Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
retx
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
retx
11y ago
Only when application was compiled on OSX 10.11 El Capitan, it's not available in previous versions.
2.
▲
by
retx
11y ago
Not affected by unsafe HTTP configuration but affected by Sparkle bug which allows to exploit it in a case when XML file on the server was replaced since it's not signed using DSA key. You can still exploit it without HTTP and MITM &qu
3.
▲
by
retx
11y ago
I know that it's hard to believe but yes, they do. It's just a one of two vulnerabilities in that case to be clear.
4.
▲
by
retx
11y ago
With this updating process when the update process itself is vulnerable is "tricky", I know but you can avoid those nasty things by: 1) Using secure and let's say trusted VPN and then all your connections are going to be encr
5.
▲
by
retx
11y ago
That's totally true but, WebView allows to execute unsafe handlers like 'file://', 'ftp://'. As a result in the worst case scenario when appcast webserver was compromised then you don't need
6.
▲
by
retx
11y ago
List of vulnerable applications is here - https://github.com/sparkle-project/Sparkle/issues/717