Sophos identifies a trojan for OS X
February 28, 2011 by Katie Gatto
(PhysOrg.com) -- Macs have, for the most part, been considered to be more secure than their PC counterparts due to the lack of developments of viruses and other malicious codes that are created for them. Most of the authors of malicious code are playing a numbers game, in order to get the best results they need to hit the largest number of machines possible with each piece of code. As Mac operating system-based machines have become more and more popular, they have become increasingly attractive to the writers of malicious code.
A team of security researchers working at Sophos have identified a trojan that is set up to exploit a security vulnerability in Mac OSX.
The code, known as "Remote Access Trojan" or "Blackhole RAT" for short is currently unfinished, but is expected to be a Mac based version of the Windows RAT known as "darkComet". If that is the case, then Blackhole Rat will allow hackers to send commands remotely.
The commands issued from this type of trojan may give the person running the code the ability to pop up a fake "Administrator Password" window in order to perpetrate phishing styles of attack against a target. The software might also be able to be used to add files to the system, or send remote commands such as: restart, shutdown or sleep command to the Mac.
Currently the site for the trojan is very basic, with a mix of text in English and German, but the site does promise that there are upgrades to the software coming in the future. No specifics have been given, all of site would say is that "much more functions" will be released when the final product out.
© 2010 PhysOrg.com
-
From lemons to lemonade: Reaction uses carbon dioxide to make carbon-based semiconductor,
30 comments
-
Thioridazine kills cancer stem cells in human while avoiding toxic side-effects of conventional cancer treatments,
3 comments
-
SpaceX private rocket blasts off for space station (Update),
42 comments
-
Climate scientists say they have solved riddle of rising sea,
30 comments
-
Research team claims to have found evidence Lake Cheko is impact crater for Tunguska Event,
18 comments
-
magnets or EMF in car bumpers to protect from fender bender
15 hours ago
-
length of wire in a coil of known dimensions?
May 25, 2012
-
India Engineering Powerhouse
May 25, 2012
-
electromagnet core dereference between hard and soft iron
May 25, 2012
-
Measuring water pressure in an open tank
May 24, 2012
-
Question from a non-engineer: Pulley Systems
May 24, 2012
- More from Physics Forums - General Engineering
More news stories
SpotterRF debuts Radar Backpack Kit (w/ Video)
(Phys.org) -- SpotterRF has announced a special radar backpack kit designed to enhance situational awareness for soldiers on the ground. The company says its special radar is designed for warfighters as part ...
Probability of contamination from severe nuclear reactor accidents is higher than expected: study
Catastrophic nuclear accidents such as the core meltdowns in Chernobyl and Fukushima are more likely to happen than previously assumed. Based on the operating hours of all civil nuclear reactors and the number ...
Technology / Energy & Green Tech
May 22, 2012 |
3.7 / 5 (20) |
50
|
Delphi gasoline-injection engine technique rivals hybrid's edge
(Phys.org) -- Running a diesel like engine on gasoline is something Delphi is doing in notable fashion. They claim they are on to a promising way to enjoy an engine that gives the vehicle owner high efficiency ...
HyperSolar shows dirty water no barrier to power world
(Phys.org) -- The Santa Barbara, California, company, HyperSolar, is set to transparently share the ups and downs of its research experiences toward the companys ultimate vision, successfully producing ...
Tesla to launch electric sedan in US on June 22
Tesla Motors said Tuesday it would begin deliveries of "the world's first premium electric sedan" on June 22, slightly ahead of schedule.
Technology / Energy & Green Tech
May 22, 2012 |
4.5 / 5 (11) |
18
Dell tablet leak: 10.1-inch display, two-battery choice
(Phys.org) -- Headline after headline talks about vendors tablets in the wings as likely number-one contenders for the iPad. Such claims have justifiably been taken with a grain of salt, considering ...
Scientist: Evolution debate will soon be history
(AP) -- Richard Leakey predicts skepticism over evolution will soon be history. Not that the avowed atheist has any doubts himself.
SpaceX capsule has 'new car' smell, astronauts say (Update)
SpaceX's Dragon cargo vessel smells like a new car, said astronauts at the International Space Station after opening the hatches Saturday following the spacecraft's landmark mission to the orbiting lab.
Keep food safety in mind this memorial day weekend
(HealthDay) -- Picnics, parades and cookouts are as much a part of Memorial Day weekend as tributes to the United States' war veterans.
Thousands of shellfish found dead in Peru
Thousands of crustaceans were found dead off the coast of Lima following the mystery mass death of dolphins and pelicans, the Peruvian Navy said Friday.
Australia hails surprise super-telescope decision
Australia has hailed a surprise decision giving it a role in a radio telescope project aimed at revolutionising astronomy, vowing to draw on its decades of experience in space science.
Feb 28, 2011
Rank: 2.3 / 5 (8)
Virus writers need to be hunted down ...and killed.
Feb 28, 2011
Rank: 3.7 / 5 (7)
Feb 28, 2011
Rank: 3 / 5 (4)
Feb 28, 2011
Rank: 5 / 5 (5)
Yeah, because your computer is more important than someone else's life.
Feb 28, 2011
Rank: 5 / 5 (2)
Your hatred of Mac is misplaced because Apple DID NOT write os-x. OS-X is BSD modified. There will never be the same kind of free for all for viruses on BSD/Linux like there is for Windoze.
Feb 28, 2011
Rank: 3.2 / 5 (5)
Correct. No OS is immune - however Windows is like a house with no locks and just signs that say "We're secure!". BSD/Linux is like a house that "can be" locked very tight.
Still skeptical? Consider this: The default file mode for ALL windows files is "executable". That stupidity is pervasive in every feature of WIndows. More importantly, MS doesn't really care - they don't have to. Afterall they STILL allow web sites to invoke active X code that can modify system files. Still. after all these years. How much do you care when you continue to allow that?
Unfortunately, the price of security is knowledge and most consumers just want a toaster - and that's what windows is - a toaster. BSD/Linux takes effort and time to learn and secure. I for one am fine with that as that will make it less of a target for the bad guys.
Mar 01, 2011
Rank: 5 / 5 (3)
A quick scroll to the bottom of the original article confirms this "Fortunately our products can detect and remove Trojans like this, and for home use they're free! If you would like to install Sophos Anti-Virus for Mac Home Edition, click on the banner below."
Free to download, but not free to run. All antivirus software consumes your computer's hardware resources - disk, memory, processer time - you bought these things and are now allowing them to be used to "protect" yourself from the viruses that the anti-virus companies tell you about. In the most part as long as you are knowledgeable and careful - and certainly on Mac/Linux based systems - you won't be "infected".
Most (non rich) people wouldn't use their money to pay someone else to protect their home, they'd do it themselves via education and care and common sense, but they seem OK to pay others to protect their computer.
Mar 01, 2011
Rank: 3.8 / 5 (6)
Mar 01, 2011
Rank: not rated yet
The idea that Linux for instance does not present enough targets is not true. Most servers run Linux, and cracking servers would be much more profitable for the virus writer than a users desktop. Currently there are no known viruses infecting Linux in the wild.
I cannot comment on Windows 7 but previous versions of Windows were demonstrably wide open.
Mar 01, 2011
Rank: 2 / 5 (4)
Mar 01, 2011
Rank: 5 / 5 (2)
Linux doesn't use an extension handling subsystem.
You're talking about specifically manipulating the system by folling it with a file name. That is not a default "all files are executable". The term you would be looking for, on the windows side, would be modifiable.
Mar 01, 2011
Rank: 2.3 / 5 (3)
Yes yes BSD being a linux based OS is very secure, and it takes a lot more to find a hole in its security but there are plenty of viruses for Mac's most are exploits that have nothing to do with the OS ...but hey if you feel safe with a overpriced computer that locks you into not only propietary software but propritary hardware that is also overpriced because of its limited market ...have fun with it
Mar 01, 2011
Rank: 2.3 / 5 (3)
Mar 01, 2011
Rank: 1 / 5 (1)
Mar 01, 2011
Rank: not rated yet
if you are having trouble with linux get a user friendly version of linux susch as Ubuntu -- it is very much like windows in style and feel and they have done a lot to (excuse the expression) dumb it down a little. Linux is made for and used by CS, math, and pysics majors. It is our perfect platform. It really is not for everyone to use, becuase its basic tool set is for text and file manipulaiton that most people have no need for in there daily lives.
Cygwin is an excellent starting point if you need linux tools on your PC -- such as the grep command.
I highly recommed Ubuntu to the average lay person to start using linux -- and you are right, it has a steep learning curve - but since i have started using it more and more i find man pages very readable and straight to the point.
Mar 01, 2011
Rank: not rated yet
Mar 02, 2011
Rank: not rated yet
upload.wikimedia.org/wikipedia/commons/5/50/
Unix_history-simple.png .
Mar 02, 2011
Rank: not rated yet
[2] In the world of personal computers, pragmatism rules - not theory. Otherwise MS never would have become what is.
Mar 02, 2011
Rank: 3.5 / 5 (2)
1. the Majority of the worlds web servers and data servers are run on linux or unix based operating systems. That means the website you are viewing right now is most-probably running on a linux based OS.
2. The best way to get Credit card numbers, SSNs, and other profitable personal information is to acquire them from the servers as the data is stored there in large files. On people's personal computers there is often only 1 set of this data, where on a server it could be hundreds of millions of data sets.
The issue of security on linux has very very little to do with the raw numbers of people using the software. Every person on this site uses linux indirectly. I would also argue that data thieves would rather have the data located in PayPal's databases than the data from 10,000 individual computers.
Mar 02, 2011
Rank: not rated yet
Mar 04, 2011
Rank: not rated yet
to be clear I am stating that the Apple OS is not the most secure OS. In fact it programs are not always written in a secure manner.
My support : google the pawn to own contest or google Charlie Miller
CM basically gained root access on a Mac using Safari in about 8 seconds. Every year this contest goes on and Mac has been losing...
So far as far as browsing is concerned Windows 7 with IE8 or Chrome --with no Flash installed -- is considered the safest combo for browsing the web.
You don;t have to agree go check it out for yourself
Mar 04, 2011
Rank: not rated yet
Mar 04, 2011
Rank: not rated yet
Maybe I was a bit harsh and "4" would have been more appropriate.
Mar 06, 2011
Rank: 4 / 5 (1)