<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: &#8220;Exploit code targets Mac OS X, iTunes, Java, Winzip&#8230;&#8221;</title>
	<atom:link href="http://geekblog.oakcircle.com/2008/07/28/exploit-code-targets-mac-os-x-itunes-java-winzip/feed/" rel="self" type="application/rss+xml" />
	<link>http://geekblog.oakcircle.com/2008/07/28/exploit-code-targets-mac-os-x-itunes-java-winzip/</link>
	<description>Miscellaneous ramblings on miscellaneous topics</description>
	<lastBuildDate>Mon, 06 Feb 2012 22:18:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Head Geek</title>
		<link>http://geekblog.oakcircle.com/2008/07/28/exploit-code-targets-mac-os-x-itunes-java-winzip/comment-page-1/#comment-1829</link>
		<dc:creator>Head Geek</dc:creator>
		<pubDate>Thu, 31 Jul 2008 02:41:00 +0000</pubDate>
		<guid isPermaLink="false">http://geekblog.oakcircle.com/?p=609#comment-1829</guid>
		<description>&lt;p&gt;Ah. Yes, other programs are still vulnerable, until their authors provide secure (signed) updates.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Ah. Yes, other programs are still vulnerable, until their authors provide secure (signed) updates.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Ploni Almoni</title>
		<link>http://geekblog.oakcircle.com/2008/07/28/exploit-code-targets-mac-os-x-itunes-java-winzip/comment-page-1/#comment-1827</link>
		<dc:creator>Ploni Almoni</dc:creator>
		<pubDate>Wed, 30 Jul 2008 21:21:49 +0000</pubDate>
		<guid isPermaLink="false">http://geekblog.oakcircle.com/?p=609#comment-1827</guid>
		<description>&lt;p&gt;Not for plug-ins and other updates. I wasn&#039;t thinking of Windows Update.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Not for plug-ins and other updates. I wasn&#8217;t thinking of Windows Update.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Head Geek</title>
		<link>http://geekblog.oakcircle.com/2008/07/28/exploit-code-targets-mac-os-x-itunes-java-winzip/comment-page-1/#comment-1826</link>
		<dc:creator>Head Geek</dc:creator>
		<pubDate>Wed, 30 Jul 2008 15:06:17 +0000</pubDate>
		<guid isPermaLink="false">http://geekblog.oakcircle.com/?p=609#comment-1826</guid>
		<description>&lt;p&gt;If he&#039;s running Windows, he&#039;s probably safe -- as mentioned above, Microsoft is almost certain to be using code-signing already.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>If he&#8217;s running Windows, he&#8217;s probably safe &#8212; as mentioned above, Microsoft is almost certain to be using code-signing already.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Ploni Almoni</title>
		<link>http://geekblog.oakcircle.com/2008/07/28/exploit-code-targets-mac-os-x-itunes-java-winzip/comment-page-1/#comment-1825</link>
		<dc:creator>Ploni Almoni</dc:creator>
		<pubDate>Wed, 30 Jul 2008 12:13:33 +0000</pubDate>
		<guid isPermaLink="false">http://geekblog.oakcircle.com/?p=609#comment-1825</guid>
		<description>&lt;p&gt;What is really bad about this is that I&#039;d been trying to encourage a friend who&#039;s system keeps getting infected to pay attention to update messages and not worry if they are going to &quot;mess up his computer&quot;, now I have to worry about this and am not sure if I feel confident in telling him that the benefits outweigh the risks. (Forget about getting him to update manually - like most computer users he prefers to take the path of least resistance, a bad course to take if you use Windows.)&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>What is really bad about this is that I&#8217;d been trying to encourage a friend who&#8217;s system keeps getting infected to pay attention to update messages and not worry if they are going to &#8220;mess up his computer&#8221;, now I have to worry about this and am not sure if I feel confident in telling him that the benefits outweigh the risks. (Forget about getting him to update manually &#8211; like most computer users he prefers to take the path of least resistance, a bad course to take if you use Windows.)</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Ploni Almoni</title>
		<link>http://geekblog.oakcircle.com/2008/07/28/exploit-code-targets-mac-os-x-itunes-java-winzip/comment-page-1/#comment-1824</link>
		<dc:creator>Ploni Almoni</dc:creator>
		<pubDate>Wed, 30 Jul 2008 12:11:01 +0000</pubDate>
		<guid isPermaLink="false">http://geekblog.oakcircle.com/?p=609#comment-1824</guid>
		<description>&lt;p&gt;Yeah, I also note Open Office is in the list - so try to apply updates only from the website I guess, and hope it too hasn&#039;t been forged.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Yeah, I also note Open Office is in the list &#8211; so try to apply updates only from the website I guess, and hope it too hasn&#8217;t been forged.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Head Geek</title>
		<link>http://geekblog.oakcircle.com/2008/07/28/exploit-code-targets-mac-os-x-itunes-java-winzip/comment-page-1/#comment-1823</link>
		<dc:creator>Head Geek</dc:creator>
		<pubDate>Tue, 29 Jul 2008 21:29:44 +0000</pubDate>
		<guid isPermaLink="false">http://geekblog.oakcircle.com/?p=609#comment-1823</guid>
		<description>&lt;p&gt;As the article says, DNS cache poisoning is only the latest way to set up the man-in-the-middle attack. I know of at least a couple others, and I just watch this stuff out of curiosity -- you can bet that anyone actually doing something with it knows a lot more.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>As the article says, DNS cache poisoning is only the latest way to set up the man-in-the-middle attack. I know of at least a couple others, and I just watch this stuff out of curiosity &#8212; you can bet that anyone actually doing something with it knows a lot more.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Ploni Almoni</title>
		<link>http://geekblog.oakcircle.com/2008/07/28/exploit-code-targets-mac-os-x-itunes-java-winzip/comment-page-1/#comment-1822</link>
		<dc:creator>Ploni Almoni</dc:creator>
		<pubDate>Tue, 29 Jul 2008 15:03:56 +0000</pubDate>
		<guid isPermaLink="false">http://geekblog.oakcircle.com/?p=609#comment-1822</guid>
		<description>&lt;p&gt;OS X Leopard has code-signing features. Trust Apple to have a security feature but not use it, assuming this is a Leopard exploit and not just Tiger and earlier. Of course, one&#039;s susceptibility is much reduced if one uses OpenDNS - the man in the middle attack usually relies on cache poisoning. Speaking of which, APPLE? PATCH BIND ON OS X! (Assuming anyone uses OS X as a DNS server... :-) )&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>OS X Leopard has code-signing features. Trust Apple to have a security feature but not use it, assuming this is a Leopard exploit and not just Tiger and earlier. Of course, one&#8217;s susceptibility is much reduced if one uses OpenDNS &#8211; the man in the middle attack usually relies on cache poisoning. Speaking of which, APPLE? PATCH BIND ON OS X! (Assuming anyone uses OS X as a DNS server&#8230; <img src='http://geekblog.oakcircle.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  )</p>]]></content:encoded>
	</item>
</channel>
</rss>

