Archive for June 20th, 2008

Fix for Apple Remote Desktop security hole

News| No Comments »

As you’ve probably heard, a vulnerability in Apple Remote Desktop allows remote users to execute commands as root when logged in as a regular user. The problem is that ARDAgent has its setuid bit set and is owned by root,

Apple to AT&T: Show Me the Money

News| No Comments »

Apple will receive an additional $100 bounty for every new AT&T customer who signs for service at an Apple Store. The early book on the new phone is very bullish, with Reiner calling for 15 million units to be sold in 2008 and another

MacBook Air Suitable Montevina Chips Due Later This Year [Updated]

News| No Comments »

PC manufacturers have recently introduced a number of new ultra-thin laptops that share a similar profile to Apple’s MacBook Air. The HP Voodoo Envy edges out the MacBook Air with a slightly smaller (0.7 vs .76 inches) maximum thickness and uses the…

Apple Retail Preparing for iPhone 3G Activation Procedures

News| No Comments »

MobileToday.co.uk reports that Apple is actively working with O2 to allow customers to buy the 3G iPhone and sign up for service at Apple Retail stores in the UK.

With the adoption of the subsidized pricing, iPhone 3G customers will be…

Add other Wikipedia languages to Firefox 3 search bar

News| No Comments »

Wikipedia articles are different in every language, and not all of them appear in the English version of Wikipedia. Firefox 3 includes in many languages versions (Spanish, German, etc., but not French) a search plug-in for Wikipedia set for the corresponding language. Download the version of Firefox 3 for the language you’re interested in using (no need to install), mount the disk image, control-click on the Firefox icon and choose Show Package Contents from the pop-up menu. Navigate to Contents » Resources » MacOS » searchplugins; the Wikipedia plug-in is an XML file that you can copy and install into your main language’s version of Firefox. Just copy and paste the file from the language of choice to the same folder in your main copy of Firefox.

If, for the language you are interested in, Firefox does not include a Wikipedia plug-in, you must modify one. Quit Firefox, then duplicate the English plugin (wikipedia.xml). Next, change the name of the duplicated file to

Two ways to possibly close an ARDAgent security hole

News| No Comments »

Yesterday, Mac software developer Intego published a security memo on an exposure that exists with the ARDAgent application on OS X 10.4 and 10.5. ARDAgent runs when you use Screen Sharing in 10.5, and if you’ve enabled Remote Management in the System Preferences panel, but this exploit actually works when ARDAgent isn’t running. As far as I know, this exploit was first published on the Apple page at Slashdot, though it probably appeared elsewhere earlier.

You can read the details of the exploit in the Slashdot entry, but basically, it relies on the fact that ARDAgent runs as root and can send AppleScript commands, such as do shell script, to the system it’s running on. Given ARDAgent is running as root, any shell script launched by ARDAgent also runs as root, so such scripts run without promptin…

One fix for ‘weak’ keys on the aluminum keyboard

News| No Comments »

I’ve had an aluminum keyboard since just after its launch, and I generally love it. However, what annoys me was that it easily misses some keystrokes, specially the 1/! key on my keyboard.

Today I decided to take a look at the key, and now I have it working much better. Simply raise the key with a nail and then gently insert a knife and pull down, so that the plastic cover is separated from the spring. Now you’ll need a small piece of paper folded three or four times — cut it if needed so you get a 2mm x 2mm square, with less than 1mm thickness. Put this folded paper on the inside part of the plastic cover, so it touches the key membrane when closed, and fix in place with a piece of tape. Here’s what my modified key looks like.

Put the key back on the spring (press until you hear a couple of clicks). Now the key will be more responsive than before. If the piece of paper i…

Possibly restore older iPhoto themes in iPhoto ‘08

News| No Comments »

Upon trying to create a book in iPhoto ‘08, I noticed a lot of the old themes were not available. Browsing around, I found the theme folder for iPhoto in the top-level Library folder, in Application Support » iPhoto » Themes.

Inside that folder were many themes not available through iPhoto itself, but that were available in older versions. As one example, BabyBoy-Hardcover.IPBookTheme isn’t available in the list of book themes pop-up menu, but it is in that folder. I can’t guarantee how safe/legal the following process is, but I was able to enable the old themes by editing a parameter in that theme’s Contents/Resources folder.

I opened Contents » Resources » Implementation.plist in a text editor (or Property List Editor) and changed the Hidden parameter from yes to no. After saving my changes and restarting iPhoto, the old theme was available in iPhoto.

[robg adds: I used BBEdit and ran a multi-file search to find the hidden th…

Why Apple Will Survive Without Steve Jobs

News| No Comments »

Everyone is concerned about Steve Jobs’ health, prompting the obvious question about succession plans at Apple. The company seems doomed without him. Who has the vision and drive? But Apple will be fine without Jobs, although it won’t

AT&T iPhone 3G $199/$299 Pricing Policy

News| No Comments »

After our story about the AT&T subsidy for the Apple iPhone, it appears there remains an enormous amount of confusion about AT&T’s iPhone 3G upgrade policy. We had previously posted a guide based on circulating rumors describing individual eligibili…