<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>iThreats</title>
	<atom:link href="http://ithreats.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://ithreats.net</link>
	<description>What Do You Think Is The Biggest Threat To Mac Users&#039; Security?</description>
	<lastBuildDate>Thu, 12 Aug 2010 16:23:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='ithreats.net' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/6cfb95912e01ba3e5913979a06571621?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>iThreats</title>
		<link>http://ithreats.net</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://ithreats.net/osd.xml" title="iThreats" />
	<atom:link rel='hub' href='http://ithreats.net/?pushpress=hub'/>
		<item>
		<title>iOS Security Updates</title>
		<link>http://ithreats.net/2010/08/12/ios-security-updates/</link>
		<comments>http://ithreats.net/2010/08/12/ios-security-updates/#comments</comments>
		<pubDate>Thu, 12 Aug 2010 16:20:43 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[#$get+216.65.3.78]]></category>
		<category><![CDATA[<</Subtype /Type1C]]></category>
		<category><![CDATA[Compact Font Format (CFF ) Type 1C]]></category>
		<category><![CDATA[CVE-2010-1797]]></category>
		<category><![CDATA[CVE-2010-2973]]></category>
		<category><![CDATA[exxpploit]]></category>
		<category><![CDATA[iOS Security Updates]]></category>
		<category><![CDATA[IOSurface property list exploit]]></category>
		<category><![CDATA[iPhone hacked]]></category>
		<category><![CDATA[iPhone worm?]]></category>
		<category><![CDATA[JailBreakMe by comex]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1134</guid>
		<description><![CDATA[iPod, iPhone and iPad users MUST immediately apply the security updates. Visit Apple Security Updates for details. Reference: iPad http://support.apple.com/kb/HT4291; iPhone and iPod http://support.apple.com/kb/HT4292 Why important? This will protect you from in-the-wild drive-by download hack attack! JailBreakMe by comex (et al.) demonstrated a serious security hole that allows users to jailbreak their iOS devices simply by [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1134&subd=ithreats&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>iPod, iPhone and iPad users <strong>MUST</strong> immediately apply the security updates.</p>
<p>Visit <a href="http://support.apple.com/kb/HT1222" target="_blank">Apple Security Updates</a> for details.</p>
<p><a href="http://ithreats.files.wordpress.com/2010/08/ios-security-update.png"><img class="aligncenter size-full wp-image-1135" title="iOS Security Update" src="http://ithreats.files.wordpress.com/2010/08/ios-security-update.png?w=600&#038;h=136" alt="" width="600" height="136" /></a></p>
<p>Reference:</p>
<p>iPad <a href="http://support.apple.com/kb/HT4291" target="_blank">http://support.apple.com/kb/HT4291</a>;</p>
<p>iPhone and iPod <a href="http://support.apple.com/kb/HT4292" target="_blank">http://support.apple.com/kb/HT4292</a></p>
<p><strong><em>Why important?</em></strong></p>
<p>This will protect you from in-the-wild drive-by download hack attack!</p>
<p>JailBreakMe by comex (et al.) demonstrated a serious security hole that allows users to jailbreak their iOS devices simply by just visiting a website and/or tapping a link. This security hole is very dangerous, by just browsing the web users could be exposed from abusive sites that may harvest their credentials and information.</p>
<p><strong><em>How it work?</em></strong></p>
<p>Safari browser loads a crafted PDF that exploits the following vulnerabilities:</p>
<p><em>First,</em> it is triggered by unrecognized font, the Compact Font Format (<em>CFF</em> ) <em>Type 1C</em>, which causes the second exploit code to execute. This vulnerability is referred as CVE-2010-1797.</p>
<p><code>&lt;&lt;/Subtype /Type1C</code></p>
<p><em> Second</em>, the value is too large for the integer data type to handle(refer example IOSurface property list below), resulting to execution of malicious code running as user to escalate to system or root privilege.</p>
<p><a href="http://ithreats.files.wordpress.com/2010/08/iosurface-plist.png"><img class="aligncenter size-full wp-image-1137" title="IOSurface plist" src="http://ithreats.files.wordpress.com/2010/08/iosurface-plist.png?w=477&#038;h=311" alt="" width="477" height="311" /></a></p>
<p>This vulnerability is referred as CVE-2010-2973.</p>
<p>So, an attacker entice a targeted user to open a URL. Upon opening the URL in Safari the PDF file will be automatically parsed and exploitation will occur. The file may also arrive as an email attachment.</p>
<p>Stay safe!</p>
<p><em>Recommended reading:</em></p>
<p><a href="http://blog.fortinet.com/iphone-4-ipad-the-keys-out-of-prison/" target="_blank">iPhone 4 / iPad: The Keys Out Of Prison by Axelle Apvrille</a></p>
<p><a href="http://community.websense.com/blogs/securitylabs/archive/2010/08/06/technical-analysis-on-iphone-jailbreaking.aspx" target="_blank">Technical Analysis on iPhone Jailbreaking by Matt Oh</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1134/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1134&subd=ithreats&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2010/08/12/ios-security-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/08/ios-security-update.png" medium="image">
			<media:title type="html">iOS Security Update</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/08/iosurface-plist.png" medium="image">
			<media:title type="html">IOSurface plist</media:title>
		</media:content>
	</item>
		<item>
		<title>0day: Apple Safari AutoFill</title>
		<link>http://ithreats.net/2010/07/23/0day-apple-safari-autofill/</link>
		<comments>http://ithreats.net/2010/07/23/0day-apple-safari-autofill/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 12:14:20 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[Apple Safari AutoFill]]></category>
		<category><![CDATA[Apple Safari 0day]]></category>
		<category><![CDATA[How to show safari preferences]]></category>
		<category><![CDATA[how to disable Safari Autofill]]></category>
		<category><![CDATA[Safari exposure of sensitive information attack]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1123</guid>
		<description><![CDATA[Description Jeremiah Grossman has discovered a weakness in Apple Safari, which can be exploited by malicious people to disclose potentially sensitive information. The weakness is caused due to the AutoFill feature being enabled to use information from the personal address book card by default. This can be exploited to secretly disclose personal information from the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1123&subd=ithreats&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Description</strong></p>
<p>Jeremiah Grossman has discovered a weakness in Apple Safari, which can be exploited by malicious people to disclose potentially sensitive information.</p>
<p>The weakness is caused due to the AutoFill feature being enabled to use information from the personal address book card by default. This can be exploited to secretly disclose personal information from the personal address book card when a user visits a specially crafted web page.</p>
<p>The weakness is confirmed in Safari version 5.0. Other versions may also be affected.</p>
<p><strong>Impact</strong> :  Exposure of sensitive information</p>
<p><em>Reference : <a href="http://secunia.com/advisories/40664/" target="_blank">Secunia Advisory SA40664</a></em></p>
<p><strong>Solution</strong><br />
Disable the AutoFill feature for address book card information.</p>
<p>How? Show Safari preferences (press Command-comma or ⌘,) and uncheck the autofill web form.</p>
<p><a href="http://ithreats.files.wordpress.com/2010/07/disable-safari-autofill.png"><img class="aligncenter size-full wp-image-1124" title="Disable Safari Autofill" src="http://ithreats.files.wordpress.com/2010/07/disable-safari-autofill.png?w=600&#038;h=163" alt="" width="600" height="163" /></a></p>
<p><em>Further reading: </em></p>
<p>http://jeremiahgrossman.blogspot.com/2010/07/i-know-who-your-name-where-you-work-and.html</p>
<p>PoC : <a href="http://ha.ckers.org/weird/safari_autofill.html" target="_blank">http://ha.ckers.org/weird/safari_autofill.html</a></p>
<p>Personal information exposed?   It depends on the data, here&#8217;s my browser result.</p>
<p><a href="http://ithreats.files.wordpress.com/2010/07/apple-safari-autofill-poc.png"><img class="aligncenter size-full wp-image-1126" title="Apple Safari AutoFill PoC" src="http://ithreats.files.wordpress.com/2010/07/apple-safari-autofill-poc.png?w=573&#038;h=412" alt="" width="573" height="412" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1123/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1123&subd=ithreats&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2010/07/23/0day-apple-safari-autofill/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/07/disable-safari-autofill.png" medium="image">
			<media:title type="html">Disable Safari Autofill</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/07/apple-safari-autofill-poc.png" medium="image">
			<media:title type="html">Apple Safari AutoFill PoC</media:title>
		</media:content>
	</item>
		<item>
		<title>About Mac OS X v10.6.4 &#8216;XProtect&#8217; Update</title>
		<link>http://ithreats.net/2010/06/19/about-mac-os-x-v10-6-4-xprotect-update/</link>
		<comments>http://ithreats.net/2010/06/19/about-mac-os-x-v10-6-4-xprotect-update/#comments</comments>
		<pubDate>Sat, 19 Jun 2010 12:50:30 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[OS X]]></category>
		<category><![CDATA[CoreTypes.bundle]]></category>
		<category><![CDATA[Mac OS X v10.6.4]]></category>
		<category><![CDATA[rbframework.dylib]]></category>
		<category><![CDATA[RBShell.rbx_0.129.dylib]]></category>
		<category><![CDATA[Safari 5 browser extension support]]></category>
		<category><![CDATA[XProtect HellRaiser]]></category>
		<category><![CDATA[XProtect.plist location]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1109</guid>
		<description><![CDATA[Pob of SophosLabs found this interesting update, please read this blog post Updated XProtect protects against OSX.HellRTS Apple Mac OS X Snow Leopard Anti-Malware signature file &#8216;XProtect.plist&#8217; has new definition detecting &#8220;OSX.HellRTS&#8221; in the latest Security Update 2010-004 / Mac OS X v10.6.4. XProtect.plist is stored inside the Resources folder of a bundle called, CoreTypes.bundle. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1109&subd=ithreats&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><em>Pob of SophosLabs found this interesting update, please read this blog post </em><a href="http://www.sophos.com/blogs/sophoslabs/?p=10136"><em>Updated XProtect protects against OSX.HellRTS</em></a></p>
<p>Apple Mac OS X Snow Leopard <em>Anti-Malware </em>signature file &#8216;XProtect.plist&#8217; has new definition detecting &#8220;OSX.HellRTS&#8221; in the latest Security Update 2010-004 / Mac OS X v10.6.4.</p>
<p><a href="http://ithreats.files.wordpress.com/2010/06/apple-xprotect-plist-update-detects-hellrts.png"><img class="aligncenter size-full wp-image-1110" title="Apple XProtect.plist Update Detects HellRTS" src="http://ithreats.files.wordpress.com/2010/06/apple-xprotect-plist-update-detects-hellrts.png?w=497&#038;h=196" alt="" width="497" height="196" /></a></p>
<p>XProtect.plist is stored inside the <em>Resources</em> folder of a bundle called, <em>CoreTypes.bundle</em>.</p>
<p><em>CoreTypes.bundle</em> contains specifications that allow Mac OS X uniquely identify data types, file format, associated icons and UTIs (<em>Uniform Type Identifiers) </em>as defined in the <em>Info.plist </em>file.</p>
<p>In this update (Mac OS X v10.6.4), there are two major update for Mac OS X detection feature (Quarantine and Anti-Malware):</p>
<p>1) Risk assessment for Safari extensions(.safariextz) is <strong>unsafe</strong>, which triggers Mac OS X quarantine feature and displays a warning &#8220;..Are you sure you want to open it?&#8221;.</p>
<p>This assessment is reflected to an XML file called S<em>ystem</em> which contains risk definitions for certain file types and extensions. The <em>risk assessment </em>has 3 categories:</p>
<p><code> </code></p>
<p><code></p>
<div id="_mcePaste">&lt;key&gt;LSRiskCategorySafe&lt;/key&gt;</div>
<div id="_mcePaste">&lt;key&gt;LSRiskCategoryMayContainUnsafeExecutable&lt;/key&gt;</div>
<div id="_mcePaste">&lt;key&gt;LSRiskCategoryUnsafeExecutable&lt;/key&gt;</div>
<p></code></p>
<p>As shown below, Safari extensions (.safariextz) was added under <code>LSRiskCategoryUnsafeExecutable key. </code></p>
<p><a href="http://ithreats.files.wordpress.com/2010/06/mac-os-x-10-6-4-update-lsriskcategoryunsafeexecutable.png"><img class="aligncenter size-full wp-image-1111" title="Mac OS X 10.6.4 Update LSRiskCategoryUnsafeExecutable" src="http://ithreats.files.wordpress.com/2010/06/mac-os-x-10-6-4-update-lsriskcategoryunsafeexecutable.png?w=600&#038;h=295" alt="" width="600" height="295" /></a></p>
<p>Apple recently released Safari  5 with support for browser extensions, and this security update make sure that nothing gets executed without a warning.</p>
<p>System file location:</p>
<p><span style="font-family:monospace;">/System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/System</span></p>
<p>2) Mac OS X Anti-Malware signature file &#8220;XProtect.plist&#8221; now includes detection for  HellRaiser version 4.2 server application.</p>
<p><a href="http://ithreats.files.wordpress.com/2010/06/xprotect-10-6-4.png"><img class="aligncenter size-full wp-image-1112" title="XProtect 10.6.4" src="http://ithreats.files.wordpress.com/2010/06/xprotect-10-6-4.png?w=600&#038;h=509" alt="" width="600" height="509" /></a></p>
<p>There are 3 definitions for OSX.HellRaiser. As highlighted in the screenshot above, it&#8217;s detecting 2 components namely: rbframework.dylib and RBShell.rbx_0.129.dylib, and searches defined hex strings for a pattern matching the Hellraiser server auto launch entry (adding login items) command.</p>
<p>The latest XProtect.plist time stamp suggest that it was updated on 24th of April, just couple days after the discovery HellRaiser 4.2 server (in-the-wild). Unfortunately, it seems that it has to wait for the combo update as released on 15th of June.</p>
<p>XProtect.plist location:</p>
<p><code>/System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/XProtect.plist</code></p>
<div>
<div></div>
<div>Btw, it is important to take note, this security feature is not capable to detect when the server is already running in background.</div>
</div>
<div></div>
<div></div>
<div><a href="http://ithreats.files.wordpress.com/2010/06/terminal-hellraiser-backdoor1.png"><img class="aligncenter size-full wp-image-1117" style="display:block;margin-left:auto;margin-right:auto;border:0 initial initial;" title="terminal hellraiser backdoor" src="http://ithreats.files.wordpress.com/2010/06/terminal-hellraiser-backdoor1.png?w=600&#038;h=209" alt="" width="600" height="209" /></a></div>
<div><a href="http://ithreats.files.wordpress.com/2010/06/terminal-hellraiser-backdoor1.png"><br />
</a></div>
<div></div>
<div>
<div>Have a nice weekend!</div>
</div>
<div></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1109/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1109&subd=ithreats&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2010/06/19/about-mac-os-x-v10-6-4-xprotect-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/apple-xprotect-plist-update-detects-hellrts.png" medium="image">
			<media:title type="html">Apple XProtect.plist Update Detects HellRTS</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/mac-os-x-10-6-4-update-lsriskcategoryunsafeexecutable.png" medium="image">
			<media:title type="html">Mac OS X 10.6.4 Update LSRiskCategoryUnsafeExecutable</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/xprotect-10-6-4.png" medium="image">
			<media:title type="html">XProtect 10.6.4</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/terminal-hellraiser-backdoor1.png" medium="image">
			<media:title type="html">terminal hellraiser backdoor</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;PremierOpinion&#8221; Spyware Now in Mac OS X</title>
		<link>http://ithreats.net/2010/06/02/premieropinion-spyware-now-in-mac-os-x/</link>
		<comments>http://ithreats.net/2010/06/02/premieropinion-spyware-now-in-mac-os-x/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 04:05:59 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Emerging Threats]]></category>
		<category><![CDATA[Malwares]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[/tmp/poinstaller]]></category>
		<category><![CDATA[7art screensaver]]></category>
		<category><![CDATA[how to check DNS in Mac]]></category>
		<category><![CDATA[how to spot mac os spyware]]></category>
		<category><![CDATA[InjectCode]]></category>
		<category><![CDATA[InjectCode.app]]></category>
		<category><![CDATA[it.kingroutecn.com:8081]]></category>
		<category><![CDATA[IzPack installer]]></category>
		<category><![CDATA[JAR malware OS X]]></category>
		<category><![CDATA[Mac OS X installer require password]]></category>
		<category><![CDATA[macmeterhk]]></category>
		<category><![CDATA[macmeterhk.bundle]]></category>
		<category><![CDATA[OSX/OpinionSpy install]]></category>
		<category><![CDATA[OSX/OpinionSpy root password]]></category>
		<category><![CDATA[PermissionResearch.app]]></category>
		<category><![CDATA[poinstaller]]></category>
		<category><![CDATA[PremierOpinion]]></category>
		<category><![CDATA[PremierOpinion spyware]]></category>
		<category><![CDATA[PremierOpinion survey]]></category>
		<category><![CDATA[Rule14.xml]]></category>
		<category><![CDATA[RunPermissionResearch.sh]]></category>
		<category><![CDATA[spyware mac os x]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1083</guid>
		<description><![CDATA[From Intego security advisory today: &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; Malware: OSX/OpinionSpy Risk: High Description: Intego has discovered a spyware application that is installed by a number of freely distributed Mac applications and screen savers found on a variety of websites. OSX/OpinionSpy is installed by a number of applications and screen savers that are distributed on sites such as MacUpdate, VersionTracker [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1083&subd=ithreats&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://ithreats.files.wordpress.com/2010/06/osx-spyware-premier-opinion-installation0.png"><img class="size-full wp-image-1085 alignnone" title="OSX Spyware &quot;Premier Opinion&quot; Installation0" src="http://ithreats.files.wordpress.com/2010/06/osx-spyware-premier-opinion-installation0.png?w=524&#038;h=327" alt="" width="524" height="327" /></a></p>
<p><em><strong>From Intego security advisory today: </strong></em></p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p><strong>Malware</strong>: OSX/OpinionSpy</p>
<p><strong>Risk</strong>: High</p>
<p><strong>Description</strong>: Intego has discovered a spyware application that is installed by a number of freely distributed Mac applications and<strong><em> screen savers found on a variety of websites</em></strong>.</p>
<div>OSX/OpinionSpy is installed by a number of applications and screen savers that are distributed on sites such as <strong>MacUpdate</strong>, <strong>VersionTracker</strong> and <strong>Softpedia</strong>.</div>
<div>Details: <a href="http://www.intego.com/news/osx-opinionspy-spyware-installed-by-freely-distributed-mac-applications.asp" target="_blank">http://www.intego.com/news/osx-opinionspy-spyware-installed-by-freely-distributed-mac-applications.asp</a></div>
<div>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</div>
<div>
<p>Who&#8217;s PremierOpinion?</p>
<p>PremierOpinion is part of an <strong><em>online market research community </em></strong>with over 2 million members worldwide. PremierOpinion <em>relies</em> on its members to <em>gain valuable</em> insight into <em>Internet trends</em> and <em>behavior</em>. In exchange for participating in periodic surveys on topics of interest to the Internet community, and for having<strong><em> their Internet browsing and purchasing activity monitored</em></strong>, PremierOpinion <em>sponsors</em> select <em>software</em> that its members can enjoy for <strong>free</strong>.</p>
<p>Website: http://www.premieropinion.com/Home.aspx</p>
<p>So, who&#8217;s the partner?</p>
<p>&#8220;PremierOpinion&#8221; Mac OS X Spyware are distributed by 7art-screensavers and published in this link: http://7art-screensavers.com/Mac_OS_X.shtml</p>
<p>Intego blog published detailed list of &#8220;PremierOpinion&#8221; Mac OS X Spyware.[<a href="http://blog.intego.com/2010/06/01/preliminary-list-of-applications-that-install-osxopinionspy-spyware/">here</a>]</p>
<p>There are 48 screensaver Mac OS X apps in this source, and there are two different packages.</p>
</div>
<div><a href="http://ithreats.files.wordpress.com/2010/06/two-packages.png"><img class="aligncenter size-full wp-image-1086" title="two packages" src="http://ithreats.files.wordpress.com/2010/06/two-packages.png?w=284&#038;h=126" alt="" width="284" height="126" /></a></div>
<div>
<p>How to spot &#8220;PremierOpinion&#8221; Mac OS X Spyware?</p>
<p>1. It uses <strong>IzPack </strong>&#8220;Package once. Deploy everywhere.&#8221; software installer generator. You&#8217;ll notice from a package inspection (press control+click on the application and from the pop-up menu choose<em> ‘Show Package Contents’), </em>the <strong><em>icons are different</em></strong> &#8211; <strong><em>7art</em></strong> while the other <strong><em>izpack.icns</em></strong>.</p>
</div>
<div><a style="text-decoration:none;" href="http://ithreats.files.wordpress.com/2010/06/izpack-vs-7art.png"><img class="aligncenter size-full wp-image-1087" title="izpack vs 7art" src="http://ithreats.files.wordpress.com/2010/06/izpack-vs-7art.png?w=600&#038;h=425" alt="" width="600" height="425" /></a></div>
<div>
<p>2. IzPack generated installers are in Java Archive (.<strong>JAR</strong>) file.</p>
<p>3. 7art screen savers installation do <strong>NOT</strong> require root password. While, PremierOpinion sponsored <strong>free </strong>software or application <strong>requires</strong> root password. Why? Because it installs spyware, which will track and monitor users&#8217; browsing behaviour, scans and gather information from the disk and sends back to its remote server. This is very <em>persistent</em> spyware, meaning it does <em>NOT want to be uninstalled</em>.</p>
</div>
<div><a href="http://ithreats.files.wordpress.com/2010/06/osx-spyware-premier-opinion-installation0.png"><img title="OSX Spyware &quot;Premier Opinion&quot; Installation0" src="http://ithreats.files.wordpress.com/2010/06/osx-spyware-premier-opinion-installation0.png?w=524&#038;h=327" alt="" width="524" height="327" /></a></div>
<div>
<p>4. Spyware installs software without user&#8217;s consent or notification.   It is often bundled with other clean application to misleads users of its true purpose and gain access to users&#8217; system. So, in this case, if you click &#8220;Cancel&#8221;, the IzPack installer will still continue by two pop-up screen: 1) PremierOpinion survey (<a href="http://ithreats.files.wordpress.com/2010/06/premieropinionsurvey.png">screenshot</a>) 2) 7art screen saver installation (<a href="http://ithreats.files.wordpress.com/2010/06/7artinstall.png">screenshot</a>).</p>
<p>&#8220;Package once. Deploy everywhere.&#8221;</p>
<p>This sneaky Mac OS X threat could be everywhere bundled and distributed in the internet.</p>
<p>Be cautious and stay safe!</p>
<p>&#8212;&#8212;&#8211;&gt; Threat Info FYI</p>
<p>File Name: poinstaller</p>
<p>File Type: Mach-O executable i386</p>
<p>File Size: 470,352 bytes</p>
<p>Threat Type: Backdoor, Downloader, Sniffer, Stealer,</p>
<p>Installation Requirement:  root</p>
<p>Remote Activity: Installation of other threats</p>
<p><a href="http://ithreats.files.wordpress.com/2010/06/ida-code-poinstaller.png"><img class="aligncenter size-full wp-image-1101" title="IDA code poinstaller" src="http://ithreats.files.wordpress.com/2010/06/ida-code-poinstaller.png?w=600&#038;h=124" alt="" width="600" height="124" /></a></p>
<p>Remote Download File: Rule14.xml</p>
<p><img class="aligncenter size-full wp-image-1102" title="rule14 xml" src="http://ithreats.files.wordpress.com/2010/06/rule14-xml.png?w=600&#038;h=213" alt="" width="600" height="213" />Remote Download: PermissionResearch.zip</p>
<p>Installation: RunPermissionResearch.sh</p>
<p><a href="http://ithreats.files.wordpress.com/2010/06/runpermissionresearch-sh.png"><img class="aligncenter size-full wp-image-1103" title="RunPermissionResearch sh" src="http://ithreats.files.wordpress.com/2010/06/runpermissionresearch-sh.png?w=600&#038;h=163" alt="" width="600" height="163" /></a>Package Name: PermissionResearch.app</p>
<p><a href="http://ithreats.files.wordpress.com/2010/06/permissionresearch-app.png"><img class="aligncenter size-full wp-image-1104" title="PermissionResearch app" src="http://ithreats.files.wordpress.com/2010/06/permissionresearch-app.png?w=600&#038;h=414" alt="" width="600" height="414" /></a>File Name: PermissionResearch</p>
<p>File Type: Mach-O executable i386</p>
<div>File Size: 4.1 MB</div>
<div></div>
<div>Resource Package Name: InjectCode.app</div>
<div></div>
</div>
<div><a href="http://ithreats.files.wordpress.com/2010/06/injectcode-app.png"><img class="aligncenter size-full wp-image-1105" title="InjectCode app" src="http://ithreats.files.wordpress.com/2010/06/injectcode-app.png?w=395&#038;h=758" alt="" width="395" height="758" /></a></div>
<div>File Name: InjectCode</div>
<div>File Type:</div>
<div>
<div id="_mcePaste">Mach-O executable i386</div>
</div>
<div>
<div>Mach-O 64-bit executable x86_64</div>
</div>
<div>File Size: 34,088 bytes</div>
<div>Resource Package Name: macmeterhk.bundle</div>
<div><a href="http://ithreats.files.wordpress.com/2010/06/macmeterhk-bundle.png"><img class="aligncenter size-full wp-image-1106" title="macmeterhk bundle" src="http://ithreats.files.wordpress.com/2010/06/macmeterhk-bundle.png?w=482&#038;h=155" alt="" width="482" height="155" /></a>File Name: macmeterhk</div>
<div>
<div>File Type:</div>
<div>
<div id="_mcePaste">Mach-O executable i386</div>
</div>
<div>
<div>Mach-O 64-bit executable x86_64</div>
</div>
<div>File Size:  894,836 bytes</div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1083/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1083/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1083/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1083/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1083/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1083/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1083/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1083/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1083&subd=ithreats&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2010/06/02/premieropinion-spyware-now-in-mac-os-x/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/osx-spyware-premier-opinion-installation0.png" medium="image">
			<media:title type="html">OSX Spyware &#34;Premier Opinion&#34; Installation0</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/two-packages.png" medium="image">
			<media:title type="html">two packages</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/izpack-vs-7art.png" medium="image">
			<media:title type="html">izpack vs 7art</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/osx-spyware-premier-opinion-installation0.png" medium="image">
			<media:title type="html">OSX Spyware &#34;Premier Opinion&#34; Installation0</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/ida-code-poinstaller.png" medium="image">
			<media:title type="html">IDA code poinstaller</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/rule14-xml.png" medium="image">
			<media:title type="html">rule14 xml</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/runpermissionresearch-sh.png" medium="image">
			<media:title type="html">RunPermissionResearch sh</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/permissionresearch-app.png" medium="image">
			<media:title type="html">PermissionResearch app</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/injectcode-app.png" medium="image">
			<media:title type="html">InjectCode app</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/06/macmeterhk-bundle.png" medium="image">
			<media:title type="html">macmeterhk bundle</media:title>
		</media:content>
	</item>
		<item>
		<title>Safari users still vulnerable to &#8220;carpet-bombing&#8221; attack</title>
		<link>http://ithreats.net/2010/05/26/safari-users-still-vulnerable-to-carpet-bombing-attack/</link>
		<comments>http://ithreats.net/2010/05/26/safari-users-still-vulnerable-to-carpet-bombing-attack/#comments</comments>
		<pubDate>Wed, 26 May 2010 02:45:52 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[OS X]]></category>
		<category><![CDATA[carpet-bombing]]></category>
		<category><![CDATA[Mac unknown download files]]></category>
		<category><![CDATA[Safari 0day]]></category>
		<category><![CDATA[Safari download folder]]></category>
		<category><![CDATA[Safari open vulnerability]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1072</guid>
		<description><![CDATA[Apple Safari carpet-bombing is a vulnerability that allows remote attacker via malicious website to silently download arbitrary files in users&#8217; default download directory (~/Download). This issue became serious in Windows because the default download is in users&#8217; Desktop. Attackers can craft any file to look like a link file (.LNK) and or image file (.JPEG) [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1072&subd=ithreats&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Apple <em>Safari </em>carpet-bombing is a vulnerability that allows remote attacker via malicious website to <strong>silently</strong> <strong>download arbitrary files</strong> in users&#8217; default download directory (~/Download).</p>
<p>This issue became serious in Windows because the default download is in users&#8217; Desktop. Attackers can craft any file to look like a link file (.LNK) and or image file (.JPEG) to entice users into clicking it. Apple immediately address this issue in Safari for Windows 3.1.2.</p>
<p>However, Safari Mac OS X  users remain exposed to this vulnerability. In May 2008, Nitesh Dhanjani disclosed details about this flaw and a year later, while I was writing my paper for VB2009, I revisited this issue and found that it is still unpatched. I have contacted him and verified whether my findings is true, and unfortunately he answered &#8220;yes&#8221;.</p>
<p>Ok, two years later, again I am writing  and reviewing same old tricks, and found that Nitesh Dhanjani recently revisited this issue in his blog post titled &#8220;<a href="http://www.dhanjani.com/blog/2010/05/2-years-later-droppin-malware-on-your-osx-carpet-bomb-style-and-then-some.html" target="_blank">2 Years Later: Droppin’ Malware on Your OSX, Carpet Bomb Style (and Then Some!)</a>&#8220;.</p>
<p>I smiled when I saw the screenshot and bonus notes, it reminds me how tricky it can get when it&#8217;s combined with other known tricks/exploits &#8211; makes it easier to get users&#8217; click.</p>
<p>Example,</p>
<p>What is this monkey doing in my download?  Opss, carpet-bomb! That monkey is a trick, it&#8217;s not an image file.</p>
<p><a href="http://ithreats.files.wordpress.com/2010/05/carpetbomb.png"><img class="aligncenter size-full wp-image-1074" title="carpetbomb" src="http://ithreats.files.wordpress.com/2010/05/carpetbomb.png?w=216&#038;h=268" alt="" width="216" height="268" /></a></p>
<p>Recommended reading:</p>
<p><a href="http://www.theregister.co.uk/2010/05/24/safari_carpet_bombing_bug/" target="_blank">http://www.theregister.co.uk/2010/05/24/safari_carpet_bombing_bug/ </a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1072/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1072/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1072/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1072/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1072/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1072/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1072/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1072/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1072/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1072/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1072/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1072/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1072/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1072/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1072&subd=ithreats&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2010/05/26/safari-users-still-vulnerable-to-carpet-bombing-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/05/carpetbomb.png" medium="image">
			<media:title type="html">carpetbomb</media:title>
		</media:content>
	</item>
		<item>
		<title>0day: Apple Safari &#8220;parent.close()&#8221;</title>
		<link>http://ithreats.net/2010/05/08/0day-apple-safari-parent-close/</link>
		<comments>http://ithreats.net/2010/05/08/0day-apple-safari-parent-close/#comments</comments>
		<pubDate>Sat, 08 May 2010 17:56:40 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Safari 0day]]></category>
		<category><![CDATA[safari redirection and pop-up]]></category>
		<category><![CDATA[suspecting trojan in mac]]></category>
		<category><![CDATA[suspicious safari behavior]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1054</guid>
		<description><![CDATA[Release Date : 2010-05-07 Criticality level : Highly critical Impact : Remote code execution Solution Status : Unpatched Description: A vulnerability has been discovered in Apple Safari, which can be exploited by malicious people to compromise a user&#8217;s system. The vulnerability is caused due to an error in the handling of parent windows and can [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1054&subd=ithreats&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Release Date : 2010-05-07<br />
Criticality level : Highly critical<br />
Impact : Remote code execution<br />
Solution Status : Unpatched</p>
<p>Description:<br />
A vulnerability has been discovered in Apple Safari, which can be exploited by malicious people to compromise a user&#8217;s system.</p>
<p>The vulnerability is caused due to an error in the handling of parent windows and can result in a function call using an invalid pointer. This can be exploited to execute arbitrary code when a user e.g. visits a specially crafted web page and closes opened pop-up windows.</p>
<p>The vulnerability is confirmed in Safari version 4.0.5 for Windows. Other versions <strong>may</strong> also be affected.</p>
<p><strong>Solution:<br />
Do not visit untrusted web sites or follow links from untrusted sources.</strong></p>
<p>PROVIDED AND/OR DISCOVERED BY:<br />
Krystian Kloskowski (h07)</p>
<p>Original Advisory:<br />
<a href="http://h07.w.interia.pl/Safari.rar" target="_blank">http://h07.w.interia.pl/Safari.rar</a></p>
<p>Advisory Reference:</p>
<p>http://secunia.com/advisories/39670/</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1054/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1054/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1054/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1054/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1054/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1054/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1054/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1054&subd=ithreats&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2010/05/08/0day-apple-safari-parent-close/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>
	</item>
		<item>
		<title>RAT for Mac</title>
		<link>http://ithreats.net/2010/04/20/rat-for-mac/</link>
		<comments>http://ithreats.net/2010/04/20/rat-for-mac/#comments</comments>
		<pubDate>Tue, 20 Apr 2010 13:30:12 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Malwares]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[coded by DCHKG]]></category>
		<category><![CDATA[HellRaiser4.2]]></category>
		<category><![CDATA[how to remove HellRaiser]]></category>
		<category><![CDATA[how to remove HellRTS]]></category>
		<category><![CDATA[lsof -i]]></category>
		<category><![CDATA[RAT for Mac]]></category>
		<category><![CDATA[Spy rat for mac]]></category>
		<category><![CDATA[trojan iPhoto Installer]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1034</guid>
		<description><![CDATA[RAT for Mac? When there&#8217;s too much RAT (Remote Administration Tool) available for Windows, people wonder if there&#8217;s good and useful RAT for Mac as well. The search and discussions about this topic goes on and on; at one point an online poll favored to continue the development: A useful description of RATs that works [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1034&subd=ithreats&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>RAT for Mac?</p>
<p>When there&#8217;s too much RAT (Remote Administration Tool) available for Windows, people wonder if there&#8217;s good and useful RAT for Mac as well.</p>
<p>The search and discussions about this topic goes on and on; at one point an online poll favored to continue the development:</p>
<p><a href="http://ithreats.files.wordpress.com/2010/04/rat-polling.png"><img class="aligncenter size-full wp-image-1035" title="RAT polling" src="http://ithreats.files.wordpress.com/2010/04/rat-polling.png?w=600&#038;h=109" alt="" width="600" height="109" /></a></p>
<p>A useful description of RATs that works in OSX can be found <a href="http://www.iantivirus.com/threats/" target="_blank">here</a>.</p>
<p>The most recent/updated development is HellRaiser version 4.2, <code>coded by DCHKG an Underground Mac Programming Team.</code></p>
<p>HellRaiser includes a configuration component, where the remote controller can specify the server parameters.</p>
<p><em><a href="http://ithreats.files.wordpress.com/2010/04/config.png"><img class="aligncenter size-full wp-image-1036" title="config" src="http://ithreats.files.wordpress.com/2010/04/config.png?w=600&#038;h=394" alt="" width="600" height="394" /></a></em>The server component is the application distributed to target OS X user. It requires manual execution to install and enable the server to run in background (hidden from dock). Once successful, the server component (or the slave) will report back to the master as shown below.</p>
<p><a href="http://ithreats.files.wordpress.com/2010/04/h4x0r1.png"><img class="size-full wp-image-1038   alignleft" title="h4x0r" src="http://ithreats.files.wordpress.com/2010/04/h4x0r1.png?w=317&#038;h=177" alt="" width="317" height="177" /></a></p>
<p>This is the same version that Intego recently discovered <a href="http://blog.intego.com/2010/04/16/intego-security-memo-hellrts-backdoor-can-allow-malicious-remote-users-to-control-macs/">in-the-wild</a> disguised as <a href="http://blog.trendmicro.com/mac-malware-disguised-as-iphoto-installer/" target="_blank">iPhoto installer</a>.</p>
<p>How would I know if HellRaiser server is installed/running?</p>
<p>option 1: You may open network utility and activity monitor (/Applications/Utilities/) and kill the process.</p>
<p>option 2: You may open terminal, and type <strong><code>lsof -i</code></strong> (this will list running processes and its matching network/internet connection). Search dubious name and internet connection, take note of the PID, and in terminal type <code><strong>kill -9 &lt;PID&gt;</strong> </code>(this will kill the process).</p>
<p>If you&#8217;re using Mac security scanner, then it&#8217;s best time to check for signature update! (most vendors detects this as OSX HellRTS)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1034/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1034/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1034/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1034/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1034/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1034/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1034/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1034/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1034/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1034/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1034/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1034/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1034/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1034/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1034&subd=ithreats&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2010/04/20/rat-for-mac/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/04/rat-polling.png" medium="image">
			<media:title type="html">RAT polling</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/04/config.png" medium="image">
			<media:title type="html">config</media:title>
		</media:content>

		<media:content url="http://ithreats.files.wordpress.com/2010/04/h4x0r1.png" medium="image">
			<media:title type="html">h4x0r</media:title>
		</media:content>
	</item>
		<item>
		<title>CVE-2010-1120</title>
		<link>http://ithreats.net/2010/04/16/cve-2010-1120/</link>
		<comments>http://ithreats.net/2010/04/16/cve-2010-1120/#comments</comments>
		<pubDate>Fri, 16 Apr 2010 06:20:30 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[CanSecWest 2010]]></category>
		<category><![CDATA[crafted PDF file opened in Preview]]></category>
		<category><![CDATA[CVE-2010-1120]]></category>
		<category><![CDATA[Pwn2Own]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1031</guid>
		<description><![CDATA[DESCRIPTION: A vulnerability has been reported in Apple Mac OS X, which can be exploited by malicious people to compromise a user&#8217;s system. The vulnerability is caused due to an indexing error in Apple Type Services within the &#8220;TType1ParsingContext::SpecialEncoding()&#8221; method in libFontParser.dylib when parsing embedded fonts. This can be exploited to corrupt memory e.g. via [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1031&subd=ithreats&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>DESCRIPTION:<br />
A vulnerability has been reported in Apple Mac OS X, which can be<br />
exploited by malicious people to compromise a user&#8217;s system.</p>
<p>The vulnerability is caused due to an indexing error in Apple Type<br />
Services within the &#8220;TType1ParsingContext::SpecialEncoding()&#8221; method<br />
in libFontParser.dylib when parsing embedded fonts. This can be<br />
exploited to corrupt memory e.g. <strong>via a specially crafted PDF file<br />
opened in Preview</strong>.</p>
<p>Successful exploitation may allow execution of arbitrary code.</p>
<p>The vulnerability is reported in Mac OS X Server 10.5, Mac OS X 10.5,<br />
Mac OS X 10.6, and Mac OS X Server 10.6.</p>
<p>SOLUTION:<br />
Apply Security Update 2010-003.</p>
<p><em>Sourced: http://secunia.com/advisories/39426/ </em></p>
<p><em>Reference: CVE-2010-1120 <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1120" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1120</a></em></p>
<p><em><strong>Description:</strong><br />
Unspecified vulnerability in Safari 4 on Apple Mac OS X 10.6 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Charlie Miller during a Pwn2Own competition at CanSecWest 2010.</em></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1031/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1031/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1031/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1031/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1031/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1031/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1031/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1031/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1031/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1031/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1031/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1031/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1031/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1031/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1031&subd=ithreats&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2010/04/16/cve-2010-1120/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>
	</item>
		<item>
		<title>Mac OS X Ransomware</title>
		<link>http://ithreats.net/2010/03/16/mac-os-x-ransomware/</link>
		<comments>http://ithreats.net/2010/03/16/mac-os-x-ransomware/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 05:35:07 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[OS X]]></category>
		<category><![CDATA[internet blocker]]></category>
		<category><![CDATA[Mac OS X ransomware]]></category>
		<category><![CDATA[mail spamming]]></category>
		<category><![CDATA[ransomeware]]></category>
		<category><![CDATA[suspecting trojan in mac]]></category>
		<category><![CDATA[weird in mac]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1024</guid>
		<description><![CDATA[I just read the blog post of Dancho this morning titled &#8220;Mac OS X SMS ransomware &#8211; hype or real threat?&#8221; Well, the Mac security community is pretty much aware of this since early last month (February 03). The package we received is source code, which serves as heads up to security researchers of what&#8217;s [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1024&subd=ithreats&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>I just read the blog post of Dancho this morning titled <em>&#8220;<a href="http://blogs.zdnet.com/security/?p=5731&amp;tag=col1;post-5731" target="_blank">Mac OS X SMS ransomware &#8211; hype or real threat?</a>&#8221; </em></p>
<p>Well, the Mac security community is pretty much aware of this since early last month (February 03). The package we received is source code, which serves as heads up to security researchers of what&#8217;s to come.</p>
<p>The underground intelligence allowed us to obtain a copy of the code for the purpose of learning disinfection to help protect Mac users for possible emergence of this threat.</p>
<p>In January, I <a href="http://community.ca.com/blogs/securityadvisor/archive/2010/01/28/taking-advantage-of-apple-ipad-hot-trending-topics.aspx" target="_blank">blogged</a> about an observation where Blackhat SEOs redirection scripts checks the browser&#8217;s USER-AGENT to identify and redirect Mac user traffics &#8211; for the hope of monetizing it. Following this post, Dancho found <a href="http://ddanchev.blogspot.com/2010/02/how-koobface-gang-monetizes-mac-os-x.html" target="_blank">similar trend</a>, where Koobface gang is also using USER-AGENT to redirect and monetize Mac users traffic. This trend raised an awareness to security community to investigate and learn why these guys are monitoring and interested to Mac users traffic &#8211; and we got our answer, we recieved the Mac OS X ransomware source code.</p>
<p>Now the questions,</p>
<p>Is it a threat to Mac users? No (not yet at the moment), but YES &#8211; this is absolutely emerging threat in Mac.</p>
<p>Is it a hype? No &#8211; there&#8217;s no exaggeration, but instead the message should serve as an awareness of this emerging threat in Mac.</p>
<p>However, we have to acknowledge that there&#8217;s on-going offensive developments in Mac and Mac users should not take chances.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1024/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1024/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1024/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1024/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1024/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1024/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1024/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1024/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1024/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1024/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1024/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1024/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1024/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1024/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1024&subd=ithreats&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2010/03/16/mac-os-x-ransomware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>
	</item>
		<item>
		<title>Apple Safari Stylesheet Redirection vulnerability</title>
		<link>http://ithreats.net/2010/01/25/apple-safari-stylesheet-redirection-vulnerability/</link>
		<comments>http://ithreats.net/2010/01/25/apple-safari-stylesheet-redirection-vulnerability/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 09:38:15 +0000</pubDate>
		<dc:creator>Methusela Cebrian Ferrer</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[safari redirected to]]></category>
		<category><![CDATA[safari stylesheet redirection]]></category>
		<category><![CDATA[suspicious safari behavior]]></category>

		<guid isPermaLink="false">http://ithreats.net/?p=1015</guid>
		<description><![CDATA[There&#8217;s a 0-day vulnerability affecting Safari 4.x users, it&#8217;s not critical, but it is important to be aware of it. &#60;link rel="stylesheet" type="text/css" href="www.yahoo.com"&#62; Hola &#60;script language="javascript"&#62; setTimeout("alert(document.styleSheets[0].href)", 10000); //setTimeout is used just to wait for page loading &#60;/script&#62; Listing 01 &#8211; Apple Safari Stylesheet Redirection PoC Cesar Cerrudo has discovered this vulnerability, and discussed [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1015&subd=ithreats&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s a 0-day vulnerability affecting Safari 4.x users, it&#8217;s not critical, but it is important to be aware of it.</p>
<p><code><br />
&lt;link rel="stylesheet" type="text/css" href="www.yahoo.com"&gt;<br />
Hola<br />
&lt;script language="javascript"&gt;<br />
setTimeout("alert(document.styleSheets[0].href)", 10000);<br />
//setTimeout is used just to wait for page loading<br />
&lt;/script&gt;</code></p>
<p><em>Listing 01 &#8211; Apple Safari Stylesheet Redirection PoC</em></p>
<p><a href="http://nomoreroot.blogspot.com/2010/01/little-bug-in-safari-and-google-chrome.html" target="_blank">Cesar Cerrudo has discovered this vulnerability</a>, and discussed that Safari wasn&#8217;t able to display the LINK specified in href value, instead it reads the stylesheets to redirect to a target URL.</p>
<p>Malicious user may take advantage of this vulnerability to steal sensitive information.</p>
<p>Be cautious when surfing the net!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithreats.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithreats.wordpress.com/1015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithreats.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithreats.wordpress.com/1015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithreats.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithreats.wordpress.com/1015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithreats.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithreats.wordpress.com/1015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithreats.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithreats.wordpress.com/1015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithreats.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithreats.wordpress.com/1015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithreats.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithreats.wordpress.com/1015/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithreats.net&blog=3681895&post=1015&subd=ithreats&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://ithreats.net/2010/01/25/apple-safari-stylesheet-redirection-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4d7b7d253fb250ab3887bbcbccd15411?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">meths</media:title>
		</media:content>
	</item>
	</channel>
</rss>