Showing posts with label Mac. Show all posts
Showing posts with label Mac. Show all posts

June 20, 2008

ALERT: MAC OS-X New Exploits

Did you really think your precious Mac was immune? That you were exempt from the Warzone that is the interwebs? Well, unless you have the intelligence of a monkey, this alert doesn't apply. This requires you to actively allow the hacker access, however for easily manipulated clients- you may need to pay heed to this latest alert.

Security vendor SecureMac has discovered multiple variants of a Trojan capable of letting a hacker remotely commandeer a Mac computer.

The malicious code is being distributed from a hacker Web site, where there have been discussions on distributing the Trojan through iChat and LimeWire, said SecureMac, which has given the Trojan a "critical" security rating. The program can infect Mac OS X 10.4 and 10.5 machines.

A Trojan is a program that appears legitimate, but performs illicit activity when it is run, such as stealing passwords, making the system more vulnerable to future entry, or simply destroying programs or data on the hard disk. LimeWire is a popular peer-to-peer file-sharing program, and iChat is Apple's instant messaging client.

Besides offering a hacker remote access to the system, the Trojan discovered by SecureMac can transmit system and user passwords. Additionally, the application can log keystrokes, take pictures with the built-in camera on a Mac, take screenshots, and turn on file sharing.

The program takes advantage of a flaw within the Apple Remote Desktop Agent. The program avoids detection by opening ports in the firewall and turning off system logging.

The Trojan is distributed as AppleScript called Asthtv05 or as an application bundle called Astht_v06. The filed must be downloaded and opened in order to infect a machine.

Malicious code targeting the Mac isn't new. Apple in May released a patch for a serious vulnerability within its iCal calendar application. The flaw made it possible for an attacker to exploit the vulnerability by adding or modifying files on a CalDAV server. The code is distributed as an .ics calendar file in an e-mail attachment, or through a malicious Web site.

June 18, 2008

Is Windows the Problem?

Using virus and malware-laden software used to just be a bad for one's productivity. As it turns out, it can also be a bad idea for one's career.

Michael Fiola, formerly an investigator with the Massachusetts Department of Industrial Accidents, was charged with possession of child pornography. He lost his community's respect, many of his friends, and his family. His crime? He was given a Windows-based laptop that was riddled with vulnerabilities that were or became prey to malware.

An investigation showed he hadn't downloaded the pornography. His computer did:

When the DIA issued Fiola his Dell Latitude laptop in November 2006, it was so badly configured that it may well have already been hacked, said Tami Loehrs, a forensics investigator hired by Fiola's defense team. The Microsoft Systems Management Server software on the laptop was misconfigured and was not receiving critical software updates, and the laptop's Symantec antivirus software was either misconfigured or not working properly, she said.

"He was handed a ticking time bomb," she said.

In this case, it's called Windows. Or, more accurately, an IT department that inflicted a poorly implemented Windows environment on Mr. Fiola. Could this have happened with Linux or the Mac? Yes and maybe. Yes, because weak IT yields weak security. But maybe, because both of these Unix-based systems handle security much better than Windows traditionally has. But that's not really the point.

The real villain here, of course, is the pornography swine that would inflict themselves on unsuspecting users. There are enough losers out there interested in porn to not have to trick them into viewing it or distributing it.

We like to think of our computers as tools. In this case, however, it was Mr. Fiola that became the tool, however unwittingly.

This calls to mind just how critical it is to ensure our systems are secure. If, in fact, Linux or Mac are more secure from this sort of problem (a point that is debatable), then the "low cost" associated with Windows and ease of use must be balanced against the very real problems that can arise from using Windows (or, at least, older versions of Windows).

Did Microsoft create this problem for Mr. Fiola? No. If anything, it sounds like his IT department is to blame. But if it were me, I'd be asking for a Mac when joining a new company. With the Mac, my odds of having a Fiola-esque experience go down dramatically.

June 11, 2008

I am controlling your PC via Bluetooth.

Microsoft's June Patch Tuesday release included a critical fix affecting all Windows Vista and XP systems, which could allow attackers to wirelessly steal confidential information from laptops by exploiting a flaw in the Bluetooth stack.

The Bluetooth stack flaw, detailed in Microsoft bulletin CVE-2008-1453 and rated 'critical', could allow an attacker to take complete control of an affected system, install programs, alter data or create new accounts with full user rights.

The MS08-030 patch modifies the way the Bluetooth stack handles a large number of service description requests.

Microsoft recommends applying the patch immediately and security experts advise users to turn off Bluetooth features until the patch has been applied.

Matthew Aburn, director of security consultancy Halcyon, said the flaw was particularly dangerous because hardware manufacturers usually set the factory default for Bluetooth as 'active'.

"Hardware-wise, most ship with Bluetooth on by default. I'd definitely recommend that if you're not using Bluetooth, you should turn it off," Aburn told ZDNet.com.au.

Rob Pregnall, Symantec's senior manager of Technical Product Management for Endpoint Security in Asia Pacific and Japan, agreed. He said hardware manufacturers should do this to make those features easier to access.

"When I look at a freshly bought machine from a reputable manufacturer, the first thing I notice is that every bell and whistle is turned on. I see it across different hardware manufacturers, including Macs," he said.

"All the different communication technologies are generally activated, so I think it's a move by manufacturers to ensure that everything is turned on so that minimal effort is needed to use the capabilities that users were sold on," Pregnall said.

In a blog, Microsoft admits that although in most cases an attacker would need to be in close range to exploit the vulnerability, there are ways to increase that distance.

"The standard range of Bluetooth is in the order of metres, although an attacker could use specialised antennas to increase this," the blog said.

This was backed up by Halcyon's Aburn.

"People look at the standard specifications for Bluetooth range of connectivity, which says you need to be so many metres away but using a directional antenna, people can target you from much further away," he said.

This month's Patch Tuesday includes fixes for a drive-by download weakness in Internet Explorer, as well as flaws in affecting Microsoft's multimedia.

The critical vulnerability affecting Internet Explorer described in CVE-2008-1442 and CVE-2008-1544 only affects Windows XP and Vista systems. The MS08-031 cumulative patch fixes a couple of vulnerabilities, including one that could allow remote code execution if a user viewed a specially crafted web page using Internet Explorer and another which could allow information disclosure if a similarly configured page was viewed using the browser.

The DirectX flaws affects all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. This update addresses the vulnerability detailed in CVE-2008-0011 and CVE-2008-1444. Microsoft says the vulnerability "could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited either of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights."