Apple today released Security Update 2010-006 (Snow Leopard) which is recommended for all users and improves the security of Mac OS X.
Security Update 2010-006
• AFP
CVE-ID: CVE-2010-1820
Available for: Mac OS X v10.6.4, Mac OS X Server v10.6.4
Impact: A remote attacker may access AFP shared folders without a valid password
Description: An error handling issue exists in AFP Server. A remote attacker with knowledge of an account name on a target system may bypass the password validation and access AFP shared folders. By default, File Sharing is not enabled. This issue does not affect systems prior to Mac OS X v10.6. Credit to Richard Noll for reporting this issue.
Security Update 2010-006 (Snow Leopard) is available via Software Update and also as a standalone installer.
More info and download link (1.93MB) here.
Where, on the Apple site, does one report a security weakness or a potential malware issue?
@grh
Sjobs@apple.com
No worries…
But a real stink is the widespread click/ping trackers, web bugs, hidden Flash cookies etc., that Apple is allowing to occur with Safari, despite private browsing mode being turned on.
Do you know there is currently about 300 web bugs tracking your every move on line and their numbers are growing rapidly?
Read the Wall Street Journal story over on Slashdot, your kids are in some peril with strangers monitoring their web use.
@grh
You could do here.
Delete Flash.
Turn Cookies Off.
‘Nuf said.
@grh
http://www.apple.com/feedback/
or
http://www.apple.com/feedback/macosx.html
There is a bug report option there for OS X.
The main problem Apple has when a regular user has a real exploit on their hands is being able to communicate that to Apple in a effective manner. Being able to show them or send them the malware. Most times they will just think something is wrong with the user or their machine, not a real vulnerability.
I came across a nasty one and had a hell of a time being able to communicate this over to Apple, they are used to working with people who are knowledgeable about finer details of OS X and the security community at large, not just users who came across a exploit and want to report it.
So the only thing I can suggest is find yourself a intermediary that can test your problem and rule out, user or other failure, perhaps a top level Apple Genius, explain first you suspect malware so they take precautions and not let it infect other systems or their networks.
And don’t send the malware to S jobs, you’ll be in a lot of trouble.
Has anyone installed it and noticed if their machine is snappier?
MDN Magic Word: “hard”, as in “Was it hard for you in the resistance?”. “Not as hard as it is now…”
@@Bizzarro
Only Firefox with Ghostery, BetterPrivacy, TACO, NoScript gets it all.
@Bizzarro.
Private browsing is not there to protect your privacy from the parties you contact on the web during your online session.
It’s there to protect your privacy from other people who have access to your computer while you’re not online anymore. Always was.
Thanks to Bizzarro, AAPLguy and jafo. Anyone interested in why I asked — my broadband provider insists either my iMac has/had some malware or there was/is a bug in my ADSL modem. They referred me to this
http://thenextweb.com/us/2010/02/22/chuck-norris-virus-roundhouse-kicks-unprotected-routers/
I’m still researching what it is/was that caused my combination iMac/modem to undertake huge data transfer rates, up and down, without me at the wheel.
Anyone interested to comment or help privately, <loloveweb@hotmail.com>
@bizarro…i don’t think you understand what private browsing does. it’s nothing to do with security protection from sites you visit.
what is your source for saying over 300 bugs tracking every move on a Mac?
Only 1.92 MB??? Pffffffttttt!
No thanks.