Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Intego warns of Trojan Horse for OS X, offers update
Macintosh News Network ^ | April 8, 2004

Posted on 04/08/2004 12:52:52 PM PDT by HAL9000

Edited on 04/29/2004 2:04:11 AM PDT by Jim Robinson. [history]

Intego today said it released an updated virus definitions for Intego VirusBarrier to protect Mac users against the first Trojan horse that affects Mac OS X. This Trojan horse, MP3Concept (MP3Virus.Gen), exploits a weakness in Mac OS X where applications can appear to be other types of files: "The Trojan horse's code is encapsulated in the ID3 tag of an MP3 (digital music) file. This code is in reality a hidden application that can run on any Macintosh computer running Mac OS X. Intego says the malicious application can delete files, propogate itself by sending a message to other users, and also infect other MP3, JPEG, GIF or QuickTime files.


(Excerpt) Read more at macnn.com ...


TOPICS: News/Current Events; Technical
KEYWORDS: apple; bwahahahahahaha; computersecurity; lowqualitycrap; macosx; macuser; mp3concept; trojanhorse
Navigation: use the links below to view more comments.
first previous 1-2021-29 last
To: general_re
Try: man sudo.

That's not going to help if I actually want to do something with sudo. :) It'll have to open a terminal first though.

Anyway, let's just sit back and see 1) what percentage of Macs get infected and what degree of harm is done, and 2) see how long it takes for a fix. With the critical IE bug released today it would be nice to see the race.

21 posted on 04/08/2004 2:54:37 PM PDT by antiRepublicrat
[ Post Reply | Private Reply | To 14 | View Replies]

To: HAL9000
Backup!

I use a firewire drive to backup my computer and then disconnect it. I also backup critical data on my central server.
22 posted on 04/08/2004 4:28:09 PM PDT by DB (©)
[ Post Reply | Private Reply | To 20 | View Replies]

To: HAL9000
Yes, but those same users have probably forgotten their administrator password anyway.

Oops. No daemons for you. Guess they won't be installing a virus scanner that could catch this sort of thing. Or patching their system once a fix is available. Or doing anything else that requires root privs to accomplish.

23 posted on 04/09/2004 8:37:11 AM PDT by general_re (The doors to Heaven and Hell are adjacent and identical... - Nikos Kazantzakis)
[ Post Reply | Private Reply | To 20 | View Replies]

To: antiRepublicrat
It'll have to open a terminal first though.

Don't blink - you might miss it.

In any case, this little bug takes care of the first half of breaking your system - surreptitiously running my code on your box. From there, I can try to social-engineer my way into rooting everything, or I can try to exploit other holes into rooting everything. Or I can not bother and just wipe out everything in your home directory, which, as someone else pointed out above, is where you keep everything valuable to you anyway. The guy who gets his dissertation erased the week before he was set to hand it in is likely not going to be comforted by the fact that his box wasn't rooted. :^)

24 posted on 04/09/2004 8:58:07 AM PDT by general_re (The doors to Heaven and Hell are adjacent and identical... - Nikos Kazantzakis)
[ Post Reply | Private Reply | To 21 | View Replies]

To: general_re
In any case, this little bug takes care of the first half of breaking your system - surreptitiously running my code on your box.

It's definitely serious, but it does require a bit more work to get on your system than someone reading an email or visiting a web site, or just being on the net period.

I wonder if this is going to be handled by Apple as a virus issue ("update your antivirus") or if they'll fix the bit that allows the program to appear as an innocent file. I don't always trust Apple to do the right thing.

25 posted on 04/09/2004 9:35:24 AM PDT by antiRepublicrat
[ Post Reply | Private Reply | To 24 | View Replies]

To: antiRepublicrat
Closing the file-type hole is the way to go, IMO. Pushing the problem off to third-party AV vendors would be a mistake.
26 posted on 04/09/2004 9:51:10 AM PDT by general_re (The doors to Heaven and Hell are adjacent and identical... - Nikos Kazantzakis)
[ Post Reply | Private Reply | To 25 | View Replies]

To: antiRepublicrat
Of course, it's not like there's no precedent for pushing the problem off onto third-party vendors - they could pull a Microsoft move out of their hats ;)
27 posted on 04/09/2004 9:52:34 AM PDT by general_re (The doors to Heaven and Hell are adjacent and identical... - Nikos Kazantzakis)
[ Post Reply | Private Reply | To 25 | View Replies]

To: HAL9000
While the first versions of this Trojan horse that Intego has isolated are benign, this technique opens the door to more serious risks.

Everybody missed this line.

28 posted on 04/09/2004 2:33:22 PM PDT by amigatec (There are no significant bugs in our software... Maybe you're not using it properly.- Bill Gates)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bush2000; antiRepublicrat; LasVegasMac; Action-America; eno_; N3WBI3; zeugma; TechJunkYard; ...
Yes, it has happened. The First OS X Trojan horse has made its appearance.

As always, if you want to be included or excluded on the Mac Ping list let me know through Freepmail.

Swordmaker
29 posted on 04/09/2004 10:03:52 PM PDT by Swordmaker (This tagline shut down for renovations and repairs. Re-open June of 2001.)
[ Post Reply | Private Reply | To 2 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-29 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson