Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.sys.mac.apps > #8993 > unrolled thread
| Started by | Fred Moore <fmoore@gcfn.org> |
|---|---|
| First post | 2012-04-06 12:16 -0400 |
| Last post | 2012-04-07 23:48 -0400 |
| Articles | 5 on this page of 25 — 9 participants |
Back to article view | Back to comp.sys.mac.apps
Flashback Infection Mechanism? Fred Moore <fmoore@gcfn.org> - 2012-04-06 12:16 -0400
Re: Flashback Infection Mechanism? dempson@actrix.gen.nz (David Empson) - 2012-04-07 12:28 +1200
Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-06 18:54 -0700
Re: Flashback Infection Mechanism? Ant <ant@zimage.comANT> - 2012-04-07 09:51 -0700
Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-07 10:00 -0700
Re: Flashback Infection Mechanism? *Hemidactylus* <ecphoric@hotmail.com> - 2012-04-07 23:47 -0400
Re: Flashback Infection Mechanism? dorayme <dorayme@optusnet.com.au> - 2012-04-07 12:39 +1000
Re: Flashback Infection Mechanism? Patty Winter <patty1@wintertime.com> - 2012-04-07 17:03 +0000
Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-07 10:06 -0700
Re: Flashback Infection Mechanism? Patty Winter <patty1@wintertime.com> - 2012-04-07 17:20 +0000
Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-07 10:30 -0700
Re: Flashback Infection Mechanism? Patty Winter <patty1@wintertime.com> - 2012-04-07 17:37 +0000
Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-07 10:46 -0700
Re: Flashback Infection Mechanism? Patty Winter <patty1@wintertime.com> - 2012-04-07 18:02 +0000
Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-07 17:38 -0700
Re: Flashback Infection Mechanism? Paul Sture <paul@sture.ch> - 2012-04-08 13:30 +0200
Re: Flashback Infection Mechanism? Paul Sture <paul@sture.ch> - 2012-04-08 13:25 +0200
Re: Flashback Infection Mechanism? *Hemidactylus* <ecphoric@hotmail.com> - 2012-04-08 00:02 -0400
Re: Flashback Infection Mechanism? Fred Moore <fmoore@gcfn.org> - 2012-04-08 13:06 -0400
Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-08 10:54 -0700
Re: Flashback Infection Mechanism? Patty Winter <patty1@wintertime.com> - 2012-04-08 23:50 +0000
Re: Flashback Infection Mechanism? dempson@actrix.gen.nz (David Empson) - 2012-04-09 14:08 +1200
Re: Flashback Infection Mechanism? Barry Margolin <barmar@alum.mit.edu> - 2012-04-07 13:58 -0400
Re: Flashback Infection Mechanism? Paul Sture <paul@sture.ch> - 2012-04-08 13:22 +0200
Re: Flashback Infection Mechanism? *Hemidactylus* <ecphoric@hotmail.com> - 2012-04-07 23:48 -0400
Page 2 of 2 — ← Prev page 1 [2]
| From | Patty Winter <patty1@wintertime.com> |
|---|---|
| Date | 2012-04-08 23:50 +0000 |
| Message-ID | <4f822452$0$16156$742ec2ed@news.sonic.net> |
| In reply to | #9081 |
In article <fmoore-1C12C3.13062108042012@news.eternal-september.org>, Fred Moore <fmoore@gcfn.org> wrote: > >For 10.6&7, I completely agree with you. However, there is a very large >installed base of 10.5, and even 10.4, users out there which Apple has >chosen to ignore. Was this vulnerability introduced in Java 1.6.0_29, or was it also present in versions before that? If the former, then folks using older versions of Java won't have a potential problem. Patty
[toc] | [prev] | [next] | [standalone]
| From | dempson@actrix.gen.nz (David Empson) |
|---|---|
| Date | 2012-04-09 14:08 +1200 |
| Message-ID | <1kiae5l.16yzlxr1rsp7raN%dempson@actrix.gen.nz> |
| In reply to | #9093 |
Patty Winter <patty1@wintertime.com> wrote: > In article <fmoore-1C12C3.13062108042012@news.eternal-september.org>, > Fred Moore <fmoore@gcfn.org> wrote: > > > >For 10.6&7, I completely agree with you. However, there is a very large > >installed base of 10.5, and even 10.4, users out there which Apple has > >chosen to ignore. > > Was this vulnerability introduced in Java 1.6.0_29, or was it also > present in versions before that? If the former, then folks using > older versions of Java won't have a potential problem. Here is the list of CVE ID numbers that Apple fixed by updating to Java 1.6.0_31: CVE-2011-3563 CVE-2011-5035 CVE-2012-0497 CVE-2012-0498 CVE-2012-0499 CVE-2012-0500 CVE-2012-0501 CVE-2012-0502 CVE-2012-0503 CVE-2012-0505 CVE-2012-0506 CVE-2012-0507 This web site lets you look up detailed descriptions of each one, by modifying the last part of the URL. Here is an example for the first one: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3563 "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote attackers to affect confidentiality and availability via unknown vectors related to Sound." Apple introduced Java 1.4.2 in Mac OS X 10.3, so this particular vulnerability will affect Mac OS X 10.3 or later. It is not clear whether Java 1.4.1 or earlier had this issue (probably not tested), so we can't tell whether Mac OS X 10.2 or earlier might be vulnerable as well. Some of the other CVE IDs only apply to later Java versions, which means some of the vulnerabilities only apply to Mac OS X 10.5 and later on Intel Macs (Java 6.0 or later), but many of them apply to Mac OS X 10.4 or later (Java 5.0 or later), and some apply to Mac OS X 10.3 or later (Java 1.4.2 or later). I haven't seen which specific vulnerability the current Flashback variant is exploiting, but it would be reasonable to assume that a revised version could make use of any known vulnerability, so anyone running Mac OS X 10.5 or earlier with Java enabled in their web browser is vulnerable. -- David Empson dempson@actrix.gen.nz
[toc] | [prev] | [next] | [standalone]
| From | Barry Margolin <barmar@alum.mit.edu> |
|---|---|
| Date | 2012-04-07 13:58 -0400 |
| Message-ID | <barmar-B5F108.13581307042012@news.eternal-september.org> |
| In reply to | #9042 |
In article <4f807765$0$16170$742ec2ed@news.sonic.net>, Patty Winter <patty1@wintertime.com> wrote: > Then to actually check for an infection, they would have to run > the suggested command-line arguments in Terminal--which is going > to flummox many people right there. MacFixit posted a link to a web-based app that checks your machine against a database of infected machines: http://public.dev.drweb.com/april/ -- Barry Margolin, barmar@alum.mit.edu Arlington, MA *** PLEASE post questions in newsgroups, not directly to me ***
[toc] | [prev] | [next] | [standalone]
| From | Paul Sture <paul@sture.ch> |
|---|---|
| Date | 2012-04-08 13:22 +0200 |
| Message-ID | <009859-fm1.ln1@news.sture.ch> |
| In reply to | #9042 |
On Sat, 07 Apr 2012 17:20:37 +0000, Patty Winter wrote:
> f I understand the situation correctly, in order to suspect that their
> computer has been compromised, someone would have to either remember
> seeing a request for an admin password at an unexpected time or have
> seen a news article about the malware.
>
> Then to actually check for an infection, they would have to run the
> suggested command-line arguments in Terminal--which is going to flummox
> many people right there.
>
> The screen shots that have been posted on tech websites will help people
> turn off Java to prevent future infections, but there could be plenty of
> people with infected computers now who don't realize it, right?
Since the virus makes contact with an outside site, something like Little
Snitch sounds appropriate. Though if you already have Little Snitch,
Xcode or certain other products installed, the virus *in its present
form* will delete itself:
<http://www.f-secure.com/v-descs/trojan-downloader_osx_flashback_i.shtml>
--- start quote ---
nstallation
On execution, the malware checks if the following path exists in the
system:
/Library/Little Snitch
/Developer/Applications/Xcode.app/Contents/MacOS/Xcode
/Applications/VirusBarrier X6.app
/Applications/iAntiVirus/iAntiVirus.app
/Applications/avast!.app
/Applications/ClamXav.app
/Applications/HTTPScoop.app
/Applications/Packet Peeper.app
If any of these are found, the malware will skip the rest of its routine
and proceed to delete itself.
--- end quote ---
--
Paul Sture
[toc] | [prev] | [next] | [standalone]
| From | *Hemidactylus* <ecphoric@hotmail.com> |
|---|---|
| Date | 2012-04-07 23:48 -0400 |
| Message-ID | <MoidneDiHMMClxzSnZ2dnUVZ_jWdnZ2d@giganews.com> |
| In reply to | #9038 |
On 04/07/2012 01:03 PM, Patty Winter wrote: > In article<1ki6kle.bnwbb4fn3aoyN%dempson@actrix.gen.nz>, > David Empson<dempson@actrix.gen.nz> wrote: >> >> What makes this Flashback trojan different to other recent trojan >> incidents is that it doesn't require an admin password (but it does ask >> for one - it gets installed in different ways depending on whether or >> not you grant it admin privileges). > > From what I've read, the trojan presents a request for your admin > password. What does it do if you click Cancel instead of typing in > your password and clicking OK? I thought it was a driveby requiring no user input to get pwned. -- *Hemidactylus*
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | comp.sys.mac.apps
csiph-web