Sophos Anti-Virus for Mac Home Edition Review

Sophos Anti-Virus for Mac Home Edition Review

Introduction

Sophos declares the following in their campaign for Sophos Anti-Virus for Mac
-Malware myth: Macs can’t get viruses.
-SophosLabs have detected over 1,000 threats for Mac OS.

Sophos Anti-Virus for Mac Home Edition runs in the background and scans files for threats whenever your Mac opens them. It comes with an uninstaller (Applications/Remove Sophos) in case you want to remove it after trying it on your system.

I’ll be going through this review step-by-step and cover all the features related to the Mac system, usability, configuration and overall experience. Feel free to follow my …

November 7, 2001 • 17 min read
iDisk under Mac OS X 10.1 is significantly less secure…By Open Door Networks

iDisk under Mac OS X 10.1 is significantly less secure…By Open Door Networks

Fix: Use the Software Update feature in Mac OS X to resolve the issues with WebDAV security issues.

Security Advisory: Apple’s Mac OS X iDisk WebDAV vulnerability

Open Door Networks recently discovered that Apple’s iDisk under Mac OS X 10.1 wasn’t properly written to WebDAV standards. They said in Mac OS X 10.1 your iDisk is usually accessed using the WebDAV protocol rather than the Apple Filing Protocol (AFP) used previously. Like AFP, WebDAV is supposed to not send your password over the Internet, so in that respect it should be as …

October 6, 2001 • 2 min read
Mac OS X Security Vulnerability setuid root applications leave root shell open for hackers

Mac OS X Security Vulnerability setuid root applications leave root shell open for hackers

Operating System: Max OS X Version Affected: up to 10.1

Security Risk: High
Remote: No
Fixed: 10.20.2001 see below

About

Mac OS X over the past few months have started to spout security concerns, this being one of the first most publicized attacks on the operating system. Once logged into Mac OS X, any user can obtain a root shell by executing a few simple applications in specific order.

Mac OS X is already on computers in every sort of nature, even after the administrator sets up multiple accounts with specific privileges keeping the user from …

October 2, 2001 • 3 min read
Startup Security Mac OS and Mac OS X Open Firmware Password Configuration Utility

Startup Security Mac OS and Mac OS X Open Firmware Password Configuration Utility

Information About Startup Security 1.1 for Mac OS 9 & Mac OS X

In case you do not know, your Macintosh may be able to have extra password protection offering you a extra touch of security if you are using Open Firmware 4.1.7 or higher running Mac OS 9 or Mac OS X.

What is Open Firmware Password Protection?

We have a whole discussion on Open Firmware Password protection here. In short it would be compared to the PC’s BIOS password where it asks you for password on startup or while trying to …

August 6, 2001 • 2 min read
AIM Password Stealing, My AIM Password is incorrect. AIMThief 5.2 for Macintosh

AIM Password Stealing, My AIM Password is incorrect. AIMThief 5.2 for Macintosh

published: 08.31.2001
remote: Yes
updated: yes
vulnerable: all aim accounts under 10 characters

The security issue was addressed by AOL and to this date does not remain a concern.

Information

Has your AOL Instant Messenger (AIM) account password come up as invalid and you are sure that you entered it correctly? Figure that your account was hijacked by someone using the program AIMThief 5.2 for the Macintosh.

Hackers found a hole in the protocol used by AIM that lets them remotely change any users passwords if the user name is 10 characters of less.

After the AIM account …

August 6, 2001 • 3 min read
Firewall Security: The Shareware Method

Firewall Security: The Shareware Method

Broadband Internet technology, with its rapidly increasing availability and affordability, has generated a need to secure personal computers in a way never conceived by its original inventors. Constantly connected PC’s are more prone to malicious attempts by the rising amount of computer hackers and “script kiddies”. To defend ourselves without busting our wallets, several software vendors have stepped up to the plate to offer software-based firewall solutions to protect the average PC user from most attacks prevalent today.

Computers on dedicated connections are more open to Internet-based attacks because they are …

August 4, 2001 • 6 min read
Stealth Signal Service for Mac OS the undetectable software-based transmitter

Stealth Signal Service for Mac OS the undetectable software-based transmitter

Computer equipment is stolen every second around the world. What makes you believe your computer is any bit safer than the next guys. The concept of Stealth Signal is simple. When you use the Stealth Signal service your computer is being kept tabs on, so the next time someone steals your laptop of desktop computer they will help you locate it, read how…

How Stealth Signal Operates

A small undetectable program (Stealth Signal Transmitter) is installed in your computer. This program silently tries to send a signal to our Monitoring Network at …

July 6, 2001 • 4 min read
Apple.com Resources, Developments and TILs on Security Issues

Apple.com Resources, Developments and TILs on Security Issues

It is recommended that you revisit this page because there will be frequent updates and additions as new security related resources at Apple pop-up.

General Security

Mac OS Security and Cryptography (ADC)
Technical Q&As – Security (ADC)
Product Security Response Support Information
PGP: Protecting Security Information
Security Updates

Mailing Lists

Product Security Notifications and Announcements
Apple’s Implementation of the Common Data Security Architecture

Software

Mac OS (General)
Keychain Manager (ADC)
Mac OS: “Unable to establish a secure connection” or “security certificate” Messages in Web Browsers (TIL 106211) [2001 March 23]
Securely Erasing, Accessing and Dismounting a Macintosh Partition (ADC FL11) [1999 January 11]
Accessing the …

July 2, 2001 • 5 min read
StaticUsers.net – Microsoft Personal Web Server

StaticUsers.net – Microsoft Personal Web Server

Microsoft Product for the Macintosh?

Ya I know It comes with os 8.x. If you have ever used a PC, or so they say, “Its Microsoft, its breaks, i tried to uninstall it, it broke” Well I tried to remove Microsoft Personal Web Server from my Macintosh and ran into a little problem i forgot to turn off 1 extension. WaMMo! My computer froze on startup. Probably the point where the extension realized all the other components were not there. I wonder if they plan on fixing it so it does …

June 6, 2001 • 2 min read
Security-Ware – Physical Security for your Macintosh. Keep your Hardware secure

Security-Ware – Physical Security for your Macintosh. Keep your Hardware secure

We all realize security is a issue for our computers, but how secure can your password and encrypted files be when your computers have been stolen?

The San Diego, California based company, SecurityWare offers a wide variety of anti theft devices for your Macintosh computers and PC’s. After careful overview of the products we felt the Cable Security kits would be most use full to the general market!

SecurityWare’s iBook/iMac kits (with or without plate) makes it possible and affordable to secure your Mac. SecureMac travels from locations and our iBooks sometimes …

June 2, 2001 • 3 min read
StaticUsers.net – AppleShare + NT Security Issues

StaticUsers.net – AppleShare + NT Security Issues

Information:

This concerns Macs connected to NT servers using Service Pack 4. If a Mac changes its password when connected to NT SP4, from that point on, PCs can log into that user account with NO password (a null password.) – contributed by John Wolf

Views:

This can be a serious bug. Its not well known, and when an Appleshare Client is added, not many people think to check for security issues because, well, it’s APPLESHARE! This causes a problem on the network.

Reasonings and Technical How-SO

snip-it from ms99-004 advisory Issue

The Windows NT Security …

June 2, 2001 • 3 min read
OSX -CGI Flaw

OSX -CGI Flaw

A fatal bug in MacOS X Server renders Apple’s new operating system practically useless as a web server. The problem is particularly critical since it affects MacOS Server X release 1.0 in one of its key features.

During a server load test at c’t Labs, the Apache web server built into the OS caused the machine to halt with a fatal “System Panic” error following successive CGI script queries.

CGI scripts (Common Gateway Interface) are a common server extension, frequently used for web queries. The test stopped the system cold whenever 32 …

June 2, 2001 • 2 min read