Jump to content

Recommended Posts

Posted

Yeah, I know it's bait, but I've not long come off the phone to my son whose PC has some sort of trojan virus caught because his girlfriend agreed to let some pop-up scan the computer for viruses. His eBay and Hotmail passwords have been changed and he is having a devil of a job getting it sorted. So I'm going to bite.

 

That couldn't happen to me. I am a Mac user. I abandoned Windows eons ago, but I often get people asking me to sort their machines out. The Windows geeks just say 'I never get a virus, I make sure I don't do x, y & z, or go to this or that dodgy site, and I have this super-duper anti-virus utility'. Basically they care not a jot for poor Joe Bloggs who gets caught out constantly. If Joe Bloggs had a Mac he'd be fine. He could go anywhere and do anything, dodgy or otherwise, without fear of spyware or viruses.

 

We have several pupils at school who cannot use their PCs at home because the machine has a virus and they don't know what to do about it. There is no way they have enough know-how to reinstall Windows from scratch - unless the machine has a restore disk.

 

It is OK the geeks saying that the only reason Macs don't get viruses is because they're not mainstream, but that is a non-argument. They don't get viruses for whatever the reason - and no amount of saying 'well they would get viruses if . . .' changes anything.

 

Macs are inherently more secure - every single one of the Windows users I know outside the school environment logs into an account where the user has admin priviliges. A virus can access system files with relative ease. Every Mac user I know (because that's how Macs work) is unable to do anything with system files unless they re-authenticate. Any Mac virus which could damage the system would need you to expressly give it the permission it needs to interfere with system files.

 

I'm not even going to mention the capabilities of Apple Macs over Windows PCs . . Well I wasn't going to, I'd best duck instead!

Posted

Yeah, webman, I used to use Linux but I found it not as user-friendly as a Mac. An example, I bought an Asus Eee PC which runs a version of Xandros, I believe. I use an external WebDAV drive on which I store my school documents. Apple OS X and Windows XP allow me to easily open my WebDAV drive as a folder on my machine. After lots of research I managed to install davfs on the Eee PC, but found I could only mount the drive on the command line, then had no desktop concept on the machine where I could pull out the spreadsheet I needed to edit, save it and pop it back into the WebDAV folder. In short it couldn't do what I wanted it to do and this was a biggie because that's why I bought the machine.

 

In the end I had to install XP on it. I used to love tinkering with Linux, rolling my own kernels, trying out different window managers and distros, but I then realised that's all I was doing! I wasn't actually doing anything productive. The Mac really gets your productivity up - the things I can do now I couldn't imagine doing with Linux or XP.

 

My technician at school is a Windows geek and he got this 'brilliant software for creating DVDs - much better than iMovie/iDVD on the Mac'. I interestedly asked him to burn me a DVD with a professional menu etc.. The disk never materialised. When challenged sometime later he sheepishly told me the program kept crashing half-way through the process. That was a year ago. I have noticed that every time we need something taken off a video camera and burnt to DVD he uses the school Macs. Hmmm ;)

Posted
Every Mac user I know (because that's how Macs work) is unable to do anything with system files unless they re-authenticate.

 

Ahem. You mean how linux/BSD works. OSX or OS 10 however you are supposed to say it is based on the BSD core. Most of the stuff that mac users currently bleat on about in their quest against Windows was 'borrowed' from an OS that they had practicaly nothing to do with.

 

Sure they made a pretty layer of user freindly candyfloss on top of it which not other linux dist has matched and added their pattented 'little timmy can too' apps with it but it is still based primarily on the work of others. Others that manage to get none of the credit from the hoards of mac users up on their high horses.

 

OSX is a nice and well put together OS but it is not some mystical cure for all ills in the world. It is an OS, that runs on some hardware, a very limited subset of hardware at that. If people insist on worshiping the OS they could at least worship the foundations it is built on rather than the sparkley tincil that has been layed on top of it.

Posted (edited)
errr.....how many apple fans do you know like this mattx?

 

Oh thats easy, every Apple owner is nothing more than a Steve Jobs worshiper. ;)

As long as the product is over expensive, has an Apple logo on, and is shown by a saddo wearing a black T-shirt and jeans then they all for it it.....:rolleyes:

 

http://www.anti-apple.com/Anti-Ads/macdoom.gif

 

Yeah, I know it's bait, but I've not long come off the phone to my son whose PC has some sort of trojan virus caught because his girlfriend agreed to let some pop-up scan the computer for viruses. His eBay and Hotmail passwords have been changed and he is having a devil of a job getting it sorted. So I'm going to bite.

 

That couldn't happen to me. I am a Mac user.

 

Ok, a mac is virus proof, not the myth the mac is WORTHLESS writing a virus for in terms of its mass......

 

Sort of blows your post out of the water - never mind. Nice try...... :-)

Edited by mattx
Posted

I've tried the proof of concept trojan and it works very nicely ... and there are a number of other malicious possibilities for Mac OS X users ... and security should be taken seriously on them, the same way you would do for any other box.

 

OS Core should be patched, apps should be patched, the machine should be hardened, any app that asks you for the admin password as part of the install should be verified that it is legit and that you have the legit copy of it.

 

Anyone running MS Office is also susceptible to passing on infected files unless they run AV software on them or ensure that *all* files that come in and out of the machine are scanned.

 

On another note ... I am a Mac user ... and I am a valid target for attacks because *I RUN VISTA* ...

 

This is my biggest concern. Yes, we will now have a group of people who are not OS X users as their primary OS, but MS Windows users. Just because they are running it on a Mac does not mean they are any less prone to viruses, trojans or worms than any other MS Windows user!

 

Then again ... my MBP is *still* the most stable machine I have had running Vista ... after trying it on 7 different notebooks (Dell, Toshiba, Acer and Fujitsu Seimens) it has the best performance and least driver problems.

 

I did laugh at the cartoon though ... I know too many Mac purists who are that sad ... then again some of that lot also drool over the idea of getting a boxed ZX81 (with appropriate games) ...

Posted (edited)
then again some of that lot also drool over the idea of getting a boxed ZX81 (with appropriate games) ...

 

Oooooeeeeeerrr, yeah baby - I bow down to sir Clive..... :-) And his 16K Ram Pack.

 

http://content.answers.com/main/content/wp/en/thumb/0/05/180px-Sinclair.zx.16k.rampack.jpg

Edited by mattx
Posted
After lots of research I managed to install davfs on the Eee PC, but found I could only mount the drive on the command line, then had no desktop concept on the machine where I could pull out the spreadsheet I needed to edit, save it and pop it back into the WebDAV folder. In short it couldn't do what I wanted it to do and this was a biggie because that's why I bought the machine.

 

err, konqueror supports webdav - in a window.

Konqueror is installed by default on the eeepc.

 

probably too complicated for mac users :confused:

Posted
err, konqueror supports webdav - in a window.

Konqueror is installed by default on the eeepc.

 

probably too complicated for mac users :confused:

 

LMAO :D

Posted
err, konqueror supports webdav - in a window.

Konqueror is installed by default on the eeepc.

 

probably too complicated for mac users :confused:

 

LMAO seconded! :p

Posted
Ahem. You mean how linux/BSD works. OSX or OS 10 however you are supposed to say it is based on the BSD core. Most of the stuff that mac users currently bleat on about in their quest against Windows was 'borrowed' from an OS that they had practicaly nothing to do with.

 

Sure they made a pretty layer of user freindly candyfloss on top of it which not other linux dist has matched and added their pattented 'little timmy can too' apps with it but it is still based primarily on the work of others. Others that manage to get none of the credit from the hoards of mac users up on their high horses.

 

OSX is a nice and well put together OS but it is not some mystical cure for all ills in the world. It is an OS, that runs on some hardware, a very limited subset of hardware at that. If people insist on worshiping the OS they could at least worship the foundations it is built on rather than the sparkley tincil that has been layed on top of it.

 

classic had it's issue, and apple obviously felt a bsd unix foundation was the best way to keep their OS relevant in the noughties.....

 

But I much prefer the old interface over the OSX candy floss. Although I am glad we no longer have to piss about with Appletalk.

  • Thanks 1
Posted
I've tried the proof of concept trojan and it works very nicely ... and there are a number of other malicious possibilities for Mac OS X users ... and security should be taken seriously on them, the same way you would do for any other box.

 

OS Core should be patched, apps should be patched, the machine should be hardened, any app that asks you for the admin password as part of the install should be verified that it is legit and that you have the legit copy of it.

 

Anyone running MS Office is also susceptible to passing on infected files unless they run AV software on them or ensure that *all* files that come in and out of the machine are scanned.

 

On another note ... I am a Mac user ... and I am a valid target for attacks because *I RUN VISTA* ...

 

This is my biggest concern. Yes, we will now have a group of people who are not OS X users as their primary OS, but MS Windows users. Just because they are running it on a Mac does not mean they are any less prone to viruses, trojans or worms than any other MS Windows user!

 

Then again ... my MBP is *still* the most stable machine I have had running Vista ... after trying it on 7 different notebooks (Dell, Toshiba, Acer and Fujitsu Seimens) it has the best performance and least driver problems.

 

I did laugh at the cartoon though ... I know too many Mac purists who are that sad ... then again some of that lot also drool over the idea of getting a boxed ZX81 (with appropriate games) ...

 

Hello.

 

The usual round of "Linux kicks " but kicks in. I agree with Tony to some extent- every OS user (no matter the system you use) should be fully aware of security in all its aspects. Admittedly, OS X users can be found complacent when it comes to this topic, simply because there has yet to be a serious infiltration of the operating system. That may come at some point- and perhaps it's inevitable (and will happen in the same way it occurs for Linux ;)

 

What I want to take issue with Tony is your statement about a "proof of concept" trojan. Can I ask which one(s) you have tried, and what you had to do to make the "concept" apply to your machine? I ask because all of the concepts I have seen for OS X have needed the "first you need to do this; then that; then some more here; also this; and that; to get this" mechanism to work, and then only most of the time affect the account executed under. That's the Unix way really. It isn't that Unix is impenetrable (it's not as history teaches us) but it is darned hard to break without the right things being in place to do it. It's like some kind of convergence of the stars :D

 

Of course, being a good Mac user I take security seriously. As a Vista user too on my MBP I have anti-virus, watch what I download (just like I watch what I eat) and if passing files between systems make sure everything is as clean as I can. That's why I run ClamAV on OS X- so that I can be a good OS citizen in this world of Windows. But it would be good to know what trojans you have been looking at and how you got them working.

 

Just for the sake of the discussion ;-)

 

Paul

Posted
@scgf: You wouldn't get those problems if you used Linux either. You'd also be a mortgage better-off financially...

 

But have less time to enjoy it without buying in lots of little loans to get it to *be* a darned house that you can live in :D

Posted

*BIG-EFFING-SIGH*

 

What I call Distro-Wars has made the rounds on EduGeek yet again. Yes...cartoon not /that/ funny. Bait for flame wars. Can't people just respect other people's right to use a bloody mac if they want to! As long as it does what they want then let them to it!!!

 

Btw....I own an Apple product and I'll have you know I'm sat here wearing an Ubuntu t-shirt and I don't worship steve jobs.

Posted
Can't people just respect other people's right to use a bloody mac if they want to!

Nope. ;-)

 

I own an Apple product and I'll have you know I'm sat here wearing an Ubuntu t-shirt and I don't worship steve jobs.

 

Yes you do, subconsciously.

 

http://www.anti-apple.com/MacRightClick.jpg

Posted
What I want to take issue with Tony is your statement about a "proof of concept" trojan. Can I ask which one(s) you have tried, and what you had to do to make the "concept" apply to your machine? I ask because all of the concepts I have seen for OS X have needed the "first you need to do this; then that; then some more here; also this; and that; to get this" mechanism to work, and then only most of the time affect the account executed under. That's the Unix way really. It isn't that Unix is impenetrable (it's not as history teaches us) but it is darned hard to break without the right things being in place to do it. It's like some kind of convergence of the stars :D

 

Leap-A was a trojan *not* a virus and relied on you entering admin details, and the recipient setting their iChat to receive files from those in their buddy list automatically. Yes, it was jumping through hoops and was targetted at stupid people, but it could be done easily. The LaunchD attack is a better example of exploiting the OS rather then an integrated application, (ie the more recent malware attacks on plugins). LaunchD was very handy to build into Automator (convince the user to enter the user details and password as part of running the Automator Action) and this can be hidden into a file that can be used for subsequent re-runs of the attack. It then leaves the device open for a string of other attacks too, if the person creating the code knows where the file containing the user deatils and password is.

 

Presently there are fewer attack vectors, but that will not last forever, and it will be down to user stupidity that the few obvious ones get exploited. The other attack vectors are down to poor coding and vunerabilities of apps that are cross platform anyway.

Posted
But have less time to enjoy it without buying in lots of little loans to get it to *be* a darned house that you can live in

 

That is ridiculous. It's windows that needs the extra (paid) programs and licenses that give it the functionality that come close to where most *nix distos are out of the box (and a 2 yr wait for MS to catch up).

Posted

@Mattx

 

Your hatred/fixation with MacOS X is bordering on the pathological.

 

What happened is there a traumatic event in your past which tuned into a Mac-o-phobe? Did the love of your life run of with a Porsche driving Mac user.;-)

Posted
That is ridiculous. It's windows that needs the extra (paid) programs and licenses that give it the functionality that come close to where most *nix distos are out of the box (and a 2 yr wait for MS to catch up).

 

I wasn't talking about Windows :rolleyes:

 

Who mentioned Windows? I just stretched the analogy to lighten things up.

 

Have a good week mate,

 

Paul :)

Posted
Leap-A was a trojan *not* a virus and relied on you entering admin details, and the recipient setting their iChat to receive files from those in their buddy list automatically. Yes, it was jumping through hoops and was targetted at stupid people, but it could be done easily. The LaunchD attack is a better example of exploiting the OS rather then an integrated application, (ie the more recent malware attacks on plugins). LaunchD was very handy to build into Automator (convince the user to enter the user details and password as part of running the Automator Action) and this can be hidden into a file that can be used for subsequent re-runs of the attack. It then leaves the device open for a string of other attacks too, if the person creating the code knows where the file containing the user deatils and password is.

 

Presently there are fewer attack vectors, but that will not last forever, and it will be down to user stupidity that the few obvious ones get exploited. The other attack vectors are down to poor coding and vunerabilities of apps that are cross platform anyway.

 

Ahhh- this one?

 

http://www.symantec.com/security_response/writeup.jsp?docid=2006-063013-2645-99&tabid=2

 

That was patched in the 10.4.7 update (check the advisory). Of course there are others, and being "proof of concept" means they "could" work given the right convergence of events. Leap-A (coming in the form of a Trojan; a file called LatestPics.tgz) had to use Tiger (it relied on Spotlight to work). You had to put the file on your machine yourself- normally delivered over chat or from other sites purporting to give away Leopard pictures :rolleyes: Some people were stupid enough to download and double click for sure. Leap-A didn't actually do anything "malicious"- it didn't recursively delete files (for example), and at the worst stopped applications from launching. Andrew Welch stated that it would do nasty things to your machine--but that wasn't seen. I tried it on my own system and it did...nothing.

 

How did people fix the system if their applications were impacted by this trojan? Just install clean versions of the applications. Getting rid of the trojan was as easy as deleting the apphook file (though the name changed later on to something else).

 

At the end of the day what we *all* need is defence in depth. And we all need educating about our respective operating system and its security needs. And then of course we all need to download from trusted sites ;-)

 

My point though, was those hoops. That needs to be remembered right now. OS X is inherently more secure than some other systems, but the weak link in the chain (I think we agree here) is the user.

 

Take care,

 

Paul

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...