«
Expand/Collapse
88 items tagged "ios"
Related tags:
freetype [+],
Software [+],
arbitrary code execution [+],
vulnerability [+],
secunia [+],
mobile safari [+],
apple mobile [+],
apple iphone [+],
software update [+],
iphone 4 [+],
bugtraq [+],
safari [+],
pages [+],
cisco [+],
certificate [+],
apple safari [+],
vulnerabilities [+],
version [+],
valid certificate [+],
unspecified [+],
touch [+],
ssl implementation [+],
ssl check [+],
ssl certificate [+],
ssl [+],
security certificate [+],
script injection [+],
read [+],
passphrase [+],
ipod [+],
ipad [+],
ios version [+],
disclosure [+],
code execution [+],
calendar issues [+],
bar [+],
address [+],
wireless network [+],
whitepaper [+],
update [+],
untethered [+],
tgz [+],
security vulnerability [+],
security management [+],
root [+],
privacy [+],
pdf [+],
nicolas seriot [+],
malware [+],
hacks [+],
hacking [+],
hackers [+],
darknet [+],
corruption issues [+],
cisco ios [+],
charlie miller [+],
cfnetwork [+],
certificate chain [+],
black hat [+],
apple updates [+],
app [+],
advisory [+],
apple ios [+],
xbmc [+],
x uri stack [+],
updates [+],
under [+],
type font [+],
tehtri security [+],
sophos [+],
shown [+],
service vulnerability [+],
security updates [+],
security security [+],
security risk [+],
security flaws [+],
security bugs [+],
security assessments [+],
router [+],
retired [+],
researcher [+],
protection mechanisms [+],
protection [+],
pirate [+],
penetration tests [+],
patch [+],
passcode [+],
overflow [+],
mulls [+],
moment [+],
mobile os [+],
mobile control [+],
mobile [+],
mac os x [+],
mac os [+],
longing [+],
link [+],
jailbreaks [+],
ios security [+],
internet group management protocol [+],
infosec world [+],
http [+],
html [+],
hours [+],
home [+],
hole [+],
hardware encryption [+],
hackers square [+],
hacker [+],
fine [+],
entertainment [+],
encryption [+],
draws [+],
dmitry sklyarov [+],
developer program [+],
dev [+],
detection [+],
denial of service [+],
david vieira [+],
data [+],
critical [+],
control 1 [+],
control [+],
comex [+],
cisco security advisory [+],
cisco security [+],
cisco patches [+],
cisco ios software [+],
cisco fixes [+],
child privacy [+],
buffer overflow vulnerability [+],
buffer [+],
box [+],
banning [+],
avr compiler [+],
arduino [+],
apple tv [+],
apple removes [+],
apple pages [+],
apple numbers [+],
apple jailbreak [+],
apple delivers [+],
apple bans [+],
android [+],
and [+],
adressbar [+],
abu dhabi [+],
Public [+],
Hardware [+],
Fixes [+],
3gs [+],
security [+],
security advisory [+],
apple security [+],
apple [+],
memory corruption [+],
iphone [+],
multiple [+],
memory [+],
jailbreak [+]
-
-
18:48
»
Packet Storm Security Misc. Files
This whitepaper details some of the vulnerabilities observed over the past year while performing regular security assessments of iPhone and iPad applications. MDSec documents some of the vulnerabilities identified as well as the methods to exploit them, and recommendations that developers can adopt to protect their iOS applications. It covers not only the security features of the platform, but provides in depth information on how to perform both black box and white box iOS penetration tests, along with suggested methodologies and compliance.
-
-
11:01
»
Hack a Day
It’s surprising what lengths people will go to in order to bring functionality to their smart phones. In this case, [Tadpol] wanted a way to develop for his Arduino on an iOS device like an iPad or iPhone. He figures it’s possible to rewrite the IDE as HTML5, but since that’s a pretty large mountain [...]
-
-
21:06
»
Packet Storm Security Advisories
Secunia Security Advisory - David Vieira-Kurz has discovered a vulnerability in Apple iOS, which can be exploited by malicious people to conduct spoofing attacks.
-
-
14:23
»
Packet Storm Security Advisories
Apple Security Advisory 2012-03-07-2 - iOS 5.1 Software Update is now available and addresses 81 vulnerabilities.
-
-
21:41
»
SecDocs
Authors:
Andrey Belenko Dmitry Sklyarov Tags:
forensic iPhone Event:
Black Hat Abu Dhabi 2011 Abstract: iOS 5 is the latest and most advanced mobile OS from Apple. Besides tweaking UI and UX, Apple has made some changes to Data Protection mechanisms that were introduced in iOS 4. Those changes provide better security for users, but they also impose additional hurdles for mobile phone forensic process. This talk will provide detailed discussion of iOS Data Protection, focusing on both technical description of defenses and on circumventing certain protections to provide forensic access to the data stored on the iOS devices. iOS versions from iOS 3 (iPhoneOS 3) to iOS 5 will be covered.
-
-
8:09
»
Packet Storm Security Recent Files
Whitepaper called Hacking Dispositivos iOS. It demonstrates how dangerous it is to be connected to a wireless network with an iOS device that has OpenSSH enabled. Written in Spanish.
-
8:09
»
Packet Storm Security Misc. Files
Whitepaper called Hacking Dispositivos iOS. It demonstrates how dangerous it is to be connected to a wireless network with an iOS device that has OpenSSH enabled. Written in Spanish.
-
-
21:08
»
Packet Storm Security Recent Files
Apple Security Advisory 2011-11-10-1 - The new iOS 5.0.1 software update addresses multiple vulnerabilities. An issue existed in CFNetwork's handling of maliciously crafted URLs. When accessing a maliciously crafted HTTP or HTTPS URL, CFNetwork could navigate to an incorrect server. Multiple memory corruption issues existed in FreeType, the most serious of which may lead to arbitrary code execution when processing a maliciously crafted font. Various other issues were also addressed.
-
21:08
»
Packet Storm Security Misc. Files
Apple Security Advisory 2011-11-10-1 - The new iOS 5.0.1 software update addresses multiple vulnerabilities. An issue existed in CFNetwork's handling of maliciously crafted URLs. When accessing a maliciously crafted HTTP or HTTPS URL, CFNetwork could navigate to an incorrect server. Multiple memory corruption issues existed in FreeType, the most serious of which may lead to arbitrary code execution when processing a maliciously crafted font. Various other issues were also addressed.
-
-
2:16
»
Packet Storm Security Advisories
Secunia Security Advisory - Two vulnerabilities have been reported in Apple Numbers for iOS, which can be exploited by malicious people to compromise a user's device.
-
2:15
»
Packet Storm Security Advisories
Secunia Security Advisory - A vulnerability has been reported in Apple Pages for iOS, which can be exploited by malicious people to compromise a user's device.
-
-
19:45
»
Packet Storm Security Advisories
Apple Security Advisory 2011-10-12-6 - Numbers for iOS version 1.5 is now available and addresses multiple arbitrary code execution vulnerabilities.
-
19:45
»
Packet Storm Security Recent Files
Apple Security Advisory 2011-10-12-6 - Numbers for iOS version 1.5 is now available and addresses multiple arbitrary code execution vulnerabilities.
-
19:45
»
Packet Storm Security Misc. Files
Apple Security Advisory 2011-10-12-6 - Numbers for iOS version 1.5 is now available and addresses multiple arbitrary code execution vulnerabilities.
-
19:42
»
Packet Storm Security Advisories
Apple Security Advisory 2011-10-12-5 - Pages for iOS version 1.5 is now available and addresses an arbitrary code execution vulnerability.
-
19:28
»
Packet Storm Security Advisories
Apple Security Advisory 2011-10-12-1 - An iOS 5 software update is now available. It addresses an SSL check in CalDAV, a script injection issue in Calendar, issues in CFNetwork, and 90+ other security issues.
-
19:28
»
Packet Storm Security Recent Files
Apple Security Advisory 2011-10-12-1 - An iOS 5 software update is now available. It addresses an SSL check in CalDAV, a script injection issue in Calendar, issues in CFNetwork, and 90+ other security issues.
-
19:28
»
Packet Storm Security Misc. Files
Apple Security Advisory 2011-10-12-1 - An iOS 5 software update is now available. It addresses an SSL check in CalDAV, a script injection issue in Calendar, issues in CFNetwork, and 90+ other security issues.
-
-
23:25
»
Sophos product advisories
You are not able to install Sophos Mobile Control (SMC) 1.1 on devices where the operating system was updated to iOS 5. The device displays the error 'Download failed. Safari cannot download this file.'
-
-
10:01
»
SecDocs
Authors:
Nicolas Seriot Tags:
malware iPhone rootkit Event:
Hashdays 2010 Abstract: Apple's AppStore moves the burden of security management from the user to the vendor. Apple semi-automatically verifies each of the 200.000 applications and their updates. Moreover, when an application is downloaded on the iPhone, a sandboxing mechanism is supposed to prevent it from reading other applications' data. We showed at Black Hat DC 2010 that such a schema did not prevent malware from reaching the App Store and harvesting personal data. This talk will discuss the current state of iOS 4 privacy and show to what extent iOS 4 fixes the issues raised earlier this year. We will also present some findings about another possible frauds happening inside the App Store eco-system such as "App Farms", which basically consists in artificially boosting applications ratings with stolen accounts.
-
10:01
»
SecDocs
Authors:
Nicolas Seriot Tags:
malware iPhone rootkit Event:
Hashdays 2010 Abstract: Apple's AppStore moves the burden of security management from the user to the vendor. Apple semi-automatically verifies each of the 200.000 applications and their updates. Moreover, when an application is downloaded on the iPhone, a sandboxing mechanism is supposed to prevent it from reading other applications' data. We showed at Black Hat DC 2010 that such a schema did not prevent malware from reaching the App Store and harvesting personal data. This talk will discuss the current state of iOS 4 privacy and show to what extent iOS 4 fixes the issues raised earlier this year. We will also present some findings about another possible frauds happening inside the App Store eco-system such as "App Farms", which basically consists in artificially boosting applications ratings with stolen accounts.
-
-
23:44
»
Packet Storm Security Advisories
Secunia Security Advisory - A vulnerability has been reported in Apple iOS, which can be exploited by malicious people to conduct spoofing attacks.
-
19:53
»
Packet Storm Security Advisories
iOS's SSL certificate parsing contains a flaw where it fails to check the basicConstraints parameter of certificates in the chain. By signing a new certificate using a legitimate end entity certificate, an attacker can obtain a "valid" certificate for any domain.
-
19:53
»
Packet Storm Security Recent Files
iOS's SSL certificate parsing contains a flaw where it fails to check the basicConstraints parameter of certificates in the chain. By signing a new certificate using a legitimate end entity certificate, an attacker can obtain a "valid" certificate for any domain.
-
19:53
»
Packet Storm Security Misc. Files
iOS's SSL certificate parsing contains a flaw where it fails to check the basicConstraints parameter of certificates in the chain. By signing a new certificate using a legitimate end entity certificate, an attacker can obtain a "valid" certificate for any domain.
-
-
1:24
»
Packet Storm Security Advisories
Secunia Security Advisory - A vulnerability has been reported in Apple iOS, which can be exploited by malicious people to compromise a vulnerable system.
-
-
23:25
»
Packet Storm Security Advisories
Secunia Security Advisory - Some vulnerabilities has been reported in Apple iOS, which can be exploited by malicious people to disclose system information and compromise a vulnerable device.
-
-
8:30
»
Hack a Day
For those who have been longing to unlock the power of the Apple TV 2 the wait is over. XBMC is now available for iOS devices. This isn’t limited to the tiny ARM-based set-top box, but extends to the entire family including iPad and iPhone 4. Included is the ability to play high def video [...]