<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Michael Gracie &#187; vulnerabilities</title>
	<atom:link href="http://michaelgracie.com/tag/vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://michaelgracie.com</link>
	<description>Clever Tagline Unavailable At Publication Time</description>
	<pubDate>Mon, 01 Dec 2008 20:43:27 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>Apple&#8217;s month it is, but controversy remains</title>
		<link>http://michaelgracie.com/2007/01/07/apples-month-it-is-but-controversy-remains/</link>
		<comments>http://michaelgracie.com/2007/01/07/apples-month-it-is-but-controversy-remains/#comments</comments>
		<pubDate>Sun, 07 Jan 2007 16:31:48 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[Apple]]></category>

		<category><![CDATA[Month of Apple Bugs]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/apples-month-it-is-but-controversy-remains/</guid>
		<description><![CDATA[This is where the whole security by obscurity thing really comes into play&#8230;
MacWorld is starting, and concurrent with it is comes a beautiful step-child - the Month of Apple Bugs.  People are finding bugs in OS X, and others are busy fixing them.  That&#8217;s great, but you can never make everyone happy - [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>This is where the whole security by obscurity thing really comes into play&#8230;</p>
<p>MacWorld is starting, and concurrent with it is comes a beautiful step-child - the <a title="Spamroll: Month of Apple Bugs gets it's first swat" href="http://www.michaelgracie.com/2007/01/02/month-of-apple-bugs-gets-its-first-swat/">Month of Apple Bugs</a>.  People are finding bugs in OS X, and others are busy fixing them.  That&#8217;s great, but you can never make everyone happy - some are <a title="Mac OS X Developers Watch Month of Apple Bugs" href="http://www.eweek.com/article2/0,1759,2079624,00.asp">questioning the concept</a> of telling the world about the security issues before notifying Apple.</p>
<blockquote><p>&#8220;In the long term, this project is making OS X more secure,&#8221; said Gus Mueller, a developer who sells his software through his company Flying Meat. &#8220;However, in the short term, these bugs, once shown, can be used destructively.&#8221;</p></blockquote>
<p>So hackers are going to run out and build new exploits, then co-opt their zombie networks for the purpose of capitalizing?  Is that what someone is suggesting?</p>
<p>First, that process would be like trying to find a needle in a haystack - Apple computers still make up a small percentage of installs worldwide.  Then, you have to target a handful of slightly obscure exploits.  If you&#8217;re the malcreant, you get started, but have to race Landon Fuller &#038; Co. while they are fixing the exploits.  All the while, you are hoping every Apple employee is at MacWorld (i.e nobody at Apple is paying attention to the finds or the fixes).</p>
<p>An unlikely scenario.</p>
<p>Meanwhile, I don&#8217;t hear anyone at Apple bitching about this.  For those in their security department (if they have one), it should be a party.  They&#8217;ve got others doing their job for them!</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2007/01/07/apples-month-it-is-but-controversy-remains/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Lucky 11 vulnerability scanners reviewed</title>
		<link>http://michaelgracie.com/2007/01/02/lucky-11-vulnerability-scanners-reviewed/</link>
		<comments>http://michaelgracie.com/2007/01/02/lucky-11-vulnerability-scanners-reviewed/#comments</comments>
		<pubDate>Tue, 02 Jan 2007 15:57:25 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[scanners]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/lucky-11-vulnerability-scanners-reviewed/</guid>
		<description><![CDATA[Once you run them, you will realize that you have 2 million cross-site scripting vulnerabilities on your site that were supposedly fixed months ago by open-source hackers, and the firewall you just paid three grand for will resemble swiss cheese because your junior sys-admin is still trying to get it configured.
Nevertheless, check out the review. [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>Once you run them, you will realize that you have 2 million cross-site scripting vulnerabilities on your site that were supposedly fixed months ago by open-source hackers, and the firewall you just paid three grand for will resemble swiss cheese because your junior sys-admin is still trying to get it configured.</p>
<p>Nevertheless, check out <a title="AskApache - Vulnerability Scanners Review" href="http://www.askapache.com/2006/security/vulnerability-scanners-review.html">the review</a>. (h/t to Slashdot).</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2007/01/02/lucky-11-vulnerability-scanners-reviewed/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Month of Apple Bugs gets it&#8217;s first swat</title>
		<link>http://michaelgracie.com/2007/01/02/month-of-apple-bugs-gets-its-first-swat/</link>
		<comments>http://michaelgracie.com/2007/01/02/month-of-apple-bugs-gets-its-first-swat/#comments</comments>
		<pubDate>Tue, 02 Jan 2007 14:12:42 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[Apple]]></category>

		<category><![CDATA[Month of Apple Bugs]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/month-of-apple-bugs-gets-its-first-swat/</guid>
		<description><![CDATA[As a result of the &#8220;Month of Apple Bugs&#8221; initiative, the first pest has been found (h/t to Slashdot).  It is a buffer overflow issue that when applied very carefully, could lead to an &#8220;exploitable remote arbitrary code execution condition.&#8221;
I won&#8217;t opine on exactly what &#8220;exploitable remote arbitrary code execution condition&#8221; Mac users might [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>As a result of the &#8220;Month of Apple Bugs&#8221; initiative, the first pest <a title="Apple Fun: MOAB-01-01-2007: Apple Quicktime rtsp URL Handler Stack-based Buffer Overflow" href="http://applefun.blogspot.com/2007/01/moab-01-01-2007-apple-quicktime-rtsp.html">has been found</a> (h/t to Slashdot).  It is a buffer overflow issue that when applied very carefully, could lead to an &#8220;exploitable remote arbitrary code execution condition.&#8221;</p>
<p>I won&#8217;t opine on exactly what &#8220;exploitable remote arbitrary code execution condition&#8221; Mac users might face, because I simply don&#8217;t know (and the find doesn&#8217;t mention any proofs of concept in action).  I&#8217;ll just take their word for it.</p>
<p>UPDATE: Sounds like the bugs <a title="Paper: Apple Options Probe Spotlights Ex-Officials" href="http://www.eweek.com/article2/0,1759,2078250,00.asp">started a while ago</a>.</p>
<p>UPDATE 2:  <a title="Slashdot | Month of Apple Fixes" href="http://apple.slashdot.org/article.pl?sid=07/01/02/2058239&#038;from=rss">Next</a>, please.</p>
<p>UPDATE 3: The quick fix is deemed <a title="security.itworld.com - Apple bug month generates counter-attack" href="http://security.itworld.com/4341/070104appleattack/page_1.html">a counter-attack</a>.  The Month of Apple Bugs is not really an attack, so lets just call all this by an infrequently used term&#8230;.cooperation.</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2007/01/02/month-of-apple-bugs-gets-its-first-swat/feed/</wfw:commentRss>
		</item>
		<item>
		<title>SANS Top 20 Hackers&#8217; Holes</title>
		<link>http://michaelgracie.com/2006/11/20/sans-top-20-hackers-holes/</link>
		<comments>http://michaelgracie.com/2006/11/20/sans-top-20-hackers-holes/#comments</comments>
		<pubDate>Mon, 20 Nov 2006 15:52:43 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/sans-top-20-hackers-holes/</guid>
		<description><![CDATA[SANS has named its top hacker targets for 2006, and surprisingly, Internet Explorer and other Windows components are on the list.
Also included, Mac OS X, including its Safari browser, the image input/output framework, wireless networking, and the ubiquitous &#8220;other.&#8221;  Most of this stuff is either patched with significant speed, or was someone else&#8217;s fault [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>SANS has <a title="SANS names top hacker targets | CNET News.com" href="http://news.com.com/SANS names top hacker targets/2100-7349_3-6135844.html">named its top hacker targets for 2006</a>, and surprisingly, Internet Explorer and other Windows components are on the list.</p>
<p>Also included, Mac OS X, including its Safari browser, the image input/output framework, wireless networking, and the ubiquitous &#8220;other.&#8221;  Most of this stuff is either patched with significant speed, or was someone else&#8217;s fault to begin with (think wireless) - the real risk to OS X is that the resurgence of UNIX-like operating systems will prompt hackers to look for vulnerabilities that will pass over.</p>
<p>As for the Windows stuff, including IE, the Libraries, MS Office, the Services, and configuration issues&#8230;well their numbers are beyond the scope of this post (or my limited attention span, while typing from 10.4.8).</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/11/20/sans-top-20-hackers-holes/feed/</wfw:commentRss>
		</item>
		<item>
		<title>US-CERT needs to learn how to count</title>
		<link>http://michaelgracie.com/2006/01/05/us-cert-needs-to-learn-how-to-count/</link>
		<comments>http://michaelgracie.com/2006/01/05/us-cert-needs-to-learn-how-to-count/#comments</comments>
		<pubDate>Thu, 05 Jan 2006 14:34:16 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[US-CERT]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/us-cert-needs-to-learn-how-to-count/</guid>
		<description><![CDATA[And people writing internet news need to pay attention to details.
In the last twelve hours, I have noted roughly fifty online articles touting the latest US-CERT Security Bulletin, and how UNIX/Linuxes have three times as many vulnerabilities as Windows.
Pay attention, and do your homework!  There are a number of popular flavors of UNIX, including [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>And people writing internet news need to pay attention to details.</p>
<p>In the last twelve hours, I have noted roughly fifty online articles touting the <a title="US-CERT Cyber Security Bulletin SB2005 -- Cyber Security Bulletin 2005 Summary" href="http://www.us-cert.gov/cas/bulletins/SB2005.html" target="">latest US-CERT Security Bulletin</a>, and how UNIX/Linuxes have three times as many vulnerabilities as Windows.</p>
<p>Pay attention, and do your homework!  There are a number of popular flavors of UNIX, including HP-UX, Solaris, and AIX.  On the Linux front, there <a title="DistroWatch.com: Put the fun back into computing. Use Linux, BSD." href="http://distrowatch.com/" target="">are at least a hundred different flavors</a>.  At last count, Microsoft Windows basically came in TWO flavors, the first consisting of Windows 95, 98, and Me, and the second being NT, 2000, and XP.  So, UNIX/Linux variants outnumber Windows by a factor of more than 100 to 1, making these upfront statements more than a bit suspect.</p>
<p>If we dig a little deeper into the government sponsored list, we note that it also includes every application generally bundled with *NIX systems, including things like Apache Web Server, the MySQL database, and even the Ethereal Packet Analyzer.  Those bundled items&#8217; open source nature presumes that vulnerabilites will get reported promptly and publically.  But those three, and many others ARE ALSO AVAILABLE FOR WINDOWS, yet no vulnerabilities related to them are in the Windows list.  Is US-CERT trying to say that vulnerabilities don&#8217;t exist for those products on the Windows platform, or are said issues just not being reported because they are fairly obscure?  Additionally, I noted on the Windows list that SQL Server 2000 occupied a single line, with a link to a statement suggesting <cite>&#8220;multiple vulnerabilities&#8221;</cite> and a link to Microsoft&#8217;s patch download area.  I don&#8217;t get it.</p>
<p>Someone needs to do a more thorough analysis of this list, otherwise I am considering its headlined conclusions nothing more than general bunk.</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/01/05/us-cert-needs-to-learn-how-to-count/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
