# Calendar
January 2007
M T W T F S S
« Dec   Feb »
1234567
891011121314
15161718192021
22232425262728
293031  
You are currently browsing the Stan’s List weblog archives for the day Thursday, January 4th, 2007.
Info End -->
You are currently browsing the Stan’s List weblog archives for the day Thursday, January 4th, 2007.

AppleInsider: New Apple product announcements at next week’s Macworld Expo in San Francisco could include iTV, a new iPod, and the iPhone, according to a Macworld Rumor Roundup issued by research and investment firm PiperJaffray on Thursday.

ZDNet looks at the negative aspects of bug finding campaigns such as the aforementioned “Month of Apple Bugs.”

“While the researchers argue that the public airing of flaws is for the greater good, not everyone agrees. After all, broadcasting details of a bug in software without informing its maker and without a patch being available puts users at risk, critics say. It goes squarely against the “responsible disclosure” practices advocated by software companies. For example, the Month of Apple Bugs includes detailed exploit code that could provide ammunition to cybercrooks for use in attacks. Software makers are sent scrambling to address the flaws. More …

The third MoAB issue shows that the previously reported worm in MySpace QuickTime vulnerability can also be used in a cross-zone scripting attack which could allow, in combination with other vulnerabilities, to remotely execute arbitrary code on the user’s machine, as well as disclosure of the filesystem contents. Less …

Landon Fuller has responded with his third MoAB security patch:

Today’s fix involves patching the QuickTime Plugin’s nNPN_GetURL() function, which is responsible for asking the browser to load a page. The patch replaces any javascript: URL requests with a javascript alert box that reads: “[MOAB] Blocked a QuickTime JavaScript Call. See for more information.

A huge thanks to both Alexander Strange and Rosyna of Unsanity for doing most of the work to track down the issue. I also owe a big favor to my friend William Carrel, who was kind enough to do a code review of the latest changes, and set up a new MOAB Fixes Google Group. More …

# iChat Update 1.0 |

Apple has released iChat Update 1.0. Here’s the sparse bit o’ spin being offered with this dot-fix:

This update renews the .Mac certificate required by iChat for encrypting text, audio and video conferences.

PPC (2.3MB)

Mactel (3.9MB)

# King of Holiday Sales |

iPod increased its market share over the November-December 2006 holiday buying season, a MediaNews article reports, citing data from research group, NDP, based on a surveys of major electronic retailers.

Over the November 19 – December 23 period, iPod took over 57% of total players sold in the US, which is a 15% increase on the same period in 2005. SanDisk took second place with 19.2%, but this represented a decrease of almost 3% on the previous year. Creative was at # 3 with 3.4% and Microsoft lagged well behind in fourth place with 2.8%. More …