Finally, evidence that people are starting to care about Apple computers

bobdoering

Stop X-bar/R Madness!!
Trusted Information Resource
New Mac malware epidemic exploits weaknesses in Apple ecosystem

Looks like "overgrown cell phones that don't make calls" (iPads) have finally pushed Apple into the forefront of popularity - as illustrated here:

For Mac owners, the nightmare scenario finally arrived. A piece of malware called Flashback, which has been in existence and steadily evolving for at least seven months, has infected more than 600,000 Macs worldwide, based on forensic analysis by a Russian antivirus company.

What makes this outbreak especially chilling is that the owners of infected Macs didn’t have to fall for social engineering, give away their administrative password, or do something stupid. All they had to do was visit a web page using a Mac that had a current version of Java installed.


Java has always been a treat.

The best point:

A gain of a few percentage points in the Mac market might not seem like a lot, but in a universe with a billion Internet-connected devices, each percentage point equals a potential 10 million victims. A market with 60 million, 80 million, or even a hundred million Mac users is big enough for the bad guys.

Upcoming versions of crimeware kits will probably be cross-platform, with the capability to build and deliver Windows and OS X packages using as many vulnerabilities and social engineering tricks as possible. On every poisoned web page, visitors get sorted by OS: Windows users this way, OS X users over there. Each group gets its own custom, toxic blend. If all it takes is a tick of a check box, the gangs using these kits can jump into the Mac market literally overnight.

So now the question is when will that day come? This year? Next year?


Apparently, the time is now. Welcome to the red carpet.
 

Marc

Fully vaccinated are you?
Leader
To start out with, it has nothing to do with iPads and/or iPhones. It has to do with Macs running OS X with an unpatched Java exploit, and while it may install its self even if an admin password isn't given, it's obvious "Houston, there's a problem" when that requester box comes up (and it shows that even though a password hasn't been entered the trojan is being installed right in the admin password requester box).

Big headline from a small Russian company. No doubt there are compromised Macs, but doubtful 600K.

There have been Mac trojans before. The main thing it's relatively fast and easy to clean up if one does end up with a compromised Mac. No registry to have to fool around with or anything. Not to mention, it checks for virus programs and other programs like "Little Snitch" (which I've used for many years), MS Office and several other rather common programs. If any of them are found, the trojan deletes its self.

It's like Apple getting skewered over the Foxconn stuff. Big news, but no one seems to mention Foxconn makes stuff for many, many brands of electronics including, but not limited to.
Acer Inc. (Taiwan)
Amazon.com (United States)
Cisco (United States)
Dell (United States)
Hewlett-Packard (United States)
Intel (United States)
Microsoft (United States)
Motorola Mobility (United States)
Nintendo (Japan)
Nokia (Finland)[38]
Samsung Electronics (South Korea)
Sony (Japan)
Toshiba (Japan)
Vizio (United States)

Yet - Only Apple is in the news.

In the last 10 years, find any significant Mac "infection". Google it.

I've been hearing the same story for so many years ("You just wait!") as Windows machines toppled like dominos, that it get's old.

Don't take me wrong. There is *NO* OS which is bullet proof. I run too many different OSes on different computers that I know that. But this isn't what the headlines would have you believe.

As a last thought, I know a lot of people complain about Apple's "walled garden" for the iPhone and iPad (and Mac OS X is going that way). Personally, I say bring it on. The majority of computer users don't need all the stuff someone like me needs. In fact computer sales are flat. Tablets are the future for most people. That's not to say something malicious can't get through, over, or under the wall (the Apple "app" store), but they do a pretty good job of screening apps.
 

Marc

Fully vaccinated are you?
Leader
Update: I have been screening the web and so far there is no collaboration on the number of infected Macs. This is turning into a farce. Yes, the exploit is (Well, was - It's patched) real, but it comes down to only one company reporting *any* numbers, and so far I haven't seen even 1 report of someone actually having found it on their Mac.

Looking at their web site, the top ribbon says "Dr.WEB®" and then "20 years" below that, with no explanation of what the 20 years refers to. Then their company history page says, "December 22, 2003 - Foundation of Doctor Web, Ltd." yet the first product mentioned is version 4.30, released on August 13, 2003. There are no official company history entries earlier than 2003.

Yet below, in the footer, we get, "Doctor Web is a Russian IT-security solutions vendor. Dr.Web anti-virus software has been developed since 1992." Maybe the people behind it operated under a different name, but that certainly isn't reflected in the 'Company History Facts' page.

Going over to Company Profile we see, "Year development and marketing of Dr.Web Anti-virus began: 1992". Good luck finding any third-party corroboration of that claim. Their sole US 'partner' appears to be http://www.firelandscs.com/

So until someone other than Dr. Web® can verify these claims and figures, I'm filing this one under 'meh'.
 

Marc

Fully vaccinated are you?
Leader
Update: So far I have found <30 users on various web sites and Twitter claiming they were infected.
 

bobdoering

Stop X-bar/R Madness!!
Trusted Information Resource
Your research may be right, 5% of the market still isn't enough of a target for them to bother to toy with. Thought there might have been a glimmer of relevance of the product.
 

Marc

Fully vaccinated are you?
Leader
Please don't get me wrong. There *are* exploits out there, but there are for every OS. "Safe" computing should be practiced by everyone. This specific case, however, appears to be being blown way out of proportion. Lots of headlines but other than that... Hard to pin anything down.
 

Marc

Fully vaccinated are you?
Leader
Update:

In the third update to Java that Apple has released this week, the update now identifies and removes the most common variants of the Flashback malware that has infected over half a million Apple machines. 'This Java security update removes the most common variants of the Flashback malware,' Apple wrote in the support document for the update. 'This update also configures the Java web plug-in to disable the automatic execution of Java applets. Users may re-enable automatic execution of Java applets using the Java Preferences application. If the Java web plug-in detects that no applets have been run for an extended period of time it will again disable Java applets.'*

Go to your Mac's "Software Updates" (apple menu items on the far left) and get your update NOW! I have!

* Smart move.
 
Thread starter Similar threads Forum Replies Date
Marc Ancient Greek music: We finally know what it sounded like Coffee Break and Water Cooler Discussions 0
GStough Upgrade to ISO 9001:2008 - Finally! Covegratulations 15
P Can OpenOffice 3.0 finally replace MS Office? After Work and Weekend Discussion Topics 22
B Audit Week Is Finally Here Imported Legacy Blogs 2
antoine.dias ISO 9001:2008 finally released ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 2
SteelMaiden Finally! CE Mark capable in construction products CE Marking (Conformité Européene) / CB Scheme 37
K Toyota Finally Settles Sludge Lawsuit World News 9
B US Economy finally "fighting back"? World News 4
W Illegal XP copies finally cornered After Work and Weekend Discussion Topics 11
A Audit Day - Well, it's finally here. After all the kicking and scratching QS-9000 - American Automotive Manufacturers Standard 1
F Clause 7.4 Communication Compliance Evidence ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 5
D Contract Review Evidence/ Sample for API Monogram Licensing Oil and Gas Industry Standards and Regulations 9
G Clause 8.5.1 -- Is non Identification evidence of ineffective control of production ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 25
T Audit Objective Evidence Photos AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 7
S ISO 14001 Operational Planning and Control - Proving evidence of communicating environmental requirements to suppliers ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 3
P AS9100D clause 8.6 - Documentation required to show evidence of conformity AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 5
G What is considered good (and practical) evidence of supervision ISO 17025 related Discussions 4
R Evidence of compliance with Directive 2013/59/Euratom EU Medical Device Regulations 3
Q Documented Evidence of Training ISO 13485: 2016 ISO 13485:2016 - Medical Device Quality Management Systems 46
S Evidence of EUDAMED Registration ISO 13485:2016 - Medical Device Quality Management Systems 2
Ashland78 Need to show evidence in accordance with QR-11012 and SPB-00001-09 Customer and Company Specific Requirements 5
GStough Objective Evidence - Are Interviews Still Considered as Objective Evidence? General Auditing Discussions 15
I Software (SaMD) mobile application verification testing: objective evidence Medical Information Technology, Medical Software and Health Informatics 6
D What evidence do I need to supply as a remote location in relation to manufacturing sites? IATF 16949 - Automotive Quality Systems Standard 14
A 8.6 Release of products and services, 8.3 Design and development - evidence required ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 9
C Where to draw the line for "sufficient evidence" to verify safety/performance of a device? CE Marking (Conformité Européene) / CB Scheme 2
D Device functionality over service life - Objective evidence required? Design and Development of Products and Processes 10
C MDCG 2020-06 Clinical evidence legacy devices EU Medical Device Regulations 3
Mr Roo ISO 9001 - 7.1.3 Infrastructure - questions concerning evidence ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 33
M Informational Critical Thinking and the Process of Evidence-Based Practice Medical Device and FDA Regulations and Standards News 0
M Informational How to perform a clinical evaluation of medical devices – Part 2 – Level of clinical evidence and what sufficient clinical evidence means Medical Device and FDA Regulations and Standards News 9
M Informational US FDA paper – Epidemiological Evidence on the Adverse Health Effects Reports in Relation to Mercury from Dental Amalgam: Systematic Literature Review Medical Device and FDA Regulations and Standards News 0
S Level of Clinical Evidence - MDR EU Medical Device Regulations 3
qualprod Evidence of a talk or phone call in approvals? ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 8
H Clinical evidence for Class II medical devices in EU and US EU Medical Device Regulations 6
CPhelan Using clinical trial safety data for evidence for CE marking EU Medical Device Regulations 8
N Best practices for capturing audit objective evidence in a practical manner? Internal Auditing 3
M Informational Health Canada – Guidance Document: Supporting Evidence for Implantable Medical Devices Manufactured by 3D Printing Medical Device and FDA Regulations and Standards News 0
R Timeframe for IATF 16949 certification to accumulate evidence of conformance of systems? IATF 16949 - Automotive Quality Systems Standard 2
M Informational TGA – Q&A: Use of market authorisation evidence from comparable overseas regulatory bodies for medical devices Medical Device and FDA Regulations and Standards News 0
E ISO 9001:2015 Clause 10.2.2 - Evidence of all nonconformities and actions ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 9
R 8.1.3 Management of change - Evidence of HIRA and related things Occupational Health & Safety Management Standards 3
Q Evidence of precautions (clinical evaluation report, risk management report) EU Medical Device Regulations 6
S Ways to demonstrate objective evidence that employee is trained and competent ISO 13485:2016 - Medical Device Quality Management Systems 28
mikinnear Evidence - Class IIb Disinfectant Sanitiser EU Medical Device Regulations 2
G FAI Objective Evidence AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 3
R Interested parties requirements - Evidence of control ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 3
K Is evidence of second party audits required for every supplier? AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 2
J MDR and Creative Clinical Evidence Other ISO and International Standards and European Regulations 2
B IATF 16949 Cl. 9.2.2.1 - Internal audit program - Types of evidence Internal Auditing 1

Similar threads

Top Bottom