Showing posts with label OS X. Show all posts
Showing posts with label OS X. Show all posts

Friday, April 6, 2012

Russian Security Experts Analyze Backdoor.Flashback.39

Backdoor.Flashback.39, the piece of malware designed to target computers running Mac OS X, caused a lot of headaches for Mac users, especially because one of the Java vulnerabilities it exploited remained unpatched by Apple.

Security experts have found that even after Apple patched the flaw, the cybercriminals behind the operation didn't seem to be discouraged.

Researchers from Russian security firm Doctor Web analyzed the malicious element and determined that the infection begins when users are redirected to shady sites from compromised domains.

A piece of JavaScript code, placed on websites such as godofwar3.rr.nu, ironmanvideo.rr.nu, killaoftime.rr.nu, or gangstasparadise.rr.nu, loads the Java applet that contains the exploit.

The exploit then saves an executable onto the infected Mac machine. This executable file connects to a remote server from which it downloads and executes the final payload.

Continue Reading

Wednesday, March 23, 2011

Apple's software chief quits as iOS eats Lion


"Major Apple [AAPL] news this morning is the departure of Apple's OS X chief, Bertrand Serlet, who is leaving the company. His departure comes as Apple prepares to introduce Mac OS X Lion and as it continues to develop its giant US data center, also expected to unleash a new era of connected computing. Serlet's departure reflects a wider change at the company.
As senior vice president of Software Engineering, Serlet has led Apple's Software Engineering group for years, reporting directly to CEO, Steve Jobs. Serlet is a key player in the Apple ecosystem -- he came to the company with Jobs in 1997 and has been deeply involved in the development of Mac OS X. He even has a connection to the famed Xerox PARC, where he spent four years before joining Jobs' NeXT in 1989
Continue reading Apple's software chief quits as iOS eats Lion

Thursday, November 4, 2010

Mac OS X Boonana Trojan Horse trojan.osx.boonana.a

"SecureMac has discovered a new trojan horse in the wild that affects Mac OS X, including Snow Leopard (OS X 10.6), the latest version of OS X. The trojan horse, trojan.osx.boonana.a, is spreading through social networking sites, including Facebook, disguised as a video. The trojan is currently appearing as a link in messages on social networking sites with the subject "Is this you in this video?"

When a user clicks the infected link, the trojan initially runs as a Java applet, which downloads other files to the computer, including an installer, which launches automatically. When run, the installer modifies system files to bypass the need for passwords, allowing outside access to all files on the system. Additionally, the trojan sets itself to run invisibly in the background at startup, and periodically checks in with command and control servers to report information on the infected system. While running, the trojan horse hijacks user accounts to spread itself further via spam messages. Users have reported the trojan is spreading through e-mail as well as social media sites."

Continue reading the SecureMac Security Bulletin



FYI: Sophos has announced the world's first free business-strength anti-virus program for Macs. The Mac anti-virus product (used by big companies around the world) available for free download to home consumers.

Tuesday, November 2, 2010

Yes, you need anti-virus on your Mac.. and now it’s free | Naked Security

Yes, you need anti-virus on your Mac.. and now it’s free | Naked Security

Sophos has today announced the world's first free business-strength anti-virus program for home Macs. As Apple computers grow more popular than ever, they're an increasingly-enticing target for hackers (Windows users are still the number one target). And these hackers aren't just mischief-makers—by targeting your computer or applications you use, these criminals are out to steal and profit from your valuable personal information. Don't let them. Get Sophos Anti-Virus Home Edition for the Mac free today.



Friday, October 15, 2010

John Sculley On Steve Jobs, The Full Interview Transcript

"The thing that separated Steve Jobs from other people like Bill Gates — Bill was brilliant too — but Bill was never interested in great taste. He was always interested in being able to dominate a market. He would put out whatever he had to put out there to own that space. Steve would never do that. Steve believed in perfection. Steve was willing to take extraordinary chances in trying new product areas but it was always from the vantage point of being a designer. So when I think about different kinds of CEOs — CEOs who are great leaders, CEOs who are great turnaround artists, great deal negotiators, great people motivators — but the great skill that Steve has is he’s a great designer. Everything at Apple can be best understood through the lens of designing."

Continue reading the full story at Cult of Mac by Leander Kahney

Tuesday, June 1, 2010

OSX/OpinionSpy Spyware Installed by Freely Distributed Mac Applications

Intego has discovered a spyware application that is installed by a number of freely distributed Mac applications and screen savers found on a variety of websites. This spyware, OSX/OpinionSpy, performs a number of malicious actions, from scanning files to recording user activity, as well as sending information about this activity to remote servers and opening a backdoor on infected Macs.

OSX/OpinionSpy is installed by a number of applications and screen savers that are distributed on sites such as MacUpdate, VersionTracker and Softpedia. The spyware itself is not contained in these applications, but is downloaded during the installation process. This shows the need for an up-to-date anti-malware program with a real-time scanner that can detect this malware when it is downloaded by the original application’s installer.

The information provided with some of these applications contains a misleading text that users must accept explaining that a “market research” program is installed with them, but not all of these specify this. Some of these programs are also distributed directly from developers’ web sites with no such warning.

The malware, a version of which has existed for Windows since 2008, claims to collect browsing and purchasing information that is used in market reports. However, this program goes much further, performing a number of insidious actions, which have led Intego to classify it as spyware.

For full technical details about OSX/OpinionSpy please visit the Intergo web site.

Saturday, April 17, 2010

The truth about Mac malware. It's a joke - War on Error - Blogs - Technology Blog and Community from IT Experts - Techworld.com

The truth about Mac malware. It's a joke - War on Error - Blogs - Technology Blog and Community from IT Experts - Techworld.com

There are less then 200 Mac malware (that’s viruses, worms, Trojans, etc) programs. Having researched these a bit further as many were unfamiliar, I discovered that they are all years old, some going back as far as a decade or more. Study the list closely and you see that many of them are variants, that is slightly different versions of the same piece of code.

As impressively long as the list looks, this is in fact a fair chunk of ALL the malware that has afflicted the Mac in the last decade. Is this the best the Mac malware writers can do? One of the examples is a reheated virus from - no kidding - 1989."

"Apple antivirus company Intego has discovered a backdoor malware attack targeting Mac users OSX.HellRTS.D. As with so many of the small number of Mac-specific malware attacks that come up from time to time, this one is a variant of an attack from 2004, the company said, which will sound quaint to Windows users hit by thousands of variants on most days."

Posted using ShareThis

Thursday, April 8, 2010

Macintosh = Hacker-Proof?

Charlie Miller has a habit of upending Apple's security claims.

Charlie A. Miller loves his Macbook Pro laptop. And his four other Apple ( AAPL - news - people ) PCs, the iPhone he uses daily and two older iPhones he keeps for tinkering. But his relationship with the company that created those gadgets is somewhat more complicated.

In March, for instance, the 36-year-old security researcher publicized his discovery of 20 security vulnerabilities in Apple's software. Each would allow a cybercriminal to take over the computer of a user who's tricked into opening a certain PDF attachment or who simply visits an infected Web page using Apple's Safari browser.

That haul of bugs is a record even for Miller, who over the last four years has become perhaps the world's most prominent Mac hacker. It may also be definitive proof that Apple devices aren't safe "right out of the box," as the company has claimed for years. "When I first began saying that Macs were less secure than Windows, everyone thought I was an idiot," says Miller. "So I had to prove it again and again and again."

In 2007 Miller became the first to hack the iPhone, using a flaw in its Safari browser to remotely gain control of the not-so-smart phone. Six months later he hacked a Macbook Air in two minutes at a competition in Vancouver. Last summer he revealed a method that allowed him to virally hijack the iPhone using text messages spread via a user's contact list.

Miller says his latest research doesn't aim to show off his elite hacking skills,most of which he learned over five years as a global network exploitation analyst for the National Security Agency. Instead, he wants to show just how easy it is to find chinks in the armor of commonly used software. Miller used a technique known as "dumb fuzzing" to find flaws. He ran the procedure more persistently than most hackers, leaving his fuzzing program to throw junk information at each target for three weeks before mining the data for exploitable flaws.

As for Apple, Miller says the company has learned to accept, if not appreciate, his work. He usually gives Apple weeks of notice before publicly describing its bugs. "They're always very polite," he says. "But I suspect they wish I didn't exist."

Read the full story at Forbes.com by Andy Greenberg

Updated:
Apple Patches Pwn2Own Bug

Friday, October 30, 2009

InfoWorld: Snow Leopard beats Windows 7

PC vs. Mac deathmatch: Snow Leopard beats Windows 7


"Windows 7 was built to fix the problems that plagued Vista, and it unquestionably succeeds in doing that. It's a bit less bloated, and it runs a bit faster. The annoying security alerts from User Account Control have been quieted. And the compatibility issues with third-party software and hardware device drivers have largely been ironed away; after all, it's been two and a half years since Vista debuted. Windows 7 even includes a virtual "XP mode" for running legacy programs.

[ Which is better? The Mac OS and Windows 7 UIs face off. | GetInfoWorld's 21-page hands-on look at the next version of Windows, from InfoWorld’s editors and contributors. | Find out what's new, what's wrong, and what's good about Windows 7 in InfoWorld's "Windows 7: The essential guide." ]

Windows 7 goes a few steps beyond merely repairing Vista. It borrows --and improves on -- tricks from the Mac's playbook to make it easier and faster to organize files and launch programs. Like Apple's operating system, Windows 7 not only looks good, but it has tools and shortcuts that help you work more efficiently. If there were ever a Windows that could challenge Mac OS X, Windows 7 is it.

Still, once you've had Mac, can you ever go back?"


Read the full story at InfoWorld

Tuesday, June 30, 2009

VirtualBox 3.0.0 for Linux Brings 3D and OpenGL 2.0 Support

"VirtualBox, the popular, amazing, open-source, virtualization software from Sun Microsystems, reached version 3.0.0 a few minutes ago. This major update brings lots of new features, many bugfixes and improvements over previous 2.x versions. The big and breathtaking news is that users can now use Direct3D 8 and 9 games or applications! Moreover, with VirtualBox 3.0.0, support for OpenGL 2.0 (only for Linux, Solaris and Windows guests) has been implemented. Another important feature is the new SMP (Symmetrical Multiprocessing) guest support with no more than 32 virtual processors. Without any further introduction, let's have a look at the main fixes/additions in VirtualBox 3.0.0 for Linux"

Read the full story here.

Friday, June 20, 2008

Apple news for the week

The Moscow News is reporting that Apple Hesitating to Sell Its New iPhone in Russia. "At an annual software conference in San Francisco, Steve Jobs, the founder and head of Apple Inc., presented a new model of the popular iPhone communicator for 3G networks. Russia and China may have felt left out, however - Apple does not yet plan to sell the latest version of its phone in these countries. But they should not worry - anyone in either country will be able to buy the fashionable device, no matter what Jobs says. As more phones are dumped on the American market than it can absorb, some of the extra ones will find their way to distributors who unlock them (a simple enough procedure) and send them on to Russia. For Apple, this is a win-win situation: they corner new markets without investing a cent in services networks."

Speedy up Mac OS X for free with Secrets


iPhone is HOT and it seems just about everyone is talking about Apples little phone that could change the way people use their phones check out some of the articles from this week: Why the new iPhone will squash BlackBerry, Selling big business on the iPhone, How the iPhone puts a bomb under mobile networks, Why the iPhone 3G is a gold mine for Apple, even at $199, Why iPhone Wannabes Don't Cut It.

There have been a number of reports this week about security flaws in XP (no big surprise), FireFox, and one possible new one for OS X. I always give the standard warning don't use P2P software and download programs as you will get more then you bargained for with this new little AppleScript.