|
|
| Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate. |
|
|||||||
| TouchArcade.com - iPhone Game Reviews and News |
|
|
Thread Tools | Search this Thread | Display Modes |
|
|
#1 | |
|
macrumors bot
Join Date: Apr 2001
|
The First Mac OS X Virus?
http://www.macrumors.com/images/macrumorsthreadlogo.gif
On the evening of the 13th, an unknown user posted a link to a file on MacRumors Forums claiming to be the latest Leopard Mac OS X 10.5 screenshots. The file was named "latestpics.tgz" The resultant file decompresses into what appears to be a standard JPEG icon in Mac OS X but was actually a compiled Unix executable in disguise. An initial disassembly reveals evidence that the application is a virus or was designed to give that impression. Routines listed include: _infect: _infectApps: _installHooks: _copySelf: The exact consequences of the application are unclear, but users who originally executed the application have noted that it appears to self propogate even after the original file has been deleted: Quote:
Update #2: The most recent updates show that the file does send itself to other users in your AIM/iChat buddy list. Last edited by Doctor Q : Feb 16, 2006 at 02:55 PM. |
|
|
|
|
|
#2 |
|
macrumors regular
|
hmmm. scary.
__________________
iMac G5 17in 1.8; MacBook Pro 2.16ghz. "Far better is it for man to give what he cannot keep to gain what he cannot lose." E.H. |
|
|
|
|
#3 |
|
macrumors newbie
Join Date: May 2003
|
the sky is falling!!
|
|
|
| Tha_Sylent1 |
| View Public Profile |
| Find More Posts by Tha_Sylent1 |
|
|
#4 |
|
macrumors member
Join Date: Jan 2004
|
Looks like I might be re-installing Norton...
|
|
|
| skinEman23 |
| View Public Profile |
| Find More Posts by skinEman23 |
|
|
#5 |
|
macrumors 6502a
Join Date: Apr 2003
Location: Connecticut (Ankara, Turkey for the next year)
|
Granted, this is just a script. It doesn't exploit a secruity flaw. Correct?
__________________
-15" MacBook Pro, 2.4 GHz, 200 GB HD, 4 GB RAM -Dell 20" 2005FPW -16 GB iPod Touch -Nikon D40 w/ Nikkor 18-200mm VR |
|
|
| Steven1621 |
| View Public Profile |
| Find More Posts by Steven1621 |
|
|
#6 |
|
macrumors god
Join Date: Sep 2002
Location: at the table with countless relatives
|
A general rule
Remember not to type your administrator password just because you get prompted for it. Always know why before you do so.
__________________
"You've just been abducted, of course you need crepes!" -- Walter Bishop |
|
|
|
|
#7 |
|
macrumors newbie
Join Date: Sep 2005
Location: Adelayed, South Australia
|
well well well......
was bound to happen |
|
|
|
|
#8 |
|
macrumors 6502a
Join Date: Mar 2003
|
so does OS X warn you that it is an executable when you D/L it? how does it disguise itself? If you get info on it does it say "open with preview", or does it say it's a script ? What does it propagate besides itself - by that I mean, how does it damage you except by spreading?
__________________
Fiction Weekly |
|
|
|
|
#9 |
|
macrumors 6502a
Join Date: Apr 2004
|
OMG
OMG OMG OMG OMG OMG OMG OMG
__________________
current: macbook air Rev. B. 128 ssd and 1.86ghz iphone 16gb, unlocked on t-mobile ipod nano 3g |
|
|
|
|
#10 |
|
macrumors newbie
Join Date: Feb 2006
|
:-o
Hell Froze over... actually it just snowed today.
|
|
|
|
|
#11 |
|
macrumors 6502
|
I think it's important to ask a few questions.
1. if you Get Info on the file what does it say? 2. when you double-click the file does it ask for your Admin password? 3. when it's downloaded does Safari indicate it's a program and not a regular file? 4. what's the uploaders IP address and has his ISP been contacted about this?
__________________
-- iMac 24" 2.1ghz/3GB/250/superdrive |
|
|
|
|
#12 |
|
macrumors 6502
Join Date: Jul 2002
|
This is great...(I used to work for MS security)
![]() Remember...that which does not kill us, only makes us stronger... We all need to take a deep breath and think about what this means. If this is indeed a virus that can either corrupt the system or delete files, then someone has done what is made possible by the OS. Also, this should be a wakeup call to all mac users. Opening any file without knowing the source is FOOLISH...I dont care what OS you are using. Just because you are using OS X, doesnt mean you should be opening any file someone TEMPTS you with.... The more I think about this, the more I laugh... Pics of OS 10.5...brilliant... Windows users are tempted by Brittney spears, mac users by a new GUI element in their operating system... |
|
|
|
|
#13 |
|
macrumors 68000
Join Date: Aug 2003
Location: At home
|
Expect this to be all over the media.
I was smuggly thinking about 'no virus's for Mac OS X' last night.
__________________
Check out the fortnightly photo challenge at Culture don't make Light of it |
|
|
|
|
#14 |
|
macrumors 6502a
|
First off : THIS IS NO VIRUS
this is just a hoax reall i mean seriously its not like it just gets onto your computer from a security flaw all it is a smart person who notice you could use resource forks like that, if anyone was smart they would of noticed it a bit odd it had to be archived with the fork, i mean sure its a virus in such the way it does the harm of a virus but its not breaking and flaws its like someone just giving you a bash script saying here its going to make your computer run faster when it actually just deletes everything |
|
|
|
|
#15 | |
|
macrumors 65816
|
Quote:
yes ... yes ... do it ...
__________________
Fetch Daddy's blue fright wig! I must be handsome when I unleash my rage. |
|
|
|
|
|
#16 | |
|
macrumors 68000
Join Date: Nov 2001
Location: here (for now)
|
Quote:
![]() It puts the security right where it should be ... in the hands of the user. ![]() peace | neut |
|
|
|
|
|
#17 |
|
Demi-God (Moderator emeritus)
Join Date: Apr 2004
Location: Adelaide, Australia
|
I wonder what Apple's move will be. At least scenarios like this keep Apple on their toes. There would be nothing worse than Apple being caught short by a sudden flaw in their OS.
__________________
Some things are better mad... |
|
|
|
|
#18 | |
|
macrumors newbie
Join Date: Jul 2004
|
Quote:
dana |
|
|
|
|
|
#19 | |
|
macrumors 68040
Join Date: Apr 2004
|
Quote:
Safari downloads this as a tar of latestpics.tgz, ie. latestpics.tgz.tar, but Deerpark and Camino download it as latestpics.tgz. In terminal, tar does not successfully open the file downloaded using Safari. But double clicking the icon does open it. The tgz files downloaded using Deerpark and Camino can be opened by double clicking on the tgz file or using gunzip from terminal. Both latestpics and ._latestpics are extracted, but the initial . means that Mac OS hides ._latestpics. Get Info shows it as a PPC executable. Although I'm using a managed account for this, I don't feel secure enough to double click the latestpics file. |
|
|
|
|
|
#20 |
|
macrumors 6502a
Join Date: Feb 2003
Location: Finland
|
It's a Trojan
If the details are correct, we're still not talking about a virus, but a trojan horse. You still have to open it yourself so that it can run.
This doesn't mean it isn't a bad thing.
__________________
I was elected to lead, not to read. |
|
|
| Windowlicker |
| View Public Profile |
| Find More Posts by Windowlicker |
|
|
#21 |
|
macrumors 6502
Join Date: Jul 2005
|
hmm....
I guess mac is really hitting mainstream now...
|
|
|
|
|
#22 | |
|
macrumors regular
Join Date: Aug 2002
Location: Home
|
Quote:
__________________
Faasnat ...on since 1984 |
|
|
|
|
|
#23 | |
|
Demi-God (Moderator)
Join Date: Dec 2002
Location: Whakatane, New Zealand
|
Quote:
|
|
|
|
|
|
#24 | |
|
macrumors 601
Join Date: Aug 2003
|
Quote:
For anyone using the first account they created when they installed OS X, it's time to put a stop to that right now, because you have the rights to change a whole bunch of important stuff like your applications that don't require becoming root. You're in the admin group, and that's a lot of power all by itself. A good idea, right now, would be to go into your system Preferences, into Accounts, and create a new user. Turn on the "Allow user to administer this computer" check box, then log into that account and make sure it works. Once you're satisfied that the new account works and that you've remembered the password, turn off the "Allow user to administer this computer" check box for your own regular account. From then on, use the new account to install software, run System Update, etc. Use your now-demoted regular account for your regular daily computing. A declawed account can still do some things that don't require special privs, like delete your own user files or send malware out to other computers. It will, however, keep your system reasonably safe from unintended modification. edit: One last bit: Check the files in your Applications folder, even after declawing, and see if you are listed as the owner of any files. If you are, log in with your new admin account (fast user switching is a help here) and change the ownership to the system or that admin user. Last edited by iMeowbot : Feb 16, 2006 at 01:35 AM. |
|
|
|
|
|
#25 | |
|
macrumors 68040
Join Date: Jan 2004
Location: Costa Rica (yes, I moved)
|
Quote:
Apple just needs to find a way to warn people of apps/scripts in disguise. Problem solved. |
|
|
|
| Thread Tools | Search this Thread |
| Display Modes | |
|
|