Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.sys.mac.apps > #8993 > unrolled thread

Flashback Infection Mechanism?

Started byFred Moore <fmoore@gcfn.org>
First post2012-04-06 12:16 -0400
Last post2012-04-07 23:48 -0400
Articles 5 on this page of 25 — 9 participants

Back to article view | Back to comp.sys.mac.apps


Contents

  Flashback Infection Mechanism? Fred Moore <fmoore@gcfn.org> - 2012-04-06 12:16 -0400
    Re: Flashback Infection Mechanism? dempson@actrix.gen.nz (David Empson) - 2012-04-07 12:28 +1200
      Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-06 18:54 -0700
        Re: Flashback Infection Mechanism? Ant <ant@zimage.comANT> - 2012-04-07 09:51 -0700
          Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-07 10:00 -0700
            Re: Flashback Infection Mechanism? *Hemidactylus* <ecphoric@hotmail.com> - 2012-04-07 23:47 -0400
      Re: Flashback Infection Mechanism? dorayme <dorayme@optusnet.com.au> - 2012-04-07 12:39 +1000
      Re: Flashback Infection Mechanism? Patty Winter <patty1@wintertime.com> - 2012-04-07 17:03 +0000
        Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-07 10:06 -0700
          Re: Flashback Infection Mechanism? Patty Winter <patty1@wintertime.com> - 2012-04-07 17:20 +0000
            Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-07 10:30 -0700
              Re: Flashback Infection Mechanism? Patty Winter <patty1@wintertime.com> - 2012-04-07 17:37 +0000
                Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-07 10:46 -0700
                  Re: Flashback Infection Mechanism? Patty Winter <patty1@wintertime.com> - 2012-04-07 18:02 +0000
                    Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-07 17:38 -0700
                    Re: Flashback Infection Mechanism? Paul Sture <paul@sture.ch> - 2012-04-08 13:30 +0200
                  Re: Flashback Infection Mechanism? Paul Sture <paul@sture.ch> - 2012-04-08 13:25 +0200
                Re: Flashback Infection Mechanism? *Hemidactylus* <ecphoric@hotmail.com> - 2012-04-08 00:02 -0400
              Re: Flashback Infection Mechanism? Fred Moore <fmoore@gcfn.org> - 2012-04-08 13:06 -0400
                Re: Flashback Infection Mechanism? Jolly Roger <jollyroger@pobox.com> - 2012-04-08 10:54 -0700
                Re: Flashback Infection Mechanism? Patty Winter <patty1@wintertime.com> - 2012-04-08 23:50 +0000
                  Re: Flashback Infection Mechanism? dempson@actrix.gen.nz (David Empson) - 2012-04-09 14:08 +1200
            Re: Flashback Infection Mechanism? Barry Margolin <barmar@alum.mit.edu> - 2012-04-07 13:58 -0400
            Re: Flashback Infection Mechanism? Paul Sture <paul@sture.ch> - 2012-04-08 13:22 +0200
        Re: Flashback Infection Mechanism? *Hemidactylus* <ecphoric@hotmail.com> - 2012-04-07 23:48 -0400

Page 2 of 2 — ← Prev page 1 [2]


#9093

FromPatty Winter <patty1@wintertime.com>
Date2012-04-08 23:50 +0000
Message-ID<4f822452$0$16156$742ec2ed@news.sonic.net>
In reply to#9081
In article <fmoore-1C12C3.13062108042012@news.eternal-september.org>,
Fred Moore  <fmoore@gcfn.org> wrote:
>
>For 10.6&7, I completely agree with you. However, there is a very large 
>installed base of 10.5, and even 10.4, users out there which Apple has 
>chosen to ignore. 

Was this vulnerability introduced in Java 1.6.0_29, or was it also 
present in versions before that? If the former, then folks using 
older versions of Java won't have a potential problem.


Patty

[toc] | [prev] | [next] | [standalone]


#9094

Fromdempson@actrix.gen.nz (David Empson)
Date2012-04-09 14:08 +1200
Message-ID<1kiae5l.16yzlxr1rsp7raN%dempson@actrix.gen.nz>
In reply to#9093
Patty Winter <patty1@wintertime.com> wrote:

> In article <fmoore-1C12C3.13062108042012@news.eternal-september.org>,
> Fred Moore  <fmoore@gcfn.org> wrote:
> >
> >For 10.6&7, I completely agree with you. However, there is a very large
> >installed base of 10.5, and even 10.4, users out there which Apple has
> >chosen to ignore. 
> 
> Was this vulnerability introduced in Java 1.6.0_29, or was it also 
> present in versions before that? If the former, then folks using 
> older versions of Java won't have a potential problem.

Here is the list of CVE ID numbers that Apple fixed by updating to Java
1.6.0_31:

CVE-2011-3563
CVE-2011-5035
CVE-2012-0497
CVE-2012-0498
CVE-2012-0499
CVE-2012-0500
CVE-2012-0501
CVE-2012-0502
CVE-2012-0503
CVE-2012-0505
CVE-2012-0506
CVE-2012-0507

This web site lets you look up detailed descriptions of each one, by
modifying the last part of the URL. Here is an example for the first
one:

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3563

"Unspecified vulnerability in the Java Runtime Environment (JRE)
component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and
earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows
remote attackers to affect confidentiality and availability via unknown
vectors related to Sound."

Apple introduced Java 1.4.2 in Mac OS X 10.3, so this particular
vulnerability will affect Mac OS X 10.3 or later. It is not clear
whether Java 1.4.1 or earlier had this issue (probably not tested), so
we can't tell whether Mac OS X 10.2 or earlier might be vulnerable as
well.

Some of the other CVE IDs only apply to later Java versions, which means
some of the vulnerabilities only apply to Mac OS X 10.5 and later on
Intel Macs (Java 6.0 or later), but many of them apply to Mac OS X 10.4
or later (Java 5.0 or later), and some apply to Mac OS X 10.3 or later
(Java 1.4.2 or later).

I haven't seen which specific vulnerability the current Flashback
variant is exploiting, but it would be reasonable to assume that a
revised version could make use of any known vulnerability, so anyone
running Mac OS X 10.5 or earlier with Java enabled in their web browser
is vulnerable.

-- 
David Empson
dempson@actrix.gen.nz

[toc] | [prev] | [next] | [standalone]


#9047

FromBarry Margolin <barmar@alum.mit.edu>
Date2012-04-07 13:58 -0400
Message-ID<barmar-B5F108.13581307042012@news.eternal-september.org>
In reply to#9042
In article <4f807765$0$16170$742ec2ed@news.sonic.net>,
 Patty Winter <patty1@wintertime.com> wrote:

> Then to actually check for an infection, they would have to run 
> the suggested command-line arguments in Terminal--which is going 
> to flummox many people right there.

MacFixit posted a link to a web-based app that checks your machine 
against a database of infected machines:

http://public.dev.drweb.com/april/

-- 
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***

[toc] | [prev] | [next] | [standalone]


#9072

FromPaul Sture <paul@sture.ch>
Date2012-04-08 13:22 +0200
Message-ID<009859-fm1.ln1@news.sture.ch>
In reply to#9042
On Sat, 07 Apr 2012 17:20:37 +0000, Patty Winter wrote:

> f I understand the situation correctly, in order to suspect that their
> computer has been compromised, someone would have to either remember
> seeing a request for an admin password at an unexpected time or have
> seen a news article about the malware.
> 
> Then to actually check for an infection, they would have to run the
> suggested command-line arguments in Terminal--which is going to flummox
> many people right there.
> 
> The screen shots that have been posted on tech websites will help people
> turn off Java to prevent future infections, but there could be plenty of
> people with infected computers now who don't realize it, right?

Since the virus makes contact with an outside site, something like Little 
Snitch sounds appropriate.  Though if you already have Little Snitch, 
Xcode or certain other products installed, the virus *in its present 
form* will delete itself:

<http://www.f-secure.com/v-descs/trojan-downloader_osx_flashback_i.shtml>

--- start quote ---
nstallation

On execution, the malware checks if the following path exists in the 
system:

    /Library/Little Snitch
    /Developer/Applications/Xcode.app/Contents/MacOS/Xcode
    /Applications/VirusBarrier X6.app
    /Applications/iAntiVirus/iAntiVirus.app
    /Applications/avast!.app
    /Applications/ClamXav.app
    /Applications/HTTPScoop.app
    /Applications/Packet Peeper.app

If any of these are found, the malware will skip the rest of its routine 
and proceed to delete itself.

--- end quote ---

-- 
Paul Sture

[toc] | [prev] | [next] | [standalone]


#9066

From*Hemidactylus* <ecphoric@hotmail.com>
Date2012-04-07 23:48 -0400
Message-ID<MoidneDiHMMClxzSnZ2dnUVZ_jWdnZ2d@giganews.com>
In reply to#9038
On 04/07/2012 01:03 PM, Patty Winter wrote:
> In article<1ki6kle.bnwbb4fn3aoyN%dempson@actrix.gen.nz>,
> David Empson<dempson@actrix.gen.nz>  wrote:
>>
>> What makes this Flashback trojan different to other recent trojan
>> incidents is that it doesn't require an admin password (but it does ask
>> for one - it gets installed in different ways depending on whether or
>> not you grant it admin privileges).
>
>  From what I've read, the trojan presents a request for your admin
> password. What does it do if you click Cancel instead of typing in
> your password and clicking OK?

I thought it was a driveby requiring no user input to get pwned.


-- 
*Hemidactylus*

[toc] | [prev] | [standalone]


Page 2 of 2 — ← Prev page 1 [2]

Back to top | Article view | comp.sys.mac.apps


csiph-web