Forums | MacLife

You are not logged in.

#1 2008-06-24 9:58 am

Kurto2021
Member
From: Wichita, KS
Registered: 2001-11-28
Posts: 2423

New Trojan horse

Of course I receive like 10 emails from my friends the day they hear about a possible trojan / virus for the mac.

To me it doesn't seem like much of a threat since it is a script you have to run.  To me it is just a program that you have to install so if you do install it you are an idiot.

http://www.securemac.com/applescript-th … -horse.php


http://i26.photobucket.com/albums/c111/circpro/OAUserbar.gif
http://img137.imageshack.us/img137/8586/ronfezuserbareg5.gif
http://img89.imageshack.us/img89/8259/ipodshuffleusercw7.jpg
http://img89.imageshack.us/img89/1374/applefk0.gif

Offline

 

#2 2008-06-24 10:13 am

Shadowless
LCpl, USMC
From: San Diego, CA
Registered: 2005-10-10
Posts: 2965

Re: New Trojan horse

...Okay, so I'd have to either use LimeWire (which I constantly recommend to my friends to uninstall from their computers), or talk to someone in iChat who I don't trust, which doesn't happen. On top of that, I'd have to not realize I'm downloading it, and then also not realize that I decided to install it.

So this is dangerous how?


http://imagegen.last.fm/Awesome35/artists/3/ShadowlessDJ.gif
http://tinyurl.com/655k86http://tinyurl.com/6b4zml

Offline

 

#3 2008-06-24 1:15 pm

sturner
Royal High Poobah
Moderator
From: Carrollton, TX USA
Registered: 2000-01-31
Posts: 9857

Re: New Trojan horse

Social engineering at its height.


"There were places in the world commemorating those times when wizards hadn't been quite as clever [as to refrain from doing magic when you knew how easy it was], and on many of them the grass would never grow again."  Terry Prachett

There are 3 types of people, those who can count and those who can't.

Offline

 

#4 2008-06-24 9:47 pm

thumbprint
giant member
Registered: 2003-06-22
Posts: 164
Website

Re: New Trojan horse

On top of that, I'd have to not realize I'm downloading it, and then also not realize that I decided to install it.

It could be disguised as a legit download like shareware/freeware program. I'll admit that even I got duped once (a number of years ago) by downloading something on my PC that was supposed to be a NES emulator... and turned out to be a trojan.

Yeah, I should have scanned it before installing it, but hey sometimes you just forget for whatever reason. Even the smartest of us have our bad days sometimes blush


=================================
I'm sorry I need this DISCLAIMER:
=================================
All my opinions are just that. Opinions. Chances are you won't agree. Chances are they won't apply to you. Even if we're arguing I'll still try to respect your opinions.

Offline

 

#5 2008-06-25 2:41 am

reece_james
TheLAD
From: Wollongong, Australia.
Registered: 2001-12-01
Posts: 3786
Website

Re: New Trojan horse

So, how is this any more dangerous than executing a file with rm -r ~/

lol


Reece [/IMHO]
"All posts on the internet are postfixed by an invisible 'IMHO'", tito
Intel iMac CD 1.83Ghz, 2GB RAM, 17" + 20", 1160GB HD, 10.5.2.
MacBook CD 1.83Ghz, 2GB RAM, 60GB HD, 10.5.2.

Offline

 

#6 2008-06-25 10:50 am

Mr. T
Uses STOS implicitly
From: omnipresent
Registered: 2002-04-02
Posts: 3591

Re: New Trojan horse

This script can run as root without a password.


while (1) {fork();}

Offline

 

#7 2008-06-25 7:17 pm

NAG
A witch!
Royal Wombat
From: /usr/local/apps/nag
Registered: 2000-09-22
Posts: 30225

Re: New Trojan horse

Hopefully they patch this soon. Still, it isn't horribly terrifying.


"You call *this* archaeology?" • Professor Henry Jones
http://homepage.mac.com/dpauw/.Pictures/misc/moron.gif

Offline

 

#8 2008-06-25 9:08 pm

mo' ron
Hates Integrated Graphics
From: NC, USA
Registered: 2002-10-15
Posts: 13507

Re: New Trojan horse

This SecureMac company always talks about threats being "in the wild" that only they can confirm.

This is an issue, but I think they are grossly exaggerating its potential, and I think they are either making the trojan themselves, or just lying about it.


What is the difference between Vista and OSX?
- Microsoft employees are excited about OSX.

Offline

 

#9 2008-06-26 1:56 pm

Antonio
Now with more cowbell!
From: San Francisco, CA
Registered: 2007-01-16
Posts: 520

Re: New Trojan horse

Mr. T wrote:

This script can run as root without a password.

With root priveleges? I somehow doubt it. Unless you install it with your password.
Which means I am taking this about as seriously as the other 'threats'.
Seems like once again the real threat is user error.

"user error"

-that should be a forum username.

Last edited by Antonio (2008-06-26 1:59 pm)


“The most merciful thing in the world, I think, is the inability of the human mind to correlate all its contents.”
--HP Lovecraft, The Call Of Cthulhu

Offline

 

#10 2008-06-26 2:37 pm

Mr. T
Uses STOS implicitly
From: omnipresent
Registered: 2002-04-02
Posts: 3591

Re: New Trojan horse

It gains root access through an exploit in Apple Remote Desktop Agent (It's not the first time an OS X vulnerability has been exploited to gain root access, and it won't be the last).  It's great that it's not the most serious of threats, but that doesn't mean we can laugh it off entirely.  And Apple needs to move its ass and get a patch out asap, no matter how serious the threat may be.

Last edited by Mr. T (2008-06-26 2:47 pm)


while (1) {fork();}

Offline

 

#11 2008-06-26 2:54 pm

thumbprint
giant member
Registered: 2003-06-22
Posts: 164
Website

Re: New Trojan horse

Is there an easy way to just REMOVE this Apple Remote Desktop Agent thing? I mean, is it an app that I can just delete?


=================================
I'm sorry I need this DISCLAIMER:
=================================
All my opinions are just that. Opinions. Chances are you won't agree. Chances are they won't apply to you. Even if we're arguing I'll still try to respect your opinions.

Offline

 

#12 2008-06-26 3:40 pm

Mr. T
Uses STOS implicitly
From: omnipresent
Registered: 2002-04-02
Posts: 3591

Re: New Trojan horse

Possibly but I wouldn't.  It's probably related to screen sharing in iChat, remote login, etc.. Sometimes even if you have no need for something, some programs expecting to find the file might not know how to deal with its absence. 

As has been said, this threat is not that critical (av companies always exaggerate these things).  Pretty much if you avoid downloading suspicious apps from LimeWire or Warez sites, you won't have any trouble.


while (1) {fork();}

Offline

 

#13 2008-06-28 7:06 am

nayrk
User Error
From: Outland
Registered: 2004-05-01
Posts: 622

Re: New Trojan horse

Mr. T wrote:

Possibly but I wouldn't.  It's probably related to screen sharing in iChat, remote login, etc.. Sometimes even if you have no need for something, some programs expecting to find the file might not know how to deal with its absence. 

As has been said, this threat is not that critical (av companies always exaggerate these things).  Pretty much if you avoid downloading suspicious apps from LimeWire or Warez sites, you won't have any trouble.

That said, screen sharing has been a god send with my parents and in-laws.


Roses are red
Violets are blue
I'm a schizophrenic
And so am I

Offline

 

#14 2008-06-28 4:31 pm

thumbprint
giant member
Registered: 2003-06-22
Posts: 164
Website

Re: New Trojan horse

Pretty much if you avoid downloading suspicious apps from LimeWire or Warez sites, you won't have any trouble.

But in my example above (when I actually got a trojan) it was downloaded from a website that purported to have created this NES emulator. It wasn't a warez site.

Now, you can write it off as me being an idiot, but the reality is I'm borderline paranoid when it comes to trojans, malware, etc. I have 6 anti-virus, anti-hack, anti-malware, anti-spyware, anti-whatever programs on my PC and 4 such programs on my Mac. And everything is behind a firewall. And I don't use Internet Explorer or any P2P programs and rarely even chat.

Yet I still got a trojan.

Point is, anybody can get one (even vigilant people) when they least expect it.


=================================
I'm sorry I need this DISCLAIMER:
=================================
All my opinions are just that. Opinions. Chances are you won't agree. Chances are they won't apply to you. Even if we're arguing I'll still try to respect your opinions.

Offline

 

#15 2008-06-28 11:49 pm

Daniel
[dp] design#
From: Indian Harbour Beach, FL
Registered: 2000-11-21
Posts: 9211
Website

Re: New Trojan horse

Antonio wrote:

Mr. T wrote:

This script can run as root without a password.

With root priveleges? I somehow doubt it. Unless you install it with your password.
Which means I am taking this about as seriously as the other 'threats'.
Seems like once again the real threat is user error.

"user error"

-that should be a forum username.

Believe it or not, OS X is not invulnerable.


Airman Dan
Private Pilot, Airplane Single-Engine Land
http://homepage.mac.com/dp.design/.Pictures/maf/crosssig.gif
ONE NATION WITH LIBERTY AND JUSTICE FOR ALL.

Offline

 

#16 2008-06-29 12:06 am

Scott Baret
Member
Registered: 2008-03-30
Posts: 54

Re: New Trojan horse

When I first saw this headline I thought we were looking at another trojan horse like the ones of the 1980s and 1990s--if anyone remembers "Font Finder", "Tetricycle", and the "Sexy Ladies" HyperCard stack you are indeed a veteran of the platform.

This one sounds pretty avoidable. Restrict your iChat to friends only and dump your file sharing services. They're risky and illegal. Getting rid of file sharing and switching to legitimate and legal sites like iTunes for purchasing music gives you two benefits--compliance with the law and a lesser chance of a virus infection.

However, if something wider-spread like this ever comes up again, we may have to lure John Norstad out of retirement...imagine Disinfectant for OS X!

Offline

 

#17 2008-06-29 12:40 am

Mr. T
Uses STOS implicitly
From: omnipresent
Registered: 2002-04-02
Posts: 3591

Re: New Trojan horse

thumbprint wrote:

Pretty much if you avoid downloading suspicious apps from LimeWire or Warez sites, you won't have any trouble.

But in my example above (when I actually got a trojan) it was downloaded from a website that purported to have created this NES emulator. It wasn't a warez site.

Now, you can write it off as me being an idiot, but the reality is I'm borderline paranoid when it comes to trojans, malware, etc. I have 6 anti-virus, anti-hack, anti-malware, anti-spyware, anti-whatever programs on my PC and 4 such programs on my Mac. And everything is behind a firewall. And I don't use Internet Explorer or any P2P programs and rarely even chat.

Yet I still got a trojan.

Point is, anybody can get one (even vigilant people) when they least expect it.

If there's any doubt, you could always just download everything from VersionTracker until apple issues an update.   Practically speaking though, the number of windows threats to mac is hundreds of thousands to one, and most of those threats are available through many different channels.  This, on the other hand is a spec of dust in the universe.  This is something that Apple needs to fix asap (before a more serious threat comes along), but for Mac users, it's mostly a reminder that we still need to exercise a reasonable amount of caution.

Last edited by Mr. T (2008-06-29 12:41 am)


while (1) {fork();}

Offline

 

#18 2008-06-29 8:28 am

ScifiterX
エロ仙人
Moderator
From: NW Palm Bay, Florida
Registered: 2000-02-10
Posts: 15845
Website

Re: New Trojan horse

Indeed but I'm quite happy it's a reasonable amount of caution rather the the insane amount I dealt with while using Windows.

Offline

 

Board footer

Powered by PunBB
© Copyright 2002–2005 Rickard Andersson