|
#1
| ||||
| ||||
|
Beware, a trojan for OS X is out. Link Quote:
"Sorry, but you won’t be able to watch those videos, as no codec was installed." Your DNS will be changed to point to malicious DNS machines. What this means is that even if you type www.apple.com in your browser’s URL area, you may be taken there, to a phishing “clone” of that site, or to another site completely—such as a porn site. Where you wind up depends solely on how the malicious DNS machines are configured. If you consider ebay.com or paypal.com, for instance, the consequences may be dire. A cron job (scheduled task) will run every minute to restore the malicious DNS info, in case you change it. More and how to remove here. Nothing to worry though as long as you don't install software from odd places - especially those that use an installer and ask for your admin password.
__________________ MacBook Pro | Dell Mini Inspiron 9 | Mac Mini | Newton 2000 | iPhone | @Work : Dell D620 & 2x20" + a lot of Macs | Workstation, VC & Fusion Twenty years from now you will be more disappointed by the things that you didn't do than by the ones you did do. ~ Samuel Clemens | Rants | Photos |
|
#2
| ||||
| ||||
|
So basically, if you ain't stupid, you've got nothing to worry about.
__________________ iMac 24" 2.4 GHz, 4 GB RAM, 320 GB HD. Mac OS X 10.6.2 MacBook Air 13" 1.6 GHz, 2 GB RAM, 80 GB HD. Mac OS X 10.6.2 Mac mini 1.83 GHz, 2 GB RAM, 80 GB HD. Mac OS X 10.6.2 MacBook nano (Lenovo S10e white) 1.6 GHz, 2 GB RAM, 250 GB HD. Mac OS X 10.5.7 iPhone 3GS 32 GB white. Mac user since 1987, Apple Sales Professional 2009, Apple Product Professional 2007-2009, Apple Certified Support Professional 10.5, Apple Certified Pro Aperture 2 (Level 1) |
|
#3
| ||||
| ||||
|
Yep
__________________ MacBook Pro | Dell Mini Inspiron 9 | Mac Mini | Newton 2000 | iPhone | @Work : Dell D620 & 2x20" + a lot of Macs | Workstation, VC & Fusion Twenty years from now you will be more disappointed by the things that you didn't do than by the ones you did do. ~ Samuel Clemens | Rants | Photos |
|
#4
| ||||
| ||||
|
Well, right now it's being used for some "racy" websites and yes, you have to be very foolish to have your system compromised by this. But I have to wonder with unpatched sites still having cross-site-scripting (XSS) issues if it's still possible to visit a legitimate site that had been compromised by a XSS vulnerability and then have something posing as a legitimate application being downloaded into your Mac. I'm sure by that time Apple would have patched it (or so I hope), but it's still something to be wary of.
__________________ • Apple iMac G5 17" (2 GHz G5) - Mac OS X 10.4.11/Ubuntu 9.10 • Asus Eee PC 901 (1.6 GHz Atom N270) - Ubuntu Netbook Remix 9.04 • Apple Macintosh Quadra 650 (33 MHz MC68040) - Mac OS 8.1 • "JHVH-1" (2 GHz AMD Athlon XP 2400+) - Slackware 13 • "Kidbuntu" (2.8 GHz Celeron D 335) - Ubuntu 9.04 |
|
#5
| ||||
| ||||
|
That's what I'm worried about, too. If this got onto YouTube or something, it would make a real mess. From what I know so far, though, it doesn't make me worry about OS X's security. Like I've always said, if you can write applications for an OS, you can write malware. That's the bottom line. Trojan horses will always be possible. So common sense must always be applied. Having said that, how many of us have never entered our admin password for an installer we downloaded? I'm guessing zero. I think the biggest threat to OS X's security is the fact that people are conditioned to enter their admin password when asked. It's something that needs to be done fairly often, so people are not as wary about it as they should be. To make matters worse, it is rarely explained WHY admin privileges are needed. I'm not sure if there's really anything Apple could do about this, but it's a problem. |
|
#6
| ||||
| ||||
| They could issue a warning via "Hot News" or directly on the main page.
__________________ • 2.66GHz Mac Pro Quad Xeon • 2.0GHz Dual PowerMac G5 • 466MHz Powerbook G4 • Mac Classic |
|
#7
| ||||
| ||||
| Quote:
__________________ http://thesalon.blogspot.com |
|
#8
| ||||
| ||||
|
__________________ http://thesalon.blogspot.com |
![]() |
| Bookmarks |
| Thread Tools | |
|
|