Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Variation on Mac trojan disables built-in OS X malware protections

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » General Discussion Donate to DU
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-19-11 01:39 PM
Original message
Variation on Mac trojan disables built-in OS X malware protections
The anti-malware protections that are built into Mac OS X could be at risk thanks to a newer Mac trojan. The trojan in question, Trojan-Downloader:OSX/Flashback.C, was discovered by researchers at F-Secure—it's a variation on the Mac trojan discovered in September that poses as a Flash Player installer, OSX/Flashback.A. The new version still poses as a Flash Player installer, but its creators have kicked things up a notch by instructing it to disable Apple's automatic updating mechanism for its system-wide malware application, meaning that those who fall victim may never receive updates from Apple to remove the trojan.

Apple added some basic malware protections into Mac OS X in 2009 as part of 10.6 Snow Leopard, but the feature became more widely known after the great Mac Defender Scare of 2011. As part of a security update issued in May, Apple not only added the ability to detect the Mac Defender trojan and its variants, the company also made it possible for its software to automatically update its malware definitions on a daily basis. After performing that update, Mac users are generally protected from Mac-targeted attacks as long as that feature, called XProtect, can stay up-to-date.

But now thanks to Flashback.C, that feature is somewhat at risk. According to F-Secure, after users enter their admin passwords into the fake Flash installer, Flashback.C decrypts the paths within XProtectUpdater and proceeds to unload the XProtectUpdater daemon. After that, the malware overwrites the files with an empty space, decimating key files that XProtect needs in order to receive regular updates from Apple.

"Attempting to disable system defenses is a very common tactic for malware—and built-in defenses are naturally going to be the first target on any computing platform," F-Secure wrote on its blog.

http://arstechnica.com/apple/news/2011/10/variation-on-mac-malware-disables-built-in-os-x-malware-protections.ars


" Eeww, PCs suck because Mac's never have problems from viruses or trojans, I don't worry, PC's suck"

To everything turn, turn, turn, there is a season turn, turn, turn.....
Printer Friendly | Permalink |  | Top
Electric Monk Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-19-11 01:41 PM
Response to Original message
1. after users enter their admin passwords....
Printer Friendly | Permalink |  | Top
 
david_vincent Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-19-11 01:42 PM
Response to Original message
2. Maybe hackers
have finally cottoned on that Apple is just another corporate behemoth that doesn't give a fig about anything but profits, exactly like MS.
Printer Friendly | Permalink |  | Top
 
Atman Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-19-11 01:45 PM
Response to Original message
3. Windows users getting boners all over the world.
SEE! Someone created a Mac virus that doesn't do anything to anyone...oh, wait, I have a new e-mail message I have to click on that will probably bring down my machine. MAX SUK!
Printer Friendly | Permalink |  | Top
 
quinnox Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-19-11 01:47 PM
Response to Original message
4. some nice news for a change
The insufferable mac users aren't so invulnerable.
Printer Friendly | Permalink |  | Top
 
twitcher Donating Member (7 posts) Send PM | Profile | Ignore Wed Oct-19-11 02:13 PM
Response to Reply #4
5. nice??
You have a warped personality if you wish bad things on people because of the brand of computer they own.
Printer Friendly | Permalink |  | Top
 
City Lights Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-19-11 02:15 PM
Response to Reply #5
6. Couldn't agree more!
Thanks for saying it!

:toast:
Printer Friendly | Permalink |  | Top
 
RebelOne Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-19-11 02:43 PM
Response to Reply #6
7. Agreed here, too.
I am a Mac user and I am not insufferable. I still love my Mac. Had so many problems with PCs to even list.
Printer Friendly | Permalink |  | Top
 
SpiralHawk Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-19-11 02:46 PM
Response to Reply #4
8. someone somehwere is 'claiming'
as usual
Printer Friendly | Permalink |  | Top
 
Shandris Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-19-11 03:41 PM
Response to Original message
9. What the Mac users are overlooking is this:
The ONLY reason they weren't targetted much before was because they had such a small market share. This was literally inevitable. They've sold themselves on the belief that Macs are more inherently secure, but that has never been true. They do lack some of the intrinsic vulnerabilities inherent in the way Windork was designed and being based off of Unix, but that makes them no more secure. In fact, compared to an Open Unix/Linux system, it tends to make them LESS secure because they combine a desire to keep users' hands off the OS with Microsoft's dreaded security-through-obscurity model.

This one may not do much...but the days of Macs avoiding attention are coming to an end. Rapidly.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Mon May 06th 2024, 04:52 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » General Discussion Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC