iOS Application (In)Security
This whitepaper details some of the vulnerabilities observed over the past year while performing regular security assessments of iPhone and iPad applications. MDSec documents some of the vulnerabilities identified as well as the methods to exploit them, and recommendations that developers can adopt to protect their iOS applications. It covers not only the security features of the platform, but provides in depth information on how to perform both black box and white box iOS penetration tests, along with suggested methodologies and compliance.
Tags: iphone, over-the-past, Security, VulnerabilitiesstrongSwan IPsec Implementation 4.6.3
strongSwan is a complete IPsec implementation for the Linux, Android, Maemo, FreeBSD, and Mac OS X operating systems.
Tags: adds-additional, modular-plugins, strongswan, trusted-networkIPhone TreasonSMS HTML Injection / File Inclusion
IPhone TreasonSMS suffers from html injection and file inclusion vulnerabilities.
Tags: html-injection, iphone, phone-treason, treasonApple Security Advisory 2012-04-12-1
Apple Security Advisory 2012-04-12-1 – Java for OS X 2012-003 and Java for Mac OS X 10.6 Update 8 is now available. As a security hardening measure, the Java browser plugin and Java Web Start are deactivated if they are unused for 35 days
Tags: browser-plugin, java, SecurityUbuntu Security Notice USN-1419-1
Ubuntu Security Notice 1419-1 – It was discovered that Puppet used a predictable filename when downloading Mac OS X package files. A local attacker could exploit this to overwrite arbitrary files.
Tags: exploit, local-attacker, SecurityZed Attack Proxy 1.4.0.1 Mac OS X Release
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing
Tags: testing-tool, tools, use-integratedApple Security Advisory 2012-04-03-1
Apple Security Advisory 2012-04-03-1 – Java for OS X 2012-001 and Java for Mac OS X 10.6 Update 7 is now available.
Tags: apple-security, code-outside, java, SecuritySecunia Security Advisory 48648
Secunia Security Advisory – Apple has issued an update for Java for Mac OS X. This fixes multiple vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
Tags: exploit, fixes, fixes-multiple, Security