Welcome Guest ( Log In | Register)



 
Reply to this topicStart new topic
> Serious Mac Os Flaws, Serious security flaws
Joe2Chance
post Mar 31 2006, 12:25 PM
Post #1


Member [Level 2]
*****

Group: Members
Posts: 75
Joined: 28-March 06
Member No.: 20,895



On the end of February was discovered that the first trojan (Leap) to target Apple Computer's Mac OS X, it was published on a new worm that exploits an 8-month-old vulnerability in the operating system, its know by the name of Inqtana, the worm use Bluetooth to propagate, once it infects a computer it searches for other Bluetooth-enabled devices and sends itself to those it finds, this may not be very alarm, but the source code could be easily modified by a future attacker to do damage like Symantec said, Symantec also says it believes the two pests were developed on a parallel time line and that Inqtana was not created in response to Leap, however, two examples of malicious software to target Mac OS X may be the start of a trend!! ohmy.gif

Now, more serious is the flaw that alows to install malicious code on computers. Iīt is possible by visiting a malicious web site using Apple's Safari Web browser, a backdoor or other malicious software could be installed on the computer without we noticing anything, SANS Internet Storm Center said: "Attackers can run shell scripts on your computer remotely just by visiting a malicious Web site". Another problem is the way that Mac OS X processes archive files, an "hacker" can embed malicious code in a zip file and host that on a web site, and the file and the embedded code would run when a Mac user visit the site using the Safari browser. Alfred Huger form Symantec said: "Essentially, the operating system is executing commands that come in the metadata for ZIP files", "That is exacerbated by the problem that Safari will automatically open the file when you encounter it on the Web", but this problem goes beyond archive files, as SANS said: "The attacker doesn't need to send a ZIP archive; the shell script itself can be disguised to practically anything"!! sad.gif


An update from Aple Computers has been launched, I know that the update fixs the worm problem and the trojan problem (since that the trojan needs to be download, and it was thru the iChat, so with the update iChat now uses download validation to warn of unknown or unsafe file types during file transfers), but the shell script I donīt know.

If you run a Mac OS X is better you download and install the security update 2006-001 via Software Update preferences, or from Apple Downloads.


Stay well.
Go to the top of the page
 
+Quote Post
sccrnlaxdude92
post Mar 31 2006, 06:43 PM
Post #2


Newbie [Level 1]
*

Group: Members
Posts: 15
Joined: 29-March 06
From: Maryland!
Member No.: 20,987



uh oh... i hope i dont get that bug..i have a mac g5. must be trouble.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. [ Aef ] Security Update For Aef Forum Software(1)
  2. Dont Get Norton Internet Security(15)
  3. Forgot Password To Trend Micro Internet Security(6)
  4. The Operating System's Security(5)
  5. Cyber Cafe Security And Maintenance(4)
  6. Test Your Browser For Security(11)
  7. Security In Lan(5)
  8. Website Security And Banning Certain Isp's(6)
  9. Windows Security Over Regedit(1)
  10. Cpanel Exploit(8)
  11. How To Improve Security Of Your Website?(3)
  12. White Paper: Security Threat Report: 2008(0)
  13. Comodo Security Software(3)
  14. Useful Laptop Tips (traveling & Mobile Security)(4)
  15. Security Warning 2008: Top 11 Malware Threats To Watch Out For(0)
  1. Google Accelerator Compromises Security!(19)
  2. New Idea For Thieves: Leave The Paintings, Take The Security Equiptment!(4)
  3. New Security Hole Discovered In Excel(0)
  4. 15 Great, Free Security Programs(5)
  5. Security Commom Sense(0)
  6. A Little Starter On Home Security With Some Links Included(4)
  7. Public Schools With Internet Security?(7)
  8. Symantec's Top 10 Internet Security Trends Of 2007(3)
  9. Linux Security Tools(5)
  10. F-secure Internet Security 2008(0)
  11. Bitdefender Review(4)
  12. Security Firm Kaspersky Lab Creates Ipod Virus(1)
  13. Security Issue Writing Files(1)
  14. Firefox Flaws Galore(7)
  15. Firefox 2.0.0.4 Released May 30, 2007(7)


 



- Lo-Fi Version Time is now: 8th October 2008 - 03:38 AM