Showing posts with label mac. Show all posts
Showing posts with label mac. Show all posts

Saturday, September 26, 2009

Hackers Paid to Hijack Macs


A network of Russian malware writers and spammers paid hackers 43 cents for each Mac machine they infected with bogus video software, a sign that Macs have become attack targets, a security researcher said yesterday.

In a presentation last week at the Virus Bulletin 2009 security conference in Geneva, Switzerland, Sophos researcher Dmitry Samosseiko discussed his investigation of the Russian "Partnerka," a tangled collection of Web affiliates who rake in hundreds of thousands of dollars from spam and malware, most of the former related to phony drug sites, and much of the latter targeting Windows users with fake security software, or "scareware."

But Samosseiko also said he had uncovered affiliates, which he dubbed "codec-partnerka," that aim for Macs. "Mac users are not immune to the scareware threat," said Samosseiko in the research paper he released at the conference to accompany his presentation. "In fact, there are 'codec-partnerka' dedicated to the sale and promotion of fake Mac software."

One example, which has since gone offline, was Mac-codec.com , said Samosseiko. "Just a few months ago it was offering [43 cents] for each install and offered various promo materials in the form of Mac OS 'video players,'" he said.

Another Sophos researcher argued that Samosseiko's evidence shows Mac users, who often dismiss security as a problem only for people running Microsoft's Windows, are increasingly at risk on the Web.

"The growing evidence of financially-motivated criminals looking at Apple Macs as well as Windows as a market for their activities, is not good news -- especially as so many Mac users currently have no anti-malware protection in place at all," said Graham Cluley , a senior technology consultant at U.K-based Sophos, in a blog entry Thursday.

Mac threats may be rare, but they do pop up from time to time. In June 2008, for example, Mac security vendor Intego warned of an active Trojan horse that exploited a vulnerability in Apple's Mac OS X. Last January, a different Trojan was found piggybacking on pirated copies of Apple's iWork '09 application suite circulating on file-sharing sites.

Mac OS X's security has been roundly criticized by vulnerability researchers , but even the most critical have acknowledged that the Mac's low market share -- it accounted for just 5% of all operating systems running machines that connected to the Internet last month -- is probably enough protection from cyber criminals for the moment.
PC World

Tuesday, September 22, 2009

MAC: Unsafe At Any [Connection] Speed


I was surprised and very concerned at the number of responses I received to my article regarding a Blended Hack Attack. The article was about how Hackers tricked people into going to a website to check to see if they had received a Parking Ticket.

Now, the creativity of combining a Social Engineering attack with a fake website is amazing but what really got me going were the number of people that think that using Apple’s Macintosh system is “protection” against an attack.

I also realized that when one can remember the evolution of a hardware platform from an 8-bit processor chip with a dual 8″ floppy storage system to the Mega Systems of today, that proves one thing. I’m getting old!

Instead of simply responding to SuperSonic Dog’s Comment, I have decided to publish a follow up article.

SuperSonic Dog reminded me that the Lack of Consumer Education is actually the greatest risk to computer security.

I am currently waiting for Steve Wozniak to verify the facts as I remember them. So please stay tuned for another post regarding Mac Hacks.

Kevin M. Nixon

Yes, A Mac Can Be Hacked and Infected Just Like PCs

Prior to January 1984, Apple had the Apple I, Apple II, and the Apple III. There were no hard drives; they ran on Dual 8″ Floppy disks. The Apple I and II were Command Line systems. No Mouse here. The motherboard contained a single MOS 6502 8-bit chip!

Steve Wozniak modified a version of BASIC and after using the booting with the floppy, the Boot Disk was removed and then the single application floppy was inserted into A: and the ONLY Commercially Off The Shelf application was Visicalc. Apple II improved speed by using the memory in the CRT device. When the Apple III was released it came with Visicalc pre-burned on the chip.

Then the world changed on January 22, 1984, during the 3rd quarter of Super Bowl XVIII, when Apple unveiled the Macintosh 128K. This was the first MAC. Up till then the devices were all named Apple.

Two days after the 1984 ad aired, the Macintosh went on sale. It came bundled with two applications designed to show off its interface: MacWrite and MacPaint.

See Timeline of Mac Models

Apple is a vertically integrated product, meaning that Apple controls every aspect of the product including the operating system. The OSX operating system will only work on Apple computers.

Despite the $1.5 Million spent on the Super Bowl Ad plus an additional $2.5 Million spent for a 39 page advertising brochure in Newsweek, Apple continued to struggle, due to various problems, such as lack of OS compatible application software, the monochrome-only display and the closed architecture.

Apple eventually gained success as a result of its introduction of desktop publishing (and later computer animation) through Apple’s partnership with Adobe Systems, which introduced the laser printer and Adobe PageMaker. Indeed, the Macintosh would become known as the de-facto platform for many industries including cinema, music, publishing and the arts.

Apple did briefly license some of its own application designs, but Apple did not allow other computer makers to “clone” the Mac until the 1990s, long after Microsoft dominated the marketplace with its broad licensing program.

By then, it was too late for Apple to reclaim its lost market share.

At the 1997 Macworld Expo, Steve Jobs announced that Apple would be entering into partnership with Microsoft. Included in this was a five-year commitment from Microsoft to release Microsoft Office for Macintosh as well a US$150 million investment in Apple. It was also announced that Internet Explorer would be shipped as the default browser on the Macintosh.

Today, a modern Mac can boot on a Windows operating system with the boot camp utility, which lets you chose between OSX and Windows when starting the computer.

A PC is a generic architecture design of hardware that will allow a Linux or Windows operating system to boot.

PC manufacturers rely on OEM software, and do not vertically integrate their products.

As a result of the interoperability of PC architecture, PC’s have around 95% market share. This is good news for the availability of software, and bad news for the availability of viruses.

Mac Hacked In Under 2 Minutes

Within 2 minutes of directing a MAC to a Web site that contained exploit code, the computer was under the hacker’s control.

The hacker (Charlie Miller) was given a $10,000 cash prize AND was quickly given a nondisclosure agreement to sign, and he’s not allowed to discuss particulars of his bug with anyone but Apple.

The Contest rules stated that the hacker could only take advantage of software that was preinstalled on the Mac, so the flaw he exploited must have been accessible by, or possibly inside, Apple’s Safari browser.

So is an Apple Mac immune to Hacks, Worms or a Virus? NO!

Every Mac owner needs to be just as concerned as a PC owner.

If a Mac was not able to be hacked or infected, why would the Apple Support Website publish Security Update Patches? Mac owners should review the following pages at Apple support to update and patch, just like 95% of all computer owners!

BX Business Week

Saturday, August 29, 2009

Snow Leopard Malware Protection a Growing Pain for Mac OS X

Mac users have long relished the fact that malware is nearly a foreign concept to them. Yet, in a tacit acknowledgment of the growing threat of malware on the Mac platform, Apple has added some rudimentary malware protection into Snow Leopard.
Malware is a virtually constant plague for Windows users and an entire industry has been built around protecting the Windows operating system from viruses, worms, Trojans, and other malware threats. Microsoft-bashers claim it's a function of poor design and insecure coding by Microsoft, but security experts have also debated whether or not it is more a function of the virtual monopoly Windows has enjoyed as a desktop operating system.

Apple demonstrated an increased concern for malware on the Mac OS X operating system by including malware detection as one of the many updates in Snow Leopard. It seems that Apple realizes that the size of the bullseye painted on the operating system is in direct proportion to the number of systems using the operating system.

It makes sense. Arguments of superior design and security aside, malware is a business. If you were designing a wonder-widget, would you want to target it at a broad audience of millions around the world, or build your wonder-widgets for a small niche audience? Similarly, if you are trying to maximize the profit potential of your malware, would you write a virus that targets millions of Windows systems around the world, or invest your time exploiting holes in the relatively niche Mac OS X operating system?

Well, now that niche is hitting the mainstream. Redmond doesn't need to be too paranoid about Snow Leopard taking over the desktop market any time soon, but the fact of the matter is that the operating system has matured and Snow Leopard in particular introduces a number of updates and features that make it more viable for both consumers and businesses.

Hopefully Apple's newfound malware concern is misguided though since the malware detection in Snow Leopard offers nothing to actually block or remove any threats. Essentially, the antimalware feature in Snow Leopard is simply a modification of the Mac OS X File Quarantine feature. It takes the File Quarantine process one step farther by comparing files against a database of known threats to notify the user that the file may be malware.

Should a user ignore the warnings, or if a threat comes through that is not recognized as a known threat in the database, Snow Leopard could still become compromised by the malware. To actually scan and clean Snow Leopard systems users will have to look into third-party malware protection tools.
PC World

Wednesday, August 26, 2009

Report: Snow Leopard To Confront Mac Malware

Adding anti-malware to Snow Leopard is a Catch-22 for Apple: In solving a problem, Apple must first admit a problem actually exists. Which is hard when one of your major selling points is that you're secure and your major competitor--Microsoft Windows--is not.

Security vendor Intego made the apparent discovery of anti-malware features in Snow Leopard, evidence of which is being shown on its Web site. Apple has neither confirmed or denied the report.

If there really is anti-malware in Snow Leopard, due for release on Friday, it would be helpful for Apple to fess-up now. It would improve first-day sales, which might help Apple forget the bitter taste of crow, which Microsoft will presumably serve up.

There seems to be no compelling reason for Apple to add the feature right now. The world is not suffering a pandemic of Apple malware. Rather, most Mac users continue to run their systems without any type of protection.

Nevertheless, adding the protection, if that is what Apple has really done, is a good idea. If it is a good anti-malware solution and offers all the protection a user needs, it will make Snow Leopard a good deal and worth the expense.

Having just yesterday complained that even at $10 (in a 5-user package) the Snow Leopard upgrade might cost more than its worth, I am ready to change my mind. I'd happily pay a good bit more than $10 to have Apple solve all my malware troubles, even the ones I don't yet have.

It is clear that, over time, Macintosh will become a more frequent malware target. Apple's free ride is going to come to an end. It is wise for Apple to deal with the future challenge itself, though a free upgrade would reach many more users more quickly than Snow Leopard will following its release this Friday.

But, since there is no hurry and the feature presumably costs money (and certainly adds value) an inexpensive paid upgrade makes sense.

PC World