Author Topic: New Mac Spyware?  (Read 3203 times)

Offline Al

  • TS Addict
  • Posts: 3105
    • View Profile
    • http://
New Mac Spyware?
« on: November 29, 2006, 06:44:44 PM »
I recieved a forwarding email from my wife today regarding new spyware for OS X.  the email was generated from an Information Security Officer from the Hawaii Education system.

Legit alert?

QUOTE
--Mac OS X Spyware Detected
(27 & 24 November 2006)
The first spyware program for Mac OS X has been detected. The
proof-of-concept code could potentially be installed without users'
knowledge. The program, known as iAdware, installs itself as a System
Library. It does not exploit a flaw, but takes advantage of a feature
in Mac OS X to run each time an application is loaded.
http://www.eweek.com/print_article2/0,1217,a=194912,00.asp
http://www.theregister.co.uk/2006/11/24/ma...ware/print.html
[Editor's Note (Skoudis): Mac users must fight the feeling that they are
invulnerable simply because they are using a different kind of computer.
As a very happy Mac user myself, I feel this temptation, but it must be
resisted. Macs are getting increased scrutiny as their numbers go up.
I'm especially concerned about client-side vulnerabilities on the Mac,
including Safari and Mail:App, which haven't gotten nearly as much
scrutiny as IE, Firefox, and Outlook. Keep your Macs patched, and
practice safe computing from them.]

Jodi Ito
Information Security Officer
27" 2.8 GHz Intel I7 iMac, 8 GB RAM, 2 TB HD, 2x 2TB OWC Mercury Elite-AL Pro external HD, EyeTV 250 Plus, 23" Acer HD monitor, OS 10.6.7
13" 2.26 GHz Intel Core 2 Duo MacBook, 4 GB RAM, 500 GB 7200 RPM HD, OS 10.6.7
13" 2.26 GHz Intel Core 2 Duo MacBook, 4 GB RAM, 250 GB HD, OS 10.6.7
(2) 5th Gen. iPods (30GB & 80GB), iPhone 4 (x2) 16 GB iOS 4.3.3, iPhone 3GS 16 GB

Offline sandbox

  • TS Addict
  • *****
  • Posts: 7825
    • View Profile
    • http://
New Mac Spyware?
« Reply #1 on: November 29, 2006, 07:35:27 PM »
From the blog that started it….. F_Secure
this is only a test. beep......beep......beep  eek2.gif

QUOTE
We recently received a proof-of-concept sample of an adware program. Normally that wouldn't be worth blogging about, but in this case it's for Mac OS X. In theory, this program could be silently installed to your User account and hooked to each application you use… and it doesn't require Administrator rights to do so. We won't disclose the exact technique used here, it's a feature not a bug, but let's just say that installing a System Library shouldn't be allowed without prompting the user. Especially as it only requires Copy permissions. An Admin could install this globally to all users.

The result: This particular sample successfully launched the Mac's Web browser when we used any of a number of applications.

This is easier to do than with Windows. After all, it's a Mac.

http://www.f-secure.com/weblog/

Offline kbeartx

  • TS Addict
  • Posts: 6772
    • View Profile
    • http://
New Mac Spyware?
« Reply #2 on: November 29, 2006, 07:35:29 PM »
'Proof-of-concept' means that the possibility exists [usually tested in a laboratory environment], NOT that any actual exploits have been seen 'in the wild'.

So don't worry.

Yet.

Offline kimmer

  • Administrator
  • TS Addict
  • *****
  • Posts: 9086
    • View Profile
New Mac Spyware?
« Reply #3 on: November 29, 2006, 07:53:56 PM »
Would this be similar to what happens when I launch "NeoOffice" (beta). Around every 3rd launch, my browser is launched and I'm taken to the "please donate" page. It's stinkin' annoying for several reasons (chief amongst them is that I've already donated and if they want money that badly then they should make their product shareware not freeware! Sorry I'll stop now).

Anyhow is this what they are talking about?
Can I remove whatever causes this in NeoOffice?
Should I be looking for something to remove regardless of NeoOffice?
And boy is it cool that FF 2.0 spell checks!

Offline krissel

  • Administrator
  • TS Addict
  • *****
  • Posts: 14735
    • View Profile
New Mac Spyware?
« Reply #4 on: November 29, 2006, 10:18:01 PM »
I believe this is the 'flaw' that references the fact that Safari is set to open downloads by default. All you have to do is change that pref.

Will find the article online....



OK, well it was mentioned in an article about the browser settings but not the same problem. Sorry.

http://www.macworld.co.uk/mac/news/index.cfm?newsid=16583
« Last Edit: November 29, 2006, 10:28:01 PM by krissel »


A Techsurvivors founder

Offline eric j

  • Super Poster
  • ***
  • Posts: 345
    • View Profile
    • http://
New Mac Spyware?
« Reply #5 on: November 29, 2006, 10:32:12 PM »
Just found this:

http://news.bbc.co.uk/2/hi/technology/6187302.stm

on the BBC site.

Refers to a possible exploitation of DMG.

eric j

Offline krissel

  • Administrator
  • TS Addict
  • *****
  • Posts: 14735
    • View Profile
New Mac Spyware?
« Reply #6 on: November 29, 2006, 10:41:27 PM »
That was the article mentioned in the link in my thread. They talked about the problem but failed to describe the 'workaround' was to disable automatic opening of downloads.

angry.gif


A Techsurvivors founder

Offline kbeartx

  • TS Addict
  • Posts: 6772
    • View Profile
    • http://
New Mac Spyware?
« Reply #7 on: November 29, 2006, 10:42:25 PM »
In my read of the article, they pointedly avoided describing the 'mechanism' by which this 'vulnerability' might be exploited, so I assume it's not something previously reported elsewhere.

Offline sandbox

  • TS Addict
  • *****
  • Posts: 7825
    • View Profile
    • http://
New Mac Spyware?
« Reply #8 on: November 29, 2006, 11:09:29 PM »
It also has to pass the administrative sniff test. You or your administrator has to allow the installation. Apple could have addressed the issue in this last security download?

In anycase it's not what I would classify as adward, malware, trojan, or virus if it is stopped by your administration password. That is unless you just allow things of unknow origin into your secure files.
« Last Edit: November 29, 2006, 11:10:26 PM by sandbox »

Offline D76

  • Super Duper Poster
  • ****
  • Posts: 438
    • View Profile
    • http://
New Mac Spyware?
« Reply #9 on: November 30, 2006, 07:27:06 AM »
There's a thread at Mac-Forums about redirects to some PC site called Drive Cleaner where some Mac users end up. One post says:
QUOTE
I used safari once to dl Firefox. I did not use my PC profile, or Bookmarks and cookies to Safari. I was just browsing away and this pop up well popped up. It took me to the drivecleaner site where it made it look like it was scanning my computer and then sujessted I dl there program which is an .exe. I find that it goes away and comes back periodically. Also I can not DL from sites or log into second life since this started.
Another;
QUOTE
Yeah I'm getting the same thing! It just started today, and it's VERY annoying, but I haven't clicked OK. I clicked "cancel" the first time and it just popped up another message (not a pop-up window but what apeared to be a message from Safari itself) with only an "OK" option. So now I just force-quit Safari every time it happens rather than click on the message at all...but needless to say this is very frustrating!!
Then more of the same, with the top two posts on the second page rather ominous.