<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
>

<channel>
	<title>SecuraBit &#187; apple</title>
	<atom:link href="http://www.securabit.com/tag/apple/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securabit.com</link>
	<description>SecuraBit Before It Bytes!</description>
	<lastBuildDate>Sun, 05 Sep 2010 23:12:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
<!-- podcast_generator="Blubrry PowerPress/1.0.9" mode="advanced" entry="normal" -->
	<itunes:summary>This is a Computer Security podcast brought to you by the guys at SecuraBit.com.  Please visit our web site at http://www.securabit.com or send questions/comments to feedback@securabit.com

Thanks for listening!</itunes:summary>
	<itunes:author>SecuraBit</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://staging.securabit.com/itunessecurabit.jpg" />
	<itunes:owner>
		<itunes:name>SecuraBit</itunes:name>
		<itunes:email>feedback@securabit.com</itunes:email>
	</itunes:owner>
	<managingEditor>feedback@securabit.com (SecuraBit)</managingEditor>
	<copyright>SecuraBit LLC</copyright>
	<itunes:subtitle>SecuraBit Before It Bytes!</itunes:subtitle>
	<itunes:keywords>security, forensics, hacking, infosec, securabit, podcast, sans, drinking, beer</itunes:keywords>
	<image>
		<title>SecuraBit &#187; apple</title>
		<url>http://securabit.com/securabitrsssmall.jpg</url>
		<link>http://www.securabit.com</link>
	</image>
	<itunes:category text="Technology">
		<itunes:category text="Tech News" />
		<itunes:category text="Software How-To" />
	</itunes:category>
		<item>
		<title>SecuraBit Episode 63:  Walking to the Waffle House with Andy Willingham</title>
		<link>http://www.securabit.com/2010/08/19/securabit-episode-63-walking-to-the-waffle-house-with-andy-willingham/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=securabit-episode-63-walking-to-the-waffle-house-with-andy-willingham</link>
		<comments>http://www.securabit.com/2010/08/19/securabit-episode-63-walking-to-the-waffle-house-with-andy-willingham/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 15:06:08 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[SecuraBits]]></category>
		<category><![CDATA[Show Releases]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[BlackHat]]></category>
		<category><![CDATA[BSides]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[hospitals]]></category>
		<category><![CDATA[net neutrality]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[phreaknic]]></category>
		<category><![CDATA[securabit]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[vxworks]]></category>

		<guid isPermaLink="false">http://www.securabit.com/?p=1640</guid>
		<description><![CDATA[SecuraBit Episode 63:  Walking to the Waffle House with Andy Willingham August 11, 2010 Hosts: Anthony Gartner – @anthonygartner http://anthonygartner.com Chris Gerling  – @chrisgerling Christopher Mills – @thechrisam Jason Mueller – @securabit_jay Andrew Borel –  @andrew_secbit Guests: Andy Willingham (Southern Fried Security Podcast) &#8211; @andywillingham http://www.andyitguy.com/blog/ General topics: DEFCON/BLACKHAT/BSides Recap &#8211;Chris’s experience this year, and [...]]]></description>
			<content:encoded><![CDATA[<div>SecuraBit Episode 63:  Walking to the Waffle House with Andy Willingham</div>
<div>August 11, 2010</div>
<div><img src="https://lh6.googleusercontent.com/fGThjmal1j5x-e-9GLQyNnB-PCZ-0-7A6u_DpRc8CSGqqbg8XgjFuzpCQCcVy8zBW7d8uYAe4JXnIIScmQYUnyY1-1B79utVzsmXtxqXFp98bqRyag" alt="" width="500px;" height="375px;" /></div>
<div>Hosts:<br />
Anthony Gartner – @anthonygartner<a href="http://anthonygartner.com/"> http://anthonygartner.com</a><br />
Chris Gerling  – @chrisgerling<br />
Christopher Mills – @thechrisam<br />
Jason Mueller – @securabit_jay<br />
Andrew Borel –  @andrew_secbit</p>
<p>Guests:<br />
Andy Willingham (Southern Fried Security Podcast) &#8211; @andywillingham <a href="http://www.andyitguy.com/blog/">http://www.andyitguy.com/blog/</a></p>
<p>General topics:<br />
DEFCON/BLACKHAT/BSides Recap<br />
&#8211;Chris’s experience this year, and a review of the medical facilities in Las Vegas<br />
&#8211;General entertaining banter</p>
<p><a href="http://blog.metasploit.com/2010/08/vxworks-vulnerabilities.html">Shiny Old VxWorks Vulnerabilities</a><br />
<a href="http://blog.metasploit.com/2010/08/vxworks-vulnerabilities.html">http://blog.metasploit.com/2010/08/vxworks-vulnerabilities.html</a></p>
<p>Facebook name extraction based on email/wrong password<br />
<a href="http://seclists.org/fulldisclosure/2010/Aug/130">http://seclists.org/fulldisclosure/2010/Aug/130</a></p>
<p>Apple Fixes PDF Vunerability that allowed webbased Jail Break.<br />
iOS 4.0.2 Software Update http://support.apple.com/kb/DL1061</p>
<p>Interview with Andy Willingham<br />
ShmooCon 2011 Dates Announced<br />
<a href="http://tinyurl.com/29nzc46">http://tinyurl.com/29nzc46</a></p>
</div>
<div>Microsoft drops the patch bomb<br />
<a href="http://www.securabit.com/2010/08/10/microsoft-drops-the-patch-bomb/">http://www.securabit.com/2010/08/10/microsoft-drops-the-patch-bomb/</a></p>
<p>Andriod Malware and Unexpected Features<br />
<a href="http://crave.cnet.co.uk/mobiles/android-gets-its-first-texting-malware-50000303/">http://crave.cnet.co.uk/mobiles/android-gets-its-first-texting-malware-50000303/</a></p>
<p>Free Android antivirus clocks up 2.5m downloads<br />
<a href="http://www.theregister.co.uk/2010/08/11/free_android_security_app/">http://www.theregister.co.uk/2010/08/11/free_android_security_app/</a></p>
<p><a href="http://www.eff.org/deeplinks/2010/08/google-verizon-netneutrality">A Review of Verizon and Google&#8217;s Net Neutrality Proposal</a><br />
<a href="http://www.eff.org/deeplinks/2010/08/google-verizon-netneutrality">http://www.eff.org/deeplinks/2010/08/google-verizon-netneutrality</a></p>
<p>Upcoming events<br />
South Florida ISSA’s Hack the flag and chili cook-off  Saturday August 14, 2010 from 12:00pm &#8211; 5:00pm<br />
<a href="http://sfissa.org/index.php/sfissa-mm-events/htf-main/85-hack-the-flag-2010">http://sfissa.org/index.php/sfissa-mm-events/htf-main/85-hack-the-flag-2010</a><br />
Hacker Halted<a href="http://www.hackerhalted.com/"> http://www.hackerhalted.com/</a> Tim Is speaking October 14th<br />
Louisivlle Infosec 10/7. <a href="http://www.louisvilleinfosec.com/">http://www.louisvilleinfosec.com/</a><br />
Atlanta B-Sides 10/8. <a href="http://www.securitybsides.com/BSidesAtlanta">http://www.securitybsides.com/BSidesAtlanta</a><br />
HacKid &#8211; <a href="http://www.hackid.org/">http://www.hackid.org/</a> 10/9-10/10<br />
Phreaknic 10/15. <a href="http://www.phreaknic.info/pn14/">http://www.phreaknic.info/pn14/</a></p>
<p>Links:</p>
</div>
<div>http://www.securabit.com</div>
<div>Chat with us on IRC at irc.freenode.net #securabit<br />
iTunes Podcast &#8211; <a href="http://itunes.apple.com/us/podcast/securabit/id280048405">http://itunes.apple.com/us/podcast/securabit/id280048405</a><br />
iPhone App Now Available &#8211; <a href="http://itunes.apple.com/us/app/securabit-mobile/id382484512?mt=8">http://itunes.apple.com/us/app/securabit-mobile/id382484512?mt=8</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.securabit.com/2010/08/19/securabit-episode-63-walking-to-the-waffle-house-with-andy-willingham/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://traffic.libsyn.com/securabit/SecuraBit_EP63.mp3" length="27555991" type="audio/mpeg" />
			<itunes:keywords>android,antivirus,apple,BlackHat,BSides,defcon,hospitals,net neutrality,patches,phreaknic,securabit,security</itunes:keywords>
		<itunes:subtitle>SecuraBit Episode 63:  Walking to the Waffle House with Andy Willingham August 11, 2010 - Hosts: Anthony Gartner – @anthonygartner http://anthonygartner.com Chris Gerling  – @chrisgerling Christopher Mills – @thechrisam Jason Mueller – @securabit_jay A...</itunes:subtitle>
		<itunes:summary>SecuraBit Episode 63:  Walking to the Waffle House with Andy Willingham
August 11, 2010

Hosts:
Anthony Gartner – @anthonygartner http://anthonygartner.com
Chris Gerling  – @chrisgerling
Christopher Mills – @thechrisam
Jason Mueller – @securabit_jay
Andrew Borel –  @andrew_secbit

Guests:
Andy Willingham (Southern Fried Security Podcast) - @andywillingham http://www.andyitguy.com/blog/

General topics:
DEFCON/BLACKHAT/BSides Recap
--Chris’s experience this year, and a review of the medical facilities in Las Vegas
--General entertaining banter

Shiny Old VxWorks Vulnerabilities
http://blog.metasploit.com/2010/08/vxworks-vulnerabilities.html

Facebook name extraction based on email/wrong password
http://seclists.org/fulldisclosure/2010/Aug/130

Apple Fixes PDF Vunerability that allowed webbased Jail Break.
iOS 4.0.2 Software Update http://support.apple.com/kb/DL1061

Interview with Andy Willingham
ShmooCon 2011 Dates Announced
http://tinyurl.com/29nzc46


Microsoft drops the patch bomb
http://www.securabit.com/2010/08/10/microsoft-drops-the-patch-bomb/

Andriod Malware and Unexpected Features
http://crave.cnet.co.uk/mobiles/android-gets-its-first-texting-malware-50000303/

Free Android antivirus clocks up 2.5m downloads
http://www.theregister.co.uk/2010/08/11/free_android_security_app/

A Review of Verizon and Google&#039;s Net Neutrality Proposal
http://www.eff.org/deeplinks/2010/08/google-verizon-netneutrality

Upcoming events
South Florida ISSA’s Hack the flag and chili cook-off  Saturday August 14, 2010 from 12:00pm - 5:00pm
http://sfissa.org/index.php/sfissa-mm-events/htf-main/85-hack-the-flag-2010
Hacker Halted http://www.hackerhalted.com/ Tim Is speaking October 14th
Louisivlle Infosec 10/7. http://www.louisvilleinfosec.com/
Atlanta B-Sides 10/8. http://www.securitybsides.com/BSidesAtlanta
HacKid - http://www.hackid.org/ 10/9-10/10
Phreaknic 10/15. http://www.phreaknic.info/pn14/

Links:


http://www.securabit.com
Chat with us on IRC at irc.freenode.net #securabit
iTunes Podcast - http://itunes.apple.com/us/podcast/securabit/id280048405
iPhone App Now Available - http://itunes.apple.com/us/app/securabit-mobile/id382484512?mt=8</itunes:summary>
		<itunes:author>SecuraBit</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:duration>57:21</itunes:duration>
	</item>
		<item>
		<title>Vulnerability Roundup</title>
		<link>http://www.securabit.com/2010/03/15/vulnerability-roundup-8/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=vulnerability-roundup-8</link>
		<comments>http://www.securabit.com/2010/03/15/vulnerability-roundup-8/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 12:02:42 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Guest Blogs]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[BIND]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[openssl]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[typo3]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://www.securabit.com/?p=1327</guid>
		<description><![CDATA[Well, it isn&#8217;t Patch Tuesday yet, but that doesn&#8217;t mean there isn&#8217;t Microsoft news.  A new 0-day has been found which exploits the help system in IE and older versions of windows (2000, XP, 2003).  I&#8217;ve included a few links with information about the vulnerability and mitigation steps.  It appears a patch for this (and [...]]]></description>
			<content:encoded><![CDATA[<p>Well, it isn&#8217;t Patch Tuesday yet, but that doesn&#8217;t mean there isn&#8217;t  Microsoft news.  A new 0-day has been found which exploits the help  system in IE and older versions of windows (2000, XP, 2003).  I&#8217;ve  included a few links with information about the vulnerability and  mitigation steps.  It appears a patch for this (and other known  vulnerabilities) will not be included in the Microsoft release on  Tuesday, which will include two bulletins, one for Office, and one for  windows, which cover 8 vulnerabilities in total.</p>
<p>Cisco has also  released three advisories for vulnerabilities in three of their  products.  Patches are now available for the Unified Communications  Manager, Digital Media Manager and the Digital Media Player Remote  display.</p>
<p>An interesting hardware/software vulnerability has been  released for OpenSSL which could allow an attacker to deduce at least  parts of the private key.  The technique used to exploit this weakness  doesn&#8217;t seem very practical for attacking a full size system, but could  be practical against embedded devices.</p>
<p>A new release of the TYPO3  Core CMS system has been released to cover a few vulnerabilities (XSS,  information disclosure).  Other Open Source projects, PHP and BIND have  also been updated with security fixes.</p>
<p>The Zero Day Initiative also  has some upcoming advisories for Apple&#8217;s Safari browser, which may mean  updates from Apple.  The ZDI has rated these as &#8220;High&#8221; severity.</p>
<p>Last,  but never least, VMWare has released and advisory for some of their  products, which includes another large list of CVEs covered.  These  updates include a long list of third party updates for packages in ESX.</p>
<ul>
<li>Microsoft: <a href="http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=10#widely4">IE Help Code Execution Vulnerability</a></li>
<li>Microsoft: <a href="http://blogs.technet.com/srd/archive/2010/03/01/help-keypress-vulnerability-in-vbscript-enabling-remote-code-execution.aspx">IE Help Code Execution Vulnerability (MS Security Research  and Defense blog)</a></li>
<li>Microsoft: <a href="http://blogs.technet.com/msrc/archive/2010/03/04/march-2010-bulletin-release-advance-notification.aspx">March 2010 Patch Tuesday Advanced Notification</a></li>
<li>Microsoft: <a href="http://www.h-online.com/security/news/item/Several-known-vulnerabilities-to-remain-unpatched-on-forthcoming-Microsoft-patch-day-947191.html">Several known vulnerabilities to remain unpatched on forthcoming  Microsoft patch day</a></li>
<li>Cisco: <a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b924.shtml">Unified Communications Manager Denial of Service Vulnerabilities</a></li>
<li>Cisco: <a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b923.shtml">Multiple Vulnerabilities in Cisco Digital Media Manager</a></li>
<li>Cisco: <a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b925.shtml">Digital Media Player Remote Display Unauthorized Content  Injection Vulnerability</a></li>
<li>OpenSSL: <a href="http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/">Private key disclosure vulnerability</a></li>
<li>TYPO3: <a href="http://www.h-online.com/security/news/item/Security-update-for-TYPO3-released-940683.html">Security update released</a></li>
<li>ISC: <a href="http://www.isc.org/files/release-notes/962.html">BIND 9.6.2 released</a></li>
<li>PHP: <a href="http://www.php.net/ChangeLog-5.php#5.2.13">PHP 5.2.13 released</a></li>
<li>Safari: <a href="http://threatpost.com/en_us/blogs/hacker-report-high-risk-flaws-safari-browser-030110">Flaws in Safari Browser</a></li>
<li>VMWare: <a href="http://lists.vmware.com/pipermail/security-announce/2010/000082.html">Multiple ESX Service Console and vMA third party  updates</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.securabit.com/2010/03/15/vulnerability-roundup-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability Roundup</title>
		<link>http://www.securabit.com/2010/02/04/vulnerability-roundup-4/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=vulnerability-roundup-4</link>
		<comments>http://www.securabit.com/2010/02/04/vulnerability-roundup-4/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 17:58:18 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Guest Blogs]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[bugzilla]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[squid]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.securabit.com/?p=1234</guid>
		<description><![CDATA[Another week, another Adobe advisory.  This time, it&#8217;s not reader, but ColdFusion 9 which shipped with a service someone forgot to lock down to the localhost which would allow an attacker to view system information as well as mess with search indexes. Two advisories from Cisco as well this week, covering two different products and [...]]]></description>
			<content:encoded><![CDATA[<p>Another week, another Adobe advisory.  This time, it&#8217;s not reader, but  ColdFusion 9 which shipped with a service someone forgot to lock down to the localhost which would  allow an attacker to view system information as well as mess with search  indexes.</p>
<p>Two  advisories from Cisco as well this week, covering two different products and a few different  vulnerabilities (XSS, SQLi, and escalation of privilege among them).  Updates  are also available for the iPhone OS for iPhones and iPod Touch devices  which resolve vulnerabilities in different aspects of the OS.  In many  cases visiting or viewing malicious content could cause overflows, which  may allow for code execution.  An update for VMWare&#8217;s vCenter with more than 50 CVE&#8217;s covered, is also listed.</p>
<p>Some Open Source applications are also  listed, one of the interesting ones is the e107 CMS, which was found to have a backdoor which was later used to  compromise the project&#8217;s site before they applied their own patch (more  details on that <a href="http://e107.org/news.php?item.857.1">here</a>).</p>
<ul>
<li>Adobe: <a href="http://www.petefreitag.com/item/738.cfm">Information Disclosure in ColdFusion 9</a></li>
<li>Cisco Systems: <a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml">Multiple  Vulnerabilities in Cisco Unified MeetingPlace</a></li>
<li>Cisco Systems: <a href="http://isc.sans.org/diary.html?storyid=8140">Cisco Secure Desktop Remote  Cross-Site Scripting  Vulnerability</a></li>
<li>Apple: <a href="http://support.apple.com/kb/HT4013">Multiple Vulnerabilities in iPhone OS</a></li>
<li>VMWare: <a href="http://lists.vmware.com/pipermail/security-announce/2010/000078.html">VMware  vCenter update release addresses multiple security issues  in  Java JRE</a></li>
<li>Lighttpd: <a href="http://www.lighttpd.net/2010/2/1/security-announce-slow-request-dos-oom-attack">slow request  DoS/OOM attack</a></li>
<li>Squid: <a href="http://www.squid-cache.org/Advisories/SQUID-2010_1.txt">DoS issue in DNS handling</a></li>
<li>Bugzilla: <a href="http://www.bugzilla.org/security/3.0.10/">Security  Advisory for Bugzilla 3.0.10, 3.2.5, 3.4.4, and 3.5.2</a></li>
<li>e107 CMS: <a href="http://osvdb.org/show/osvdb/62016">Admin Authentication Backdoor</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.securabit.com/2010/02/04/vulnerability-roundup-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
