|
|
| Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate. |
|
|||||||
| TouchArcade.com - iPhone Game Reviews and News |
|
|
Thread Tools | Search this Thread | Display Modes |
|
|
#1 |
|
macrumors bot
Join Date: Apr 2001
|
Mac OS X Virus/Trojan Summary
http://www.macrumors.com/images/macrumorsthreadlogo.gif
The announcement of the release of a Mac OS X trojan/virus/worm yesterday has drawn a lot of attention, confusion and significant misinterpretation. While much of the attention was aimed at the "virus vs trojan" distinction, this energy was misguided. On the one hand, some users were quick to dismiss it as a simple "trojan" that anyone could easily script in minutes. While the application was setup to trick the end-user into launching it, the resultant actions it took were far more sophisticated as it was designed to inject itself into other applications on the users' hard drive. Despite much confusion on this detail, most users were not prompted for the administrator password before the file modifications took place. (The Application directory is writable by the Admin accounts which most Mac OS X user accounts are established as, by default.) On the other hand, several saw this as a much more ominous sign for the Mac platform. However, this application itself is of a rather limited threat by the nature of its propogation -- and no particular Mac OS X vulnerability exists which allows the unimpeded transmission of a virus. Unless you specifically downloaded and launched this file, there is no way your Mac could have been infected. The signficance of this event is simply the intention behind the release of such malware under Mac OS X. For additional reading, Symantec provides a step-by-step guide on what happens when the application launches and what modifications it makes to the users applications, while Andrew Welch of Ambrosia SW finished a detailed technical summary of the application. |
|
|
|
|
#2 |
|
macrumors Demi-God
Join Date: May 2004
Location: La Villa Strangiato
|
Scary. For real - this is the first time ever I have doubted the security of my Mac.
__________________
Mac Pro Octophallus 2.8 | 13" UMBP 2.26 |
|
|
|
|
#3 |
|
macrumors 68040
|
Now we just have to see how Apple compares to Microsoft on turn around updates.
I find it amusing that the first possible malicious code to attack the mac platform was released here at our nice forum.
__________________
Spare me my life. MBP 2.2 glossy, Alu Macbook 2.4, iMac G5, iPhone3GS 32gb white, iPodz |
|
|
|
|
#4 |
|
macrumors 6502
Join Date: Feb 2006
Location: Calgary, Canada
|
I read the whole thing on the Symantec website, but I'm still a little confused. What would the end-user see? I know what the malware technically did, but what did it visually do? What was it's purpose?
|
|
|
|
|
#5 | |
|
macrumors Demi-Goddess
Join Date: Mar 2005
Location: Londrizzle, UK
|
Quote:
|
|
|
|
|
|
#6 | |
|
macrumors 68020
|
Quote:
But hey, this isn't scary. If you have common sense and take precaution, a future trojan can be easily avoidable. I'm sure Apple will release some sort of patch to aid users in the future. I'm still relieved it isn't an actual virus... if it was, then I'd scared. |
|
|
|
|
|
#7 | |
|
macrumors 601
Join Date: Aug 2003
Location: sitting on your shoulder
|
Quote:
__________________
"People shouldn't use word processors as web development tools. It's like using a domestic cat to spread butter on your toast." -ad |
|
|
|
|
|
#8 |
|
macrumors 68030
Join Date: Jul 2004
Location: Melbourne, Australia
|
How do you patch against users downloading and running applications from people they don't know?
__________________
A penny saved is ridiculous. |
|
|
|
|
#9 | |
|
macrumors Demi-God
Join Date: May 2004
Location: La Villa Strangiato
|
Quote:
It will be interesting to see if Apple even responds to this. My guess is....NOT.
__________________
Mac Pro Octophallus 2.8 | 13" UMBP 2.26 |
|
|
|
|
|
#10 |
|
macrumors 601
|
That freaking Bas$$%^$ that posted that crap should be placed in the middle of a town and burn before all the mac heads......na just kidding
Bless
__________________
I take everything to Jah in prayer
|
|
|
|
|
#11 | |
|
macrumors Demi-Goddess
Join Date: Mar 2005
Location: Londrizzle, UK
|
Quote:
|
|
|
|
|
|
#12 | |
|
macrumors 65816
Join Date: Jun 2005
Location: the ruins of the Cherokee nation
|
Quote:
__________________
creation through destruction
|
|
|
|
| faintember |
| View Public Profile |
| Find More Posts by faintember |
|
|
#13 | |
|
macrumors 68000
Join Date: Oct 2005
Location: Nelson, BC. Canada
|
Quote:
(I've since created a new admin account and demoted my day-to-day account to 'standard') Last edited by Danksi : Feb 17, 2006 at 12:22 AM. |
|
|
|
|
|
#14 | |
|
macrumors 601
Join Date: Aug 2003
Location: sitting on your shoulder
|
Quote:
![]() So am I, I laughed
__________________
"People shouldn't use word processors as web development tools. It's like using a domestic cat to spread butter on your toast." -ad |
|
|
|
|
|
#15 | |
|
macrumors 68020
|
Quote:
I just hope Apple does something about this... I think they would. They seem to care about their OS being the best one on the market. I don't think they would let some trojan knock them off that path. |
|
|
|
|
|
#16 | |
|
macrumors 65816
Join Date: Feb 2006
Location: Portland
|
Quote:
|
|
|
|
|
|
#17 |
|
macrumors Demi-Goddess
Join Date: Mar 2005
Location: Londrizzle, UK
|
|
|
|
|
|
#18 |
|
macrumors 65816
Join Date: Jun 2005
Location: the ruins of the Cherokee nation
|
p0intblank, I cant take credit for the idea, it was posted by another MR member on a separate thread about the new trojan. This seems like an easy enough thing to stop, but then again i am not a programmer, so what do i know.
All i know is a executable, at some level, has to look like an executable to the OS, so why not visually distinguish them from other file types for the user? Edit: Good point iBlue, but why not make that, and say the "red text" or "exclamation" all on by default with no way of turning them off? No harm in that....
__________________
creation through destruction
|
|
|
| faintember |
| View Public Profile |
| Find More Posts by faintember |
|
|
#19 | |
|
macrumors Demi-God
Join Date: Sep 2004
Location: On the roadside
|
Quote:
|
|
|
|
|
|
#20 |
|
macrumors 601
Join Date: May 2002
Location: Blinking blue dot
|
If you want to side-step definitions of what a virus is (some would call this a very weak virus, others wouldn't), you're best bet is to tell people there's never been an OS X virus that could function without the user's help. (Several steps of help, in fact.)
|
|
|
|
|
#21 | |
|
macrumors 65816
Join Date: Feb 2006
Location: Portland
|
Quote:
I saw that on mac addict, had a spasm of terror, then started laughing and couldn't stop. |
|
|
|
|
|
#22 |
|
macrumors regular
|
Best Fix
The best thing that apple can do to fix this problem is require any person buying a Apple computer to pass an intelligence test. If you fail you don't get to own one of their computers. The problem is stupidity and I don't think that it is the job of Apple to protect us from ourselves. My feeling is that if you are dumb enough to open a file from a source you are not sure of then you get what you deserve. Kinda like the idiot that puts his hot fast-food coffee between his legs and then burns himself when it spills. With any luck those idiots will sterilize themselves and we won't have to worry about them dumbing down the gene pool any more then it already is.
I have zero tolerance policy on stupidity. My $0.02
__________________
"I gotta tell ya, at this point, the length of this conversation is way out of proportion to my interest in it.” |
|
|
|
|
#23 | |
|
macrumors 68020
|
Quote:
|
|
|
|
|
|
#24 | |
|
macrumors 601
Join Date: May 2002
Location: Blinking blue dot
|
Quote:
Apps in folder pop-up menus from the Dock should throb as well. And in Column view if you have icons turned off, a symbol should throb next to executables. |
|
|
|
|
|
#25 | |
|
macrumors member
Join Date: Feb 2006
|
Quote:
All that happens is that businesses such as Data Doctors open and charge lot's of money to fix people's computers. Data Doctors is making huge amounts of money from stupid users who do stupid things with their computers (mostly PC's). This is good by the way because when I go by a Data Doctors location, I get the opportunity for a laugh. Mostly at the stupid users inside getting repairs. lol
__________________
I used to have super powers, but my therapist took them away. |
|
|
|
| Thread Tools | Search this Thread |
| Display Modes | |
|
|