[Log In ] [New Posts] []
Go Back   GotApex? Forums Forums > General Topics > Software, OS, and the Internet
User Name
Password

Reply
 
Thread Tools Search this Thread Display Modes
Old 04-09-2004, 04:58 AM   #1
ribitch
Rear Admiral Upper Half
 
ribitch's Avatar
 
Join Date: Sep 2001
Location: Michigan
Posts: 3,672
Send a message via AIM to ribitch
OS X got its first trojan

i guess its no longer a version. It attacks using an application embeded in a file that has a .mp3 extension. Get Info tells you the file is an Application, but the finder sees its an MP3 due to the .MP3 extension.

http://www.intego.com/news/pr40.html

Quote:
– Intego, the Macintosh security specialist, has just released updated virus definitions for Intego VirusBarrier to protect Mac users against the first Trojan horse that affects Mac OS X. This Trojan horse, MP3Concept (MP3Virus.Gen), exploits a weakness in Mac OS X where applications can appear to be other types of files.


The Trojan horse's code is encapsulated in the ID3 tag of an MP3 (digital music) file. This code is in reality a hidden application that can run on any Macintosh computer running Mac OS X.


Mac OS X displays the icon of the MP3 file, with an .mp3 extension, rather than showing the file as an application, leading users to believe that they can double-click the file to listen to it. But double clicking the file launches the hidden code, which can damage or delete files on computers running Mac OS X, then iTunes to play the music contained in the file, to make users think that it is really an MP3 file . While the first versions of this Trojan horse that Intego has isolated are benign, this technique opens the door to more serious risks.



This Trojan horse has the potential to do any of the following:
- Delete all of a user's personal files
- Send an e-mail message containing a copy of itself to other users
- Infect other MP3, JPEG, GIF or QuickTime files


Due to the use of this technique, users can no longer safely double-click MP3 files in Mac OS X. This same technique could be used with JPEG and GIF files, though no such cases of infected graphic files have yet been seen.


Intego VirusBarrier eradicates this Trojan horse, and Intego remains diligent to ensure that VirusBarrier will also eradicate any future viruses that may try to exploit this same technique. All Intego VirusBarrier users should make sure that their virus definitions are up to date by using the NetUpdate preference pane in the Mac OS X System Preferences.

Should be a easy fix because the OS already reports that the file is an Application. From what I understand, it requires resource data it retain its viral stealth. Transferring with any popular file swapping program to my knowledge doesnt send this data.

1 virus in over 3 years. I am impressed. How many did widows have in that timespan?
ribitch is offline   Reply With Quote
Old 04-09-2004, 06:00 AM   #2
gear02
Admiral
 
gear02's Avatar
 
Join Date: Apr 2000
Location: Seattle, WA
Posts: 7,223
Send a message via ICQ to gear02 Send a message via AIM to gear02 Send a message via Yahoo to gear02
awww....how cute! It finally becomes a man. I hope the girl was nice and the experience wasn't very awkward, cause you know those pharmacy checkout people can be sooo intimidating...

oh wait, you mean a trojan VIRUS. Oh ok...
gear02 is offline   Reply With Quote
Old 04-09-2004, 08:34 AM   #3
g222leav
Rear Admiral Lower Half
 
g222leav's Avatar
 
Join Date: Dec 2000
Location: halfway between lost and found
Posts: 2,948
Send a message via AIM to g222leav Send a message via Yahoo to g222leav
Quote:
Originally Posted by gear02
awww....how cute! It finally becomes a man. I hope the girl was nice and the experience wasn't very awkward, cause you know those pharmacy checkout people can be sooo intimidating...

oh wait, you mean a trojan VIRUS. Oh ok...


you know, i work in a pharmacy, and i check out people for condoms all the time (i guess that's why there placed there so that embarressed people can check out right away)...but i applaud them for their efforts. a less venerial infected and baby producing society is the way to go! it's sort of humorous though, those guys that come up all geeked up that they're gonna get some...
__________________


"it's more fun than it looks" - Red Foreman
"trying is the first step in failing" - Homer J. Simpson
"the world needs more dumb people...dumb people can't start wars" - mike lam
g222leav is offline   Reply With Quote
Old 04-09-2004, 08:45 AM   #4
gear02
Admiral
 
gear02's Avatar
 
Join Date: Apr 2000
Location: Seattle, WA
Posts: 7,223
Send a message via ICQ to gear02 Send a message via AIM to gear02 Send a message via Yahoo to gear02
Quote:
Originally Posted by g222leav
you know, i work in a pharmacy, and i check out people for condoms all the time (i guess that's why there placed there so that embarressed people can check out right away)...but i applaud them for their efforts. a less venerial infected and baby producing society is the way to go! it's sort of humorous though, those guys that come up all geeked up that they're gonna get some...

I was just making a joke...but I guess I didn't do a good job...
gear02 is offline   Reply With Quote
Old 04-09-2004, 08:55 AM   #5
bachviet
What's Da Pho*?
 
bachviet's Avatar
 
Join Date: Aug 2001
Location: SoCal (714)
Posts: 13,296
Send a message via ICQ to bachviet Send a message via AIM to bachviet
I didn't know the OS X is that mature and could use a condom.
__________________
Dell Dimension 9200 | Intel Core 2 Quad Q6600 (2.4GHz) | 4x1GB DDR2 | 256MB nVidia GeForce 8800GT

Dell Studio 17 | Intel Core i7-720QM (1.6GHz) | 2x2GB DDR3 1066MHz | 1GHz ATI Mobility Radeon HD 4650

Intel P4-C 3.0GHz | ECS 865PE-A | 3x512MB PC3200 | 128MB PNY GeForce 6600GT

bachviet is offline   Reply With Quote
Old 04-09-2004, 08:56 AM   #6
g222leav
Rear Admiral Lower Half
 
g222leav's Avatar
 
Join Date: Dec 2000
Location: halfway between lost and found
Posts: 2,948
Send a message via AIM to g222leav Send a message via Yahoo to g222leav
Quote:
Originally Posted by gear02
I was just making a joke...but I guess I didn't do a good job...


oh no, i got the joke, i was just making a side comment is all...no offense...
g222leav is offline   Reply With Quote
Old 04-10-2004, 03:19 AM   #7
verve247
Commander
 
verve247's Avatar
 
Join Date: Apr 2001
Location: San Francisco
Posts: 1,486
I chuckled.
__________________
Vegetarian - Old indian word meaning poor hunter.
verve247 is offline   Reply With Quote
Old 04-11-2004, 10:06 PM   #8
DarkFury
Secretary of the Navy
 
DarkFury's Avatar
 
Join Date: Feb 2001
Location: Chillin' N Da 'Hood
Posts: 34,997
Wow...someone finally thought Apple users were worthy enough to write a virus for... geez.

Oh well... dayuum hackers/malicious code programmers!
__________________


DarkFury's Pimptopia - Don't Hate the Playa, Hate the Game!
Home of the Original OG Pimp (accept NO imitations)
DarkFury is offline   Reply With Quote
Old 04-20-2004, 06:47 PM   #9
dpp2k1
Ensign
 
Join Date: Jul 2002
Posts: 15
FYI: Not really a danger

Rest easy OS X users, it's just a POC "virus".

http://www.sophos.com/virusinfo/articles/macmp3.html
dpp2k1 is offline   Reply With Quote
Old 04-22-2004, 01:57 AM   #10
spigidygak
Admiral
 
spigidygak's Avatar
 
Join Date: May 2000
Location: Redlands & San Diego, CA.
Posts: 5,882
Send a message via ICQ to spigidygak Send a message via AIM to spigidygak Send a message via MSN to spigidygak Send a message via Yahoo to spigidygak
Personally I think it was just a marketting ploy for intego to get a bigger name. They've been a real small shareware company and looks like they're trying to step it up a notch by getting some recognition. Found it more amusing since they have a av program but isn't as great as virex from mcafee. Haven't been following up closely with this story but I don't remember seeing a statement from mcafee yet and find that odd if this was really a threat like intego first tried to make it seem.
__________________
spigidygak is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -7. The time now is 01:53 PM.