Forums | MacLife
You are not logged in.
#1 2008-06-24 9:58 am
- Kurto2021
- Member
- From: Wichita, KS
- Registered: 2001-11-28
- Posts: 2423
New Trojan horse
Of course I receive like 10 emails from my friends the day they hear about a possible trojan / virus for the mac.
To me it doesn't seem like much of a threat since it is a script you have to run. To me it is just a program that you have to install so if you do install it you are an idiot.
http://www.securemac.com/applescript-th … -horse.php
Offline
#2 2008-06-24 10:13 am
- Shadowless
- LCpl, USMC

- From: San Diego, CA
- Registered: 2005-10-10
- Posts: 2965
Re: New Trojan horse
...Okay, so I'd have to either use LimeWire (which I constantly recommend to my friends to uninstall from their computers), or talk to someone in iChat who I don't trust, which doesn't happen. On top of that, I'd have to not realize I'm downloading it, and then also not realize that I decided to install it.
So this is dangerous how?
Offline
#3 2008-06-24 1:15 pm
- sturner
- Royal High Poobah
- Moderator

- From: Carrollton, TX USA
- Registered: 2000-01-31
- Posts: 9857
Re: New Trojan horse
Social engineering at its height.
"There were places in the world commemorating those times when wizards hadn't been quite as clever [as to refrain from doing magic when you knew how easy it was], and on many of them the grass would never grow again." Terry Prachett
There are 3 types of people, those who can count and those who can't.
Offline
#4 2008-06-24 9:47 pm
- thumbprint
- giant member

- Registered: 2003-06-22
- Posts: 164
- Website
Re: New Trojan horse
On top of that, I'd have to not realize I'm downloading it, and then also not realize that I decided to install it.
It could be disguised as a legit download like shareware/freeware program. I'll admit that even I got duped once (a number of years ago) by downloading something on my PC that was supposed to be a NES emulator... and turned out to be a trojan.
Yeah, I should have scanned it before installing it, but hey sometimes you just forget for whatever reason. Even the smartest of us have our bad days sometimes 
=================================
I'm sorry I need this DISCLAIMER:
=================================
All my opinions are just that. Opinions. Chances are you won't agree. Chances are they won't apply to you. Even if we're arguing I'll still try to respect your opinions.
Offline
#5 2008-06-25 2:41 am
- reece_james
- TheLAD

- From: Wollongong, Australia.
- Registered: 2001-12-01
- Posts: 3786
- Website
Re: New Trojan horse
So, how is this any more dangerous than executing a file with rm -r ~/
Reece [/IMHO]
"All posts on the internet are postfixed by an invisible 'IMHO'", tito
Intel iMac CD 1.83Ghz, 2GB RAM, 17" + 20", 1160GB HD, 10.5.2.
MacBook CD 1.83Ghz, 2GB RAM, 60GB HD, 10.5.2.
Offline
#6 2008-06-25 10:50 am
- Mr. T
- Uses STOS implicitly

- From: omnipresent
- Registered: 2002-04-02
- Posts: 3591
Re: New Trojan horse
This script can run as root without a password.
while (1) {fork();}
Offline
#7 2008-06-25 7:17 pm
- NAG
- A witch!
- Royal Wombat

- From: /usr/local/apps/nag
- Registered: 2000-09-22
- Posts: 30225
Re: New Trojan horse
Hopefully they patch this soon. Still, it isn't horribly terrifying.
Offline
#8 2008-06-25 9:08 pm
- mo' ron
- Hates Integrated Graphics

- From: NC, USA
- Registered: 2002-10-15
- Posts: 13507
Re: New Trojan horse
This SecureMac company always talks about threats being "in the wild" that only they can confirm.
This is an issue, but I think they are grossly exaggerating its potential, and I think they are either making the trojan themselves, or just lying about it.
What is the difference between Vista and OSX?
- Microsoft employees are excited about OSX.
Offline
#9 2008-06-26 1:56 pm
- Antonio
- Now with more cowbell!

- From: San Francisco, CA
- Registered: 2007-01-16
- Posts: 520
Re: New Trojan horse
Mr. T wrote:
This script can run as root without a password.
With root priveleges? I somehow doubt it. Unless you install it with your password.
Which means I am taking this about as seriously as the other 'threats'.
Seems like once again the real threat is user error.
"user error"
-that should be a forum username.
Last edited by Antonio (2008-06-26 1:59 pm)
“The most merciful thing in the world, I think, is the inability of the human mind to correlate all its contents.”
--HP Lovecraft, The Call Of Cthulhu
Offline
#10 2008-06-26 2:37 pm
- Mr. T
- Uses STOS implicitly

- From: omnipresent
- Registered: 2002-04-02
- Posts: 3591
Re: New Trojan horse
It gains root access through an exploit in Apple Remote Desktop Agent (It's not the first time an OS X vulnerability has been exploited to gain root access, and it won't be the last). It's great that it's not the most serious of threats, but that doesn't mean we can laugh it off entirely. And Apple needs to move its ass and get a patch out asap, no matter how serious the threat may be.
Last edited by Mr. T (2008-06-26 2:47 pm)
while (1) {fork();}
Offline
#11 2008-06-26 2:54 pm
- thumbprint
- giant member

- Registered: 2003-06-22
- Posts: 164
- Website
Re: New Trojan horse
Is there an easy way to just REMOVE this Apple Remote Desktop Agent thing? I mean, is it an app that I can just delete?
=================================
I'm sorry I need this DISCLAIMER:
=================================
All my opinions are just that. Opinions. Chances are you won't agree. Chances are they won't apply to you. Even if we're arguing I'll still try to respect your opinions.
Offline
#12 2008-06-26 3:40 pm
- Mr. T
- Uses STOS implicitly

- From: omnipresent
- Registered: 2002-04-02
- Posts: 3591
Re: New Trojan horse
Possibly but I wouldn't. It's probably related to screen sharing in iChat, remote login, etc.. Sometimes even if you have no need for something, some programs expecting to find the file might not know how to deal with its absence.
As has been said, this threat is not that critical (av companies always exaggerate these things). Pretty much if you avoid downloading suspicious apps from LimeWire or Warez sites, you won't have any trouble.
while (1) {fork();}
Offline
#13 2008-06-28 7:06 am
- nayrk
- User Error

- From: Outland
- Registered: 2004-05-01
- Posts: 622
Re: New Trojan horse
Mr. T wrote:
Possibly but I wouldn't. It's probably related to screen sharing in iChat, remote login, etc.. Sometimes even if you have no need for something, some programs expecting to find the file might not know how to deal with its absence.
As has been said, this threat is not that critical (av companies always exaggerate these things). Pretty much if you avoid downloading suspicious apps from LimeWire or Warez sites, you won't have any trouble.
That said, screen sharing has been a god send with my parents and in-laws.
Roses are red
Violets are blue
I'm a schizophrenic
And so am I
Offline
#14 2008-06-28 4:31 pm
- thumbprint
- giant member

- Registered: 2003-06-22
- Posts: 164
- Website
Re: New Trojan horse
Pretty much if you avoid downloading suspicious apps from LimeWire or Warez sites, you won't have any trouble.
But in my example above (when I actually got a trojan) it was downloaded from a website that purported to have created this NES emulator. It wasn't a warez site.
Now, you can write it off as me being an idiot, but the reality is I'm borderline paranoid when it comes to trojans, malware, etc. I have 6 anti-virus, anti-hack, anti-malware, anti-spyware, anti-whatever programs on my PC and 4 such programs on my Mac. And everything is behind a firewall. And I don't use Internet Explorer or any P2P programs and rarely even chat.
Yet I still got a trojan.
Point is, anybody can get one (even vigilant people) when they least expect it.
=================================
I'm sorry I need this DISCLAIMER:
=================================
All my opinions are just that. Opinions. Chances are you won't agree. Chances are they won't apply to you. Even if we're arguing I'll still try to respect your opinions.
Offline
#15 2008-06-28 11:49 pm
Re: New Trojan horse
Antonio wrote:
Mr. T wrote:
This script can run as root without a password.
With root priveleges? I somehow doubt it. Unless you install it with your password.
Which means I am taking this about as seriously as the other 'threats'.
Seems like once again the real threat is user error.
"user error"
-that should be a forum username.
Believe it or not, OS X is not invulnerable.
Offline
#16 2008-06-29 12:06 am
- Scott Baret
- Member
- Registered: 2008-03-30
- Posts: 54
Re: New Trojan horse
When I first saw this headline I thought we were looking at another trojan horse like the ones of the 1980s and 1990s--if anyone remembers "Font Finder", "Tetricycle", and the "Sexy Ladies" HyperCard stack you are indeed a veteran of the platform.
This one sounds pretty avoidable. Restrict your iChat to friends only and dump your file sharing services. They're risky and illegal. Getting rid of file sharing and switching to legitimate and legal sites like iTunes for purchasing music gives you two benefits--compliance with the law and a lesser chance of a virus infection.
However, if something wider-spread like this ever comes up again, we may have to lure John Norstad out of retirement...imagine Disinfectant for OS X!
Offline
#17 2008-06-29 12:40 am
- Mr. T
- Uses STOS implicitly

- From: omnipresent
- Registered: 2002-04-02
- Posts: 3591
Re: New Trojan horse
thumbprint wrote:
Pretty much if you avoid downloading suspicious apps from LimeWire or Warez sites, you won't have any trouble.
But in my example above (when I actually got a trojan) it was downloaded from a website that purported to have created this NES emulator. It wasn't a warez site.
Now, you can write it off as me being an idiot, but the reality is I'm borderline paranoid when it comes to trojans, malware, etc. I have 6 anti-virus, anti-hack, anti-malware, anti-spyware, anti-whatever programs on my PC and 4 such programs on my Mac. And everything is behind a firewall. And I don't use Internet Explorer or any P2P programs and rarely even chat.
Yet I still got a trojan.
Point is, anybody can get one (even vigilant people) when they least expect it.
If there's any doubt, you could always just download everything from VersionTracker until apple issues an update. Practically speaking though, the number of windows threats to mac is hundreds of thousands to one, and most of those threats are available through many different channels. This, on the other hand is a spec of dust in the universe. This is something that Apple needs to fix asap (before a more serious threat comes along), but for Mac users, it's mostly a reminder that we still need to exercise a reasonable amount of caution.
Last edited by Mr. T (2008-06-29 12:41 am)
while (1) {fork();}
Offline
#18 2008-06-29 8:28 am
Re: New Trojan horse
Indeed but I'm quite happy it's a reasonable amount of caution rather the the insane amount I dealt with while using Windows.
Offline







