728x90_newspapers_dark_1.gif

Monday, October 18, 2010

Geohot Releases iOS 4.1 Jailbreak, Chronic Dev Team Forced to Delay GreenPois0n - DailyTech


Two bootrom exploits, two jailbreak solutions; only one can survive

Today was supposed to be the big day for GeenPois0n, an iOS 4.1 jailbreak tool based on the SHAtter exploit. However, Geohot dropped in to steal the show yesterday with the release of his own Limera1n tool.

The problem comes from the fact that Geohot's Limera1n tool uses a different bottom exploit than the one that was supposed to be released today based the work of the Chronic Dev Team and the iPhone Dev Team. Since Apple likely wouldn't release a new hardware revision for current generation devices to block the bootrom exploit, it would be useable until Apple releases its next generation iOS devices.

Instead of releasing two separate bootrom exploits in short succession, giving Apple the opportunity to kill both of them at once when the latest crop of iOS devices are released, the Chronic Dev Team has made the decision to delay its SHAtter-based exploit and instead release a new tool based on Geohot's implementation according to Redmond Pie.

The Chronic Dev Team states:

Thanks to the irresponsible antics of geohot, we will have to delay the release of greenpois0n (new ETA = as soon as possible), so that we have time to clean up his little mess and integrate the exploit he uses in limera1n into greenpois0n. This way, we can save SHAtter for future devices that may still be vulnerable to it.

We know that this is not what some people want to hear, but due to geohot needing to feed his ego (as usual) and revealing his limera1n exploit, we do not have any other responsible options.

The Chronic Dev Team seems especially peeved that Geohot's Limera1n is simply a beta release and has plenty of bugs in it, and that it was seemingly released a day before GreenPois0n just to steal the spotlight. In addition, Geohot's jailbreak only works on Windows-based machines -- for now.

But the good news is that a jailbreak solution for the iPhone 4 and iPod touch 4G is now available, albeit in less than optimum form. If you want to take your chances and use Geohot's solution, you can grab it here (Windows-only). However, it may be a safer bet until GreenPois0n is updated to take advantage of Geohot's exploit.

"This is from the DailyTech.com. It's a science website." -- Rush Limbaugh
Most Popular ArticlesStudy: Android is Terminating RIM, Apple's Marketshare
October 5, 2010, 10:50 PM
Report: Verizon iPhone a Done Deal, New Form-Factor Incoming
October 7, 2010, 8:08 AM
Say Bye to BIOS and Hello to PCs that Boot in Seconds With UEFI
October 4, 2010, 9:24 AM
U.S. Farmers Realize Disadvantages of Genetically Engineered Seed
October 5, 2010, 3:41 PM
Jailbreakers Free Apple TV From Its Maker's Restrictions
October 1, 2010, 11:03 AM


View the original article here

Serb police clash with anti-gay rioters - BusinessWeek

By JOVANA GEC

BELGRADE, Serbia

Serbia's riot police fought running battles on Sunday with hundreds of far-right supporters who tried to disrupt a gay pride march in downtown Belgrade. Several dozen people were hurt, officials said.

Thousands of police officers sealed off the streets in the capital where the march took place, repeatedly clashing at several locations with rioters who were trying to burst through security cordons.

Several parked cars were set on fire or damaged, shop windows were broken, garbage containers were overturned and streets signs destroyed.

The rioters fired shots and hurled petrol bombs at the headquarters of the ruling pro-Western Democratic Party, setting the garage of the building on fire. The state TV building and other political parties headquarters were were also attacked, with many of the house windows shattered by stones.

The protesters, chanting "death to homosexuals!" hurled Molotov cocktails, bricks, stones, glass bottles and firecrackers at riot police. Police responded by firing tear gas and deploying armored vehicles to disperse the charging protesters in the heart of the capital even after the brief pride march ended.

The protesters hijacked a bus, ordered all of its passengers and the driver out, and pushed it down a steep street before hit an electric pole on a main Belgrade square.

Belgrade emergency hospital said 57 people have been injured, including 47 policemen, one seriously. Police said several rioters were arrested.

Right-wing groups say the gay events are contrary to Serbian family and religious values. Most of the rioters Sunday were young football fans whose groups have been infiltrated by neo-Nazi and other extremist organizations.

"These riots obviously have nothing to do with the gay parade or any moral values," said Democratic Party spokeswoman Jelana Trivan. "These are hooligan gangs which must be punished severely."

Defense Minister Dragan Sutanovac, vice president of the Democratic Party, said a part of the party's archive, warehouse and phone lines at the building were destroyed and shots were also fired at the building.

"It is high time that we deal in a very democratic way, through the courts, with those who call themselves members of the patriotic organizations," Sutanovac said. "Is this Belgrade or the wild West?"

Senior Justice Ministry official Slobodan Homen said that the state response will be "fierce." He said that the city center is covered with surveillance cameras and that the rioters have been identified and many already detained. He said they could face up to eight years in prison.

Sunday's march was viewed as a major test for Serbia's government, which has launched pro-Western reforms and pledged to protect human rights as it seeks European Union membership.

Right-wing groups broke up a pride march in 2001 and forced the cancellation of last year's event.

Vincent Degert, the head of the EU mission in Serbia, addressed around 1,000 gay activists and their supporters who gathered at a park in downtown Belgrade which was surrounded by riot police, including armored vehicles.

"We are here to celebrate this very important day ... to celebrate the values of tolerance, freedom of expression and assembly," Degert told the crowd waving rainbow flags.

The same right-wing group set the U.S. Embassy on fire during riots in 2008 to protest U.S. support for Kosovo's independence.

U.S. Secretary of State Hillary Rodham Clinton plans to visit Belgrade in coming days as part of a Balkan tour.

------

Associated Press writer Dusan Stojanovic contributed to this report.



View the original article here

Microsoft plans colossal Patch Tuesday next week - Computerworld

Computerworld - Microsoft today said it will deliver a record 16 security updates next week to patch a whopping 49 vulnerabilities in Windows, Internet Explorer (IE), Office and SharePoint.

Andrew Storms, director of security operations for nCircle Security, called the massive update "daunting, again."

Four of the 16 updates were tagged with Microsoft's "critical" label, the highest threat ranking in its four-step scoring system. Another 10 were marked "important," the second-highest rating, while the remaining pair were labeled as "moderate."

Nine of the updates could be exploited by attackers to inject malicious code into vulnerable PCs, Microsoft said in its usual bare-bones advance notification of the updates scheduled for release Oct. 12. Microsoft often labels remote code executable bugs -- the most dangerous -- as important when the vulnerable components are not switched on by default or when other mitigating factors, such as defensive measures like ASLR and DEP, may protect some users.

Next week's Patch Tuesday is a record on almost every count.

The 16 updates -- Microsoft dubs them "bulletins" -- are a record, beating the count from August 2010 by two. The 49 individual patches easily exceeds the single-month record of 34, which was first set in October 2009 and repeated in this past June and August.

Microsoft has been shipping alternating large and small batches of fixes, with the larger-sized updates landing in even-numbered months, so October's big numbers shouldn't come as a shock. In August, for example, the company issued 14 bulletins patching 34 vulnerabilities. September's batch, however, included 9 bulletins that fixed 11 flaws.

"I have a theory about the large October updates," said Storms, pointing out that Microsoft released 13 bulletins and patched 34 vulnerabilities in the month last year, and issued 12 updates and fixed 21 flaws in October 2008. "It's the year-end financial and retail push by most companies, which go into lockdown mode the last two months of the year, when they don't update their systems," he said.

Twelve of the 16 bulletins are aimed at Windows, either the desktop or server editions, or in some cases both. Two from next week's slate affect Office -- Word and Excel, specifically -- and are likely patches for one or more file format vulnerabilities in those applications, said Storms.

One of the bulletins will address a problem in SharePoint, Microsoft's enterprise-grade collaboration server software. According to the advance notification, the SharePoint update will be related in some way to Office Web Apps, the online editions of Microsoft's Word, Excel, PowerPoint and OneNote applications.

Other than the sheer number of updates users will have to apply, Storms also noted that several apply to the newest versions of Microsoft's operating system, Windows 7 on the desktop and Windows Server 2008 R2 on the server side.


View the original article here