Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 25th, 2011, 10:07 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,451
Exclamation Hacker writes easy-to-use Mac Trojan

Quote:
IIn a sign that hackers, like everyone else, are taking an interest in everything Apple, researchers at Sophos say they've spotted a new Trojan horse program written for the Mac.

It's called the BlackHole RAT (the RAT part is for "remote access Trojan") and it's pretty easy to find online in hacking forums, according to Chet Wisniewski a researcher with antivirus vendor Sophos. There's even a YouTube video demonstration of the program that shows you what it can do.
Computerworld Article by Robert McMillan.
__________________
JR
"You don't have to win every argument. Agree to disagree." Regina Brett
  #2  
Old February 26th, 2011, 10:15 AM
twl845's Avatar
twl845 twl845 is offline
Massive Poster
 
Join Date: Apr 2005
Location: New York, USA
Posts: 3,331
Default Re: Hacker writes easy-to-use Mac Trojan

How does Sophos Free AV stack up against Intego AV for Mac? I am probably going to buy an iMac as soon as the new Lion OS comes out this Summer, and as a long time pc user, I don't buy Apple's claim that they don't get virus'. Maybe they don't..yet, but I'd rather be safe than sorry.
__________________
Now that I'm older, I seem to have more patience.
It turns out I just don't give a crap.

WIN 7 64x, Avast! PRO V8, Outpost FW Pro 8.x, MBAM Pro Real Time, Shadow Defender, Active@ Disk Image, Macrium Reflect Standard, AX64 Time Machine
  #3  
Old February 26th, 2011, 12:18 PM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: Hacker writes easy-to-use Mac Trojan

Quote:
Originally Posted by twl845
How does Sophos Free AV stack up against Intego AV for Mac? I am probably going to buy an iMac as soon as the new Lion OS comes out this Summer, and as a long time pc user, I don't buy Apple's claim that they don't get virus'. Maybe they don't..yet, but I'd rather be safe than sorry.

No need for AV software if you simply don't install the trojan. That article is quoting a researcher at Sophos, who has a financial interest in getting you to buy worthless AV products. Never listen to someone with something to sell when it comes to computer security.

AV has proven to be a failure even on Windows.
  #4  
Old February 26th, 2011, 12:33 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,457
Default Re: Hacker writes easy-to-use Mac Trojan

Quote:
Originally Posted by chronomatic
No need for AV software if you simply don't install the trojan. That article is quoting a researcher at Sophos, who has a financial interest in getting you to buy worthless AV products. Never listen to someone with something to sell when it comes to computer security.

AV has proven to be a failure even on Windows.

Regardless AVs being necessary or not (and I guess that depends on what users have on their hands - both O.S knowledge and knowledge on how to operate other tools), Sophos provides a free AV for the Mac.
  #5  
Old February 26th, 2011, 02:28 PM
Someheresomethere Someheresomethere is offline
Regular Poster
 
Join Date: Feb 2011
Posts: 71
Default Re: Hacker writes easy-to-use Mac Trojan

With Sophos I did notice somewhat of an impact on my Mac's performance. I like ESET and Intego better, but you should try them out yourself to judge. Intego has the most experience, and a built in firewall.
  #6  
Old February 26th, 2011, 02:55 PM
whitedragon551's Avatar
whitedragon551 whitedragon551 is offline
Very Frequent Poster
 
Join Date: Sep 2008
Location: USA
Posts: 2,760
Default Re: Hacker writes easy-to-use Mac Trojan

Quote:
Originally Posted by chronomatic
No need for AV software if you simply don't install the trojan. That article is quoting a researcher at Sophos, who has a financial interest in getting you to buy worthless AV products. Never listen to someone with something to sell when it comes to computer security.

AV has proven to be a failure even on Windows.

Security through obscurity is ignorant.
__________________
|Kaspersky Anti-Virus 2013|Private Firewall|HitmanPro|MBAM|Keriver Image|WinPatrol Plus|

Looking for volunteer authors to write articles, reviews, and How-Tos. If you think you have what it takes, contact me.
|http://pc-babble.com/|
  #7  
Old February 26th, 2011, 06:06 PM
twl845's Avatar
twl845 twl845 is offline
Massive Poster
 
Join Date: Apr 2005
Location: New York, USA
Posts: 3,331
Default Re: Hacker writes easy-to-use Mac Trojan

Quote:
Originally Posted by chronomatic
No need for AV software if you simply don't install the trojan.
What if you don't recognize the item as a trojan when it's presented to you?
__________________
Now that I'm older, I seem to have more patience.
It turns out I just don't give a crap.

WIN 7 64x, Avast! PRO V8, Outpost FW Pro 8.x, MBAM Pro Real Time, Shadow Defender, Active@ Disk Image, Macrium Reflect Standard, AX64 Time Machine
  #8  
Old February 27th, 2011, 10:43 AM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: Hacker writes easy-to-use Mac Trojan

Quote:
Originally Posted by whitedragon551
Security through obscurity is ignorant.

Explain where I mentioned security through obscurity and what it has to do with this.

Quote:
Originally Posted by twl845
What if you don't recognize the item as a trojan when it's presented to you?

Don't install untrusted software. This means don't go torrenting for software and don't search random websites. This means only install software from reputable sources (doesn't Apple have their own software repository?).
  #9  
Old February 27th, 2011, 10:57 AM
twl845's Avatar
twl845 twl845 is offline
Massive Poster
 
Join Date: Apr 2005
Location: New York, USA
Posts: 3,331
Default Re: Hacker writes easy-to-use Mac Trojan

Quote:
Originally Posted by chronomatic
Explain where I mentioned security through obscurity and what it has to do with this.



Don't install untrusted software. This means don't go torrenting for software and don't search random websites. This means only install software from reputable sources (doesn't Apple have their own software repository?).
Right, Apple has their own brand software, and there are quite a few non-Apple companies that accept Mac. What is a random website? If you are doing a search for instance, what makes you avoid a link to what you're looking for?
__________________
Now that I'm older, I seem to have more patience.
It turns out I just don't give a crap.

WIN 7 64x, Avast! PRO V8, Outpost FW Pro 8.x, MBAM Pro Real Time, Shadow Defender, Active@ Disk Image, Macrium Reflect Standard, AX64 Time Machine
  #10  
Old February 27th, 2011, 11:20 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,457
Default Re: Hacker writes easy-to-use Mac Trojan

Here's a perfect example of what a reputable source is: -http://www.eweek.com/c/a/Security/Kasperskys-Download-Site-Hacked-Directs-Users-to-Fake-AntiVirus-336193/
  #11  
Old February 27th, 2011, 12:34 PM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: Hacker writes easy-to-use Mac Trojan

Quote:
Originally Posted by m00nbl00d
Here's a perfect example of what a reputable source is: -http://www.eweek.com/c/a/Security/Kasperskys-Download-Site-Hacked-Directs-Users-to-Fake-AntiVirus-336193/

That's pretty humorous. But it goes to show how important the digitally signing of files are. Such a "redirect" could have been made moot if people checked sigs on the files they download (of course it helps if developers actually sign their software).
  #12  
Old February 27th, 2011, 12:50 PM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,998
Default Re: Hacker writes easy-to-use Mac Trojan

You forgot the part where you may have to pay before you download the software in the first place. Services such as ClearCloud and SmartScreen would protect you from viewing the page itself.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #13  
Old February 27th, 2011, 02:18 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,457
Default Re: Hacker writes easy-to-use Mac Trojan

Quote:
Originally Posted by funkydude
You forgot the part where you may have to pay before you download the software in the first place. Services such as ClearCloud and SmartScreen would protect you from viewing the page itself.

I actually gave an example not so long ago regarding a fake Malwarebytes Anti-Malware. People first would need to go through a phishing scam, and then download the supposed to be Malwarebytes Anti-Malware application and even more rogue crap, once they paid all that.

The UI was the real one actually; the one in the phishing website, that is. After I provided this, it was taken down by Malwarebytes team. Just a drop in the ocean, though.

People also forget about malware using stolen digital signatures. A digital signature by no means is a sign that an application is trustworthy. I may be wrong, though.
  #14  
Old February 27th, 2011, 09:10 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,457
Default Re: Hacker writes easy-to-use Mac Trojan

Quote:
Originally Posted by chronomatic
That's pretty humorous. But it goes to show how important the digitally signing of files are. Such a "redirect" could have been made moot if people checked sigs on the files they download (of course it helps if developers actually sign their software).

Not that humorous. I'd say that humorous is the fact Kaspersky got hacked more than once. I guess they were caught unguarded.
  #15  
Old February 27th, 2011, 09:34 PM
J_L's Avatar
J_L J_L is online now
Massive Poster
 
Join Date: Nov 2009
Posts: 4,833
Default Re: Hacker writes easy-to-use Mac Trojan

If you're connected to the internet or any other devices, there's always danger lurking somewhere. Doesn't matter which OS you run.
__________________
  #16  
Old February 27th, 2011, 10:24 PM
twl845's Avatar
twl845 twl845 is offline
Massive Poster
 
Join Date: Apr 2005
Location: New York, USA
Posts: 3,331
Default Re: Hacker writes easy-to-use Mac Trojan

Quote:
Originally Posted by J_L
If you're connected to the internet or any other devices, there's always danger lurking somewhere. Doesn't matter which OS you run.
Exactly. So it might be a good idea to use an AV in your Apple OS. It's like having flood insurance a mile from the river.
__________________
Now that I'm older, I seem to have more patience.
It turns out I just don't give a crap.

WIN 7 64x, Avast! PRO V8, Outpost FW Pro 8.x, MBAM Pro Real Time, Shadow Defender, Active@ Disk Image, Macrium Reflect Standard, AX64 Time Machine
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:13 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums