|
#41
| ||||
| ||||
| I see nothing in the Sophos advisory about it running things at root level. Maybe I'm blind, but if someone can quote anything that says "root" or "privilege" or "escalation", I'd appreciate it. Perhaps it was removed. Please remember that without escalation, the damage to your system is limited to your data or any programs that you installed without providing the system password. That sucks, but it won't rob you of a working computer. If a virus or trojan can escalate itself, through a vulnerability in the OS (or by you providing it with the system password), everything on your system is at risk. Also, this is a trojan. A trojan needs you to install it before it can do a single thing to your system. If you don't install it, you won't get infected. If you install lots of public scripts or use warez, this sort of trojan should worry you. But then again, you should probably have always been worrying if you installed such things. Sophos, being an anti-virus company, says absolutely nothing about how this trojan has been distributed so far. None of this worries me. Also, this is not the first trojan for OS X. Search Sophos for "Renepo". Also, according to Sophos, this is a proxy trojan -- that is it can be used by its author to turn your computer into a gateway to launch attacks on other systems while hiding his/her identity. This sort of infection has a LONG history in UNIX. I would frankly be surprised if there weren't more of these in the wild. If the author really wanted to be a dick, its payload could be much worse. |
|
#42
| ||||
| ||||
| It doesn't say how it gets installed or what it does. Doesn't say anything about running as root or how it does this. They list it as a low priority.
__________________ MacBook Pro 2.16GHz Core2Duo 3GB RAM, G4 1.4GHz OSX Tiger 1.25GB RAM, Dual 2GHz G5 OSX Tiger 2GB RAM (freakin shweet) Athlon 64 Windoze XP for school work (programming) 1GB RAM dferns@macosx.com |
|
#43
| ||||
| ||||
| Use a Folder Action to notify you if anything tries to put something in the Startup Items. A safeguard is to keep an eye on two OS X folders: Library/StartUp Items and System/Library/StartUp Items. You can check them manually or you can use one of the Folder Action scripts provided by Apple as part of OS X. Using a folder action will automate the process and help you keep an eye on future additons to the folders. Here is how to do it: 1. Go to Library/Scripts/FolderActions. 2. Locate Enable Folder Actions.scpt. 3. Double-click the script. 4. Click the "Run" button and close the script window. Now you can run folder action scripts on your Mac! 5. Go to Library/StartUp Items. 6. Control-click the folder icon and choose Attach a Folder Action from the drop-down menu. 7. In the dialog box find and select Library/Scripts/Folder Actions/add-new item alert.scpt. 8. Go to System/StartUpItems. 9. Repeat steps 6 and 7. Now whenever anything new is added to either of the folders you will automatically get an alert.
__________________ |
|
#44
| ||||
| ||||
| Now that there is a Trojan on OS X what is the best anti-virus software out there? Sophos, Norton, or Virex? I currently have norton installed on my laptop. Is there any free ones like Avast for the PC? I can see it now, all the PC user's i know will be like there's a Trojan for the Mac! Yea, but it's only 1 compared to how many on the PC?
__________________ Its not the machine that makes you creative and get a better job, its what you can do with it. 17" MacBook Pro HD 4 GB Non Video Pod Nano Blue |
|
#45
| ||||
| ||||
| Norton's is probably the worst of the three. Get rid of anything on your hard drive that bears the name "Norton" -- it's worse than the virus itself! I also don't see anything mentioned about the level of access that trojan provides to the remote user.
__________________ Power Macintosh G4/500MHz "Yikes!" 10.4.11 Server • 1024MB • 3 x 120GB + 320GB • DVR-111D • 2 x Radeon 7000 PCI • 2 x 17" CRT MacBook 2.0GHz Core 2 Duo - White 10.5.5 • 2048MB • 80GB • CD-RW/DVD-ROM iPod Photo 60GB • iPod nano 1GB • AT&T DSL 6Mb/768k http://www.jeffhoppe.com |
|
#46
| |||
| |||
|
__________________ MBP 15" 2.16Ghz, 1GB, 120GB, ATI Radeon X1600, OSX 10.5.4 iPod Shuffle |
|
#47
| ||||
| ||||
| Take anything Sophos says with a healthy grain of salt! They seem to have trouble with the subtlies of truth. Doug
__________________ "Just as some newborn race of superintelligent robots are about to consume all humanity, our dear old species will likely be saved by a Windows crash. The poor robots will linger pathetically, begging us to reboot them, even though they'll know it would do no good." -Anonymous |
|
#48
| ||||
| ||||
| Here's the WiredNew's Article on the Worm Quote:
![]()
__________________ Its not the machine that makes you creative and get a better job, its what you can do with it. 17" MacBook Pro HD 4 GB Non Video Pod Nano Blue |