Wednesday, June 11, 2008

Mac Security Advise For Enterprise Users


One of the useful email lists I belong to is the 'Mac OS X enterprise deployment project.' You can join the list and view archives at:

http://lists.psu.edu/archives/macenterprise.html

In April I wrote up a quick article in response to someone's question about preventative maintenance for Mac OS X Server. Interest was expressed in my publishing the article formally on the Internet, so it is provided below. The information is a bit high end, directed specifically to enterprise users of Mac systems. But serious Mac security newbies will find a lot of useful references as well.


:-Derek

===============

From: Derek Currie
Date: April 15, 2008 10:57:25 PM EDT
To: Mac OS X enterprise deployment project
Subject: Re: Apple's guidelines for preventative maintenance for XServes and/or OS X Server.


On Apr 15, 2008, at 04/15, 4:19 PM, Rich Trouton wrote:
"Does anyone know if Apple has posted specifications or guidelines for preventative maintenance for XServes and/or OS X Server? We're doing our regular security re-certification, and one of the things we're being asked for is documentation of how we're doing routine and preventative maintenance "in accordance with manufacturer or vendor specifications and/or organizational requirements." Right now, we don't have organizational requirements, so I'm trying to find Apple's specifications and I'm not finding them. Tempting as it may be, I don't think our re-certification folks are going to accept "there aren't any specifications, so I guess I don't have to do anything" as an valid answer."


Actually, Apple do provide some relevant documentation. See #6 ahead. But first let me provide a long winded brain storm:


1) Detail your backup strategy. I consider making backups the #1 rule of computing and the first step in computer security. Apple provide TimeMachine in Leopard Server.

2) Talk about KeyChain for storing and protecting passwords. I also use 1Password, and excellent shareware program.

3) Discuss what encryption you are using to protect critical data. You can use FileVault or use encrypted disk images created in Disk Utility. (Personally I use an encrypted .sparseimage for storing my database of server clients and other critical odds and ends I would never want stolen). Leopard server offers 256 bit encryption. You shouldn't need anything stronger. As long as you use a ridiculously un-guessable password, theoretically it would take the length of the life of the universe to crack.


==============
Sideline Rant:

If you're not using encryption, start using it already. I know you know this, but for everyone else: Federal servers are now notorious for having been cracked by the Red Hacker Alliance in China, among others. If the data is seriously encrypted, they're wasting their time. Many businesses now demand encryption. Here is a blurb from the SANS Institute's security newsletter NewsBites Vol. 10 Num. 28 regarding some incredible ignorance at the NIH:

On Apr 8, 2008, at 04/08, 5:00 PM, The SANS Institute wrote:

-- NIH Workers May Not Store Sensitive Data on MacBooks
(April 4 & 7, 2008)

A National Institutes of Health (NIH) agency memo forbids employees from storing sensitive data on MacBook laptop computers. As of April 4, all NIH laptops running Windows or Linux operating systems must have the Pointsec encryption tool; Windows Vista users may also use that operating system's BitLocker disk encryption tool. There is presently a beta version of Pointsec for MacBooks, but not an approved version. The ban on MacBooks holding sensitive data applies to contractors as well as in-house employees.


http://www.informationweek.com/shared/printableArticle.jhtml?articleID=207001840
http://www.fcw.com/online/news/152173-1.html

[Editor's Note
(Schultz): As said so many previous times, nothing serves as a wake-up call for security as much as a serious security-related incident.
(Liston): Note: The issue here is the lack of an approved version of whole-disk encryption, not with OSX itself. Apple Fanboys: Return to standby. Nothing to see here-- you may safely return to caressing your MacBooks and iPhones.]


Obviously FileVault would be 'approved' if they bothered to notice it was there in Mac OS X.

(Also note that I pointed out Mr. Liston's lack of professionalism in an email I sent all over SANS. I got into a friendly back and forth with the President of SANS, a very nice fellow. He assured me of Mr. Liston's skills and privately told me that he pulls troll manoeuvres such as the above as a way of blowing off steam during a long boring day of security analysis, wink wink. Hopefully my efforts will shut the guy up in the future).
==============


4) Discuss the fact that Mac OS X uses the PDF document format as part of its foundation, and that any PDF can be locked such that only a user with its password can open it. Discuss how locked PDFs are used in the work environment.
http://docs.info.apple.com/article.html?path=Mac/10.5/en/8152.html

5) Discuss your implementation of PGP or GPG (the free Open Source version of PGP) in your work environment. Sources:
http://www.pgp.com/
http://www.gnupg.org/

6) Apple has some security documents relevant to Mac OS X Server:

a) Mac OS X Server - Security Configuration - For Version 10.4 or Later - Second Edition
http://manuals.info.apple.com/en/Tiger_Server_Security_Config_021507.pdf

- If an update is provided specific to Leopard Server, it will be posted on the Security Configuration Guides page:
http://www.apple.com/support/security/guides/

b) Mac OS X, Mac OS X Server: Protection for sensitive files when using Apache on an HFS+ volume
http://docs.info.apple.com/article.html?artnum=300422

c) Mac OS X: How to keep network computers secure
http://docs.info.apple.com/article.html?artnum=61534

d) Mac OS X Leopard - Features - Security
http://www.apple.com/macosx/features/300.html#security

7) Apple also offer their Security-Announce mailing list. You can get it via email or via RSS:
http://lists.apple.com/
http://lists.apple.com/mailman/listinfo/security-announce
feed://rss.lists.apple.com/security-announce.rss


----------------
Bonus Points:

1) Some nifty security statistics from March 2008 to quote in defense of Mac OS X's excellent security record:

http://www.insanely-great.com/news.php?id=8665
http://www.zone-h.org/content/view/14928/30/

An excerpt from the Zone-H Statistics Report 2005-2007, the number of registered computer attacks:

OS ________ | Year 2005 | Year 2006 | Year 2007
------------------------------------------------
MacOSX ________ 2.139 _____ 2.247 _____ 1.488
Windows 2003 _ 72.377 ___ 183.953 ___ 114.137

To quote M. Sharp from Insanely-Great Mac:
"Assuming that the Mac's server market share is growing—the most-recent data on Apple sales I could find (Q2 of last year) had unit volume up 78 percent—then the above figures indicate that attacks are declining absolutely even as the number of servers increases proportionately and absolutely."

2) Apple provide references to security related software from third-party vendors at their 'Macintosh Products Guide' pages:
http://guide.apple.com/

Examples:
a) Go to the Mac Software/Products and Utilities page. In the 'Sub-category' popup menu choose "Security" and hit the Search button. Today there are 135 security related apps listed.

b) Go to the Mac Software/Servers, Networking & Communications page. In the 'Sub-category' popup menu choose "Security" and hit the Search button. Today there are 20 related apps listed.

You could also search for software firewalls, hardware firewalls, etc.
----------------

That should get you going!

:-Derek

===================
Derek Currie
derekcurrie@mac.com.invalid
===================
http://Mac-Security.blogspot.com
http://MacSmarticles.blogspot.com
http://zunipus.blogspot.com
http://movies.groups.yahoo.com/group/dwaynecameronfanclub
http://groups.yahoo.com/group/ymorare

© 2008-04-15 Derek Gordon Currie

Wednesday, May 28, 2008

Mac OS X 10.5.3 IS HERE! So is Security Update 003 with 27 Security Patches! And, And, And...


At last, at last!
10.5.3 is HERE AT LAST!

I gave up counting bugs in 10.5.2 when I hit #35. I am crossing my fingers they are all stamped out with this ENORMOUS update. If you use Software Update from within Leopard, the client version of Mac OS X 10.5.3 Update is 420 MB! The server version is 496 MB! If you want the Combo versions, the client version is 536 MB! The Combo server version is 632 MB!

But just as eye-opening are the 27+ security patches (Twenty Seven +!) included in Security Update 2008-003. The PPC client version is 72 MB (Seventy Two!). The Intel client version is 111 MB (One Hundred And Eleven!). The PPC server version is 88.9 MB (Eighty Eight Point Nine Megabytes!). The Universal Binary server version is 118 MB (One Hundred And Eighteen!).

And I'm not finished yet! Pay attention!

Also new is the Digital Camera RAW Compatibility Update 2.1 at 2.4 MB.

AND the Logic Express Update version 8.0.2 at 73.5 MB.

AND Server Admin Tools 10.5.3 at 64.5 MB.

IOW: Get ready for a snoozer of a download marathon.

Now for the boring but useful part. Here are all the URLs where you can read about and download the update disk images, followed by a list of security patches. I dare you to read them all! Will you survive?

Mac OS X 10.5.3 Update
Mac OS X Server 10.5.3 Update

Mac OS X 10.5.3 Combo Update
Mac OS X Server 10.5.3 Combo Update

Security Update 2008-003 (PPC)
Security Update 2008-003 (Intel)

Security Update 2008-003 Server (PPC)
Security Update 2008-003 Server (Universal)

Server Admin Tools 10.5.3

Digital Camera RAW Compatibility Update 2.1

Logic Express Update 8.0.2

Here is a summary of the new Mac OS X security updates, published in the Secunia Weekly Summary - Issue: 2008-22, which you can read at the most excellent Secunia website.

Quoting:
___________

Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.

The vulnerabilities include:

- An error in AFP server

- Various vulnerabilities in Apache (for Mac OS X Server v10.4.x)

- An unspecified error in AppKit

- Multiple unspecified errors in the processing of Pixlet video files

- An unspecified error exists in Apple Type Services when processing embedded fonts in PDF files

- An error in Safari's SSL client certificate handling

- An integer overflow exists in CoreFoundation when handling CFData objects

- An error due to an uninitialised variable in CoreGraphics

- A weakness due to users not being warned before opening certain potentially unsafe content types

- An error when printing to password-protected printers with debug logging enabled

- Various vulnerabilities in Adobe Flash Player

- An integer underflow error in Help Viewer when handling help:topic URLs

- A conversion error exists in ICU when handling certain character encodings

- Unspecified parameters in Image Capture's embedded web server not being properly sanitised before use

- An error in the handling of temporary files in Image Capture

- A boundary error in the BMP and GIF image decoding engine in ImageIO

- Various vulnerabilities in ImageIO due to the use of vulnerable libpng code

- An integer overflow error in ImageIO within the processing of JPEG2000 images

- An error in Mail is caused due to an uninitialised variable

- A vulnerability in Mongrel

- A weakness in the sso_util command-line tool

- An error in Wiki Server

- A vulnerability in Apple iCal

- A vulnerability due to an error in the handling of return values of "hashes()" in the "cs_validate_page()" function when processing signed Mach-O binaries

- A vulnerability due to an error within the "ipcomp6_input()" function in bsd/netinet6/ipcomp_input.c when processing packets with an IPComp header
___________

And that's not the complete list!

In other Mac OS X security news, there remains only 1 (ONE) bona fide malware in the wild, the so-called 'Porno Trojan'. (BWAHAHAHA! I love that name). News has it that it has mutated, thanks to scurrilous Phishing scam entrepreneurs, into other manifestations at other websites. So be wary of all unverified, untrusted downloads, particularly those pretending to be 'video codecs' you are supposed to need to install to view a web video. If you think you are a victim you can obtain the FREE removal tool at the generous MacScan website:

DNSChanger Removal Tool

Remember that Microsoft Office macro viruses still abound. Please take precautions, such as using a safer office suite of applications. May I suggest NeoOffice, the freeware Open Source office suite that created the now international standard Open Doc format. Or alternatively consider Apple's elegant iWork suite including Pages, Keynote and Numbers.

You can read my evaluation of Leopard update 10.5.3 over at my other Macintosh blog, MacSmarticles.

Share and EnJoY!

:-Derek

Saturday, March 29, 2008

The VERY SCARY Second Mac OS X Malware Arrives: Troj/MacSwp-B




"MacSweeper"
from "Imunizator" sounds like slackerware right off the bat. In this case it is nasty spooky SCAREWARE! Run for your life, yawn, zzz.

This slackerware is actually a few weeks old, but since it was discovered by Sophos it has officially become 'malware'. The BIG question: What DAMAGE does this rubbish do to your Mac????

Nothing at all.

Thus I yawn.

So is this actually 'malware'? Well, it is in the sense that it takes advantage of the eternal 'wetware vulnerability' problem, damaging your personal sense of logic, scaring you into thinking you need to pay for this fraudulent crapware or your computer will meet a horrible doom. (And yes everyone, I was the one who invented the term 'crapware'. Seriously! I'm not kidding! - Well, actually a friend pointed out it is an obvious term that anyone could have created. So much for my creativity).

Then what does this thingy actually do? By definition this is SOCIAL ENGINEERING malware. It is a form of PHISHING. This particular method is very old, like well over a decade. Here is how it works:

1) You download the thing because it was offered at a nefarious website you shouldn't have visited. (NOTE: Instead you should have checked VersionTracker or MacUpdate to see if they had ever heard of it and consider it a worthwhile program, which they don't. Then you should have Googled its name to see if there are reports about its reputation).

2) You install and run it. (This is very naughty. Don't do this with anything you have not already verified to be legitimate, having a good reputation).

3) It pretends to scan your Mac's "Universal Binnaries". (Again: Slackerware much?)

4) It then lies to you and says you have privacy violations that require your attention or you'll suffer the consequences. And of course the only way to avoid this terrible fate is to pay for this crapware in order to activate its ability to fix the fake problems.

5) You pay for the crapware. You lose your identity. The crooks use your identity to buy lots of toys and stiff you with the bill. They then sell your identity to others and further stiffing behavior continues until you or your credit card company get the clue and stop payment, invalidating your card. And that's not fun, OK?

Do you need to buy anti-malware to protect you from Troj/MacSwp-B? NO. Clam will do nicely, thank you. Instead you should familiarize yourself with social engineering strategies. You can read about social engineering at:

Wikipedia

Here is the source report of Troj/MacSwp-B:

Sophos

You can read a snide evaluation of Troj/MacSwp-B at:

Mac-Daily News

As MDN sez:
"Do not download, authorize, and install software from unknown, untrusted Websites or any other sources."

Especially, never-ever provide your administrator password when installing or running ANY program unless you know absolutely, totally, fur shur that the software is legitimate. Otherwise you are giving away the farm and the malware rulz your Mac. And that's bad, OK?

Now go watch something
really scary like the latest US political speech on CNN. Yes, mentally-challenged fascist vampires do exist.

Tuesday, March 11, 2008

Version 12.0.1 Security Update for Office 2008


Microsoft today released the version 12.0.1 update for Mac Office 2008. It contains security as well as bug patches. It has repairs for every application in Office 2008. Included are fixes for:


1) "... Vulnerabilities that an attacker can use to overwrite the contents of a computer's memory by using malicious code."

2) Issues that can cause Office 2008 to stop responding or quit.

3) Over 20 bug repairs.

Needless to say, this update is 'CRITICAL'.

You can read more about it HERE and HERE.

You can download it HERE.

You can get toss Office in the dumpster and replace it with the free/donationware NeoOffice HERE. Recommended. It is a thoroughly 'Macified' version of OpenOffice for X11. It has over twenty features that the X11 version does not. It can read and write most Office files. It includes a word processor, spreadsheet and presentation program. It has built-in support for Microsoft's new 'OpenXML' document format found in Office 2007 and Office 2008. It invented the new ISO 26300 OpenDocument universal file standard. It has a new QuickLook plug-in. It has a Spotlight importer. Its HTML code export feature follows international web standards (unlike Office 2008). It can export presentations to Flash format. It still supports Visual Basic for Applications macros (unlike Office 2008). It is also compatible with WordPerfect and Microsoft Works documents. You can compare the rest of its feature set with Office HERE. And yes, it really is free and well worth supporting.

;-Derek

Sunday, March 9, 2008

Office for Mac 'CRITICAL' Security Flaw


The SANS Institute is well known for its IT security training. They typically go a bit overboard trying to FUD Mac users. But if you ignore that rubbish they are a very good source of computer security information. If you are interested they also have a very good Mac security course schedule. I wouldn't mind attending!


This week SANS reported that Microsoft are going to be releasing four security bulletins on March 11, 2008. All the bulletins discuss 'CRITICAL' security flaws. Three are in Microsoft Office and one is in Microsoft Office Web Components. The affected versions of Office and its applications are Office 2000, Office XP, Office 2003, Excel, Office Outlook and Office for Mac. The vulnerability of interest here is the one affecting Office for Mac. You can read more at:

http://www.eweek.com/c/a/Security/Microsoft-Critical-MS-Office-Patches-Coming/
http://www.microsoft.com/technet/security/Bulletin/MS08-mar.mspx

When I learn specifics about this flaw I will have a follow-up post.

This information was provided in SANS NewsBites Vol. 10 Num. 19. You can obtain a free subscription at:

http://portal.sans.org/
_

Thursday, February 28, 2008

New Exploit: "ipcomp6_input()" Denial Of Service


Today Secunia posted in their weekly report a vulnerability in Mac OS X 10.5, and possibly earlier versions, that can be used in Denial Of Service (DoS) attacks. So far it remains unpatched by Apple. You can read the details
HERE:

I seriously doubt this is going to affect much of anyone at this point in time as it requires the use of IPv6 packets. IPv6 is up and coming, but not yet in major use.

Secunia offer the following solution while we wait for a patch: "Use a firewall to block IPv6 packets containing an IPComp header." There are a couple complicated ways to do this on Mac OS X. The first is to go into the Mac OS X CLI (character line interface) and configure IPFW. You can read the man (manual) page of IPFW in the Terminal. The other method is to download WaterRoof HERE, which provides a GUI for IPFW. Neither method is for the faint of heart, and certainly not for an average Mac user. Have fun! :-D

Monday, December 17, 2007

Mac-Security Column for December 2007


[NOTE: This is an article I published in the Syracuse Macintosh User Group (SMUG) monthly newsletter, AppleTree. Anyone is welcome to further publish it wherever they wish as long as the article is not further edited while my name as author and my copyright remain intact. Breaka da rulez and I breaka you head].


Mac Security column
2007-12-16
© Derek Currie

Last month I made a quick mention of Clam as a cross platform freeware anti-malware application. For Mac OS X you can obtain and use it in the form of ClamXav or Leopard Cache Cleaner (which runs on Jaguar, Panther and Tiger as well). This month I wanted to point out a couple more shareware anti-malware programs that may or may not be of interest.

But first let's take a tour through the many security enhancements Apple have provided in the past month:

November 12th Apple released the iPhone and iPod Touch version 1.1.2 update. It addressed an all too familiar problem with maliciously crafted images being able to terminate a running program or being able to run arbitrary code, also known as an infamous buffer overflow. This happens when the memory space designated for an application is overrun with data such that it runs into the next contiguous memory sectors. The resulting data can bomb the program using the offended memory sector, or if the trouncing data is properly designed and executed it could potentially take over your computer.

November 14 Apple released the Mac OS X 10.4.11 update as well as Security Update 2007-008 which is applicable to Mac OS X 10.3.9. The both cover the same security issues. Security repairs were provided for the following parts of Mac OS X:

• AppleRAID
• BIND
• CFFTP
• CFNetwork
• CoreFoundation
• CoreText
• Kerberos
• Kernel (6 fixes)
• Networking (5 fixes)
• NFS
• NSURL
• remote_cmds
• Safari (2 fixes)
• SecurityAgent
• WebCore (9 fixes)
•WebKit (3 fixes)

This update also provides a new security fix version of the Flash Plug-in.

November 14 Apple also released Safari 3 Beta version 3.0.4 for Windows. It patches two vulnerabilities in Safari itself, three vulnerabilities in WebCore and three vulnerabilities in WebKit. The most numerous patches it provides are related to cross-site scripting.

November 15 Apple released the Mac OS X 10.5.1 update, which included three security updates to its firewall. The Leopard firewall has been met with skepticism and disdain. These patches address the most noted problems.

December 13 Apple released QuickTime version 7.3.1 which includes three security updates. Earlier in the month Apple had been slammed by the likes of Secunia and SANS Institute for the continuation of a seemingly unending string of QuickTime security flaws. This update address a few of the problems specifically related to maliciously crafted RTSP movie files, QTL files and the QT Flash media handler. This update is for Mac OS X 10.3.9 on up as well as Windows XP SP2 and Vista.

December 14 Apple released Java 6 for Mac OS X 10.4. Does anyone remember when we were all fed the marketing spin that Java was supposed to the 'safe' programming language that couldn't harm your operating system and hardware? Yeah right, we wish. Surprise! This update covers thirty security flaws in Java for Mac OS X. The fixes prevent the ability of a malicious web page to raid or add to your Keychain (which is an outrageous security flaw) the usual arbitrary code execution and privilege escalation.

In all, these security updates are crucial, many of them patching vulnerabilities that could potentially lead to a hacker taking over your computer. Therefore, as usual, be sure you keep your Mac OS X security updates up-to-date! You can read about all these security updates in detail at:

http://docs.info.apple.com/article.html?artnum=61798


CONCLUSION: Software coding remains a mysterious art that is constantly full of flaws. Microsoft may be the masters at security blunders, but like it or not there are blunders using even the most deliberately secure of contemporary coding methods. In other words, expect more Mac security flaws and perhaps more Mac malware in the future. But also feel secure that Apple are on their toes these days cleaning up Mac OS X security problems.


Now on to a couple more anti-malware programs for Mac OS X. The first is called MacScan, which claims to identify and isolate Mac OS X Trojans, spyware and Tracking cookies. It is a shareware program that costs around $25. When it is downloaded you are provided with a 30 day demo period. The second program is freeware called Zebra Scanner, which claims to identify disguised Trojans. It has not been updated since 2005.

Let's save some time and let me share my conclusion that both of these programs are useless and unnecessary. However, there are a couple caveats to that statement I will provide below if you care to keep reading:

MacScan has been known in the shareware world as 'MacScam' because of the rather high price for its ability to do next to nothing. Example: I used it to scan for the demo Trojan that Zebra Scanner provides. It couldn't find it. I used it to find Tracker Cookies. It found false positives, it failed to find others until I ran it a second time, and when I asked it to remove those it found it did absolutely nothing. I had to remove the Tracker Cookies by hand. And I'm supposed to pay for this privilege?

The one useful thing MacScan does provide is a list of known 'LEGAL' spyware programs for Mac OS X. You can find this list on their website as well. Legal spyware includes keystroke loggers, VNC and remote administration programs that are openly provided to the Mac market. They are typically used in professional network situations where the network administrator or the boss want to keep track of the work being done by their computer clients or employees. You can find a slew of them available for download by searching with the term 'spyware' at VersionTracker.com.

Meanwhile, I tried to find the blacklist MacScan is supposedly using to identify Tracking Cookies, but I failed. Something tells me I can find one on the Internet, so I will be in search of it this coming month and will share it when I find it.

What are Tracking Cookies? They technically are a mini-version of spyware under the guise of website cookies. They watch where you go on the web, store that information, then feed it back to their home site the next time you visit. It is supposed to be a marketing tool that a website can use for choosing what products to advertise to you. Personally, I consider it privacy intrusion. So I enjoy removing tracking cookies and blocking them from being allowed by my browsers.


Last and least we come to Zebra Scanner. Back when it was written there was a scare than hackers were going to attack the Mac with Trojans that were disguised as such benign things as JPEG files and text messages. But a security fix in Mac OS X 10.4 ended that possibility. Therefore, Zebra Scanner became useless. But there is one small possibility you could still get fooled by a malware application in disguise. That would be if you have your Finder set to NOT show file extensions. I am someone who was rather angry that Apple chose to go with file extensions to identify Mac OS X file types as opposed to the file types being embedded in the file's headers. Those stupid 'dot three' extensions on files are so Windows, so Luddite, so retro, so ugly. Apple actually compromised on the issue and still allows header file type identification, but for the purposes of avoiding Trojans, the dopey file extensions actually come in handy. Here is the example Zebra Scanner provide:



Suppose you are sent something that has a folder icon and has the title 'Christmas Icons'. Great, you figure it has nifty Christmas icons inside the folder. But darn, you have the Finder set to NOT show file extensions. So you have no idea that this bogus folder is actually an application with a fake folder icon pasted on top. So you 'open the folder' but actually find you are infecting yourself with the Trojan.


If you think you could be subject to that infection method, then you should use Zebra Scanner. If however you leave your file extensions left ON, then you can't be fooled. That fake folder's name has '.app' as an extension at the end.


So what if some goon physically removes the '.app' extension? It is very easy to do in Mac OS X. Then what you can do is a Get Info on the file before you do anything with it. The operating system will STILL tell you that it is an application. Therefore, don't run it.

Don't bother trying to come up with other crafty ways to fool the operating system. If you fake an application to be a .txt file the OS will attempt to open it ONLY as a .txt file. It will NOT run it as an application. You are safe. What you will get is an error message saying that the text file is unreadable, which makes sense since it is actually an application. This same routine follows if you change the application to any other extension as well.


CONCLUSION: Be wary of anything at all you receive out of the blue and don't absolutely know to be safe. Expect it to be bad news. (1) Have your extensions turned on in the Finder (2) Always do a Get Info on suspicious anything. (3) To be extra-super-safe, only use your Mac inside a standard account, not an administrator's account. This will help prevent Trojans from doing nasty stuff on an adminstrative level. Only your current standard user account can be hurt.

Next month I will hopefully have a source for a Tracking Cookie blacklist. So stay tuned if you are interested. In the meantime you can keep track of my ongoing Mac security news here at:

http://mac-security.blogspot.com

Share and Enjoy,

:-Derek