|
|||||||
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
|
#1 | |
|
600,000 Macs Worldwide Reportedly Infected by Flashback Trojan
![]() Ars Technica reports on a Tweet from Russian malware analyst Ivan Sorokin at Dr. Web claiming that the Flashback trojan has now infected over 600,000 Macs worldwide. That number reportedly includes 274 machines "from Cupertino", presumably meaning at Apple's headquarters. Quote:
The most recently-seen version of Flashback surfaced earlier this week, exploiting a Java vulnerability that was unpatched on OS X. While Oracle had released an update closing the hole on Windows back in February, Apple had yet to issue a fix for Macs, as the company has historically maintained its own Java updates that are deployed some time after Oracle issues its own corresponding updates. But just a day after that report, Apple did update Java to address the vulnerability being exploited by Flashback. Antivirus firm F-Secure has instructions on how users can determine whether their machines are infected by the Flashback trojan. The instructions do involve running commands in Terminal, and users should thus take care to follow the instructions exactly. Article Link: 600,000 Macs Worldwide Reportedly Infected by Flashback Trojan |
||
|
|
0
|
|
|
#2 |
|
Here we go again....
At least it appears to be easier to remove than a Windows style malware infection... |
|
|
|
-25
|
|
|
#3 |
|
One more reason to keep Java disabled in my browsers, Java gets patched more often every year than I actually need Java in a browser.
|
|
|
|
7
|
|
|
#5 |
|
Hopefully Apple is out with a malware cleaner sooner rather than later. I'd guess that most people don't know Terminal exists, let alone know how to use it.
Apple does need to do a better job of getting these patches out sooner. The Java fix was available in February. Perhaps they need something like Microsoft's "Patch Tuesday." |
|
|
|
12
|
|
|
#6 |
|
Curious, how is the virus being delivered? Example: Email, Pop Up ad, ect...
__________________
GIBBS |
|
|
|
0
|
|
|
#7 | |
|
From the instructions:
Quote:
|
||
|
|
5
|
|
|
#8 |
|
clean here, update your system often and you should not run into this trojans...
The malware self-installs after you visit a compromised or malicious webpage. Obviously, it would be a good idea to update any Macs in your control. For those who want to check if mac is infected (from F-Secure instructions): Run the following command in terminal: defaults read /Applications/Safari.app/Contents/Info LSEnvironment defaults read ~/.MacOSX/environment DYLD_INSERT_LIBRARIES If you get "The domain/default pair ... does not exist" for both - you are clean from 9to5mac |
|
|
|
42
|
|
|
#9 |
|
Totally clean here. I'm not someone who goes around clicking on anything online or even anything that pops up on the computer. I've learned plenty from using PCs. I figure most of the people who get this are probably those who aren't able to keep a windows machine clean or assume that OSX (or any OS for that matter) is bulletproof. I do love how much better my Mac is at security though
|
|
|
|
1
|
|
|
#10 |
|
|
1
|
|
|
#11 |
|
If I'm reading the information on the F-secure website correctly, the trojan wont install itself if it discovers that Microsoft Office or Skype is already installed?
Interesting. |
|
|
|
2
|
|
|
#12 |
|
Screw it, the instructions look pretty long
|
|
|
|
-6
|
|
|
#13 |
|
What's quite mysterious is how does that "Dr. Web" company do to estimate that number of infected Macs?
Edit: okay I found out. It's probably with a technique called "Sinkholing".
__________________
21" 2008 iMac, 13" MBP, 32Gb iPod Touch 4, 2002 eMac, iPod Touch 2 8GB, iPod Nano 1st gen, iPad 3 white 32 GB 3G, iPhone 5 16 GB. Uhmm... Fanboi! |
|
|
|
1
|
|
|
#14 |
|
This is exactly what I illustrated before, fact of the matter is that not all users are computer savvy, not everyone will know what is safe and what's isn't.. That is why these Trojan etc.. Can indeed be a problem to some users..
|
|
|
|
8
|
|
|
#15 |
|
Here comes the debate between the definitions of "Malware" and "Virus"
__________________
Difficult takes a few seconds; impossible, a few minutes |
|
|
|
-6
|
|
|
#16 |
|
I guess it feels that we are suffering enough already with these installed. Hmm, this must be a new, more compassionate trojan.
__________________
Mac Pro Dual Quad 2.4: | 15" Retina MacBook Pro | 17" MacBook Pro | iPhone 5 White iPad 3rd Gen White |
|
|
|
29
|
|
|
#17 | |
|
Quote:
__________________
scoob |
||
|
|
-6
|
|
|
#18 |
|
You only need to run the two commands.
defaults read /Applications/Safari.app/Contents/Info LSEnvironment defaults read ~/.MacOSX/environment DYLD_INSERT_LIBRARIES Copy and paste chisperro's two lines into a terminal.
__________________
2x 3825|2x 2811|1x 2851|4x 3560-8PC|1x 3560G-24PS|4x 7961G|2X 7962G i7 2760QM|16GB 1600mhz|6990M|2x Intel 510 240GB Raid 0|750GB Momentus|Bigfoot 1103|AUO B173HW01 V.5|ICD 7 And some Apple stuff! |
|
|
|
13
|
|
|
#19 |
|
This is bad news for light users, the ones that hated Windows because it was more difficult to learn and don't do much on their computers (so they lack these "preventive" applications leading them would be more likely to be infected).
__________________
Mac Pro | 27" iMac | 15" MacBook Pro with Retina display | iPhone 5 | iPad 3 | iPad mini
|
|
|
|
2
|
|
|
#20 |
|
|
0
|
|
|
#21 |
|
This is very bad news for consumers who should be safe from these problems when using a Mac. But it's important to note a trojan is not a virus. So we're still well ahead of Windoze users.
|
|
|
|
-14
|
|
|
#22 |
|
|
21
|
|
|
#23 |
|
|
2
|
|
|
#24 | |
|
Quote:
You cannot protect ignorant people, even if you like. Difference here is that you only get infected if you explicitly allow malware to run. In MS world you get infected without even knowing it. |
||
|
|
-12
|
|
|
#25 | |
|
Quote:
__________________
ShootStorm - universal neo-retro iOS shoot-em-up action ShootStorm Survival - free single-life version |
||
|
|
0
|
![]() |
|
«
Previous Thread
|
Next Thread
»
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
All times are GMT -5. The time now is 04:14 PM.









Linear Mode
