MAAS History
Disclaimer
exocrine exocrine

All information Provided as is.

Entries in Condition:GREEN (119)

Tuesday
Apr122011

Condition GREEN

We are aware of a report of an iPhone virus called "Unlock For Free", this appears to be UNCONFIRMED. We consider it as Hoax at this time. There are plenty of domains related to unlocking your phone based on the model which all types of utilities to alter mobile devices. iOS devices are listed as well. 

What to do:

 

  • Do not spread the rumor or forward links related to the hoax.
  • Make sure that you do not jailbreak or unlock your iOS device unless you understand the security implications.
  • Do not click links in email from untrusted sources. 
  • Turn off Auto Fill in mobile Safari and Safari web browsers. 

 

Monday
Apr112011

Condition Remains GREEN

Adobe has posted Security Advisory APSA11-02 for Adobe Flash Player, Acrobat and Reader related to the Authplay.dll. The exploit was first reported publicly by http://krebsonsecurity.com/. The 0day is being used as part of a spear phishing campaign which includes a Microsoft Word document with the .SWF file embedded within it. At this time there is no attack specific to Mac OSX or iOS. 

Users and Administrators should take the following action:

  • Do not install Adobe products such as Reader or Flash on Mac OSX production servers.
  • Use Preview.app for PDF files.
  • Do not download files that are un-trusted via email. 
  • Disable Flash Player if you do not need it.
  • Use No Script, Click to Flash or Flash Block to block Flash content. 
  • Run the Flash Player via a Script in /usr/share/sandbox or custom script using any of the following: /usr/bin/sand-exec or /usr/bin/sand_init() ** See man pages for specifics. 
  • Beware of any attachments from un-trusted sources.
  • Do not add to the problem by forwarding an email from an un-trusted source.