Free Republic
Browse · Search
General/Chat
Topics · Post Article

While technically the XcodeGhost was an OS X app that ran on Macs, it was not a vulnerability in OS X, but rather a social engineering attack on Chinese iOS developers who were in too much of a hurry to download Xcode from Apple's servers which the Chinese government would not allow to be hosted on shore. So they downloaded Xcode from third-party servers with greater and faster bandwidth and got a malicious version, XcodeGhost that inserted malicious code in the iOS Apps that attacked not OS X computers, but rather iOS devices.

The Register's second example, FlashBack was a closed vulnerability in JAVA, from 2011 and the so-called 700,000 member MacBot was a HOAX perpetrated by Dr. Web in 2012, a Russian security firm trying to sell their new Enterprise anti-virus for Apple Macs. They claimed they had discovered a massive, coordinated spambot which was made up of 98% Apple Macs and only 2% Windows computers. . . and all of them were only in English speaking countries. Yet to get infected with this Trojan that carried the malicious code, one had to log onto a Russian language game website, download a character definition for an obscure Russian language game which had only been download 19,000 times, and install the character in the game, on a Mac which had JAVA installed, ignoring the warnings that the Flashback trojan was present in the download, ignore the warning when the intaller was run, and ignore it again when the game was run for the first time with the new character. Add that JAVA was not a default install on OS X Macs, and that Dr. Web's "honey pot" server which they claimed was "intercepting the infected Macs calling home to the malicious server" and recording the UUID's of the infected Macs had a list of Macs that did NOT have the required JAVA installed, had never had it installed, and included Macs that had never been sold, taken out of the box, and in some instances, had YET TO BE MANUFACTURED! Not one (read that as ZERO) infected OS X Macs were found in the wild. Not a single one. I had two in my office whose UUID's indicated were members of the MacBot. One had never been allowed connection to the Internet. The other did not have Java installed. Both were not infected. It was a hoax. In the space of a two-three weeks, the numbers being claimed infected dropped drastically from 700,000 to 270,000 by the second week, to 186,000 a few days later, to under 100k, to less than 50k, then disappeared completely from the news, never to be heard from again, as people reported NOT finding infected Macs, even in large installation locations such as universities.

Two years later, Dr. Web, when they were trying to sell their Dr. Web anti-virus for personal computers, announced they had found a Flashback MacBot of only 20,000 Macs. . . using a similar honeypot server. . . again, no Flashback infected Macs were ever found in the wild. Even in the original Flashback in 2011, the number of infected Macs was under 100.

1 posted on 11/05/2015 11:57:39 AM PST by Swordmaker
[ Post Reply | Private Reply | View Replies ]


To: Swordmaker

Let them bite the Big Apple, and leave my Linux alone...


2 posted on 11/05/2015 12:07:36 PM PST by farming pharmer
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dayglored; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; ..
The Register UK has come out with another of its regular FUD articles on OS X being hit with malware. . . filled with half-truths and downright untruths and exaggerations on the state of OS X exploits intended to scare potential and current users, based on a press release from a anti-virus security firm with something to sell. The article claims to be about a massive increase in OS X "exploits" in 2015 but spends its space and the readers' time talking about old, closed vulnerabilities and a hoax from years past, before 2015, and then basically mentions that for more information one must REGISTER with The Register to read more. In my view, this certainly looks like FUD. -- PING!

Thanks to dayglored for the heads up!


Apple OS X FUD
Down the Rabbit Hole
Ping!

The Latest Apple/Mac/iOS Pings can be found by searching Keyword "ApplePingList" on Freerepublic's Search.

If you want on or off the Mac Ping List, Freepmail me.

3 posted on 11/05/2015 12:09:49 PM PST by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker
The Dell XPS 13 and 15 are so far superior to any MacBook right now. Once you use the near-zero bezel of the XPS, the MacBooks seem 5 years old.

Btw, those are both 13". But the Dell screen is much larger, and UHD.

4 posted on 11/05/2015 12:14:37 PM PST by montag813
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker

5 posted on 11/05/2015 12:29:45 PM PST by smokingfrog ( sleep with one eye open (<o> ---)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker

You have to wonder how much these publications get paid from MicroSoft or other Windoz platform manufactures to write this stuff(?)! Macs and OSX are far from perfect but I have used Macs since 1992 and have had nothing but excellent service. Most of my computers were refurbished though I did buy a new LC and a new iMac + a MacBook Pro for one of my sons. In all that time I had 1 hard drive go bad (on the LC but lost no data - and by that point I had more than gotten my money out out of that thing. I know Dell users who can say the same thing but I’ve never worried about a virus nor reloading software or other issues many Windows machine users have had. Both platforms are pretty good today but I’m sticking with Apple.


11 posted on 11/05/2015 4:10:24 PM PST by Lake Living
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker

I have rarely used Safari. Does it have a good search function and bookmarks function? Can the bookmarks be transferred to Firefox and in the other direction?
And does it not track you?
Thanks

For using it on Windows 7......


17 posted on 11/05/2015 9:03:39 PM PST by dennisw (The first principle is to find out who you are then you can achieve anything -- Buddhist monk)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker

J ust
A nother
V ulnerability
A nnouncement


23 posted on 11/06/2015 5:38:54 AM PST by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson