Skip to comments.
World's first OS X virus hits Apple
TechWorld.com ^
| 2/16/2006
| News Story by John E. Dunn
Posted on 02/24/2006 11:24:48 AM PST by Swordmaker
click here to read article
Navigation: use the links below to view more comments.
first 1-20, 21-32 next last
Leap-A is believed to have originally been posted on a Web site for Apple users, posing as a software update.
"Believed" by whom??? This is an example of the FUD written by people who really don't know what they are talking about. A cursory investigation would have revealed that we know exactly WHERE Leap.A was first seen and by whom... and it was NOT as a "software update." It was masquerading as a zipped set of supposed JPEG images of the next incarnation of OSX, Leopard.
To: 1234; 6SJ7; Action-America; af_vet_rr; afnamvet; Alexander Rubin; anonymous_user; ...
More hyperventilating from the ignorant press about Leap.A or Oomp.A Trojan for Mac OS X. PING!
This one ads even more mis-information.
2
posted on
02/24/2006 11:26:14 AM PST
by
Swordmaker
(Beware of Geeks bearing GIFs.)
To: Swordmaker
With all due respect this was bound to happen. With increasing market share and Mac users constantly bragging about how their computers didn't get viruses, it was only a matter of time before some hacker decided to meet the challenge.
To: Swordmaker
Relax. Malware happens, and it shouldn't reduce the enjoyment you derive from your platform of choice. Are you on the payroll or something?
4
posted on
02/24/2006 11:30:40 AM PST
by
Doohickey
(If you choose not to decide, you still have made a choice...I will choose freewill.)
To: Swordmaker
Clicking on the file allows the malware to install and disguise itself as a harmless-seeming .jpeg icon. SO inother words the use installs something that does bad stuff, this is a trojan not a virus.
5
posted on
02/24/2006 11:39:59 AM PST
by
N3WBI3
(If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
To: Swordmaker
Thanks for the updates! New Mac Ping icon for you if you'd like. :)
6
posted on
02/24/2006 12:09:57 PM PST
by
anonymous_user
(62% of repondents say they lie to pollsters.)
To: Swordmaker; All
Has anyone have any first hand experience with this...
7
posted on
02/24/2006 12:29:05 PM PST
by
tubebender
(Everything I know about computers I learned on Free Republic...)
To: Swordmaker
Bring out your dead!
Bring out your dead!
The end is near!
8
posted on
02/24/2006 12:48:22 PM PST
by
sergeantdave
(You can count on phalanges)
To: Swordmaker
The fact is that most viruses now require permission from the user to install, and no operating system can be completely immune from user permissions.
9
posted on
02/24/2006 12:54:52 PM PST
by
js1138
(Great is the power of steady misrepresentation.)
To: tubebender
I ran the test. The virus opened terminal and launched the calculator. Turn off automatic opening of trusted files in Safari to solve the problem. If you move terminal to a different location, the program doesn't know where to find it, and thus cannot execute.
They noted that instant messaging is the new target of choice, and I think that everyone should be aware that every time a new program type comes out, there will be vulnerabilities, especially for the first little while.
To: N3WBI3
Sure it's a trojan. It's an executable disguised as something seemingly innocuous that would entice the user to open it. The very definition of trojan.
11
posted on
02/24/2006 2:25:27 PM PST
by
Doohickey
(If you choose not to decide, you still have made a choice...I will choose freewill.)
To: Richard Kimball
Thanks. I use FireFox as my primary browser. Are there any issues there?
12
posted on
02/24/2006 3:13:42 PM PST
by
tubebender
(Everything I know about computers I learned on Free Republic...)
To: tubebender
Firefox gives you an option on download of saving to disk or opening with the default application. Select download to disk. This will keep you from accidentally opening a file thinking you were clicking on a link. It won't necessarily protect you if you deliberately download a zip file and then double click it to open it. As has been pointed out on this thread, many of th MS "viruses" actually get on the system by social engineering. They convince the user to install it. The best protection, AFAIC, is to be careful about downloading and installing programs. Especially, if anything asks for a password, and it's not a program you intend to install, don't give it. No media or information file (jpeg, mov, avi, psd, pdf, doc, etc.) should need a system password. Oh, if I am going to a non-trusted site, I shut off java and javascript.
To: tubebender
Well, sort of. Firefox shows the file as a tar.gz file and then downloads it to your directory of choice. You still have to double-click on the file to execute the shell script.
14
posted on
02/24/2006 4:11:20 PM PST
by
opticks
To: Behind Liberal Lines
With increasing market share and Mac users constantly bragging about how their computers didn't get viruses, it was only a matter of time before some hacker decided to meet the challenge. But he hasn't "met the challenge"... this is far from a self replicating, self propagating virus... it is a Trojan and not the first of that breed for the Mac OS X.
15
posted on
02/24/2006 7:03:56 PM PST
by
Swordmaker
(Beware of Geeks bearing GIFs.)
To: anonymous_user
I like... thanks. I will incorporate it in the next Mac Ping list Ping... nice job, Anonymous.
Swordmaker
16
posted on
02/24/2006 7:05:37 PM PST
by
Swordmaker
(Beware of Geeks bearing GIFs.)
To: Richard Kimball
They noted that instant messaging is the new target of choice, and I think that everyone should be aware that every time a new program type comes out, there will be vulnerabilities, especially for the first little while. This one is even more limited than that... it only "works" on "Bonjour" iChat... a local network protocol. I put the word "works" in quotes because it took two MacWorld Macintosh experts with the assistance of a security company four hours to get it to send itself from one computer to another. And that's with the recipient WANTING to accept it! It's not very virulent, is it.
17
posted on
02/24/2006 7:09:39 PM PST
by
Swordmaker
(Beware of Geeks bearing GIFs.)
To: Doohickey
Sure it's a trojan. It's an executable disguised as something seemingly innocuous that would entice the user to open it. The very definition of trojan. And that makes it not a virus.. and it's not even the first Mac OS X trojan. That dis-honor goes to a 400k file that surfaced a couple of years ago pretending to be a compressed copy of the Microsoft Office for Mac Install CD. That one actually did some damage to the two or three greedy Mac users who downloaded it and ran it... it wiped their user directories... something they richly deserved.
18
posted on
02/24/2006 7:13:45 PM PST
by
Swordmaker
(Beware of Geeks bearing GIFs.)
To: tubebender
Thanks. I use FireFox as my primary browser. Are there any issues there? Yes. You can still download the gZipped file and manually uncompress it and click on the supposed JPEG file thereby executing the payload. Like any trojan, it relies on tricking a user into installing and running it. Social Engineering. The Nigerians use the same approach to empty some foolish peoples' bank accounts.
I could create a similar Terminal script attach a .MOV icon to it and post it as a picture of Hillary Clinton cuddling with Vincent Foster... and trick people into clicking on it.
The fault here is that on OS X, the Icon and .extension do not necessarily denote the real type of file. That is determined by metadata in the file itself. Apple needs to insert routines to compare icon type to metadata before allowing a file to appear in the Finder. At least a warning should appear that says "WARNING: File type and Extension do not Match".
19
posted on
02/24/2006 7:22:49 PM PST
by
Swordmaker
(Beware of Geeks bearing GIFs.)
To: Behind Liberal Lines
Bound to happen? You mean ONE proof-of-concept that is not "in the wild" as virus gurus like to call it (despite what has been reported, it is not on the loose)?
This is the same stale news, reprinted with even more wrong information.... looks like those in the technology media industry are no better at fact-checking or even doing a little research on their own than the Lame-stream media sources.
I will be the first to admit when I feel ANY threat to my computers. That time has yet to come (and I don't expect it any time soon).
And yes, I know what you really meant - that someone would finally take a stab at MacOS X simply because of it's reputation (even if it's a "limited" market).
20
posted on
02/24/2006 7:29:54 PM PST
by
TheBattman
(Islam (and liberalism)- the cult of Satan and a Cancer on Society)
Navigation: use the links below to view more comments.
first 1-20, 21-32 next last
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson