Showing posts with label Apple. Show all posts
Showing posts with label Apple. Show all posts

Are Apple developers on the hacker hit list?

Note: this post is condensed from an article written for Digital New Asia.

Apple's developer website for its Mac, iPhone and iPad products was taken offline about two weeks ago; shortly afterwards, Apple released a statement saying that the site had been suffered an intrusion.

Soon after, a grey hat Turkish security researcher, Ibrahim Balic, in London claimed responsibility for the intrusion in a video posted on his YouTube channel, in which he claimed that he had filed bug reports prior to the takedown of the website.

Although there has been no further comments or statements from Apple about Balic's claim, Apple does seem to be taking the occurrence seriously and is currently still working restoring their web services.

Now the issue is — why are developers, particularly iOS developers, being targeted now more than ever? The intrusion on the developer site, though allegedly done with benign intent, brings greater attention to the importance of securing developer accounts, and the potential consequences if such accounts are compromised and misused.

This is in light of an attack earlier this year on the popular iOS Mobile developers' forum iPhoneDevSDK, which successfully garnered victims from the big tech companies, like Apple, Facebook and Twitter and so on.

Security Researcher Takes Credit For Apple Developer Website Hack

Access to the developer site has been partially restored, but the iOS and Mac Dev Centers remain down

http://www.darkreading.com/attacks-breaches/security-researcher-takes-credit-for-app/240158670
Apple Developer website hack
A security researcher has taken credit for a hack of a website for Apple developers last week that exposed user data and led Apple to take portions of the site offline.

The website's iOS and Mac Dev centers remain down as of publication. In the aftermath of the disclosure, a security researcher named Ibrahim Balic took credit for the hack, and claimed he was only attempting to alert Apple to the presence of vulnerabilities on the site. In a statement to developers on Sunday, Apple warned that its website had been taken down after the hack, and that personal data belonging to users may have been stolen by the culprit.

"Last Thursday, an intruder attempted to secure personal information of our registered developers from our developer website," according to a note posted on the website. "Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed. In the spirit of transparency, we want to inform you of the issue. We took the site down immediately on Thursday and have been working around the clock since then."

Apple took three days to tell developers about a site hack

For three days now, anyone trying to access Apple's members-only developer page has been greeted with the following message:
http://www.theatlanticwire.com/technology/2013/07/apple-took-three-days-tell-developers-about-site-hack/67423/
Apple`s developer page
And on Sunday, the company finally explained why: Their developer site was the target of a hack that may have compromised the security of some development site users' names, email addresses, and mailing addresses. And while the company says that any sensitive information taken is safely encrypted, some developers with accounts at the site have reported unauthorized, and repeated, password reset requests. 

Super Mario Zips Through A Loophole In Apple's App Restrictions

Lots of gamers have long wanted to play classics like Pokémon and Super Mario on the iPhone. Unfortunately, publishers like Nintendo have no desire to undermine their own handheld ecosystem. Those determined to bring GameBoy functionality to their iDevices have pretty much been forced to jailbreak them.

http://readwrite.com/2013/07/16/super-mario-zips-through-a-loophole-in-apples-app-restrictions#awesm=~obWBxBjbmfiDKk
Super Mario zips through a loophole
No longer, at least for the moment. Thanks to an unexpected loophole in Apple's developer restrictions, it's currently possible for anyone to install a fully functioning Game Boy Advance emulator on the iPhone or iPad for free—without jailbreaking their device. Emulator developer Riley Testut created the app, called GBA4iOS, by basing it on another popular jailbreak emulator called gpSphone.

Anatomy of a buffer overflow - learning from Apple's latest security update

Apple has released its latest Security Update for OS X. Dubbed simply 2013-003, the update fixes a trifecta of memory corruption bugs in QuickTime caused by buffer overflows.Technically, one of the bugs is listed as a buffer underflow, which is just a buffer overflow the other way round. An overflow writes past the end of your own memory buffer, trampling on the next block of memory, which may well be in use for something else; an underflow writes in front of your memory, with a similarly risky outcome.
http://nakedsecurity.sophos.com/2013/07/04/anatomy-of-a-buffer-overflow-learning-from-apples-latest-security-update/
Apple`s latest security update
These bug fixes should all be considered critical, because they could be exploited for remote code execution.
In other words, a deliberately-tweaked movie file could trick your Mac into running program code hidden in the movie itself, even though such files are supposed to consist entirely of data.

Silent war / Cyber-conflicts

On the hidden battlefields of history’s first known cyber-war, the casualties are piling up. In the U.S., many banks have been hit, and the telecommunications industry seriously damaged, likely in retaliation for several major attacks on Iran. Washington and Tehran are ramping up their cyber-arsenals, built on a black-market digital arms bazaar, enmeshing such high-tech giants as Microsoft, Google, and Apple. With the help of highly placed government and private-sector sources, Michael Joseph Gross describes the outbreak of the conflict, its escalation, and its startling paradox: that America’s bid to stop nuclear proliferation may have unleashed a greater threat.

http://www.vanityfair.com/culture/2013/07/new-cyberwar-victims-american-business
Cyber-conflict
Cyber- conflict | Vanity Fair

Apple releases security update for Mac OS X


Apple has released Security Update 2013-003 for Mac OS X 10.8.4 (Mountain Lion), 10.8.4 Server, 10.7.5 (Snow Leopard), 10.7.5 Server, 10.6.8 (Lion) and 10.6.8 Server. This is the third standalone security update that Apple has released in 2013.
http://www.h-online.com/security/news/item/Apple-releases-security-update-for-Mac-OS-X-1910729.html
Apple releases security update
The update's advisory note says that there are three QuickTime flaws, specifically buffer overflows when handling Sorenson-encoded movies and H.264 movies, and a buffer underflow when handing "mvhd" atoms. The problems are said to lead to application crashes or, in the worst case, allow arbitrary code execution. All three flaws were reported by researchers working with HP's Zero Day Initiative.