Register FAQ/Rules Forum Spy Search Today's Posts Mark Forums Read

Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate.

 
Go Back   Mac Forums > Archive > Archives of Old Posts > New Mac Application Announcements
TouchArcade.com - iPhone Game Reviews and News

 
 
Thread Tools Search this Thread Display Modes
Old May 12, 2004, 09:47 AM   #1
MacBytes
macrumors bot
 
Join Date: Jul 2003
Fake Word 2004 demo file causes irradication of a mac's Hom...


Category: 3rd Party Software
Link: Fake Word 2004 demo file causes irradication of a mac\'s Home folder
Posted on MacBytes.com

Approved by Mudbug
MacBytes is offline  
Old May 12, 2004, 10:57 AM   #2
MacBandit
macrumors 601
 
MacBandit's Avatar
 
Join Date: Aug 2002
Location: Springfield, OR (Home of the Simpsons)
Send a message via AIM to MacBandit
I love it. If you Pirate software you have to be ready for the consequences. A malicious file on the other hand should be the least of your worries.
__________________
Folding@Home
"Folding FAQ," for more information.
Fold with your PS3. Message me on the Playstation Network ID 'MacBandit'
MacBandit is offline  
Old May 12, 2004, 11:35 AM   #3
FosterKanig
macrumors member
 
Join Date: Jul 2003
Now THAT"S funny.

I love his explanation: "I downloaded the file in the hope that perhaps Microsoft had released some sort of public beta."

Yes, and we all know that downloading off Limewire would be much quicker than downloading from Microsoft's servers. Geez.
FosterKanig is offline  
Old May 12, 2004, 12:58 PM   #4
Flowbee
macrumors 68030
 
Flowbee's Avatar
 
Join Date: Dec 2002
Location: Alameda, CA
Just out of curiosity, is there any way to tell, just by examining the file itself, that it is not actually MS Word 2004?

(And before I get a lecture about pirating software, I own a copy of Office X, which I paid for, and have no intention of upgrading to 2004.)
__________________
Podophile.com >> Home of Nike+iPod hacks and FAQs.
Flowbee is offline  
Old May 12, 2004, 01:53 PM   #5
iMeowbot
macrumors 601
 
iMeowbot's Avatar
 
Join Date: Aug 2003
Quote:
Originally Posted by Flowbee
Just out of curiosity, is there any way to tell, just by examining the file itself, that it is not actually MS Word 2004?
Nah, it's the whole problem of proving a negative.

When software gets released online, the real distributors will offer downloads directly, provide an official list of mirror locations, and/or supply checksums (usually MD5 hashes). Anonymous distribution channels like p2p networks are a really bad place to get executables or sources, unlless you can also get that checksum (and preferably size too) information from a trusted source.
iMeowbot is offline  
Old May 12, 2004, 01:59 PM   #6
Doctor Q
macrumors god
 
Doctor Q's Avatar
 
Join Date: Sep 2002
Location: at the table with countless relatives
Quote:
Originally Posted by Flowbee
Just out of curiosity, is there any way to tell, just by examining the file itself, that it is not actually MS Word 2004?
I assumed your comment was a joke, i.e., you were pretending that it might have been MS Word 2004 itself that he downloaded, and that it had a small bug that wipes out your home folder.

If that's what you meant, good joke!
If that's not what you meant, then I claim that joke as my own!
__________________
"You've just been abducted, of course you need crepes!" -- Walter Bishop
Doctor Q is offline  
Old May 12, 2004, 02:02 PM   #7
Mr. Anderson
Demi-God (Moderator)
 
Mr. Anderson's Avatar
 
Join Date: Nov 2001
Location: Back in VA
Send a message via AIM to Mr. Anderson
wow, now that's just got to suck

Unfortunately, this might just be the beginning - I'm sure more will be showing up soon...



D
__________________
"Klaatu varada nikto!"
Mr. Anderson is offline  
Old May 12, 2004, 02:12 PM   #8
Flowbee
macrumors 68030
 
Flowbee's Avatar
 
Join Date: Dec 2002
Location: Alameda, CA
Quote:
Originally Posted by Doctor Q
I assumed your comment was a joke
No joke intended (rare for me, I know). Just wondering if there are any obvious (or not so obvious) give-aways that the file you've downloaded is not what it claims to be.
__________________
Podophile.com >> Home of Nike+iPod hacks and FAQs.
Flowbee is offline  
Old May 12, 2004, 03:00 PM   #9
Lancetx
macrumors 65816
 
Lancetx's Avatar
 
Join Date: Aug 2003
Location: Texas
Quote:
Originally Posted by Flowbee
No joke intended (rare for me, I know). Just wondering if there are any obvious (or not so obvious) give-aways that the file you've downloaded is not what it claims to be.
Well, in the case of this particular trojan it's easy, it's only 108KB, so there is no way it could be a demo of Word 2004.
Lancetx is offline  
Old May 12, 2004, 03:25 PM   #10
Flowbee
macrumors 68030
 
Flowbee's Avatar
 
Join Date: Dec 2002
Location: Alameda, CA
Ha! And here I thought it was more sophisticated than that. Talk about an obvious clue...
__________________
Podophile.com >> Home of Nike+iPod hacks and FAQs.
Flowbee is offline  
Old May 12, 2004, 04:06 PM   #11
Awimoway
macrumors 65816
 
Join Date: Sep 2002
Location: at the edge
There's a pretty good discussion of the issue here (MacOSXHints).

And I believe I read there that checking the file size will not necessarily work because this Unix command could also be inserted into the ID tags of, say, a song file (remember last month's proof of concept trojan?), although it seems to me that Apple already did what they could to patch that exploit.

For this particular trojan, one particular protection would be to create a dummy user to open all suspect files, but if the Unix command deleted more than just your user folder, that wouldn't help much.

Essentially, it sounds like the only protection is not to open a file that you don't trust. Call it an MPAA conspiracy, but it sure makes P2P seem like a lot less fun.
Awimoway is offline  
Old May 12, 2004, 05:02 PM   #12
eyeluvmyimac
macrumors regular
 
Join Date: Oct 2002
dont you have to enter an admin password to delete the home directory? who wants to test the idea? hehe
__________________
Macbook... iPhone... Mac Pro: 2.66ghz, 3GB, 7300GT ...a 15.2" Alu PowerBook G4, 15" iMac 800 Mhz, iPod..and..Apple IIGS
====

tmartin316.com
eyeluvmyimac is offline  
Old May 12, 2004, 05:12 PM   #13
arn
macrumors god
 
arn's Avatar
 
Join Date: Apr 2001
Send a message via AIM to arn
I only posted this on MacRumors because it has gotten so much attention on various sites.

But my opinion is "no **** sherlock". I don't actually think the person here was an "innocent victim". You search for "Word 2004" on Limewire, then you take your risks.

arn
arn is offline  
Old May 12, 2004, 05:14 PM   #14
Marble
macrumors 6502a
 
Marble's Avatar
 
Join Date: May 2003
Location: Norwich, Norfolk
You have to enter a password, don't you?
Marble is offline  
Old May 12, 2004, 05:20 PM   #15
Hattig
macrumors 65816
 
Join Date: Jan 2003
Quote:
Originally Posted by Marble
You have to enter a password, don't you?
Not for your own home directory.

This is just a case of user stupidity and greed. Nothing to do with MacOS X. It is equally doable on Linux, FreeBSD, Windows ...

You have to take and pass a test to drive a car. I wish the same were true of using computers and the internet.
Hattig is offline  
Old May 12, 2004, 05:29 PM   #16
Jetson
macrumors 6502
 
Join Date: Oct 2003
Red face Bloated Egos

Quote:
This is just a case of user stupidity and greed. Nothing to do with MacOS X. It is equally doable on Linux, FreeBSD, Windows ...

You have to take and pass a test to drive a car. I wish the same were true of using computers and the internet.
Why oh why do people feel the need to insult and put others down? The guy did us a favor by reporting some malicious software and he gets attacked from the people who should be thanking him. Sheesh!

Last edited by Jetson : May 12, 2004 at 06:12 PM.
Jetson is offline  
Old May 12, 2004, 05:29 PM   #17
rotorblade
macrumors member
 
Join Date: Jul 2003
Quote:
Originally Posted by Flowbee
Just out of curiosity, is there any way to tell, just by examining the file itself, that it is not actually MS Word 2004?
Sure. In this guys case, all he needed to do was use Get-Info. Once the Finder's Get Info window displays, he could have clicked on the icon at the top of this window, then pressed the Delete key. Being that this was an AppleScript, it would have displayed the generic AppleScript applet icon.

I don't use Word, so I can't check the installer icon, but I'd assume you could use the same approach.
rotorblade is offline  
Old May 12, 2004, 05:38 PM   #18
dontmakemehurtu
macrumors regular
 
Join Date: Jan 2004
Location: New York City
Counting this one, there are now two viruses for Mac OS X. One thing that I find interesting is: Isn't it interesting that Intego has announced both of them?
__________________
"My hormones don't rage. Oh sure, they get mad sometimes, but then they just stop speaking to each other." -Daria Morgendorfer
dontmakemehurtu is offline  
Old May 12, 2004, 05:40 PM   #19
xtbfx
macrumors regular
 
Join Date: Nov 2003
Quote:
Originally Posted by Jetson
Why oh why do people feel the need to insult and put others down? The guy did us a favor by reporting some malicious software and he gets attacked from the people who should be thanking him. Sheesh!
hahah. This guy told us that he was going to pirate Microsoft Word 2004.

He didn't do us a favor. If you're going to pirate software, you should get a virus (let's just call it a slap on the wrist).

Download a demo version. haha, I wonder how long it took him to come up with that excuse.
xtbfx is offline  
Old May 12, 2004, 05:42 PM   #20
CrackedButter
macrumors 68030
 
CrackedButter's Avatar
 
Join Date: Jan 2003
Location: 51st State of America
Quote:
Originally Posted by dontmakemehurtu
Counting this one, there are now two viruses for Mac OS X. One thing that I find interesting is: Isn't it interesting that Intego has announced both of them?
Interesting moreso that one of those is a concept and the other is a trojan, not a virus.
__________________
"Absorb what is useful, Discard what is not, Add what is uniquely your own" - Bruce Lee
http://jonathanjk.viewbook.com/
CrackedButter is offline  
Old May 12, 2004, 05:43 PM   #21
idkew
macrumors 68020
 
idkew's Avatar
 
Join Date: Sep 2001
Location: where the concrete to dirt ratio is better
Send a message via AIM to idkew
Quote:
Originally Posted by dontmakemehurtu
Counting this one, there are now two viruses for Mac OS X. One thing that I find interesting is: Isn't it interesting that Intego has announced both of them?
i would no call it a virus though. i could make an applescript that would do this in 5 lines.

it is just a way to have some ignorant fool (purposefully) delete their home directory. no root files can be touched with this, without a password.
idkew is offline  
Old May 12, 2004, 05:53 PM   #22
dizastor
macrumors 6502a
 
dizastor's Avatar
 
Join Date: Dec 2001
Location: Los Angeles
Quote:
...some sort of public beta...
Released exclusively on Limewire.

I'm sure that's where everyone goes when looking for public betas of software.
__________________
ejc on Twitter
dizastor is offline  
Old May 12, 2004, 05:56 PM   #23
nagromme
macrumors 601
 
nagromme's Avatar
 
Join Date: May 2002
Location: Blinking blue dot
The app deleted the user's home folder... so that includes the app itself, right? So how did this get reported to Macworld?

I'm suspicious that the original reporter didn't truly "fall victim" at all.
__________________
nagromme
Would you like a treatment?
nagromme is offline  
Old May 12, 2004, 05:59 PM   #24
Frisco
macrumors 68000
 
Frisco's Avatar
 
Join Date: Sep 2002
Location: Nutley, NJ
Send a message via AIM to Frisco
Talking

So the lesson of the story is Always Back Up your Home Folder before downloading software off P2P
__________________
Frisco
Frisco is offline  
Old May 12, 2004, 06:01 PM   #25
davecuse
macrumors 6502
 
Join Date: Feb 2004
Location: NYC
Later this month it comes out that Microsoft released this, not as malware but as a feature specific only to software pirates. This would definitely be an effective tactic towards steering people away from piracy over P2P networks.
davecuse is offline  

 

Mac Forums > Archive > Archives of Old Posts > New Mac Application Announcements

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 10:32 PM.

Mac News | Mac Rumors | iPhone Game Reviews | iPhone Apps

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright 2002-2009, MacRumors.com, LLC