<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hawk Wings &#187; exploits</title>
	<atom:link href="http://www.hawkwings.net/tag/exploits/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hawkwings.net</link>
	<description>Tips and add-ons to make Apple Mail / Mail.app even better</description>
	<lastBuildDate>Tue, 26 Jul 2011 07:44:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>More security flaws in Mac OSX</title>
		<link>http://www.hawkwings.net/2006/04/22/more-security-flaws-in-mac-osx/</link>
		<comments>http://www.hawkwings.net/2006/04/22/more-security-flaws-in-mac-osx/#comments</comments>
		<pubDate>Sat, 22 Apr 2006 13:38:42 +0000</pubDate>
		<dc:creator>Tim Gaden</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Apple Mail]]></category>
		<category><![CDATA[attachments]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[images]]></category>
		<category><![CDATA[mac osx]]></category>
		<category><![CDATA[mail.app]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[zip files]]></category>

		<guid isPermaLink="false">http://www.hawkwings.net/2006/04/22/more-security-flaws-in-mac-osx/</guid>
		<description><![CDATA[Security Researcher Tom Ferris has found another seven security flaws in Mac OSX.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.hawkwings.net/wp-content/uploads/2006/04/wp-images/macattack-1.jpg" height="105" width="110" border="0" align="right" hspace="10" vspace="0" alt="macattack" title="macattack" />Californian Security Researcher Tom Ferris <a href="http://www.security-protocols.com/index.php">has found another seven security flaws</a> <img src="http://www.hawkwings.net/images/extlink.jpg"/> in Mac OSX.</p>
<p>They mostly involve the handling of images and decompression of zip files. </p>
<p>He expects that they will be addressed in the next Apple security update. </p>
<p>A St Louis Post-Dispatch article on the flaws <a href="http://www.stltoday.com/blogs/business-talking-tech/2006/04/trouble-visits-mac-users-again/">urges caution</a> <img src="http://www.hawkwings.net/images/extlink.jpg"/>, &#8220;Avoid opening strange or unusual e-mail attachments, and beware of Web links embedded in unsolicited Web correspondence.&#8221;</p>
<p>As many people <a href="http://www.hawkwings.net/2006/02/23/mac-attack-snack-pack/">pointed out</a> during the excitement of the last round of security flaws, this has been pretty sensible advice since, like, forever.<tags>security, exploits, zip files, mac osx, images, attachments, mail.app, apple mail</tags>  <strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.hawkwings.net/2006/02/23/mac-attack-snack-pack/" rel="bookmark" title="23 February 2006, 12:06 am">Mac Attack Snack Pack</a></li>
<li><a href="http://www.hawkwings.net/2007/01/09/toggle-image-and-attachment-display-in-mailapp/" rel="bookmark" title="9 January 2007, 12:20 am">Toggle image and attachment display in Mail.app</a></li>
<li><a href="http://www.hawkwings.net/2006/02/25/mailapp-too-dangerous-to-use/" rel="bookmark" title="25 February 2006, 7:51 am">Mail.app too dangerous to use?</a></li>
<li><a href="http://www.hawkwings.net/2006/08/29/omic-a-plugin-to-extract-winmaildat-files/" rel="bookmark" title="29 August 2006, 11:07 pm">OMiC: A plugin to extract winmail.dat files</a></li>
<li><a href="http://www.hawkwings.net/2006/06/04/quickly-saving-attachments-in-mailapp/" rel="bookmark" title="4 June 2006, 9:20 pm">Quickly saving attachments in Mail.app</a></li>
</ul>
<p><!-- Similar Posts took 11.421 ms --></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hawkwings.net/2006/04/22/more-security-flaws-in-mac-osx/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Mac Attack Snack Pack</title>
		<link>http://www.hawkwings.net/2006/02/23/mac-attack-snack-pack/</link>
		<comments>http://www.hawkwings.net/2006/02/23/mac-attack-snack-pack/#comments</comments>
		<pubDate>Wed, 22 Feb 2006 13:06:25 +0000</pubDate>
		<dc:creator>Tim Gaden</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Apple Mail]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[scripts]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Trojan horse]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.hawkwings.net/2006/02/23/mac-attack-snack-pack/</guid>
		<description><![CDATA[A tasty selection of links to a variety of takes on this week's security excitement in the Mac world.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.hawkwings.net/wp-content/wp-images/macattack.jpg" height="105" width="110" border="0" align="right" hspace="10" vspace="0" alt="macattack" title="macattack" />A tasty assortment of links on the recent security excitment, which also <a href="http://www.hawkwings.net/2006/02/22/security-flaw-with-scripts-in-mailapp/">affects Mail.app</a>.</p>
<p><b>Well-done</b></p>
<p>Secunia <a href="http://secunia.com/advisories/18963/">rates the Safari vulnerability</a> <img src="http://www.hawkwings.net/images/extlink.jpg"/> as &#8220;extremely critical&#8221;, a rating the company gives when &#8220;successful exploitation does not normally require any interaction and exploits are in the wild.&#8221; Secunia is a provider of IT-security services. </p>
<p>Anti-virus company Intego has analysed the Leap-A (&#8220;Oompa-Loompa&#8221;) Trojan horse. After exhaustive testing, <a href="http://www.it-observer.com/news/5753/the_real_threat_mac_os_x_trojan/">the company reported</a> <img src="http://www.hawkwings.net/images/extlink.jpg"/> that &#8220;the best protection against this Trojan horse and its variants is Intego VirusBarrier X4&#8243;. CEO Laurent Marteau says, &#8220;it is clear that antivirus software on a Macintosh computer is as essential as wearing a seat belt in a car&#8221;. </p>
<p><b>Medium</b></p>
<p>ZDNet Australia <a href="http://zdnet.com.au/news/security/soa/Mac_community_must_wake_up_to_security/0,2000061744,39210762,00.htm">carries an interview</a> <img src="http://www.hawkwings.net/images/extlink.jpg"/> with Paul Ducklin, Sophos&#8217; Asia-Pacific head of technology. &#8221; &#8220;There is not a clear and present danger like there is with Windows but the same risks apply&#8221;, he says. </p>
<p>Eric Bangeman on Ars Technica <a href="http://arstechnica.com/news.ars/post/20060221-6225.html">thinks</a> <img src="http://www.hawkwings.net/images/extlink.jpg"/> that &#8220;the malware may be less destructive, more difficult to find, and less prevalent than on other platforms. But it&#8217;s there, and it&#8217;s not going to go away.&#8221;</p>
<p><b>Medium-rare</b></p>
<p>At Wired, <a href="http://www.wired.com/news/columns/0,70257-0.html">Leander Kahney</a> <img src="http://www.hawkwings.net/images/extlink.jpg"/> is keeping his cool: &#8220;These Mac security holes are a storm in a teacup,&#8221; he says.</p>
<p><a href="http://daringfireball.net/2006/02/safari shell_script_exploit">The Daring Fireball</a> <img src="http://www.hawkwings.net/images/extlink.jpg"/> puts it all in perspective. John Gruber writes: &#8220;It boils down to this: you can&#8217;t safely double-click files from untrusted sources, and you never could. This is no different today on Mac OS X 10.4 than it was a decade ago on Mac OS 8 and 9.&#8221;</p>
<p><a href="http://www.stephan-schwab.com/2006/02/21/1140543254514.html">Stephan Schwab</a> <img src="http://www.hawkwings.net/images/extlink.jpg"/> is also fairly relaxed: &#8220;Of course this unwanted interference is annoying and it&#8217;s far better to let the user decide when to execute something, but it&#8217;s not a security threat of any magnitude.&#8221;<tags>Trojan horse, exploits, virus, mac OS X, security, apple, safari, scripts</tags><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.hawkwings.net/2006/04/22/more-security-flaws-in-mac-osx/" rel="bookmark" title="22 April 2006, 11:38 pm">More security flaws in Mac OSX</a></li>
<li><a href="http://www.hawkwings.net/2006/01/24/will-windows-vista-be-apples-trojan-horse/" rel="bookmark" title="24 January 2006, 12:31 am">Will Windows Vista be Apple&#8217;s Trojan Horse?</a></li>
<li><a href="http://www.hawkwings.net/2006/03/02/mail-safari-patched/" rel="bookmark" title="2 March 2006, 9:05 am">Mail and Safari patched</a></li>
<li><a href="http://www.hawkwings.net/2006/11/27/image-spam-powered-by-russian-bot-net/" rel="bookmark" title="27 November 2006, 11:20 pm">Image spam surge powered by Russian bot-net</a></li>
<li><a href="http://www.hawkwings.net/2006/10/24/spam-tops-80-of-all-email/" rel="bookmark" title="24 October 2006, 8:21 pm">Spam tops 80% of all email</a></li>
</ul>
<p><!-- Similar Posts took 39.778 ms --></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hawkwings.net/2006/02/23/mac-attack-snack-pack/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

