stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


First malware for OS X?







First malware for OS X?

First malware for OS X? 04/09/2004 04:04 PM

One of the selling points of OS X has been, to date, the lack of any viruses, worms, or Trojan horses. Intego reports that it has identified a Trojan horse called MP3Concept.

Mac OS X displays the icon of the MP3 file, with an .mp3 extension, rather than showing the file as an application, leading users to believe that they can double-click the file to listen to it. But double clicking the file launches the hidden code, which can damage or delete files on computers running Mac OS X, then iTunes to play the music contained in the file, to make users think that it is really an MP3 file . While the first versions of this Trojan horse that Intego has isolated are benign, this technique opens the door to more serious risks.
Link

Meeroh sez: The Mac OS X mp3 trojan is being blown completely out of proportion. Quick review of facts so far:

1. It was pointed out in a Usenet thread that it is possible to embed arbitrary data in an mp3 2. It was subsequently suggested that the arbitrary data could be executable 3. An enterprising developer proceeded to then create a file which to any mp3 player will appear as an mp3 file, but the Mac OS X Finder sees it as an application 4. An anti-virus vendor published advertising for their product saying that it has a cure for this form of Trojan.

Some other relevant points:

1. This has little to do with Mac OS X vs. Mac OS 9. The exact same file will do the exact same thing on Mac OS 9 -- be playable by mp3 players, and act as an application 2. This has little to do with Mac OS X using extensions to identify file types. The icon shown by the Finder could be embedded in the file itself, in which case the file would look like an mp3 file regardless of its name. 3. This trick requires using the resource fork, and therefore the file has to be transmitted encoded. Any mp3 file that is transferred as a plain binary file (as opposed to a Mac binary file, with the resource fork), is harmless. 4. The fact that the file can be played in am mp3 player is irrelevant; if the trojan were malicious, the user would be doomed after double-clicking on it regardless of whether the file is a valid audio file.

To summarize, a Mac application can have any icon or name whatsoever, including a name and an icon that make it look like a document. Exactly what happens when you receive such an application (in email or by downloading it in your browser) depends on your settings, but I am not aware of any case in which it will be automatically launched.

Therefore, to activate this Trojan you have to either receive a Mac-encoded attachment and double-click on it in the Finder, or you have to download a Mac-encoded a file (which is then usually decoded to your desktop) and double-click it in the Finder.

The only reason that this is news is that a vendor of anti-virus software took it as an opportunity to generate some advertising, as far as I can tell.




This is a GrokNews Entry: (what is grok?)





Similar Items

First malware for OS X?

Grok Headline matches for First malware for OS X?

Malware Inc.


Malware Inc. 04/04/2005 08:50 PM
In news that should surprise absolutely none of you, it appears that the people who used to write viruses for ego purposes are increasingly writing spyware for money instead. Basically, what the study (bias alert: done by a security company who's trying to sell you stuff) points out is that, just like with file sharing applications, spyware and adware have become a business model for virus writers. They're wrapping up their viruses with spyware; they still get the ego boost, but also some profit as well. No wonder virus companies are desperately trying to come up with decent anti-spyware offerings.

Malware on the way out


Malware on the way out 07/15/2004 12:21 PM
Are spyware & adware on the way out? More and more I'm hearing about companies taking the turn for the better. BOUT TIME! Even the once-accused WeatherBug has taken strong stances and stronger actions against malware, and is called for it. But will it last, has features and views beat the 'ware?

Malware: Do you know your enemy?


Malware: Do you know your enemy? 02/05/2005 09:11 PM
ZDNet Feb 4 2005 12:40PM GMT

New Malware Causes Concern


New Malware Causes Concern 06/25/2004 12:46 AM
Developing | NetSec Inc. has detected a new vulnerability that is infecting users of Microsoft Windows with malware. By visiting a malicious website with the Internet Explorer web browser, users can become silently infected with arbitrary code that is embedded in images on web pages. Once installed, the code begins to log keystrokes and then calls home to servers which then upload even more payload onto infected systems.

Click Here For Malware


Click Here For Malware 09/23/2004 06:52 AM
TechTree Sep 23 2004 10:05AM GMT

Analyzing malware


Analyzing malware 02/19/2004 04:11 AM
Malware is a set of instructions that run on your computer and make your system do something that an attacker wants it to do. I strongly encourage you to run attack and defensive tools in a laboratory of your own. Here's how.

All quiet on the malware front


All quiet on the malware front 07/01/2004 06:55 AM
Zafi tops viral charts in placid June

Malware attacks IE users via pop-ups


Malware attacks IE users via pop-ups 06/30/2004 07:34 AM
Oh dear

Big muscle on the way to battle malware


Big muscle on the way to battle malware 12/27/2004 04:34 AM
USA Today Dec 27 2004 8:50AM GMT

Other News: Using Malware for Profit


Other News: Using Malware for Profit 09/09/2004 10:37 AM
USA Today spent eight months digging into details of computer malware and its use for profit.

Other News: Sniffer Malware


Other News: Sniffer Malware 09/20/2004 10:43 AM
The latest malware sniffs network traffic for sensitive information, a nasty new trick.

Malware Might Become a Problem for
Macintosh


Malware Might Become a Problem for
Macintosh
09/04/2004 01:38 AM

Direct and Related Links for 'Malware Might Become a Problem for Macintosh'

“Macintosh users have had some bragging rights over their Windows counterparts for various reasons, not the least of which is “malware” — viruses, worms and Trojan horses — that is a frequent pain to Windows users. But on March 20, a “proof of concept” Trojan horse named MPSConcept (file name MP3Virus.Gen) was discovered, paving the way for more serious malware. The malware is theoretically benign but is intended to show a particular vulnerability in an…

First 64-Bit Malware for Windows Appears


First 64-Bit Malware for Windows Appears 05/27/2004 11:05 AM
Proof-of-concept threat not spreading in wild, only affects 64-bit Windows systems.

Malware Analysis for Administrators


Malware Analysis for Administrators 05/24/2004 12:36 PM

Stopping Malware Before It Hits


Stopping Malware Before It Hits 11/16/2003 06:14 PM
SpudGunMan writes "John Lockwood, Ph.D, an assistant professor of computer science at Washington University, and the graduate students that work in his ...

Other News: Macs and Malware


Other News: Macs and Malware 03/19/2005 02:34 AM
One anti-virus executive says Macs are untroubled by malware, but here's why you need to keep up your guard.

Symantec: Mac OS X Becoming a Malware
Target


Symantec: Mac OS X Becoming a Malware
Target
03/22/2005 04:42 PM
Slashdot Mar 22 2005 1:34AM GMT

Adware dominates PC malware infections


Adware dominates PC malware infections 03/24/2005 01:48 PM
vnunet.com Mar 24 2005 4:06PM GMT

Nasty Malware Fouls PCs With Porn


Nasty Malware Fouls PCs With Porn 04/30/2004 04:52 AM
An especially evil new browser hijacker is sweeping the Net, spying on users of infected machines and pummeling them with truly vile pornography. Some folks are screaming for vengeance, but the problem is finding out who unleashed the vicious code. By Michelle Delio.

Toxic bl0gs spreading malware


Toxic bl0gs spreading malware 04/14/2005 03:22 PM
Computer Weekly Apr 14 2005 5:59PM GMT

DNS Cache Poisoning Spreads Malware


DNS Cache Poisoning Spreads Malware 04/06/2005 01:53 PM

New mobile malware wipes phones


New mobile malware wipes phones 04/06/2005 01:50 PM
Personal Computer World Apr 6 2005 5:14PM GMT

Microsoft to Squash Malware with 'A1'


Microsoft to Squash Malware with 'A1' 01/05/2005 08:49 AM
Microsoft's upcoming antivirus/anti-spyware subscription service, dubbed "A1" is going beta. Microsoft Watch is reporting that even while Redmond has remained tight-lipped, it has silently begun to inform partners of its plans for the service. A1 will "secure the perimeter" around Windows.

Identity checks combat malware


Identity checks combat malware 03/29/2005 04:43 PM
vnunet.com Mar 29 2005 8:15PM GMT

Has Mass-Mailed Malware Peaked?


Has Mass-Mailed Malware Peaked? 03/27/2005 12:28 PM

Microsoft Prepares to Dash Malware with
"A1"


Microsoft Prepares to Dash Malware with
"A1"
01/05/2005 03:30 AM
Microsoft's upcoming antivirus/anti-spyware subscription service, dubbed "A1" is going beta. Microsoft Watch is reporting that even while Redmond has remained tight-lipped, it has silently begun to inform partners of its plans for the service. A1 will "secure the perimeter" around Windows, making flaws in its design less significant than in the past.

Malware infects BitTorrent downloads


Malware infects BitTorrent downloads 06/17/2005 07:12 PM
Those using BT in the legally and ethically questionable act of downloading copyrighted content may become victims of a legally and ethically questionable act.


Malware Hijacking Google Homepage


Malware Hijacking Google Homepage 10/28/2003 11:08 PM
A lot of malware has been going around lately, some of it preventing you from visiting the actual Google website, or putting up a notice when you try to visit. The most common reason for this is spyware or malware -- software that's included with other programs and stows away in your computer watching what you're doing, popping up ads, and doing other bad things. To get rid of it, you can install LavaSoft's Ad-Aware or Spybot Search and Destroy. Both are free but neither me nor Google are recommending either....

Malware - Fighting Malicious Code


Malware - Fighting Malicious Code 04/19/2004 01:50 PM

spyware, adware, sneakware, malware


spyware, adware, sneakware, malware 05/07/2004 07:56 AM

A script to prevent damage from rm -rf
malware


A script to prevent damage from rm -rf
malware
05/18/2004 10:37 AM
After reading about the malware / Trojan Horse business that has been flying around lately, I realized that there is a fairly easy way to protect against this kind of thing. I wrote a script which duplicates a folder (like a ...

Twenty years of malware--and counting


Twenty years of malware--and counting 11/12/2003 01:12 PM
ZDNet Nov 12 2003 10:40AM ET

New malware masquerades as Microsoft
update


New malware masquerades as Microsoft
update
01/09/2004 09:57 PM
A Trojan horse program that appears to be a Microsoft Corp. security update can download malicious code from a remote Web site and install a back door on the compromised computer, leaving it vulnerable to remote control. IDefense Inc., a Reston, Va., computer security company, said the malicious code is the latest example of so-called social engineering to fool Windows users. It is similar to the W32Swen worm, which last year passed itself off as a Microsoft patch.

Malware: Fighting Malicious Code


Malware: Fighting Malicious Code 06/11/2004 06:33 AM
A comprehensive guide for defending against viruses, worms, rrotkits and more.

New IE Malware Captures Passwords Ahead
Of SSL


New IE Malware Captures Passwords Ahead
Of SSL
06/29/2004 03:30 PM

Malware records banking passwords


Malware records banking passwords 06/30/2004 03:13 AM
ZDNet UK Jun 30 2004 7:55AM GMT

Mozilla Developers Respond to Malware


Mozilla Developers Respond to Malware 07/13/2004 10:13 AM

Malware Writers Using Open-Source
Tactics


Malware Writers Using Open-Source
Tactics
09/09/2004 12:30 PM

Adobe Acrobat Toolbar Worse than
Malware?


Adobe Acrobat Toolbar Worse than
Malware?
03/23/2005 04:48 PM
Slashdot Mar 23 2005 7:59PM GMT
Grok Description matches for First malware for OS X?
GrokA matches for First malware for OS X?

First malware for OS X?

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

Subservient
Chicken's X-Rated
Bits Exposed by Code

Audio Interview --
authors of report
about P2P's effect
on CD sales

Try your hand at
balancing the
federal budget

Spaced Out on the
Interplanetary
Internet

Battery recharges in
30 seconds

Computers, Freedom
and Privacy reg is
open

Distributed
audiobook for Down
and Out

Metafilter Matt
CSSifies Boing Boing

The truth about
camel spiders

Apple I clones for
sale

Playfair bullied
offline by Apple,
reappears on Indian
site

Canada's NDP leader
endorses P2P

American "Japgrish"
tattoos

Promising
anti-obesity pill

Photo of a male
whale's reproductive
organ

Owen Wilson's
Celeb-Blog?

The $14 SteadyCam
Good time waster:
simple sliding tile
puzzle

CSS shakedown issues
with
Konquerer/Safari

Apache httpd 2.0.49
Released

How useful are
'proprietary vs.
open source' TCO
studies?

A first look at the
Nvu Web authoring
application

Is there a rootkit
hunter in your
arsenal?

A babe in Tuxland
A first look at
Vector Linux 4.0,
SOHO edition

VoteHere source code
release, however
flawed, is huge

Exclusive: Former
Sun exec Green
moving to Cassatt

Why SCOX price has
been so up and down

Linux breathes new
life into old
hardware

Linux Advisory Watch
- April 9, 2004

You Have Huge Guts
Pain in the
Asteroids

Son of a Gun
And Here is the
Steeple

Chipmunks: Behind
the Music

For Male Connectors
Only

Bringing Up the Rear
But What If I Don't
Want To Search The
Whole Web?

Hey, Is That A Phone
You're Holden?

Latest Scam: Fake
Internet Pharmacy
Just Steals Money
From You

All This Buzz
Certainly Sounds
Familiar

Gator Wants To Go
Public As Claria

No One Will Take
Down Microsoft But
Microsoft

Online Casinos
Advertising Over
Gamblers Anonymous
Page

File Sharing Against
Censorship

Building Playlists
Of Free MP3s

Tax Time: Should You
Ignore Taxes On
Online Purchases?

A quick and dirty
CSS hack: PNG
backgrounds

I am USER, hear me
roar!

Formatting numbers
for currency display
and more.

what is grok?