<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AllThingsD &#187; exploit</title>
	<atom:link href="http://allthingsd.com/tag/exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://allthingsd.com</link>
	<description></description>
	<lastBuildDate>Sat, 11 Feb 2012 15:49:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><image>
		  <url>http://allthingsd.com/theme/images/logo-rss.jpg</url>
		  <title>All Things Digital</title>
		  <link>http://allthingsd.com/</link>
		  <width>144</width>
		  <height>22</height>
	</image>		<item>
		<title>Yes, Apple's Working on a Fix for That Safari Autofill Hack</title>
		<link>http://allthingsd.com/20100722/yes-apples-working-on-fix-for-safari-autofill-hack/</link>
		<comments>http://allthingsd.com/20100722/yes-apples-working-on-fix-for-safari-autofill-hack/#comments</comments>
		<pubDate>Thu, 22 Jul 2010 21:08:17 +0000</pubDate>
		<dc:creator>John Paczkowski</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[John Paczkowski]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[Safari Autofill Hack]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://digitaldaily.allthingsd.com/?p=45370</guid>
		<description><![CDATA[So that Safari AutoFill vulnerability? The one that can reportedly be exploited to pilfer a user’s first name, last name, work place, city, state, and email address? Apple’s aware of it and working to repair it.]]></description>
			<content:encoded><![CDATA[<p><img src="http://digitaldaily.allthingsd.com/files/2010/07/appleworm.jpg" alt="" title="appleworm" width="150" height="130" class="alignright size-full wp-image-45373" />So that <a href="http://voices.allthingsd.com/20100722/apple-crowned-miss-software-insecurity-2010/">Safari AutoFill vulnerability</a>? The one that can reportedly be exploited to <a href="http://jeremiahgrossman.blogspot.com/2010/07/i-know-who-your-name-where-you-work-and.html">pilfer a user’s first name, last name, work place, city, state, and email address</a>? Apple’s aware of it and working to repair it. &#8220;We take security and privacy very seriously,&#8221; a spokesperson tells me. &#8220;We&#8217;re aware of the issue and working on a fix.&#8221;</p>
<p>When does Apple expect to issue that fix? The company won&#8217;t say.</p>
<p>[<em>Image credit: <a href="http://www.engadget.com/2007/07/23/safari-exploit-gives-hackers-full-control-of-your-iphone/">Engadget</a></em>] </p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20100722/yes-apples-working-on-fix-for-safari-autofill-hack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>So Much for Hijacking &quot;Every iPhone in the World&quot;</title>
		<link>http://allthingsd.com/20090731/so-much-for-hijacking-every-iphone-in-the-world/</link>
		<comments>http://allthingsd.com/20090731/so-much-for-hijacking-every-iphone-in-the-world/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 20:14:10 +0000</pubDate>
		<dc:creator>John Paczkowski</dc:creator>
				<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[AAPL]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Charlie Miller]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[flaw]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPhone OS 3.0.1]]></category>
		<category><![CDATA[John Paczkowski]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[personal information]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SMS]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[telecom]]></category>
		<category><![CDATA[text messaging]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://digitaldaily.allthingsd.com/?p=22594</guid>
		<description><![CDATA[Once again, the iPhone is safe for text messaging. Apple on Friday distributed iPhone OS 3.0.1, a point release to the operating system that addresses a security vulnerability that could have allowed a malicious hacker to seize control of an iPhone with an unusual SMS text message.]]></description>
			<content:encoded><![CDATA[<p><img src="http://digitaldaily.allthingsd.com/files/2009/07/iphone-pwned.jpg" alt="iphone-pwned" title="iphone-pwned" width="150" height="150" class="alignright size-full wp-image-22596" />Once again, the iPhone is safe for text messaging. Apple on Friday distributed  <a href="http://support.apple.com/kb/HT3754">iPhone OS 3.0.1</a>,  a point release to the operating system that addresses a <a href="http://www.forbes.com/2009/07/28/hackers-iphone-apple-technology-security-hackers.html">security vulnerability</a> that could have allowed a malicious hacker to seize control of an iPhone with an unusual SMS text message.</p>
<p>The flaw was <a href="http://news.cnet.com/8301-27080_3-10299378-245.html?tag=TOCmoreStories.0">first demonstrated Thursday.</a> &#8220;This is serious. The only thing you can do to prevent it is turn off your phone,&#8221; security researcher Charlie Miller said of it earlier this week. &#8220;Someone could pretty quickly take over every iPhone in the world with this.&#8221;</p>
<p>Well, not anymore, as Apple (AAPL) was quick to note. &#8220;This morning, less than 24 hours after a demonstration of this exploit, we’ve issued a free software update that eliminates the vulnerability from the iPhone,&#8221; said an Apple spokesperson. &#8220;Contrary to what’s been reported, no one has been able to take control of the iPhone to gain access to personal information using this exploit.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20090731/so-much-for-hijacking-every-iphone-in-the-world/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>So Much for Hijacking "Every iPhone in the World"</title>
		<link>http://allthingsd.com/20090731/so-much-for-hijacking-every-iphone-in-the-world-2/</link>
		<comments>http://allthingsd.com/20090731/so-much-for-hijacking-every-iphone-in-the-world-2/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 20:14:10 +0000</pubDate>
		<dc:creator>John Paczkowski</dc:creator>
				<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[AAPL]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Charlie Miller]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[flaw]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPhone OS 3.0.1]]></category>
		<category><![CDATA[John Paczkowski]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[personal information]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SMS]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[telecom]]></category>
		<category><![CDATA[text messaging]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://digitaldaily.allthingsd.com/?p=22594</guid>
		<description><![CDATA[Once again, the iPhone is safe for text messaging. Apple on Friday distributed iPhone OS 3.0.1, a point release to the operating system that addresses a security vulnerability that could have allowed a malicious hacker to seize control of an iPhone with an unusual SMS text message.]]></description>
			<content:encoded><![CDATA[<p><img src="http://digitaldaily.allthingsd.com/files/2009/07/iphone-pwned.jpg" alt="iphone-pwned" title="iphone-pwned" width="150" height="150" class="alignright size-full wp-image-22596" />Once again, the iPhone is safe for text messaging. Apple on Friday distributed  <a href="http://support.apple.com/kb/HT3754">iPhone OS 3.0.1</a>,  a point release to the operating system that addresses a <a href="http://www.forbes.com/2009/07/28/hackers-iphone-apple-technology-security-hackers.html">security vulnerability</a> that could have allowed a malicious hacker to seize control of an iPhone with an unusual SMS text message.   </p>
<p>The flaw was <a href="http://news.cnet.com/8301-27080_3-10299378-245.html?tag=TOCmoreStories.0">first demonstrated Thursday.</a> &#8220;This is serious. The only thing you can do to prevent it is turn off your phone,&#8221; security researcher Charlie Miller said of it earlier this week. &#8220;Someone could pretty quickly take over every iPhone in the world with this.&#8221;</p>
<p>Well, not anymore, as Apple (AAPL) was quick to note. &#8220;This morning, less than 24 hours after a demonstration of this exploit, we’ve issued a free software update that eliminates the vulnerability from the iPhone,&#8221; said an Apple spokesperson. &#8220;Contrary to what’s been reported, no one has been able to take control of the iPhone to gain access to personal information using this exploit.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20090731/so-much-for-hijacking-every-iphone-in-the-world-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Here&#039;s a Patch for You, Adobe: \Acrobat\Uninstall.exe</title>
		<link>http://allthingsd.com/20090220/heres-a-patch-for-you-adobe-acrobatuninstallexe/</link>
		<comments>http://allthingsd.com/20090220/heres-a-patch-for-you-adobe-acrobatuninstallexe/#comments</comments>
		<pubDate>Fri, 20 Feb 2009 17:03:56 +0000</pubDate>
		<dc:creator>John Paczkowski</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Acrobat]]></category>
		<category><![CDATA[Adobe Reader]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Foxit]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Javascript]]></category>
		<category><![CDATA[John Paczkowski]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[preview]]></category>
		<category><![CDATA[sercurity]]></category>
		<category><![CDATA[Shadowserver]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Xpdf]]></category>

		<guid isPermaLink="false">http://digitaldaily.allthingsd.com/?p=13265</guid>
		<description><![CDATA[There’s a critical vulnerability in Adobe Reader and Acrobat and at least one zero-day exploit for them in the wild already. Yet Adobe won’t have a fix in place until March 11, and then only for Adobe Reader 9 and Acrobat 9. Patches for earlier versions of the software will arrive sometime after that.
Two and half weeks or longer to wait for a critical patch.]]></description>
			<content:encoded><![CDATA[<p><img src="http://digitaldaily.allthingsd.com/files/2009/02/adobe-acrobat-reader-256x256-150x150.png" alt="adobe-acrobat-reader-256x256" width="150" height="150" class="alignright size-thumbnail wp-image-13267" />There&#8217;s <a href="http://www.adobe.com/support/security/advisories/apsa09-01.html">a critical vulnerability in Adobe&#8217;s Reader and Acrobat PDF software</a> and <a href="http://www.avertlabs.com/research/blog/index.php/2009/02/19/new-backdoor-attacks-using-pdf-documents/">at least one zero-day exploit</a> for them in the wild already. Yet Adobe (ADBE) won&#8217;t have a fix in place until March 11, and then only for Adobe Reader 9 and Acrobat 9. Patches for earlier versions of the software will arrive sometime after that.</p>
<p>Two and half weeks or longer to wait for a critical patch.</p>
<p>In the meantime, exploits for the flaw will no doubt grow in number and cunning&#8211;a nightmare since the PDF format and Adobe&#8217;s related apps are so widely used. &#8220;Right now we believe these files are only being used in a smaller set of targeted attacks,&#8221; <a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219">security group Shadowserver said in an advisory on the matter</a>. &#8220;However, these types of attacks are frequently the most damaging and it is only a matter of time before this exploit ends up in every exploit pack on the Internet.&#8221;</p>
<p>Shadowserver recommends disabling Javascript in Acrobat and Reader to limit exposure to such attacks.  There are, of course, other solutions as well&#8211;<a href="http://www.foxitsoftware.com/">Foxit</a> for Windows users, <a href="http://www.apple.com/macosx/features/300.html#preview">Preview</a> for Mac users, and <a href="http://www.foolabs.com/xpdf/about.html">Xpdf</a> for Linux users.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20090220/heres-a-patch-for-you-adobe-acrobatuninstallexe/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Here's a Patch for You, Adobe: AcrobatUninstall.exe</title>
		<link>http://allthingsd.com/20090220/heres-a-patch-for-you-adobe-acrobatuninstallexe-2/</link>
		<comments>http://allthingsd.com/20090220/heres-a-patch-for-you-adobe-acrobatuninstallexe-2/#comments</comments>
		<pubDate>Fri, 20 Feb 2009 17:03:56 +0000</pubDate>
		<dc:creator>John Paczkowski</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Acrobat]]></category>
		<category><![CDATA[Adobe Reader]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Foxit]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Javascript]]></category>
		<category><![CDATA[John Paczkowski]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[preview]]></category>
		<category><![CDATA[sercurity]]></category>
		<category><![CDATA[Shadowserver]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Xpdf]]></category>

		<guid isPermaLink="false">http://digitaldaily.allthingsd.com/?p=13265</guid>
		<description><![CDATA[There’s a critical vulnerability in Adobe Reader and Acrobat and at least one zero-day exploit for them in the wild already. Yet Adobe won’t have a fix in place until March 11, and then only for Adobe Reader 9 and Acrobat 9. Patches for earlier versions of the software will arrive sometime after that.
Two and half weeks or longer to wait for a critical patch.]]></description>
			<content:encoded><![CDATA[<p><img src="http://digitaldaily.allthingsd.com/files/2009/02/adobe-acrobat-reader-256x256-150x150.png" alt="adobe-acrobat-reader-256x256" width="150" height="150" class="alignright size-thumbnail wp-image-13267" />There&#8217;s <a href="http://www.adobe.com/support/security/advisories/apsa09-01.html">a critical vulnerability in Adobe&#8217;s Reader and Acrobat PDF software</a> and <a href="http://www.avertlabs.com/research/blog/index.php/2009/02/19/new-backdoor-attacks-using-pdf-documents/">at least one zero-day exploit</a> for them in the wild already. Yet Adobe (ADBE) won&#8217;t have a fix in place until March 11, and then only for Adobe Reader 9 and Acrobat 9. Patches for earlier versions of the software will arrive sometime after that.</p>
<p>Two and half weeks or longer to wait for a critical patch.</p>
<p>In the meantime, exploits for the flaw will no doubt grow in number and cunning&#8211;a nightmare since the PDF format and Adobe&#8217;s related apps are so widely used. &#8220;Right now we believe these files are only being used in a smaller set of targeted attacks,&#8221; <a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219">security group Shadowserver said in an advisory on the matter</a>. &#8220;However, these types of attacks are frequently the most damaging and it is only a matter of time before this exploit ends up in every exploit pack on the Internet.&#8221; </p>
<p>Shadowserver recommends disabling Javascript in Acrobat and Reader to limit exposure to such attacks.  There are, of course, other solutions as well&#8211;<a href="http://www.foxitsoftware.com/">Foxit</a> for Windows users, <a href="http://www.apple.com/macosx/features/300.html#preview">Preview</a> for Mac users, and <a href="http://www.foolabs.com/xpdf/about.html">Xpdf</a> for Linux users.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20090220/heres-a-patch-for-you-adobe-acrobatuninstallexe-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Explorer Found in Serious Security Flaw</title>
		<link>http://allthingsd.com/20081216/maybe-you-should-rename-it-aieeeeeee/</link>
		<comments>http://allthingsd.com/20081216/maybe-you-should-rename-it-aieeeeeee/#comments</comments>
		<pubDate>Tue, 16 Dec 2008 19:41:45 +0000</pubDate>
		<dc:creator>John Paczkowski</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[John Paczkowski]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://digitaldaily.allthingsd.com/?p=9746</guid>
		<description><![CDATA[There’s a critical security hole in Internet Explorer, Microsoft’s flagship browser. Well, there's a shocker. IE’s catalog of vulnerabilities and the security bulletins announcing them are so voluminous and overlarge at this point, it takes Security Focus 18 pages to list them all. So reports today that IE suffers from a vulnerability that affords attackers access to any sensitive data on your PC isn’t unusual. What is unusual is that the flaw--found in all versions of the browser--is being widely exploited.]]></description>
			<content:encoded><![CDATA[<p><img src="http://digitaldaily.allthingsd.com/files/2008/12/noie.jpg" alt="" title="noie" width="200" height="200" class="alignright size-full wp-image-9770" />There’s a <a href="http://news.bbc.co.uk/2/hi/technology/7784908.stm">critical security hole in Internet Explorer</a>, Microsoft&#8217;s (MSFT) flagship browser.</p>
<p>Well, there&#8217;s a shocker. IE&#8217;s <a href="http://www.securityfocus.com/cgi-bin/index.cgi?c=12&amp;op=display_list&amp;vendor=Microsoft&amp;title=Internet%20Explorer%22%3E">catalog of vulnerabilities</a> and the security bulletins announcing them are so voluminous and overlarge at this point, it takes Security Focus 18 pages to list them all. So reports today that IE suffers from a vulnerability that <a href="http://www.microsoft.com/technet/security/advisory/961051.mspx">affords attackers access to any sensitive data on your PC</a> isn&#8217;t unusual. What is unusual is that <a href="http://sophos.com/support/knowledgebase/article/50389.html">the flaw</a>&#8211;found in all Windows versions of the browser&#8211;has gone unpatched for so long that it&#8217;s being <a href="http://www.sophos.com/security/blog/2008/12/2204.html">widely exploited</a>. &#8220;Based on our stats, since the vulnerability has gone public, roughly 0.2 percent of users worldwide may have been exposed to Web sites containing exploits of this latest vulnerability,&#8221; <a href="http://blogs.technet.com/mmpc/archive/2008/12/13/the-new-ie-exploits-for-advisory-961051-now-hosted-on-pornography-sites.aspx">the Microsoft Malware Protection Center said Saturday</a>. &#8220;That percentage may seem low, however it still means that a significant number of users have been affected. The trend for now is going upwards: we saw an increase of over 50 percent in the number of reports today compared to yesterday.&#8221;</p>
<p>And that was three days ago (the Microsoft Malware Protection Center has been oddly silent the past few days).</p>
<p>What&#8217;s an IE user to do? <a href="http://blogs.technet.com/swi/archive/2008/12/12/Clarification-on-the-various-workarounds-from-the-recent-IE-advisory.aspx#workarounds">Microsoft has a few suggestions</a>&#8211;&#8220;follow our Protect Your PC guidance&#8221; (&#8230; BAHAHAHAHA)&#8211;but really, at this point it&#8217;s obvious what needs to be done. <a href="http://getfirefox.com/">Find</a>. <a href="http://www.apple.com/safari/download/">Yourself</a>. <a href="http://www.opera.com/">Another</a>. <a href="http://caminobrowser.org/">Browser</a>.</p>
<p>Here&#8217;s looking forward to the next browser market share report&#8230;.</p>
<p>[<em>Image credit: <a href="http://www.billnavarro.com/">Bill Navarro</a></em>]</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20081216/maybe-you-should-rename-it-aieeeeeee/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

