various vulnerabilities in Apache (for Mac OS X Server v10.4.x)

- An unspecified error in AppKit

- Multiple unspecified errors in the processing of Pixlet video files

- An unspecified error exists in Apple Type Services when processing embedded fonts in PDF files

- An error in Safari's SSL client certificate handling

- An integer overflow exists in CoreFoundation when handling CFData objects

- An error due to an uninitialised variable in CoreGraphics

- A weakness due to users not being warned before opening certain potentially unsafe content types

- An error when printing to password-protected printers with debug logging enabled

- Various vulnerabilities in Adobe Flash Player

- An integer underflow error in Help Viewer when handling help:topic URLs

- A conversion error exists in ICU when handling certain character encodings

- Unspecified parameters in Image Capture's embedded web server not being properly sanitised before use

- An error in the handling of temporary files in Image Capture

- A boundary error in the BMP and GIF image decoding engine in ImageIO

- Various vulnerabilities in ImageIO due to the use of vulnerable libpng code

- An integer overflow error in ImageIO within the processing of JPEG2000 images

- An error in Mail is caused due to an uninitialised variable

- A vulnerability in Mongrel

- A weakness in the sso_util command-line tool

- An error in Wiki Server

- A vulnerability in Apple iCal

- A vulnerability due to an error in the handling of return values of "hashes()" in the "cs_validate_page()" function when processing signed Mach-O binaries

- A vulnerability due to an error within the "ipcomp6_input()" function in bsd/netinet6/ipcomp_input.c when processing packets with an IPComp header
___________

And that's not the complete list!

In other Mac OS X security news, there remains only 1 (ONE) bona fide malware in the wild, the so-called 'Porno Trojan'. (BWAHAHAHA! I love that name). News has it that it has mutated, thanks to scurrilous Phishing scam entrepreneurs, into other manifestations at other websites. So be wary of all unverified, untrusted downloads, particularly those pretending to be 'video codecs' you are supposed to need to install to view a web video. If you think you are a victim you can obtain the FREE removal tool at the generous MacScan website:

DNSChanger Removal Tool

Remember that Microsoft Office macro viruses still abound. Please take precautions, such as using a safer office suite of applications. May I suggest NeoOffice, the freeware Open Source office suite that created the now international standard Open Doc format. Or alternatively consider Apple's elegant iWork suite including Pages, Keynote and Numbers.

You can read my evaluation of Leopard update 10.5.3 over at my other Macintosh blog, MacSmarticles.

Share and EnJoY!

:-Derek

Saturday, March 29, 2008

The VERY SCARY Second Mac OS X Malware Arrives: Troj/MacSwp-B




"MacSweeper"
from "Imunizator" sounds like slackerware right off the bat. In this case it is nasty spooky SCAREWARE! Run for your life, yawn, zzz.

This slackerware is actually a few weeks old, but since it was discovered by Sophos it has officially become 'malware'. The BIG question: What DAMAGE does this rubbish do to your Mac????

Nothing at all.

Thus I yawn.

So is this actually 'malware'? Well, it is in the sense that it takes advantage of the eternal 'wetware vulnerability' problem, damaging your personal sense of logic, scaring you into thinking you need to pay for this fraudulent crapware or your computer will meet a horrible doom. (And yes everyone, I was the one who invented the term 'crapware'. Seriously! I'm not kidding! - Well, actually a friend pointed out it is an obvious term that anyone could have created. So much for my creativity).

Then what does this thingy actually do? By definition this is SOCIAL ENGINEERING malware. It is a form of PHISHING. This particular method is very old, like well over a decade. Here is how it works:

1) You download the thing because it was offered at a nefarious website you shouldn't have visited. (NOTE: Instead you should have checked VersionTracker or MacUpdate to see if they had ever heard of it and consider it a worthwhile program, which they don't. Then you should have Googled its name to see if there are reports about its reputation).

2) You install and run it. (This is very naughty. Don't do this with anything you have not already verified to be legitimate, having a good reputation).

3) It pretends to scan your Mac's "Universal Binnaries". (Again: Slackerware much?)

4) It then lies to you and says you have privacy violations that require your attention or you'll suffer the consequences. And of course the only way to avoid this terrible fate is to pay for this crapware in order to activate its ability to fix the fake problems.

5) You pay for the crapware. You lose your identity. The crooks use your identity to buy lots of toys and stiff you with the bill. They then sell your identity to others and further stiffing behavior continues until you or your credit card company get the clue and stop payment, invalidating your card. And that's not fun, OK?

Do you need to buy anti-malware to protect you from Troj/MacSwp-B? NO. Clam will do nicely, thank you. Instead you should familiarize yourself with social engineering strategies. You can read about social engineering at:

Wikipedia

Here is the source report of Troj/MacSwp-B:

Sophos

You can read a snide evaluation of Troj/MacSwp-B at:

Mac-Daily News

As MDN sez:
"Do not download, authorize, and install software from unknown, untrusted Websites or any other sources."

Especially, never-ever provide your administrator password when installing or running ANY program unless you know absolutely, totally, fur shur that the software is legitimate. Otherwise you are giving away the farm and the malware rulz your Mac. And that's bad, OK?

Now go watch something
really scary like the latest US political speech on CNN. Yes, mentally-challenged fascist vampires do exist.

Tuesday, March 11, 2008

Version 12.0.1 Security Update for Office 2008


Microsoft today released the version 12.0.1 update for Mac Office 2008. It contains security as well as bug patches. It has repairs for every application in Office 2008. Included are fixes for:


1) "... Vulnerabilities that an attacker can use to overwrite the contents of a computer's memory by using malicious code."

2) Issues that can cause Office 2008 to stop responding or quit.

3) Over 20 bug repairs.

Needless to say, this update is 'CRITICAL'.

You can read more about it HERE and HERE.

You can download it HERE.

You can get toss Office in the dumpster and replace it with the free/donationware NeoOffice HERE. Recommended. It is a thoroughly 'Macified' version of OpenOffice for X11. It has over twenty features that the X11 version does not. It can read and write most Office files. It includes a word processor, spreadsheet and presentation program. It has built-in support for Microsoft's new 'OpenXML' document format found in Office 2007 and Office 2008. It invented the new ISO 26300 OpenDocument universal file standard. It has a new QuickLook plug-in. It has a Spotlight importer. Its HTML code export feature follows international web standards (unlike Office 2008). It can export presentations to Flash format. It still supports Visual Basic for Applications macros (unlike Office 2008). It is also compatible with WordPerfect and Microsoft Works documents. You can compare the rest of its feature set with Office HERE. And yes, it really is free and well worth supporting.

;-Derek

Sunday, March 9, 2008

Office for Mac 'CRITICAL' Security Flaw


The SANS Institute is well known for its IT security training. They typically go a bit overboard trying to FUD Mac users. But if you ignore that rubbish they are a very good source of computer security information. If you are interested they also have a very good Mac security course schedule. I wouldn't mind attending!


This week SANS reported that Microsoft are going to be releasing four security bulletins on March 11, 2008. All the bulletins discuss 'CRITICAL' security flaws. Three are in Microsoft Office and one is in Microsoft Office Web Components. The affected versions of Office and its applications are Office 2000, Office XP, Office 2003, Excel, Office Outlook and Office for Mac. The vulnerability of interest here is the one affecting Office for Mac. You can read more at:

http://www.eweek.com/c/a/Security/Microsoft-Critical-MS-Office-Patches-Coming/
http://www.microsoft.com/technet/security/Bulletin/MS08-mar.mspx

When I learn specifics about this flaw I will have a follow-up post.

This information was provided in SANS NewsBites Vol. 10 Num. 19. You can obtain a free subscription at:

http://portal.sans.org/
_

Thursday, February 28, 2008

New Exploit: "ipcomp6_input()" Denial Of Service


Today Secunia posted in their weekly report a vulnerability in Mac OS X 10.5, and possibly earlier versions, that can be used in Denial Of Service (DoS) attacks. So far it remains unpatched by Apple. You can read the details
HERE:

I seriously doubt this is going to affect much of anyone at this point in time as it requires the use of IPv6 packets. IPv6 is up and coming, but not yet in major use.

Secunia offer the following solution while we wait for a patch: "Use a firewall to block IPv6 packets containing an IPComp header." There are a couple complicated ways to do this on Mac OS X. The first is to go into the Mac OS X CLI (character line interface) and configure IPFW. You can read the man (manual) page of IPFW in the Terminal. The other method is to download WaterRoof HERE, which provides a GUI for IPFW. Neither method is for the faint of heart, and certainly not for an average Mac user. Have fun! :-D

Monday, December 17, 2007

Mac-Security Column for December 2007


[NOTE: This is an article I published in the Syracuse Macintosh User Group (SMUG) monthly newsletter, AppleTree. Anyone is welcome to further publish it wherever they wish as long as the article is not further edited while my name as author and my copyright remain intact. Breaka da rulez and I breaka you head].


Mac Security column
2007-12-16
© Derek Currie

Last month I made a quick mention of Clam as a cross platform freeware anti-malware application. For Mac OS X you can obtain and use it in the form of ClamXav or Leopard Cache Cleaner (which runs on Jaguar, Panther and Tiger as well). This month I wanted to point out a couple more shareware anti-malware programs that may or may not be of interest.

But first let's take a tour through the many security enhancements Apple have provided in the past month:

November 12th Apple released the iPhone and iPod Touch version 1.1.2 update. It addressed an all too familiar problem with maliciously crafted images being able to terminate a running program or being able to run arbitrary code, also known as an infamous buffer overflow. This happens when the memory space designated for an application is overrun with data such that it runs into the next contiguous memory sectors. The resulting data can bomb the program using the offended memory sector, or if the trouncing data is properly designed and executed it could potentially take over your computer.

November 14 Apple released the Mac OS X 10.4.11 update as well as Security Update 2007-008 which is applicable to Mac OS X 10.3.9. The both cover the same security issues. Security repairs were provided for the following parts of Mac OS X:

• AppleRAID
• BIND
• CFFTP
• CFNetwork
• CoreFoundation
• CoreText
• Kerberos
• Kernel (6 fixes)
• Networking (5 fixes)
• NFS
• NSURL
• remote_cmds
• Safari (2 fixes)
• SecurityAgent
• WebCore (9 fixes)
•WebKit (3 fixes)

This update also provides a new security fix version of the Flash Plug-in.

November 14 Apple also released Safari 3 Beta version 3.0.4 for Windows. It patches two vulnerabilities in Safari itself, three vulnerabilities in WebCore and three vulnerabilities in WebKit. The most numerous patches it provides are related to cross-site scripting.

November 15 Apple released the Mac OS X 10.5.1 update, which included three security updates to its firewall. The Leopard firewall has been met with skepticism and disdain. These patches address the most noted problems.

December 13 Apple released QuickTime version 7.3.1 which includes three security updates. Earlier in the month Apple had been slammed by the likes of Secunia and SANS Institute for the continuation of a seemingly unending string of QuickTime security flaws. This update address a few of the problems specifically related to maliciously crafted RTSP movie files, QTL files and the QT Flash media handler. This update is for Mac OS X 10.3.9 on up as well as Windows XP SP2 and Vista.

December 14 Apple released Java 6 for Mac OS X 10.4. Does anyone remember when we were all fed the marketing spin that Java was supposed to the 'safe' programming language that couldn't harm your operating system and hardware? Yeah right, we wish. Surprise! This update covers thirty security flaws in Java for Mac OS X. The fixes prevent the ability of a malicious web page to raid or add to your Keychain (which is an outrageous security flaw) the usual arbitrary code execution and privilege escalation.

In all, these security updates are crucial, many of them patching vulnerabilities that could potentially lead to a hacker taking over your computer. Therefore, as usual, be sure you keep your Mac OS X security updates up-to-date! You can read about all these security updates in detail at:

http://docs.info.apple.com/article.html?artnum=61798


CONCLUSION: Software coding remains a mysterious art that is constantly full of flaws. Microsoft may be the masters at security blunders, but like it or not there are blunders using even the most deliberately secure of contemporary coding methods. In other words, expect more Mac security flaws and perhaps more Mac malware in the future. But also feel secure that Apple are on their toes these days cleaning up Mac OS X security problems.


Now on to a couple more anti-malware programs for Mac OS X. The first is called MacScan, which claims to identify and isolate Mac OS X Trojans, spyware and Tracking cookies. It is a shareware program that costs around $25. When it is downloaded you are provided with a 30 day demo period. The second program is freeware called Zebra Scanner, which claims to identify disguised Trojans. It has not been updated since 2005.

Let's save some time and let me share my conclusion that both of these programs are useless and unnecessary. However, there are a couple caveats to that statement I will provide below if you care to keep reading:

MacScan has been known in the shareware world as 'MacScam' because of the rather high price for its ability to do next to nothing. Example: I used it to scan for the demo Trojan that Zebra Scanner provides. It couldn't find it. I used it to find Tracker Cookies. It found false positives, it failed to find others until I ran it a second time, and when I asked it to remove those it found it did absolutely nothing. I had to remove the Tracker Cookies by hand. And I'm supposed to pay for this privilege?

The one useful thing MacScan does provide is a list of known 'LEGAL' spyware programs for Mac OS X. You can find this list on their website as well. Legal spyware includes keystroke loggers, VNC and remote administration programs that are openly provided to the Mac market. They are typically used in professional network situations where the network administrator or the boss want to keep track of the work being done by their computer clients or employees. You can find a slew of them available for download by searching with the term 'spyware' at VersionTracker.com.

Meanwhile, I tried to find the blacklist MacScan is supposedly using to identify Tracking Cookies, but I failed. Something tells me I can find one on the Internet, so I will be in search of it this coming month and will share it when I find it.

What are Tracking Cookies? They technically are a mini-version of spyware under the guise of website cookies. They watch where you go on the web, store that information, then feed it back to their home site the next time you visit. It is supposed to be a marketing tool that a website can use for choosing what products to advertise to you. Personally, I consider it privacy intrusion. So I enjoy removing tracking cookies and blocking them from being allowed by my browsers.


Last and least we come to Zebra Scanner. Back when it was written there was a scare than hackers were going to attack the Mac with Trojans that were disguised as such benign things as JPEG files and text messages. But a security fix in Mac OS X 10.4 ended that possibility. Therefore, Zebra Scanner became useless. But there is one small possibility you could still get fooled by a malware application in disguise. That would be if you have your Finder set to NOT show file extensions. I am someone who was rather angry that Apple chose to go with file extensions to identify Mac OS X file types as opposed to the file types being embedded in the file's headers. Those stupid 'dot three' extensions on files are so Windows, so Luddite, so retro, so ugly. Apple actually compromised on the issue and still allows header file type identification, but for the purposes of avoiding Trojans, the dopey file extensions actually come in handy. Here is the example Zebra Scanner provide:



Suppose you are sent something that has a folder icon and has the title 'Christmas Icons'. Great, you figure it has nifty Christmas icons inside the folder. But darn, you have the Finder set to NOT show file extensions. So you have no idea that this bogus folder is actually an application with a fake folder icon pasted on top. So you 'open the folder' but actually find you are infecting yourself with the Trojan.


If you think you could be subject to that infection method, then you should use Zebra Scanner. If however you leave your file extensions left ON, then you can't be fooled. That fake folder's name has '.app' as an extension at the end.


So what if some goon physically removes the '.app' extension? It is very easy to do in Mac OS X. Then what you can do is a Get Info on the file before you do anything with it. The operating system will STILL tell you that it is an application. Therefore, don't run it.

Don't bother trying to come up with other crafty ways to fool the operating system. If you fake an application to be a .txt file the OS will attempt to open it ONLY as a .txt file. It will NOT run it as an application. You are safe. What you will get is an error message saying that the text file is unreadable, which makes sense since it is actually an application. This same routine follows if you change the application to any other extension as well.


CONCLUSION: Be wary of anything at all you receive out of the blue and don't absolutely know to be safe. Expect it to be bad news. (1) Have your extensions turned on in the Finder (2) Always do a Get Info on suspicious anything. (3) To be extra-super-safe, only use your Mac inside a standard account, not an administrator's account. This will help prevent Trojans from doing nasty stuff on an adminstrative level. Only your current standard user account can be hurt.

Next month I will hopefully have a source for a Tracking Cookie blacklist. So stay tuned if you are interested. In the meantime you can keep track of my ongoing Mac security news here at:

http://mac-security.blogspot.com

Share and Enjoy,

:-Derek

Saturday, December 8, 2007

Symantec Massive Booboo, Again


I suspect this post will come off as snotty. But the fact is that Symantec have consistently been the #1 purveyor of anti-Mac security FUD since 2005. They pulled another FUD attack just this past month.


As ever, FUD is used as a propaganda tactic in order to frighten people into doing your bidding. Our current USA federal executive branch is using FUD to drive a war machine for the purpose of their special interests, as opposed to the actual interests of the citizens they are supposed to be representing. Their particular FUD phrase is 'The Long War' referring to the non-existant 'war' on terrorism.

What has been Symantec's purpose? They want to sell Norton Anti-Virus to Mac users. Not surprisingly their FUD started precisely at the time when it became blatantly evident that Norton AV was one of the single most buggy applications available for Macintosh. Needless to say, Symantec's efforts so far have been rebuffed. The usual response is that Mac users are deliberately ignorant about security. In actuality I think we can all agree that Mac users will very much become knowledgeable about Mac security at such time as it proves to be of actual importance.

Payback is a bitch. And Symantec pulled quite a booboo this past week. You can read all about it here:

http://www.pcmag.com/article2/0,2704,2229576,00.asp


To quote PC Magazine:

Update: Symantec Screwup Is 'Worse Than Any Virus'
12.06.07
By Chloe Albanesius

A routine update from Symantec Security Response wreaked havoc on a California company's clientele this week when it inadvertently tagged a program produced by Solid Oak Software as a virus and cut off the Internet access of Solid Oak customers.

. . .

Solid Oak customers including schools, libraries and personal accounts, were not provided with a recovery mechanism and subsequently lost Internet access. Solid Oak did not have an exact number of those affected, but it likely numbers in the tens of thousands, according to a spokeswoman.

Customers have had to re-install entire operating systems and software, she said.

. . .

This is the third time in less than a year that Symantec's Norton products have caused severe damage to computers running CYBERsitter software offerings, said Brian Milburn, president of Solid Oak Software, in a statement. "In my opinion, Norton products are worse than any virus I can think of," he said.

"We have thousands of users with no Internet access and all Symantec has done is to provide our mutual customers with a non-functioning support number that tell them to use on-line support," Milburn added. "The problem is even worse because [it's] the holiday season. Users are trying to order gifts on-line and they can't."

. . .

The situation is "embarrassing" for Solid Oak, Solid Oak's spokeswoman said. The company has been forced to pass along to customers instructions from Symantec, but nothing is working as of Thursday, she said. "People are upset," she said.

Solid Oak received an e-mail from Kevin Haley, Symantec's director of product management for Security Response, at 11 a.m. PST Thursday but no further instructions were relayed at the original time of this story's publication, according to Solid Oak.


Happily Symantec issued a solution this Friday.

Personal blether-fest related to the subject:

As I tell everyone, we are still in 'The Stone Age Of Computing.' Software development in particular is remarkably primitive, a PITA, consistently unreliable, and still requires drastic improvements in user-friendliness. Essentially, the software development task, using the crummy tools and coding philosophies we have at this time, is well beyond the comprehension of any one human being. And as usual, once you get into the process of coding by committee, you can break up a project into pieces, but getting the pieces to all be of the same quality and getting them all to work together properly is just about impossible.

A great example to watch right now is the progress of Mac OS X 10.5 Leopard. Undoubtedly it is the best OS on the market. But new bugs are discovered every single day. It clearly is suffering from what is called the '1.0' effect where the first publicly released version of any program is not-ready-for-prime-time. Why this effect happens so consistently is a complicated matter I may discuss some other time. Suffice it to say that it is expected and eventually works itself out. But nothing is perfect.

Much as I love Mac OS X Tiger, even at the 11th revision it still has bugs. Example: Have you noticed that even in 10.4.11 you still have the icons of some of the files in a folder disappear from time to time? It is because of flaws in the Finder. You can find a freeware tool called Refresh Finder to help overcome this nonsense at:

http://www.soderhavet.com/refresh/


CONCLUSION: Every software company consistently makes mistakes. It is part of our times. But it is particularly satisfying, in a mean-spirited kind of way I must admit, when a lying, fear-mongering company like Symantec fall of their face due to their own incompetence and arrogance. Let's hope we all learn from our mistakes and learn to treat each other with more understanding and respect.