<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Mac Virus</title>
	<atom:link href="http://macviruscom.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://macviruscom.wordpress.com</link>
	<description>The Official Mac Virus blogsite</description>
	<lastBuildDate>Sun, 19 May 2013 19:27:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='macviruscom.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Mac Virus</title>
		<link>http://macviruscom.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://macviruscom.wordpress.com/osd.xml" title="Mac Virus" />
	<atom:link rel='hub' href='http://macviruscom.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Mac spyware</title>
		<link>http://macviruscom.wordpress.com/2013/05/19/mac-spyware/</link>
		<comments>http://macviruscom.wordpress.com/2013/05/19/mac-spyware/#comments</comments>
		<pubDate>Sun, 19 May 2013 19:27:18 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[David Harley]]></category>
		<category><![CDATA[F-Secure]]></category>
		<category><![CDATA[Africa]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://macviruscom.wordpress.com/?p=2473</guid>
		<description><![CDATA[I missed this last week, being at a couple of security workshops and cursed with a very erratic email connection, but F-Secure has reported an interesting item of spyware found on an African activist&#8217;s Mac at the Oslo Freedom Forum. According to VirusTotal, there is wide detection of the sample (19/47). While I don&#8217;t want [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=macviruscom.wordpress.com&#038;blog=11223042&#038;post=2473&#038;subd=macviruscom&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://macviruscom.wordpress.com/2013/05/19/mac-spyware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/b8199c10cb3e0346f93177950eae3108?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>iOS 6.1.4: a security bypass</title>
		<link>http://macviruscom.wordpress.com/2013/05/03/ios-6-1-4-a-security-bypass/</link>
		<comments>http://macviruscom.wordpress.com/2013/05/03/ios-6-1-4-a-security-bypass/#comments</comments>
		<pubDate>Fri, 03 May 2013 13:47:12 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Naked Security]]></category>

		<guid isPermaLink="false">http://macviruscom.wordpress.com/?p=2468</guid>
		<description><![CDATA[Paul Ducklin manages to make an article on Apple ships jolly uninteresting iOS 6.1.4 update  prettyinteresting. From the point of view of iOS security, though, the only interesting feature is that it doesn&#8217;t add any security features. More specifically, it doesn&#8217;t fix the lockscreen bug introduced in 6.1.3. And in fact unless you have an [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=macviruscom.wordpress.com&#038;blog=11223042&#038;post=2468&#038;subd=macviruscom&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://macviruscom.wordpress.com/2013/05/03/ios-6-1-4-a-security-bypass/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/b8199c10cb3e0346f93177950eae3108?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>A Bad Apple in a Bowl in the Window</title>
		<link>http://macviruscom.wordpress.com/2013/04/30/badapple/</link>
		<comments>http://macviruscom.wordpress.com/2013/04/30/badapple/#comments</comments>
		<pubDate>Tue, 30 Apr 2013 17:51:46 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[David Harley]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Sorin Mustaca]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[.EXE]]></category>
		<category><![CDATA[.SCR]]></category>
		<category><![CDATA[screensaver]]></category>
		<category><![CDATA[TR/Kazy.169263.1]]></category>
		<category><![CDATA[TR/Rogue.957311]]></category>

		<guid isPermaLink="false">http://macviruscom.wordpress.com/?p=2463</guid>
		<description><![CDATA[One for German readers. Sorin Mustaca warns of a spam campaign with emails appearing to come from Apple or Plus.de, claiming that the recipient owes money for a recent purchase. This &#8216;Dritte Mahnung&#8217; is presented as if it&#8217;s the third and final reminder before the company hands over the documentation relating to the &#8216;non-payment&#8217; to the [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=macviruscom.wordpress.com&#038;blog=11223042&#038;post=2463&#038;subd=macviruscom&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://macviruscom.wordpress.com/2013/04/30/badapple/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/b8199c10cb3e0346f93177950eae3108?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Siri, are you a blabbermouth?</title>
		<link>http://macviruscom.wordpress.com/2013/04/20/siri-are-you-a-blabbermouth/</link>
		<comments>http://macviruscom.wordpress.com/2013/04/20/siri-are-you-a-blabbermouth/#comments</comments>
		<pubDate>Sat, 20 Apr 2013 09:50:26 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPod Touch]]></category>
		<category><![CDATA[Dictation]]></category>
		<category><![CDATA[iOS policy]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Siri]]></category>

		<guid isPermaLink="false">http://macviruscom.wordpress.com/?p=2458</guid>
		<description><![CDATA[I came across (by way of @teamcymru) an interesting article from Zack Whittaker on the implications of Apple&#8217;s hard-to-find privacy policy regarding Siri and Dictation data. (not that hard to find, fortunately: Whittaker dug up this document on the Apple site, which tells us that: By using Siri or Dictation, you agree and consent to Apple’s and [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=macviruscom.wordpress.com&#038;blog=11223042&#038;post=2458&#038;subd=macviruscom&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://macviruscom.wordpress.com/2013/04/20/siri-are-you-a-blabbermouth/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/b8199c10cb3e0346f93177950eae3108?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Trojan Adware Installer news from Intego</title>
		<link>http://macviruscom.wordpress.com/2013/04/17/trojan-adware-installer-news-from-intego/</link>
		<comments>http://macviruscom.wordpress.com/2013/04/17/trojan-adware-installer-news-from-intego/#comments</comments>
		<pubDate>Wed, 17 Apr 2013 20:05:28 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Intego]]></category>
		<category><![CDATA[adware]]></category>
		<category><![CDATA[ChatZum]]></category>
		<category><![CDATA[Lysa Myers]]></category>
		<category><![CDATA[Softonic]]></category>
		<category><![CDATA[Zako]]></category>

		<guid isPermaLink="false">http://macviruscom.wordpress.com/?p=2456</guid>
		<description><![CDATA[If you&#8217;ve used the Softonic download site recently, you might want to be aware of Intego&#8217;s blog on Softonic Download Site Briefly Delivers Trojan Adware Installer. Lysa Myers reports on &#8220;&#8230;packages [that] purported to install a toolbar&#8230; related to ChatZum. Even if the user declined the offer to install &#8230; the package would silently install [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=macviruscom.wordpress.com&#038;blog=11223042&#038;post=2456&#038;subd=macviruscom&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://macviruscom.wordpress.com/2013/04/17/trojan-adware-installer-news-from-intego/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/b8199c10cb3e0346f93177950eae3108?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Brod on Flashback: the Movie</title>
		<link>http://macviruscom.wordpress.com/2013/04/04/brod-on-flashback-the-movie/</link>
		<comments>http://macviruscom.wordpress.com/2013/04/04/brod-on-flashback-the-movie/#comments</comments>
		<pubDate>Thu, 04 Apr 2013 12:41:27 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[David Harley]]></category>
		<category><![CDATA[F-Secure]]></category>
		<category><![CDATA[Virus Bulletin]]></category>
		<category><![CDATA[Broderick Aquilino]]></category>
		<category><![CDATA[OSX/Flashback]]></category>

		<guid isPermaLink="false">http://macviruscom.wordpress.com/?p=2452</guid>
		<description><![CDATA[Further to yesterday&#8217;s post Krebs on Flashback, which cites F-Secure&#8217;s report, Virus Bulletin has now made available the video of Broderick Aquilino&#8217;s presentation at Virus Bulletin&#8217;s 2012 conference, on VB&#8217;s new YouTube channel. David Harley CITP FBCS CISSP Mac Virus ESET Senior Research Fellow<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=macviruscom.wordpress.com&#038;blog=11223042&#038;post=2452&#038;subd=macviruscom&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://macviruscom.wordpress.com/2013/04/04/brod-on-flashback-the-movie/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/b8199c10cb3e0346f93177950eae3108?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Krebs on Flashback</title>
		<link>http://macviruscom.wordpress.com/2013/04/03/krebs-on-flashback/</link>
		<comments>http://macviruscom.wordpress.com/2013/04/03/krebs-on-flashback/#comments</comments>
		<pubDate>Wed, 03 Apr 2013 11:27:40 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Anti-malware]]></category>
		<category><![CDATA[Apple malware]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[F-Secure]]></category>
		<category><![CDATA[Brian Krebs]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[OSX/Flashback]]></category>

		<guid isPermaLink="false">http://macviruscom.wordpress.com/?p=2448</guid>
		<description><![CDATA[Brian Krebs offers some useful research and insight into &#8220;Who Wrote the Flashback OS X Worm?&#8220;. The F-Secure report he cites in that article, by the way, is this one. The comparison with Conficker is interesting, but it&#8217;s not a perfect fit, even if you measure &#8216;success&#8217; by the number of machines infected, which seems a slightly [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=macviruscom.wordpress.com&#038;blog=11223042&#038;post=2448&#038;subd=macviruscom&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://macviruscom.wordpress.com/2013/04/03/krebs-on-flashback/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/b8199c10cb3e0346f93177950eae3108?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>My earliest conference paper&#8230;</title>
		<link>http://macviruscom.wordpress.com/2013/04/02/my-earliest-conference-paper/</link>
		<comments>http://macviruscom.wordpress.com/2013/04/02/my-earliest-conference-paper/#comments</comments>
		<pubDate>Tue, 02 Apr 2013 20:18:56 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[David Harley]]></category>
		<category><![CDATA[papers]]></category>
		<category><![CDATA[Virus Bulletin]]></category>
		<category><![CDATA[conference papers]]></category>

		<guid isPermaLink="false">http://macviruscom.wordpress.com/?p=2445</guid>
		<description><![CDATA[&#8230;was presented in 1997 at the Virus Bulletin conference in San Francisco. In fact, it&#8217;s already available on this site, but I&#8217;m in the process of putting all &#8211; well, most &#8211; of my available papers and articles together on the same site, so it&#8217;s now also available, along with a gradually increasing number of [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=macviruscom.wordpress.com&#038;blog=11223042&#038;post=2445&#038;subd=macviruscom&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://macviruscom.wordpress.com/2013/04/02/my-earliest-conference-paper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/b8199c10cb3e0346f93177950eae3108?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>iSnitch</title>
		<link>http://macviruscom.wordpress.com/2013/03/26/isnitch/</link>
		<comments>http://macviruscom.wordpress.com/2013/03/26/isnitch/#comments</comments>
		<pubDate>Tue, 26 Mar 2013 08:32:50 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[David Harley]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[Infosecurity Magazine]]></category>
		<category><![CDATA[mobile forensics]]></category>

		<guid isPermaLink="false">http://macviruscom.wordpress.com/?p=2440</guid>
		<description><![CDATA[What forensic examination of your smartphone might say about you, according to the ACLU  (and Andy Greenberg): commentary for Infosecurity Magazine in If Your iPhone Could Talk&#8230; David Harley Small Blue-Green World ESET Senior Research Fellow<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=macviruscom.wordpress.com&#038;blog=11223042&#038;post=2440&#038;subd=macviruscom&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://macviruscom.wordpress.com/2013/03/26/isnitch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/b8199c10cb3e0346f93177950eae3108?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Beware the IDs of March</title>
		<link>http://macviruscom.wordpress.com/2013/03/25/beware-the-ids-of-march/</link>
		<comments>http://macviruscom.wordpress.com/2013/03/25/beware-the-ids-of-march/#comments</comments>
		<pubDate>Mon, 25 Mar 2013 17:14:02 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[authentication]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[Sorin Mustaca]]></category>
		<category><![CDATA[Stephen Cobb]]></category>

		<guid isPermaLink="false">http://macviruscom.wordpress.com/?p=2436</guid>
		<description><![CDATA[Or dancing the authentication pas de deux&#8230;. Stephen Cobb, my colleague at ESET, has just looked at Apple&#8217;s two-step authentication in rather more depth than I did here. Another friend from the security industry, Sorin Mustaca, is a little more brutal: &#8220;We are happy to inform you that Apple finally decided to join the club [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=macviruscom.wordpress.com&#038;blog=11223042&#038;post=2436&#038;subd=macviruscom&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://macviruscom.wordpress.com/2013/03/25/beware-the-ids-of-march/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/b8199c10cb3e0346f93177950eae3108?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
	</channel>
</rss>
