Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Wolf! [Apple malware scares]
daring fireball ^

Posted on 05/05/2011 3:29:50 PM PDT by Gomez

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-28 last
To: MrShoop

I stand corrected. The front end is Java-based, and there is OS X specific code behind it. But for it to install, the user has to accept a Java applet signed by an unknown authority; accept the certificate for that authority; then enter an administrator password after the Java applet has downloaded a native installer. The user has to actively bypass security three times.


21 posted on 05/06/2011 12:09:21 PM PDT by ReignOfError
[ Post Reply | Private Reply | To 20 | View Replies]



Here’s What We Think
Of People Who Can Donate
But Won’t


Sponsoring FReepers leapfrog0202 and another person will contribute $10
Each time a new monthly donor signs up!
Get more bang for your buck
Sign up today

Save our wonderful Lazamataz.

22 posted on 05/06/2011 12:36:50 PM PDT by TheOldLady
[ Post Reply | Private Reply | View Replies]

To: MrShoop
Some infection numbers from Sophos from people who run their software. http://nakedsecurity.sophos.com/2010/11/18/free-anti-virus-for-mac-150000-active-users-and-plenty-of-malware-found/

MrShoop, That chart was reported on and discussed on FR back in November. It would never have been a news item had not Sophos' AV not basically TURNED OFF the anti-malware that OSX itself has in place to block Trojans. Of those 19 listed malware, only TWO are OSX Trojans. . .OSX/Jahlav-C and OSX.DNSCha-E . . . the rest are ALL Windows malware that were found imbedded in JPEGS, FLASH, eMails, etc. None of which would have any effect on a Mac. The two that could have had an effect on a Mac would have been blocked by the Mac itself had not Sophos effectively gotten in the way so THEIR anti-virus could find something. Whoopee-doo. This report and Sophos way of generating is considered unethical, to deliberately prevent the SYSTEM from doing its job so your software CAN FIND SOMETHING? Pathetic. That's the essence of Scareware.

23 posted on 05/06/2011 12:59:27 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Swordmaker

I agree it is kind of sleazy of Sophos. Nonetheless, you are the one who was saying, “number of OSX viruses, worms, and involuntary spam bots is still ZERO.” Will you admit there are at least a few?


24 posted on 05/06/2011 1:06:59 PM PDT by Wayne07
[ Post Reply | Private Reply | To 23 | View Replies]

To: MrShoop
I agree it is kind of sleazy of Sophos. Nonetheless, you are the one who was saying, “number of OSX viruses, worms, and involuntary spam bots is still ZERO.” Will you admit there are at least a few?

Nope. Those are Windows malware and two Trojan horse applications that will run on a Mac. They are NOT "OSX viruses, worms and involuntary spambots". A Trojan horse is merely an application that does something other than what it claims to do... and requires the user install it like any other application. My statement is absolutely true. Just because an anti-virus application can identify WINDOWS malware coming into a Mac, it does not make that Mac vulnerable TO that Malware unless that Mac is running Windows!

25 posted on 05/06/2011 3:36:41 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 24 | View Replies]

To: MrShoop

As I told you, there are 18 known Trojans in five distinct families (means of attack) in the wild for OSX. OSX identifies and warns the user about all of them if the user attempts to download, install, or run any of them. The user is given three distinct warnings and is required to submit three distinct administrator permissions with name and password for each of those steps to over ride those warnings... it really takes industrial strength stupidity to get infected with a Trojan on a Mac. Sophos’ AV intervened in the download step so that their software could report it found those Trojans. It allowed the Trojan downloads to occur! I think it’s better to prevent the download in the first place, as soon as OSX recognizes the signature.


26 posted on 05/06/2011 3:51:20 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 24 | View Replies]

To: MrShoop
This particular Trojan (that Symantec detects as Trojan.Jnanabot) is one such attempt to target multiple platforms. Jnanabot has numerous functionalities that include key logging, connection to IRC servers, and posting malicious links on social networking sites, affecting users on Windows, Mac OSX, and Linux platforms.

this is what is known as a proof-of-concept trial Trojan... It never escalated to anything that worked in OSX.. It had similar problems in trying to get it to work in Linux.

It had several problems, MrShoop... On a Mac, these library files may exist, but they have been placed in non-executable memory locations... they cannot run where they are placed. In addition, the library it needs to be placed in requires ROOT level permission to alter. For these to execute in the Mac, something needs to be placed elsewhere and this exploit has yet to find that ability... That's why it's still listed as WINDOWS only. It's a cross platform wanna be... And isn't there yet because of the usual problem... no Mac vector to get the rest of the exploit in place.

27 posted on 05/06/2011 4:15:27 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 20 | View Replies]

To: MrShoop

We may have just had our first OSX Worm...

http://www.freerepublic.com/focus/f-chat/2716314/posts


28 posted on 05/06/2011 4:37:41 PM PDT by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 27 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-28 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson