Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

To: for-q-clinton
Do you understand how it works? The user just goes to update his Mac and unknown to him he's installing a malicious update. That isn't anytthing special--unless you consider updating your computer a special operation.

Apparently YOU don't understand how it works...

How is the putative attacker going to get the malicious applications installed on the victim machine, replacing the legitimate apps? To do so requires access to the machine itself at the keyboard AND knowledge of the Administrator Name and Password (ROOT level, no less) so that the hacker can install his malware. If the attacker can do that, he already has all the access he needs to install anything he wants.

If he can't get to the computer, he has to trick the administrator into installing his malicious package...

To get to the point of "The user just goes to update his Mac and unknown to him, etc" the user MUST DOWNLOAD AND INSTALL A MALICIOUS TROJAN. It cannot download and install itself... it has to have permission to be installed... and in the latest version of OX it has to have permission to run for the first time. This relies on psychology to be spread... tricking the user into installing it himself. There is nothing autonomous about this first step.

186 posted on 08/24/2005 9:05:53 PM PDT by Swordmaker (Beware of Geeks bearing GIFs.)
[ Post Reply | Private Reply | To 172 | View Replies ]


To: Swordmaker
Apparently YOU don't understand how it works...

When installing updates, what can be updated? And what level of access is required?

192 posted on 08/25/2005 5:20:44 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 186 | View Replies ]

To: Swordmaker
To get to the point of "The user just goes to update his Mac and unknown to him, etc" the user MUST DOWNLOAD AND INSTALL A MALICIOUS TROJAN. It cannot download and install itself... it has to have permission to be installed

So my option is to either go unpatched or risk running the patch program? Hmmmmm....sounds like a bad deal to me.

193 posted on 08/25/2005 5:22:25 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 186 | View Replies ]

Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson