Read post #95 in this thread. Also: http://www.f-secure.com/v-descs/trojan_bash_qhost_wb.shtmlSo did the program get on my computer or not?
Read post #95 in this thread. Also: http://www.f-secure.com/v-descs/trojan_bash_qhost_wb.shtmlSo did the program get on my computer or not?
Hey at least as Mac users aren't stupid enough to download crap from mysterious sites like how Windows user do. Windows has 100 of viruses. Us Mac have only 2.
I type into terminal /etc/hosts...and then says permisson denied. What does this mean?
cat /etc/hosts
menu go to folder ..type this: /etc/
then open - hosts
the inside should look like this if it has not been modified
##
# Host Database
#
# localhost is used to configure the loopback interface
# when the system is booting. Do not change this entry.
##
127.0.0.1 localhost
255.255.255.255 broadcasthost
::1 localhost
fe80::1%lo0 localhost
Mine has two extra lines of text. Is this normal?
##
# Host Database
#
# localhost is used to configure the loopback interface
# when the system is booting. Do not change this entry.
##
127.0.0.1 localhost
255.255.255.255 broadcasthost
::1 localhost
fe80::1%lo0 localhost
74.208.10.249 gs.apple.com
#127.0.0.1 gs.apple.com
I knew one day apple would have a virus but before the NBA lockout is resolved?
Mine has two extra lines of text. Is this normal?
##
# Host Database
#
# localhost is used to configure the loopback interface
# when the system is booting. Do not change this entry.
##
127.0.0.1 localhost
255.255.255.255 broadcasthost
::1 localhost
fe80::1%lo0 localhost
74.208.10.249 gs.apple.com
#127.0.0.1 gs.apple.com
I think that you should be worried:
W:\Win7x64> nslookup gs.apple.com
Server: dns1.lsanca.sbcglobal.net
Address: 206.13.29.12
Non-authoritative answer:
Name: gs.apple.com.akadns.net
Address: 17.151.36.30
Aliases: gs.apple.com
W:\Win7x64> nslookup 74.208.10.249
Server: dns1.lsanca.sbcglobal.net
Address: 206.13.29.12
Name: nginx.saurik.com
Address: 74.208.10.249
W:\Hobbs>whois nginx.saurik.com
Whois v1.01 - Domain information lookup utility
Connecting to COM.whois-servers.net...
Connecting to whois.dotster.com...
Jay Freeman
6935 Phelps Road
Apartment #27
Goleta, CA 93117
US
Registrar: DOTSTER
Domain Name: SAURIK.COM
Created on: 13-JUL-97
Expires on: 12-JUL-12
Last Updated on: 28-JUN-11
Administrative, Technical Contact:
Freeman, Jay saurik@saurik.com
6935 Phelps Road
Apartment #27
Goleta, CA 93117
US
(805) 895-7209
Domain servers in listed order:
NS-57.AWSDNS-07.COM
NS-661.AWSDNS-18.NET
NS-1335.AWSDNS-38.ORG
NS-1947.AWSDNS-51.CO.UK
End of Whois Information
Something has modified your DNS lookup path to substitute a fixed address for a nodename.
Software that thinks that it is accessing an Apple address are going to Jay Freeman in Goleta, CA, US and http://www.saurik.com/.
Might be explainable, but on the surface doesn't look good....
Its totally fine.
Just a Jailbreak program on his computer backing up his Cydia blobs
I think,...could be wrong
The hosts file is not the only file in OS X that can be altered to yield malicious results. Apple would have to undertake an enormous amount of effort to protect every file that a given instance of malware can tamper with.
The problem, to me, seems to be traditional installers that do all kinds of things behind the user's back. I don't understand why Apple even supports installers anymore. Apple created a brilliant method of software installation with app bundles. Just drag and drop the app to your Applications folders and it's done. I'd always assumed that's where OS X was headed eventually and that installers were on their way out.
I knew one day apple would have a virus but before the NBA lockout is resolved?
Let's get this out of the way right now : This is not an OS X virus.
Hey at least as Mac users aren't stupid enough to download crap from mysterious sites like how Windows user do. Windows has 100 of viruses. Us Mac have only 2.
People use the word 'virus' so easily! Mac's don't have viruses. They have other types of malware, but not viruses.
Anyway, viruses aren't really a problem any more. Not even for Windows. It's the other forms of malware that are the problem.
Just in case you didn't know, malware is any type of malicious software. So viruses, Trojan's, spyware, worms and other things like that are all forms of malware. They're all bad, but a Trojan (like what this story is about) isn't as bad because it doesn't replicate itself and isn't as harmful to the computer.
Use Google Chrome and you never have to worry about Flash installs and updates.
No, you are quite right, it's the firmware signing address for iPhones. This is completely inert, nothing to see there. AidenShaw is simply demonstrating a lack of knowledge and basic research skills. If this is not enough, check on the website that AidenShaw posted, and read why the address is in the hosts file.
Seeing as the original server is gone, no one has anything to worry about. Macrumours should really update the article to reflect that.