Jump to content

Recommended Posts

Posted

I wouldn't believe everything you read.....

 

Aren't we ALWAYS being told by the fanbois how it's impossible for an Apple product to get infected?

 

Nothing to see here....Move along please!!!

Posted
*anything* can be infected with the right will. With the level of mac usage in US education, it will just become more and more rife.

 

I have tried to point this out to people, but they refuse to believe it.....

Posted
So Have i!!

 

Finally I can gloat to some staff here!!!

 

It's the way that some people have that supercillious attitude that Macs are impervious to any outside influence.

 

I like to point out that that is because their share of the market is so miniscule as to not make writing a virus that worthwhile. Why hit the 2%, when you can hit the other 95% (or whatever the current share is!! The remaining 3% being Linux....which can also get viruses!!) However, with the popularity of iOS increasing, more and more viruses/bots will be released into the wild.

 

This, somewhat, passes over their heads....

Posted

Minor nitpick. This is a trojan, not a virus.

 

I know the average person doesn't understand what the difference is, but it's worth pointing out. :)

Posted
Minor nitpick. This is a trojan, not a virus.

 

I know the average person doesn't understand what the difference is, but it's worth pointing out. :)

 

So you wouldn't call having a bot on a Mac as being infected?

 

That was the point of my previous post. The bot is still an outside influence, is it not?

 

;)

Posted
So you wouldn't call having a bot on a Mac as being infected?

That wasn't what I meant. :)

 

A computer virus is a computer program that can replicate itself and spread from one computer to another. The term "virus" is also commonly, but erroneously used, to refer to other types of malware, including but not limited to adware and spyware programs that do not have a reproductive ability.

 

Viruses are sometimes confused with worms and Trojan horses, which are technically different. A worm can exploit security vulnerabilities to spread itself automatically to other computers through networks, while a Trojan horse is a program that appears harmless but hides malicious functions. Worms and Trojan horses, like viruses, may harm a computer system's data or performance. Some viruses and other malware have symptoms noticeable to the computer user, but many are surreptitious or simply do nothing to call attention to themselves. Some viruses do nothing beyond reproducing themselves. (Source)

 

Semantics aside, you are correct that it is not a nice thing to have running on your computer.

Posted
That wasn't what I meant. :)

 

 

 

Semantics aside, you are correct that it is not a nice thing to have running on your computer.

 

I know, and I apologise! Just a bit of crankiness creeping in, as I'm less than 2 hours away from a week off!!

 

And I DO quite need it!!!

Posted

Anyone following Naked Security has been aware of this risk for a very long time. It just needs better coverage.

 

Mac malware devkits have been developed at last and waiting to pounce! I had the deputy head tell me about his Macbook and "Oh yes, it has no viruses!" One malware education lesson later...

Posted

Regardless of OS, perhaps the best advice is to uninstall or disable Java if you don't need it. According to Secunia, last year Java had over ten times as many vulnerabilities as Flash Player! :eek:

 

If you need Java on your Mac only for a specific application (such as OpenOffice), you can unplug it from the browser by disabling its plugin. In Safari, this can be done by clicking Preferences, and then the Security tab (uncheck “Enable Java”). In Google Chrome, open Preferences, and then type “Java” in the search box. Scroll down to the Plug-ins section, and click the link that says “Disable individual plug-ins.” If you have Java installed, you should see a “disable” link underneath its listing. In Mozilla Firefox for Mac, click Tools, Add-ons, and disable the Java plugin(s).

 

I can’t stress this point strongly enough: If you don’t need Java, remove it from your system, whether you are a Mac or Windows user. If you need further convincing of my reasons for this recommendation, I’d encourage you to browse through some of my past Java-related posts. (Source)

 

Just a bit of crankiness creeping in, as I'm less than 2 hours away from a week off!!

No worries. I sometimes get like that too.

Posted (edited)

If the web app works in Google Chrome, it might be worth using this instead of Safari because it will display the prompt below whenever you visit websites containing Java apps. In theory this should prevent drive-by infections.

 

http://i.imgur.com/cJAQ1.png

Edited by Arthur
Posted

 

Aren't we ALWAYS being told by the fanbois how it's impossible for an Apple product to get infected?

 

I hear this so many times... and I have yet to hear this from a single person who actually understands Technical Support always some one who "I can use a MAC so that makes me a Know it all"..............

Posted
I guess alot of people would crap themselves if they did actually run a virus scan on their mac and see what it found. And then take it back to the apple store to get it sorted.
Posted

A couple of useful links...

 

Detect FlashBack Malware in Mac OS X the Easy Way « OS X Daily

A new application has been released which makes checking a Mac for the Flashback malware infection as simple as clicking a button. This is a huge help for assisting less tech savvy people for checking their Macs...

 

http://i.imgur.com/khv4T.jpg

 

This new app-based detection method is very nontechnical and is just a two step process. (Source)

 

Apple to release Flashback removal software, working to take down botnet « Ars Technica

Apple plans to release software that will detect and remove Flashback malware infections on the Mac, the company announced Tuesday. In a knowledge base link published late in the day, Apple explained that it's aware of the infection—which takes advantage of a previously unpatched Java vulnerability—saying that the software was coming, but no specific release date was given.

 

In addition to the Flashback detection software, Apple said that it's "working with ISPs worldwide" to disable the botnet's command and control (C&C) servers. Kaspersky researcher Kurt Baumgartner told Forbes earlier on Tuesday that "Apple is taking appropriate action by working with the larger Internet security community to shut down the Flashfake [also known as Flashback] C2 domains," and Apple's latest efforts seem to coincide with Baumgartner's statement.

 

"Apple is developing software that will detect and remove the Flashback malware," Apple wrote. "In addition to the Java vulnerability, the Flashback malware relies on computer servers hosted by the malware authors to perform many of its critical functions. Apple is working with ISPs worldwide to disable this command and control network." (Source)

Posted

I have to say, reading this article it goes to show just how amateurish and childish Apple really are when it comes to security.

 

Apple really need to wake up and stop pretending their software is unbreakable. Microsoft's procedures are a perfect example how a new security vulnerability should be handled and patched accordingly.

 

It wouldn't surprise me that proportionately, we'll start seeing more malware/viruses targeting Apple software rather than Microsoft software. You could argue it's getting increasingly more difficult to find vulnerabilities in Microsoft software and that Apple's software is comparatively untouched and potentially full of vulnerabilities to exploit.

Posted

Apple have released their own Flashback removal tool now (it's part of the Java for OS X Lion 2012-003 and Java for Mac OS X 10.6 Update 8 updates).

 

This Java security update removes the most common variants of the Flashback malware.

 

This update also configures the Java web plug-in to disable the automatic execution of Java applets. Users may re-enable automatic execution of Java applets using the Java Preferences application. If the Java web plug-in detects that no applets have been run for an extended period of time it will again disable Java applets.

 

In other news, Sophos have discovered a new trojan horse called OSX/Sabpab.A which uses the same Java vulnerability as Flashback.

 

http://i.imgur.com/Iuoij.jpg

Posted
Apple really need to wake up and stop pretending their software is unbreakable.

Java for OS X is developed by Oracle (but distributed to Mac's by Apple). Don't you think Oracle should get some of the blame for creating one of the most vulnerable pieces of software on the planet?

 

Even when Oracle distribute the updates themselves (i.e. on Windows), you still find a lot of people have old versions installed because their updater sucks. :(

 

Based on the Java patching habits of 28 million unique Internet users, Rapid7 estimates that 60-80% of computers running Java are vulnerable to this attack today.

 

Looking long term, upwards of 60% of Java installations are never up to the current patch level. Since so many computers aren’t updated, even older exploits can be used to compromise victims.

 

Rapid7 researched the typical patch cycle for Java and identified a telling pattern of behavior. We found that during the first month after a Java patch is released, adoption is less than 10%. After 2 months, approximately 20% have applied patches and after 3 months, we found that more than 30% are patched. We determined that the highest patch rate last year was 38% with Java Version 6 Update 26 3 months after its release. (Source)

Posted

You could argue however that Apple have chosen to include and distribute Java as part of the OS. Microsoft do not include Java, although many OEMs do install it on their base images.

 

I agree that the Auto Updater on older versions of Java isn't great, but newer versions do tend to download or at least prompt the user to download the update.

Posted
Java for OS X is developed by Oracle (but distributed to Mac's by Apple). Don't you think Oracle should get some of the blame for creating one of the most vulnerable pieces of software on the planet?

 

Even when Oracle distribute the updates themselves (i.e. on Windows), you still find a lot of people have old versions installed because their updater sucks. :(

 

Not only that but look at the size of corporate networks - Java will be very much like IE was. Thorough testing has to occur before roll-out of patches.

 

Not to mention the fact that they don't release patches. They release new versions every time. So every time we have to do a network wide update, we end up having 5 minutes at boot for it to install. And they update *a lot*.

Posted

I suppose the other question of course is why is this Java exploit only being exploited on Mac and not Windows? Both OSes use Java, but it probably underlines other factors when it comes to OS design.

 

As I say, Microsoft software proportionately is exhausted and it is getting increasingly harder to find vulnerabilities. I do suspect the Apple virus/malware is a bigger problem than many people realise.

Posted
Java for OS X is developed by Oracle (but distributed to Mac's by Apple). Don't you think Oracle should get some of the blame for creating one of the most vulnerable pieces of software on the planet?

 

Oracle missed their true calling, blue movies, honestly the amount of penitration and domination perpatrated on their software should see it selling in adult stores in the extreme section.

  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...