Focus on Apple
Month of Apple Bugs Dec 19 2006 03:33PM
mfossi securityfocus com (4 replies)
Re: Month of Apple Bugs Dec 20 2006 04:54PM
jot (jot cotse net) (2 replies)
Re: Month of Apple Bugs Dec 20 2006 07:01PM
Mark Senior (senatorfrog gmail com) (2 replies)
Re: Month of Apple Bugs Dec 20 2006 11:32PM
K F \(lists\) (kf_lists digitalmunition com)
Re: Month of Apple Bugs Dec 20 2006 10:39PM
Dave Schroeder (das doit wisc edu)
Re: Month of Apple Bugs Dec 20 2006 05:12PM
Dave Schroeder (das doit wisc edu)
Re: Month of Apple Bugs Dec 19 2006 04:56PM
Dave Schroeder (das doit wisc edu) (1 replies)
Re: Month of Apple Bugs Dec 19 2006 07:10PM
K F \(lists\) (kf_lists digitalmunition com)
Re: Month of Apple Bugs Dec 19 2006 04:16PM
Philippe Devallois (phdevallois intego com) (3 replies)
Re: Month of Apple Bugs Dec 20 2006 12:51AM
David Fedoruk (david fedoruk gmail com) (1 replies)
Re: Month of Apple Bugs Dec 20 2006 02:39PM
Dave Schroeder (das doit wisc edu)
Re: Month of Apple Bugs Dec 19 2006 07:03PM
david (macosxforme gmail com)

On Dec 19, 2006, at 11:16 AM, Philippe Devallois wrote:

>
> On 19 déc. 06, at 16:33, mfossi (at) securityfocus (dot) com [email concealed] wrote:
>
>> Coming to a Mac near you in January...
>>
>> http://blog.washingtonpost.com/securityfix/2006/12/
>> january_2007_month_of_apple_bu.html
>>
>
> Thanks, but before that, you may look at this report:
>
> http://lists.apple.com/archives/macos-x-server/2006/Dec/msg00422.html
>

To which the most appropriate reply I've seen so far is:

On Dec 19, 2006, at 12:29 PM, Dave Schroeder wrote (on the Apple OS X
Server mailing list):

> Compromises via vulnerable PHP-based web applications where things
> end up in /tmp or /var/tmp are ridiculously common, and just as
> applicable to Mac OS X as any other platform, and I'd bet nearly
> anything that's what this represents, not some scary "new" OS X
> compromise. That directory is probably owned by www, and probably
> just means this person is running insecure/vulnerable web
> applications on the machine.
>
> Can the original poster confirm, please? What is the ownership on
> this ".darwin" directory?
>

[ reply ]
Re: Month of Apple Bugs Dec 19 2006 05:25PM
Dave Schroeder (das doit wisc edu) (1 replies)
Re: Month of Apple Bugs Dec 19 2006 05:58PM
Philippe Devallois (phdevallois intego com)
Re: Month of Apple Bugs Dec 19 2006 04:07PM
david (macosxforme gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus