Saturday, February 16
Toshiba to give up on HD DVD
Money Quote: "TOKYO (Reuters) - Toshiba Corp is planning to give up on its HD DVD format for high definition DVDs, conceding defeat to the competing Blu-Ray technology backed by Sony Corp, a company source said on Saturday."
Glad I went the Blu-Ray route.
Friday, February 15
Google Calendar and iCal Syncing
So I made a calendar in Google Calendar under my wife's Google account and tied the Blackberry to that.
Now I had to get her iCal (where she presently has all her events) to be able to sync with her Google Calendar. Here is the tricky part. You can read and subscribe to a Google Calendar, even setting permissions, per user, but you can't write to a Google Calendar (you can't use webdav from iCal to publish to Google Calendar. That sucks. (Hey Google, fix this, I know a couple of you read this blog. I have logs, I have logs...)
So I found this app called SpanningSync which syncs your Google Calendar and you iCal (both ways). Which is essentially the solution. Only problem with this solution that I see is that you have to pay for the app. I mean, I don't mind paying for software, I think coders should get paid too, but 65 bucks? It's a tad bit much. If it were, say 29 bucks for lifetime usage, then that would be the way to go. Anyway, I hope this helps you all.
Mossberg previews Lenovo's 'Air-killer' X300
So let's take a look. This thing has 3 USB ports (as opposed to the MacBook Air's 1), it has a DVD Drive, (Air doesn't), has Wifi, and an optional 3G or GPS receiver, a removable battery (air doesn't -- well, easily) and not one, but TWO mouse pointing devices.
So there are pros and cons.
Lenovo --
Has more USB, Apple could do with more USB devices.
DVD Drive, I think Apple did the right thing here and killed the DVD drive. In fact, I think that they will kill off the optical drive in all systems and start shipping their software on USB sticks. Think about how much THAT would save in shipping costs.
Removable Battery -- Okay, well, I'd like to have the ability to easily swap out the MacBook Air's battery. So I kinda have to agree with it.
The Lenovo is thicker, uglier, and really Lenovo, wtf is with TWO mice? The red stick and the trackpad? I have never met anyone, ever that likes the red stick. The trackpad has become the standard, please get with the program. I remember seeing a laptop not too long ago that had the stick, the trackpad, AND the damn trackball. 3 mice. Seriously. Knock it off. Go with the trackpad it seems to work.
Has a slot for a 3G card. Now THAT is what the Macbook Air is lacking. They need the express card slot.
MacBook Air --
Sexy. The Lenovo is the typical Thinkpad ugly ass computer.
Simple. It's a damn Mac!
Lacks more USB
Lacks Optical Drive (so what?)
Lacks Removable Battery
Bottom line, it depends on what you are looking for. Personally I'd like the MacBook Air, but there are too many drawbacks. However, I'd buy it simply because it's a Mac and I refuse to use anything else as my desktop (well, I'd use a bsd or a linux distro as well I guess, but given the option, I'd use a Mac 100%). But I have a Macbook pro. I love this computer, I am writing on it right now. I think the MacBook Pro has it going on.
There is a certain demographic that the MacBook Air is aimed towards, and I think it will sell well in that demographic.
In other news, the same website is reporting that Best Buy is out of the 15in MacBook Pro. Which usually means that Apple has a new one right around the corner. Thinner? Sleeker? Better?
Wordpress plugin exploit
The Difference between two operating systems
Its simply because its hard to explain. When you are using Microsoft Windows, let's say XP because that's what I am forced to use, you get the overwhelming sense of misplacement. Things don't function as they should, icons, toolbars, and menus feel out of place and not well constructed. The whole OS just feels like a kludge. Like it was designed by a commitee, on a white board, and no one in the room was told "no" to any idea.
Installing apps is insane. Next, next, next, agree, ok, next, done, reboot (sometimes). Now yes there are a bunch of mac programs that do the same thing, especially the ones from Apple itself but I think the apps that really get it right on the Mac platform are the ones that, when you download them, they automount and present you with two icons. The one for the program you just downloaded, and a shortcut icon for the Applications folder. All you have to do is a one second drag and drop from left to right. The program installs. Done.
That's the way it should be.
This article that I just read really hits the nail in the head. I enjoyed reading it it prompted many of the thoughts that I just wrote up there. So excuse if you read some redundancy.
Take a read. Its a great article.
Wordpress plugin exploit
The Difference between two operating systems
Its simply because its hard to explain. When you are using Microsoft Windows, let's say XP because that's what I am forced to use, you get the overwhelming sense of misplacement. Things don't function as they should, icons, toolbars, and menus feel out of place and not well constructed. The whole OS just feels like a kludge. Like it was designed by a commitee, on a white board, and no one in the room was told "no" to any idea.
Installing apps is insane. Next, next, next, agree, ok, next, done, reboot (sometimes). Now yes there are a bunch of mac programs that do the same thing, especially the ones from Apple itself but I think the apps that really get it right on the Mac platform are the ones that, when you download them, they automount and present you with two icons. The one for the program you just downloaded, and a shortcut icon for the Applications folder. All you have to do is a one second drag and drop from left to right. The program installs. Done.
That's the way it should be.
This article that I just read really hits the nail in the head. I enjoyed reading it it prompted many of the thoughts that I just wrote up there. So excuse if you read some redundancy.
Take a read. Its a great article.
Thursday, February 14
Teen hax0rs iPhone. Again.
Money quote: "The latest salvo was fired late last week, following a 24-hour hacking spree by Geohot that was broken up by only three hours of sleep. It turns out the latest firmware contained modifications to the device's memory registers to prevent unlocking. Geohot worked around those changes by finding another, much higher register that was vulnerable."
When the SDK comes out, I am sure some of the hacking (or the pace of it) will probably slow down, because people will actually have a legit way of getting apps on the iPhone. However, there will be a certain percentage that will be interested in it because of the SIM card unlocks.
>People want to be able to take their phones to other networks. I have a buddy of mine that has his on T-Mobile.
But I know alot of people that have hacked their iPhones for the apps. I used to have my iPhone hacked, but then the firmware update (1.1.1)? came out that allowed me to download music directly on the phone. That's all I wanted. After I got that, there really wasn't any other apps I was interested in.
There are a couple Apps I would like Apple to come out with.
1) A to-do syncer
2) Notes syncer
3) .mac syncing OTA
4) iChat interface.
If Apple had those features on the iPhone (while the top two are also updates to iTunes, pretty much), I'd be pretty happy.
Thanks goes to Craig who sent me this article.
Teen hax0rs iPhone. Again.
Money quote: "The latest salvo was fired late last week, following a 24-hour hacking spree by Geohot that was broken up by only three hours of sleep. It turns out the latest firmware contained modifications to the device's memory registers to prevent unlocking. Geohot worked around those changes by finding another, much higher register that was vulnerable."
When the SDK comes out, I am sure some of the hacking (or the pace of it) will probably slow down, because people will actually have a legit way of getting apps on the iPhone. However, there will be a certain percentage that will be interested in it because of the SIM card unlocks.
>People want to be able to take their phones to other networks. I have a buddy of mine that has his on T-Mobile.
But I know alot of people that have hacked their iPhones for the apps. I used to have my iPhone hacked, but then the firmware update (1.1.1)? came out that allowed me to download music directly on the phone. That's all I wanted. After I got that, there really wasn't any other apps I was interested in.
There are a couple Apps I would like Apple to come out with.
1) A to-do syncer
2) Notes syncer
3) .mac syncing OTA
4) iChat interface.
If Apple had those features on the iPhone (while the top two are also updates to iTunes, pretty much), I'd be pretty happy.
Thanks goes to Craig who sent me this article.
Wednesday, February 13
Handler posting
I had to work with Snort, some rules, and a few pcaps today for a customer. So I am tired ;)
Tuesday, February 12
Apple releases Apple TV "Take 2" software update
Apple releases Apple TV "Take 2" software update
Apple on Tuesday quietly released its much-anticipated Apple TV "Take 2" software update, which introduces a brand new on-sreen interface and allows users to rent high definition movies directly from their widescreen TVs. The update is available f...
iLife Support Update 8.2
Apple releases Apple TV "Take 2" software update
Apple releases Apple TV "Take 2" software update
Apple on Tuesday quietly released its much-anticipated Apple TV "Take 2" software update, which introduces a brand new on-sreen interface and allows users to rent high definition movies directly from their widescreen TVs. The update is available f...
Leopard Graphics Update
SC Magazine Interview
Along the lines of listening to it's users -- a lot of people didn't like Stacks, (the fan), they liked the list format that was popular in Tiger. So Apple put that back in. Some people didn't like the translucent menu bar, so Apple gave you a way to turn it off. There was no obvious way to tell when a Time Machine backup last occurred without opening System Preferences and looking it up. Or there was no way to tell when a backup was taking place. So Apple put an icon in the menu bar to tell you. Taking it a step further, even allowing you to click on "Back Up Now", forcing the backup. Figuring out better interoperability with 3rd party routers with Back to My Mac and iChat. Figuring out how to make a consistent user experience. All of this to me shows that Apple is listening to their users, making features that users really like present in the product.
Apple furthermore having the Leopard Graphics Update come out really shows where Apple shines. Having the hardware and software coupled together allows Apple to maintain a better user experience for their customers. The ability to upgrade drivers through a patch, pushed down from the vendor, without the user having to go to 30 different sites to update their BIOS, their graphics drivers, their OS patches, etc... This really makes for a consistent user experience. The ability for Apple users to get ALL of their updates in the SAME place, just by going to Software Update. It's priceless in my opinion. I'd like to see more convergence in this space as well. The ability for a user to click on Software Update, and not only get patches for OSX, but also for third party applications, such as Firefox or Thunderbird even the Cisco VPN client. Having all these updates come from a single location would be ideal.
As for the security updates, of course, as OSX gains market share, it will become increasingly a target. That is inevitable. However, Apple has made the decision in the past to kill legacy hardware and software. They killed off an entire OS! (OS 9 -- Classic) Sometimes at the detriment of their users. However, they don't have to deal with driver issues and hardware/software issues that Windows has been plagued with for years. Windows has had to drag all this old code along in each of their OS updates, and while Microsoft has made a lot of progress in recent years with the security of it's platform, the same old Spyware, Malware, Trojans, Worms, and Viruses are still a problem. I believe that OSX increasingly will be in the crosshairs of the malware/spyware/trojans/worm/virus/exploit writers, and there is recent evidence of this when it comes to the Safari browser and Quicktime. Apple has been dealing a lot better with the community and those that find vulnerabilities in OSX, communicating better between researchers and the Product Security Department.
Apple also integrates alot of Open Source code into their Operating System, take a patch for Samba that just came out with the 10.5.2 (Security Update 2008-0001). Samba is a piece of Open Source code that allows for interoperability with Windows networks. While the vulnerability isn't one of Apple's, but that of Samba's. Apple integrates Samba's code, so Apple is also responsible for patching OSX as well. "
iLife Support Update 8.2
Leopard Graphics Update
Monday, February 11
Mac OSX 10.5.2 and Security Update 2008-0001 hit the streets
Active Directory
- Addresses issues which could hinder or prevent binding Mac OS X 10.5.x clients to Active Directory domains.
AirPort
- Improves connection reliability and stability
- Includes 802.1X improvements.
- Resolves certain kernel panics.
Back to my Mac
- Adds support for more third-party routers, as detailed in this article.
Dashboard
- Improves performance of certain Apple Dashboard widgets (such as Dictionary).
- Addresses an issue in which Dashboard widgets may no longer be accessible after switching to or from an account that has Parental Controls enabled.
Dock
- Updates Stacks with a List view option, a Folder view option, and an updated background for Grid view.
Desktop
- Addresses legibility issues with the menu bar with an option to turn off transparency in Desktop & Screen Saver preferences.
- Adjusts menus to be slightly-less translucent overall.
iCal
- Improves iCal so that it accurately reflects responses to recurring meetings.
- Addresses an issue in which a meeting may remain on the calendar after being cancelled.
- Addresses stability issues related to .Mac syncing of iCal calendars.
- Resolves an intermittent issue in which editing an event with attendees would cause the event to shrink and not register that the event was updated.
iChat
- Addresses an issue with simultaneously-logged in accounts in which iChat sounds generated from one account might be heard in another account.
- Fixes an issue in which iChat idle time is affected by Time Machine backups.
- Improves connectivity when running iChat behind a router that doesn’t preserve ports.
- Enables logged chats from previous versions of iChat to open faster and more reliably.
- Addresses an issue with text chats in which users may be unable to receive messages from the sender.
- Addresses an issue that may prevent rejoining an AIM chat room without reopening iChat.
- Addresses video chat compatibility issues with AIM 6 and third-party routers.
- Fixes an issue with case-sensitivity of AIM handles.
iSync
- Adds support for Samsung D600E and D900i phones.
Finder
- Addresses an issue in which Finder could unexpectedly quit when displaying folder contents in Column view.
- Addresses an issue in which Finder could unexpectedly quit when accessing Users and Groups in a Get Info pane.
- Resolves an issue that prevented setting permissions on a folder alias.
- Resolves an issue in which the Eject command could write to a disc in the optical drive.
- Fixes an issue in which the scroll bar might disappear when deleting a file within a folder that includes files that are out of view.
- Fixes an issue in the Sharing & Permissions section of Get Info windows, in which the gear icon appears to be gray/disabled after authentication.
- Addresses an issue in which the Show Icon Preview preference might not be not saved when turning it off.
- Fixes an issue that could occur when trying to print an image from the Finder.
- Addresses an issue with Message menu's "Mark As Read" choice.
- Fixes an issue in which duplicate On My Mac folders may appear in the sidebar after upgrading to Leopard.
- Improves the accuracy of the Data Detectors feature.
- Resolves an issue with scrolling through a Note that is displayed using the split view in the message window.
- Fixes an issue with deleting messages located in the Drafts folder.
- Fixes an issue in which dragging the icon in the Safari URL field into a Mail message creates an attachment instead of a link.
- Addresses an issue found when opening a item in the Notes folder that is not a Note.
- Fixes an issue that may prevent RSS feeds from being delivered in Mail.
- Resolves an issue in which a selected message could "flash" from blue to gray when in Organize by Thread mode.
- Fixes an issue with scrolling between multiple To Dos in an email message.
- Fixes an issue in which the body of email messages with certain MIME structures may not be displayed.
- Improves performance with America Online (AOL) account-based messages in Mail.
- Addresses issues with some ISPs during automatic set-up in Mail.
- Addresses an issue in which Mail might not send mail on some networks to some SMTP servers.
- Mail now automatically disables the (unsupported) third-party plugin GrowlMail version 1.1.2 or earlier to avoid issues.
- Adds an option to view large icons in the Mailbox list.
Networking
- Addresses a hanging issue that may occur when connecting to an AFP network volume.
Parental Controls
- Improves stability when opening the Parental Controls System Preferences pane.
- Fixes an issue that may prevent changes to the email address for permission requests.
- Addresses an issue with printer administration for a guest account enabled with Parental Controls.
- Addresses an issue with setting printer administration privileges from another Mac on the local network.
- Fixes an issue that could prevent certain applications from being allowed.
- Addresses accuracy issues with the web content filter.
Preview
- Improves stability when scrolling through a PDF document.
- Fixes an issue that prevents tabbing within a PDF document after clicking on the PDF.
- Improves the Mail Document feature so that email attachments are more reliably created from Print Preview.
Printing
- Addresses an issue in which remote printers may be deleted when the computer is put to sleep.
- Improves printing performance when using some Microsoft Office applications.
- Resolves an issue with some printing options, such as landscape orientation, number of copies, two-sided printing, and so forth that may not have functioned with some printers shared by Microsoft Windows.
- Adds support for certain printers connected to the USB port of an AirPort Extreme or AirPort Express base station.
- Resolves a stalling issue that could occur when installing certain Canon printing software from a disc.
RAW Image
- Adds RAW image support for several cameras, as detailed in this article.
Safari
- Addresses issues with Safari reliably resolving certain domains.
Login and Setup Assistant
- Addresses an issue in which Setup Assistant could unexpectedly appear each time Mac OS X 10.5 starts up.
- Improves stability and performance during log in.
System
- Improves the accuracy of the grammar checker.
- The computer will now shut down if an automatic disk repair does not succeed during startup.
Time Machine
- Adds a menu bar option for accessing Time Machine features (the menu extra can be enabled in Time Machine preferences).
- Improves backup reliability when computer name contains slash or non-ASCII characters.
- Fixes an issue in which the backup disk displayed in the Finder may be out of sync with the disk chosen for Time Machine.
- Addresses issues in which some external drives are not recognized by Time Machine.
- The status menu now appears by default.
Other
- Improves general stability when running third-party applications.
- Addresses an issue in which the incorrect search results may be displayed for certain Automator Find/Filter actions.
- Addresses an issue with the Latvian and Russian keyboard layouts.
- Addresses an issue in which the backlight could turn off before Energy Saver's backlight setting.
Mac OS X v10.5.2 / Security Update 2008-001
Directory Services
CVE-ID: CVE-2007-0355
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
Impact: A local user may be able to execute arbitrary code with system privileges
Description: A stack buffer overflow exists in the Service Location Protocol (SLP) daemon, which may allow a local user to execute arbitrary code with system privileges. This update addresses the issue through improved bounds checking. This has been described on the Month of Apple Bugs web site (MOAB-17-01-2007). This issue does not affect systems running Mac OS X v10.5 or later. Credit to Kevin Finisterre of Netragard for reporting this issue.
Foundation
CVE-ID: CVE-2008-0035
Available for: Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: Accessing a maliciously crafted URL may lead to an application termination or arbitrary code execution
Description: A memory corruption issue exists in Safari's handling of URLs. By enticing a user to access a maliciously crafted URL, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of URLs. This issue does not affect systems prior to Mac OS X v10.5.
Launch Services
CVE-ID: CVE-2008-0038
Available for: Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: An application removed from the system may still be launched via the Time Machine backup
Description: Launch Services is an API to open applications or their document files or URLs in a way similar to the Finder or the Dock. Users expect that uninstalling an application from their system will prevent it from being launched. However, when an application has been uninstalled from the system, Launch Services may allow it to be launched if it is present in a Time Machine backup. This update addresses the issue by not allowing applications to be launched directly from a Time Machine backup. This issue does not affect systems prior to Mac OS X v10.5. Credit to Steven Fisher of Discovery Software Ltd. and Ian Coutier for reporting this issue.
Mail
CVE-ID: CVE-2008-0039
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
Impact: Accessing a URL in a message may lead to arbitrary code execution
Description: An implementation issue exists in Mail's handling of file:// URLs, which may allow arbitrary applications to be launched without warning when a user clicks a URL in a message. This update addresses the issue by displaying the location of the file in Finder rather than launching it. This issue does not affect systems running Mac OS X v10.5 or later.
NFS
CVE-ID: CVE-2008-0040
Available for: Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: If the system is being used as an NFS client or server, a remote attacker may cause an unexpected system shutdown or arbitrary code execution
Description: A memory corruption issue exists in NFS's handling of mbuf chains. If the system is being used as an NFS client or server, a malicious NFS server or client may be able to cause an unexpected system shutdown or arbitrary code execution. This update addresses the issue through improved handling of mbuf chains. This issue does not affect systems prior to Mac OS X v10.5. Credit to Oleg Drokin of Sun Microsystems for reporting this issue.
Open Directory
Available for: Mac OS X v10.4.11, Mac OS X v10.4.11 Server
Impact: NTLM authentication requests may always fail
Description: This update addresses a non-security issue introduced in Mac OS X v10.4.11. An race condition in Open Directory's Active Directory plug-in may terminate the operation of winbindd, causing NTLM authentications to fail. This update addresses the issue by correcting the race condition that could terminate winbindd. This issue only affects Mac OS X v10.4.11 systems configured for use with Active Directory.
Parental Controls
CVE-ID: CVE-2008-0041
Available for: Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: Requesting to unblock a website leads to information disclosure
Description: When set to manage web content, Parental Controls will inadvertently contact www.apple.com when a website is unblocked. This allows a remote user to detect the machines running Parental Controls. This update addresses the issue by removing the outgoing network traffic when a website is unblocked. This issue does not affect systems prior to Mac OS X v10.5. Credit to Jesse Pearson for reporting this issue.
Samba
CVE-ID: CVE-2007-6015
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: A remote attacker may cause an unexpected application termination or arbitrary code execution
Description: A stack buffer overflow may occur in Samba when processing certain NetBIOS Name Service requests. If a system is explicitly configured to allow "domain logons", an unexpected application termination or arbitrary code execution could occur when processing a request. Mac OS X Server systems configured as domain controllers are also affected. This update addresses the issue by applying the Samba patch. Further information is available via the Samba web site at http://www.samba.org/samba/history/security.html Credit to Alin Rad Pop of Secunia Research for reporting this issue.
Terminal
CVE-ID: CVE-2008-0042
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: Viewing a maliciously crafted web page may lead to arbitrary code execution
Description: An input validation issue exists in the processing of URL schemes handled by Terminal.app. By enticing a user to visit a maliciously crafted web page, an attacker may cause an application to be launched with controlled command line arguments, which may lead to arbitrary code execution. This update addresses the issue through improved validation of URLs. Credit to Olli Leppanen of Digital Film Finland and Brian Mastenbrook for reporting this issue.
X11
CVE-ID: CVE-2007-4568
Available for: Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: Multiple Vulnerabilities exist in X11 X Font Server (XFS) 1.0.4
Description: Multiple vulnerabilities in X11 X Font Server (XFS), the most serious of which may lead to arbitrary code execution. This update addresses the issue by updating to version 1.0.5. Further information is available via the X.Org website at http://www.x.org/wiki/Development/Security
X11
CVE-ID: CVE-2008-0037
Available for: Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: Changing the settings in the Security Preferences Panel has no effect
Description: The X11 server is not reading correctly its "Allow connections from network client" preference, which can cause the X11 server to allow connections from network clients, even when the preference is turned off. This update addresses the issue by ensuring the X11 server reads its preferences correctly. This issue does not affect systems prior to Mac OS X v10.5.
Handler Shift on Wednesday
Mac OSX 10.5.2 and Security Update 2008-0001 hit the streets
Active Directory
- Addresses issues which could hinder or prevent binding Mac OS X 10.5.x clients to Active Directory domains.
AirPort
- Improves connection reliability and stability
- Includes 802.1X improvements.
- Resolves certain kernel panics.
Back to my Mac
- Adds support for more third-party routers, as detailed in this article.
Dashboard
- Improves performance of certain Apple Dashboard widgets (such as Dictionary).
- Addresses an issue in which Dashboard widgets may no longer be accessible after switching to or from an account that has Parental Controls enabled.
Dock
- Updates Stacks with a List view option, a Folder view option, and an updated background for Grid view.
Desktop
- Addresses legibility issues with the menu bar with an option to turn off transparency in Desktop & Screen Saver preferences.
- Adjusts menus to be slightly-less translucent overall.
iCal
- Improves iCal so that it accurately reflects responses to recurring meetings.
- Addresses an issue in which a meeting may remain on the calendar after being cancelled.
- Addresses stability issues related to .Mac syncing of iCal calendars.
- Resolves an intermittent issue in which editing an event with attendees would cause the event to shrink and not register that the event was updated.
iChat
- Addresses an issue with simultaneously-logged in accounts in which iChat sounds generated from one account might be heard in another account.
- Fixes an issue in which iChat idle time is affected by Time Machine backups.
- Improves connectivity when running iChat behind a router that doesn’t preserve ports.
- Enables logged chats from previous versions of iChat to open faster and more reliably.
- Addresses an issue with text chats in which users may be unable to receive messages from the sender.
- Addresses an issue that may prevent rejoining an AIM chat room without reopening iChat.
- Addresses video chat compatibility issues with AIM 6 and third-party routers.
- Fixes an issue with case-sensitivity of AIM handles.
iSync
- Adds support for Samsung D600E and D900i phones.
Finder
- Addresses an issue in which Finder could unexpectedly quit when displaying folder contents in Column view.
- Addresses an issue in which Finder could unexpectedly quit when accessing Users and Groups in a Get Info pane.
- Resolves an issue that prevented setting permissions on a folder alias.
- Resolves an issue in which the Eject command could write to a disc in the optical drive.
- Fixes an issue in which the scroll bar might disappear when deleting a file within a folder that includes files that are out of view.
- Fixes an issue in the Sharing & Permissions section of Get Info windows, in which the gear icon appears to be gray/disabled after authentication.
- Addresses an issue in which the Show Icon Preview preference might not be not saved when turning it off.
- Fixes an issue that could occur when trying to print an image from the Finder.
- Addresses an issue with Message menu's "Mark As Read" choice.
- Fixes an issue in which duplicate On My Mac folders may appear in the sidebar after upgrading to Leopard.
- Improves the accuracy of the Data Detectors feature.
- Resolves an issue with scrolling through a Note that is displayed using the split view in the message window.
- Fixes an issue with deleting messages located in the Drafts folder.
- Fixes an issue in which dragging the icon in the Safari URL field into a Mail message creates an attachment instead of a link.
- Addresses an issue found when opening a item in the Notes folder that is not a Note.
- Fixes an issue that may prevent RSS feeds from being delivered in Mail.
- Resolves an issue in which a selected message could "flash" from blue to gray when in Organize by Thread mode.
- Fixes an issue with scrolling between multiple To Dos in an email message.
- Fixes an issue in which the body of email messages with certain MIME structures may not be displayed.
- Improves performance with America Online (AOL) account-based messages in Mail.
- Addresses issues with some ISPs during automatic set-up in Mail.
- Addresses an issue in which Mail might not send mail on some networks to some SMTP servers.
- Mail now automatically disables the (unsupported) third-party plugin GrowlMail version 1.1.2 or earlier to avoid issues.
- Adds an option to view large icons in the Mailbox list.
Networking
- Addresses a hanging issue that may occur when connecting to an AFP network volume.
Parental Controls
- Improves stability when opening the Parental Controls System Preferences pane.
- Fixes an issue that may prevent changes to the email address for permission requests.
- Addresses an issue with printer administration for a guest account enabled with Parental Controls.
- Addresses an issue with setting printer administration privileges from another Mac on the local network.
- Fixes an issue that could prevent certain applications from being allowed.
- Addresses accuracy issues with the web content filter.
Preview
- Improves stability when scrolling through a PDF document.
- Fixes an issue that prevents tabbing within a PDF document after clicking on the PDF.
- Improves the Mail Document feature so that email attachments are more reliably created from Print Preview.
Printing
- Addresses an issue in which remote printers may be deleted when the computer is put to sleep.
- Improves printing performance when using some Microsoft Office applications.
- Resolves an issue with some printing options, such as landscape orientation, number of copies, two-sided printing, and so forth that may not have functioned with some printers shared by Microsoft Windows.
- Adds support for certain printers connected to the USB port of an AirPort Extreme or AirPort Express base station.
- Resolves a stalling issue that could occur when installing certain Canon printing software from a disc.
RAW Image
- Adds RAW image support for several cameras, as detailed in this article.
Safari
- Addresses issues with Safari reliably resolving certain domains.
Login and Setup Assistant
- Addresses an issue in which Setup Assistant could unexpectedly appear each time Mac OS X 10.5 starts up.
- Improves stability and performance during log in.
System
- Improves the accuracy of the grammar checker.
- The computer will now shut down if an automatic disk repair does not succeed during startup.
Time Machine
- Adds a menu bar option for accessing Time Machine features (the menu extra can be enabled in Time Machine preferences).
- Improves backup reliability when computer name contains slash or non-ASCII characters.
- Fixes an issue in which the backup disk displayed in the Finder may be out of sync with the disk chosen for Time Machine.
- Addresses issues in which some external drives are not recognized by Time Machine.
- The status menu now appears by default.
Other
- Improves general stability when running third-party applications.
- Addresses an issue in which the incorrect search results may be displayed for certain Automator Find/Filter actions.
- Addresses an issue with the Latvian and Russian keyboard layouts.
- Addresses an issue in which the backlight could turn off before Energy Saver's backlight setting.
Mac OS X v10.5.2 / Security Update 2008-001
Directory Services
CVE-ID: CVE-2007-0355
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
Impact: A local user may be able to execute arbitrary code with system privileges
Description: A stack buffer overflow exists in the Service Location Protocol (SLP) daemon, which may allow a local user to execute arbitrary code with system privileges. This update addresses the issue through improved bounds checking. This has been described on the Month of Apple Bugs web site (MOAB-17-01-2007). This issue does not affect systems running Mac OS X v10.5 or later. Credit to Kevin Finisterre of Netragard for reporting this issue.
Foundation
CVE-ID: CVE-2008-0035
Available for: Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: Accessing a maliciously crafted URL may lead to an application termination or arbitrary code execution
Description: A memory corruption issue exists in Safari's handling of URLs. By enticing a user to access a maliciously crafted URL, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of URLs. This issue does not affect systems prior to Mac OS X v10.5.
Launch Services
CVE-ID: CVE-2008-0038
Available for: Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: An application removed from the system may still be launched via the Time Machine backup
Description: Launch Services is an API to open applications or their document files or URLs in a way similar to the Finder or the Dock. Users expect that uninstalling an application from their system will prevent it from being launched. However, when an application has been uninstalled from the system, Launch Services may allow it to be launched if it is present in a Time Machine backup. This update addresses the issue by not allowing applications to be launched directly from a Time Machine backup. This issue does not affect systems prior to Mac OS X v10.5. Credit to Steven Fisher of Discovery Software Ltd. and Ian Coutier for reporting this issue.
Mail
CVE-ID: CVE-2008-0039
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
Impact: Accessing a URL in a message may lead to arbitrary code execution
Description: An implementation issue exists in Mail's handling of file:// URLs, which may allow arbitrary applications to be launched without warning when a user clicks a URL in a message. This update addresses the issue by displaying the location of the file in Finder rather than launching it. This issue does not affect systems running Mac OS X v10.5 or later.
NFS
CVE-ID: CVE-2008-0040
Available for: Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: If the system is being used as an NFS client or server, a remote attacker may cause an unexpected system shutdown or arbitrary code execution
Description: A memory corruption issue exists in NFS's handling of mbuf chains. If the system is being used as an NFS client or server, a malicious NFS server or client may be able to cause an unexpected system shutdown or arbitrary code execution. This update addresses the issue through improved handling of mbuf chains. This issue does not affect systems prior to Mac OS X v10.5. Credit to Oleg Drokin of Sun Microsystems for reporting this issue.
Open Directory
Available for: Mac OS X v10.4.11, Mac OS X v10.4.11 Server
Impact: NTLM authentication requests may always fail
Description: This update addresses a non-security issue introduced in Mac OS X v10.4.11. An race condition in Open Directory's Active Directory plug-in may terminate the operation of winbindd, causing NTLM authentications to fail. This update addresses the issue by correcting the race condition that could terminate winbindd. This issue only affects Mac OS X v10.4.11 systems configured for use with Active Directory.
Parental Controls
CVE-ID: CVE-2008-0041
Available for: Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: Requesting to unblock a website leads to information disclosure
Description: When set to manage web content, Parental Controls will inadvertently contact www.apple.com when a website is unblocked. This allows a remote user to detect the machines running Parental Controls. This update addresses the issue by removing the outgoing network traffic when a website is unblocked. This issue does not affect systems prior to Mac OS X v10.5. Credit to Jesse Pearson for reporting this issue.
Samba
CVE-ID: CVE-2007-6015
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: A remote attacker may cause an unexpected application termination or arbitrary code execution
Description: A stack buffer overflow may occur in Samba when processing certain NetBIOS Name Service requests. If a system is explicitly configured to allow "domain logons", an unexpected application termination or arbitrary code execution could occur when processing a request. Mac OS X Server systems configured as domain controllers are also affected. This update addresses the issue by applying the Samba patch. Further information is available via the Samba web site at http://www.samba.org/samba/history/security.html Credit to Alin Rad Pop of Secunia Research for reporting this issue.
Terminal
CVE-ID: CVE-2008-0042
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: Viewing a maliciously crafted web page may lead to arbitrary code execution
Description: An input validation issue exists in the processing of URL schemes handled by Terminal.app. By enticing a user to visit a maliciously crafted web page, an attacker may cause an application to be launched with controlled command line arguments, which may lead to arbitrary code execution. This update addresses the issue through improved validation of URLs. Credit to Olli Leppanen of Digital Film Finland and Brian Mastenbrook for reporting this issue.
X11
CVE-ID: CVE-2007-4568
Available for: Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: Multiple Vulnerabilities exist in X11 X Font Server (XFS) 1.0.4
Description: Multiple vulnerabilities in X11 X Font Server (XFS), the most serious of which may lead to arbitrary code execution. This update addresses the issue by updating to version 1.0.5. Further information is available via the X.Org website at http://www.x.org/wiki/Development/Security
X11
CVE-ID: CVE-2008-0037
Available for: Mac OS X v10.5 and v10.5.1, Mac OS X Server v10.5 and v10.5.1
Impact: Changing the settings in the Security Preferences Panel has no effect
Description: The X11 server is not reading correctly its "Allow connections from network client" preference, which can cause the X11 server to allow connections from network clients, even when the preference is turned off. This update addresses the issue by ensuring the X11 server reads its preferences correctly. This issue does not affect systems prior to Mac OS X v10.5.
YHOO says No to MSFT
Handler Shift on Wednesday
YHOO says No to MSFT
Saturday, February 9
MSFT posts 3 part series on ActiveX killbits
Friday, February 8
12 MSFT Bulletins next week
Hot on the heels
What are your distractions?
12 MSFT Bulletins next week
Hot on the heels
Microsoft is Stupid, Apple is Not (I didn't make the title up)
Wednesday, February 6
QuickTime 7.4.1
QuickTime 7.4.1
Why were you hired?
Tuesday, February 5
Using your tools to focus
Monday, February 4
Apple to buy Yahoo?
Apple to buy Yahoo?
Friday, February 1
Mail.app in Leopard, GTD, and how I made things a bit more efficient.
Getting Things Done (GTD), with David Allen himself.
Microsoft to buy Yahoo?
Microsoft to buy Yahoo?
Thursday, January 31
Inbox Zero
AT&T Wireless Data Outage
Thanks all of you that have written in. We have seen the articles that say that AT&T is having a wireless data outage.
We have heard from multiple sources on the issue, and it seems to be limited to only certain regions of the US. (Central and South East primarily). I am currently in the NE section of the country, writing this entry on my AT&T 3G Wireless card. So I know it's working here (plus my iPhone and my wife's Blackberry work fine too).
We have also heard that this problem has been resolved. So everything should be back (if not already) to normal soon.
AT&T Wireless Data Outage
Thanks all of you that have written in. We have seen the articles that say that AT&T is having a wireless data outage.
We have heard from multiple sources on the issue, and it seems to be limited to only certain regions of the US. (Central and South East primarily). I am currently in the NE section of the country, writing this entry on my AT&T 3G Wireless card. So I know it's working here (plus my iPhone and my wife's Blackberry work fine too).
We have also heard that this problem has been resolved. So everything should be back (if not already) to normal soon.
Tuesday, January 29
So, you want RSS feeds in your inbox?
So, you want RSS feeds in your inbox?
Jobs named "most powerful person in business"
Quote: "That's five industries that Jobs has upended - computers, Hollywood, music, retailing, and wireless phones. At this moment, no one has more influence over a broader swath of business than Jobs. "
Jobs named "most powerful person in business"
Quote: "That's five industries that Jobs has upended - computers, Hollywood, music, retailing, and wireless phones. At this moment, no one has more influence over a broader swath of business than Jobs. "
Back to my Mac
-
Without going off the deep-end here and discussing every single Snort rule keyword, I just wanted to touch on a few modifiers that people so...
-
Recently I needed the ability to grab a domain name (specifically the hostname) out of a URL using Shortcuts. I wanted to integrate this f...
-
For those of you that haven't heard of DropBox, it's essentially a synced drive that is stored on DropBox's servers (in the clou...