MacNN | exploit News http://www.macnn.com/ MacNN is the leading source for news about Apple and the Mac industry. It offers news, reviews, discussion, tips, troubleshooting, links, and reviews every day. The best place for Mac News. Period. en-us exploit, Latest News, Headlines, Stories; http://images.macnn.com/images/macnn-logo-bw.gif http://www.macnn.com/ New Mac OS X Trojan horse identified http://www.macnn.com/articles/08/06/20/mac.os.x.trojan.found/ <img align='left' src='http://images.macnn.com/macnn/news/0806/trojan.jpg' border='0' width='176' height='120' />Multiple variants of a new 'Trojan Horse', designed to allow a malicious user complete remote access to a Mac OS X system have been discovered in the wild earlier this week according to makers of Mac anti-spyware and anti-virus solutions SecureMac. Dubbed 'Applescript.THT Trojan' and disguised as an application bundle called 'AStht_v06' (3.1MB in size), the malware seemingly originated, and is dis... http://www.macnn.com/articles/08/06/20/mac.os.x.trojan.found/ Fri, 20 Jun 2008 12:40:00 GMT Anti-hacker features added to QuickTime http://www.macnn.com/articles/08/04/08/quicktime.security/ <img align='left' src='http://images.macnn.com/macnn/news/0804/2-updates-sm.jpg' border='0' width='176' height='120' />Apple's recent QuickTime 7.4.5 release includes exploit prevention mechanisms designed to block attacks from hackers, according to a recent report from eWeek. QuickTime for Windows Vista now features ASLR (address space layout randomization), technology that randomly arranges key data addresses to prevent developers of malware from predicting targets. ASLR is already used by Mac OS X Leopard to re... http://www.macnn.com/articles/08/04/08/quicktime.security/ Tue, 08 Apr 2008 18:15:00 GMT Code crashes Safari in iPhone 1.1.4, fixed for Mac/PC http://www.macnn.com/articles/08/03/19/code.crashes.iphone.114/ <img align='left' src='http://images.macnn.com/macnn/news/0803/18-vulnerability-sm.jpg' border='0' width='176' height='120' />A new exploit has surfaced for the iPhone's Safari browser that, while drawing parallels to an earlier issue, requires no user input to function. According to iPhone World, the vulnerability is triggered by previously conceived code that has been refined in the above manner. The issue affects firmware version 1.1.4 iPhones, and presumably previous versions. Safari on the Mac and PC were also affec... http://www.macnn.com/articles/08/03/19/code.crashes.iphone.114/ Wed, 19 Mar 2008 04:30:00 GMT Hacker unlocks iPhone 1.1.2 via new exploit http://www.macnn.com/articles/08/02/08/new.iphone.112.unlock/ <img align='left' src='http://images.macnn.com/macnn/news/0801/unl_080208_unlockedsm.jpg' border='0' width='176' height='120' />An iPhone hacker has discovered a new way to unlock Apple's iPhone firmware version 1.1.2 without the need to downgrade to a prior firmware revision and then re-upgrade after unlocking the device. The unlock technique relies on a bug that allows hackers to erase the contents of memory within a range of specific addresses, coupled with a second bug that allows users to copy data before validation o... http://www.macnn.com/articles/08/02/08/new.iphone.112.unlock/ Fri, 08 Feb 2008 17:10:00 GMT iPhone denial-of-service bug surfaces http://www.macnn.com/articles/08/02/07/iphone.dos.surfaces/ <img align='left' src='http://images.macnn.com/macnn/news/0801/app_080207_iphonesafsm.jpg' border='0' width='176' height='120' />An exploit for Apple's iPhone has surfaced that can crash the device when unsuspecting users visit a maliciously crafted Web page. SecurityFocus notes that successful attacks cause a kernel panic, crashing the iPhone which could ultimately lead to remote code execution. The firm states that iPhone firmware version 1.1.2 and 1.1.3 are both affected, and suggest that other versions may also be vulne... http://www.macnn.com/articles/08/02/07/iphone.dos.surfaces/ Thu, 07 Feb 2008 16:25:00 GMT QuickTime exploit circulates on Web http://www.macnn.com/articles/07/11/30/quicktime.72.exploit/ <img align='left' src='http://images.macnn.com/macnn/news/0711/29-symantec-sm.jpg' border='0' width='176' height='120' />Symantec has notified DeepSight customers that a bug in QuickTime's Real Time Streaming protocol can lead towards the execution of malicious code on any computer running QuickTime 7.2 or later, and that a working proof-of-concept set of code being circulated on the internet. Computerworld reports that the bug was originally posted on milw0rm.com, and that the exploit code had worked when tested ag... http://www.macnn.com/articles/07/11/30/quicktime.72.exploit/ Fri, 30 Nov 2007 06:20:00 GMT