Tuesday, April 24, 2012

Flashback Malware and Java : FYI Notes


~~~~~~~~~~~~~~
I just posted an FYI set of notes over at MacDaily news to help sort out some misinformation regarding what has been occurring thanks to the Russian malware rats who write the Flashback series of malware. It may be helpful here as well.
~~~~~~~~~~~~~~


FYI:
The worst previous Mac malware infection was due to Trojan.OSX.iServices.A-C. It was a Trojan horse that was infiltrated into Warez versions of a few different Mac apps available at Torrent websites. The result was a botnet estimated to contain 10,000 Macs. That was in early 2009.

The worst estimate for the Flashback botnet (created by an estimated 19 different versions of the Flashback malware) was about 600,000 Macs. That is larger than the iServices botnet by a factor of 60.
All of the Mac malware previous to the recent few Java versions of Flashback, have been Trojan horses with infections preventable by basic safe user practices. The people who infected themselves are generally considered either to be Mac newbies or to be ‘LUSERS’ who would figure out a way to become infected if not for their account administrators.
The recent versions of Flashback have been unique in the history of Mac OS X malware because they were drive-by infections from websites that required no user interaction. The cause of this problem was two-fold:
1) Oracle don’t give a rat’s about Java and have allowed it to become the #1 source of third party security vulnerabilities for Mac users. Oracle don’t care.
2) Apple’s experiment with having Oracle provide timely updates of Java for Mac OS X has FAILed. Oracle don’t care.
My personal recommendations:
A) Don’t install Java onto Mac OS X 10.7. Most people never need it.
B) If you do install Java onto 10.7, or you run a previous version of Mac OS X, TURN JAVA OFF. This can be done in the Java Preferences app in your Utilities folder. Only turn it on again for critical uses, then turn it OFF when you’re done.
IOW: Java now sucks. Avoid Java as much as possible. 
Java is now even more dangerous than JavaScript, aka LiveScript, aka ECMAScript, aka JScript (by Microsoft), aka ActionScript (by Adobe). It is now even more dangerous than the real Adobe Flash Player plugins.
Hopefully this Java catastrophe has woken Apple up to being preemptive about Java security holes and their danger to Mac Java users. Oracle don’t care.
Ideally, Oracle will at long last allow Java to become an open source project. However, I don't see that happening in the near term as Oracle will be reaping some major bucks off Google for having ripped off Java technology for their Android OS. Oh well.

Sunday, April 15, 2012

Flashback Malware And
The Confusing Case Of
The Apple Flashback Malware Remover v1.0

--
[Updated 2012-04-18:
Symantec are now reporting that, according to their data collection, the Flashback botnet is down to 140, 000 Macs. That's still a vast number, but a remarkable improvement thanks to Apple's Java update and Remover. 


Also new: 
My net friend Al Varnell, who performs a great deal of vigilant work with ClamXav and the ClamAV project, has provided me with new information and insight reflected below. Of greatest interest is the fact that the Flashback malware series has been specifically aimed at Intel CPU Macs only. PPC Macs are immune.]


Apple has provided a separate tool for Mac OS X 10.7 users (only) for the removal of most versions of the Flashback malware. It is entitled (despite odd journalist claims to the contrary) the 'Flashback Malware Remover.' Apple also call it their 'Flashback malware removal tool.' The Software Update system in 10.7 is offering the tool to those who have no installed Java. Optionally, you can manually download it from Apple's Downloads site:


http://support.apple.com/kb/DL1517


Here is Apple's description of the Flashback malware removal tool:
About Flashback malware removal tool 
This update removes the most common variants of the Flashback malware. This update contains the same malware removal tool as Java for OS X 2012-003.If the Flashback malware is found, a dialog will be presented notifying the user that malware was removed. 
In some cases, the Flashback malware removal tool may need to restart your computer in order to completely remove the Flashback malware. 
This update is recommended for all OS X Lion users without Java installed.
Why does the description say 'without' Java installed? Because there have been quite a few versions of the Flashback malware that did not involve Java. Mac users who do not have Java installed (which is the default starting with Mac OS X 10.7) would never have been offered Java for OS X 2012-003 via Software update and therefore would never have run Flashback Malware Remover on their Macs via that update. Rather than leaving those users out in the cold, Apple have provided the Remover as a standalone installer application.


NOTE: The Remover only runs on Mac OS 10.7. I checked.


What is confusing about the Remover is that Apple have NOT provided an actual application tool. Instead Apple has provided an 'installer' package that runs within their Installer program and that is ALL that it does. 






Essentially, Apple took the Java for OS X 2012-003 installer and removed everything except the Remover process from the installation. In other words: NOTHING is installed on your Mac. Not-a-thing. And yes, that is freaky. The installer is the Remover. Get it? This is going to freak out and confuse quite a few Mac users. This has already been proven to be the case up on Apple's Discussion forums at their Support site. I can't blame them! It makes no sense, except that Apple had the Remover handy inside their Java for OS X 2012-003 installer, so they sped the Remover out the door within that same format.


Don't worry about it! Just run the installer and the Remover will run. Keep the .dmg file if you would like to run it again in the future. This is a great idea because the older Trojan horse versions of Flashback (of which there are reportedly 13 versions that don't use Java) are going to remain out in the wild on the Internet.


Please refer back to my previous article for details about how to avoid being infected with Trojan horse malware, along with other security rules and tips:

The Rules of Computing: Keeping Your Mac Secure

The Numbers:


Adding up all the Macs infected with ALL the variations of the Flashback malware, apparently well over 600,000 Macs were affected:



After Apple's three Java updates, the last of which included the Remover, the number dropped to half, less than 300,000 infected Macs:


Who's left in the Flashback botnet?

1) Users with Mac OS X 10.6 or 10.7 with Java installed who have not run the most recent updater or Apple's separate Flashback Malware Remover.

2) Users with Mac OS X 10.7 who never installed Java and have not yet run Apple's Flashback Malware Remover.

3) Anyone using Mac OS X 10.5 on Intel Macs. From the data of which I am aware, the Flashback malware code is directly ONLY at Intel Macs, making PPC Macs immune. It is not clear whether there has been infection of Mac OS X 10.4 Intel Macs. However, I continue to suspect there have. The Java security hole exploited by Malware.OSX.Flashback.N, the latest version (according to Intego) is apparently present in the last Java update for that version of Mac OS X.

Kaspersky has provided a web page where you can check if your specific Mac was infected with Flashback. However, I can't recommend it as the page requires you to enter your Mac's hardware UUID (Universally Unique Identifier). That's a bit like giving away your social security number and could be used by hackers to fake being you on the Internet. I suggest you only give it away to people you know and trust. Therefore, I'm not going to link Kaspersky's Flashback infection checking page here. If you'd like to use it, go digging around at the Kaspersky.com website.

Is this the time to buy Mac Anti-Malware software?
(Often wrongly called 'Anti-Virus' software). 

Probably not, unless you are dealing with the 'LUSER Factor' or unless you have an Intel Mac with Mac OS X 10.5 or 10.4. Even then, I suggest you first download and use Mark Allan's ClamXav software. It's FREE. My Mac Security friends and I work to keep the ClamAV open source project up-to-date with the latest Mac malware definitions. Install it, update its malware definitions and have it scan your entire boot drive.

There are also a number of free scanner versions of commercial anti-malware apps. I'd suggest checking out Sophos Free Anti-Virus for Mac. (I can no longer recommend the free PC Tools iAntiVirus app, which is drastically out-of-date).

If you'd like to buy the best Anti-Malware program, I continue to recommend Intego's VirusBarrier. They have a 30 trial version. I own it, use it and like it. It ships with excellent bells and whistles including its own firewall, Internet website protection, good background scanning that doesn't eat your CPU, and its own reverse firewall (similar to the renowned Little Snitch software). The only drawback is the yearly fee for malware definitions. I pay it and don't mind.

I have friends who like F-Secure Anti-Virus. They offer free online tools and a 30 day free trial. (Use the 'campaign code' on their AV page). The only reason I avoid F-Secure is that they are FUD mongers, attempting to scare Mac users with exaggerated reports about Mac malware. I don't deal with that.

Sophos is the best if you are running a small business or enterprise network of Macs. They also offer a free trial. I also like their free Sophos Security Monitor app for iOS devices. It provides timely computer security information.

The other anti-malware providers can be anywhere from OK to total CRAP. The crap includes (IMHO of course) anything from ZeoBIT and Symantec. IOW: Run away from MacKeeper and Norton Anti-Virus. 


Coming Up:


Over at my MacSmarticles blog, I will be posting an article about ZeoBIT paying their users to bombard Mac software review sites, a grotesque abuse of marketing.

Here at the Mac-Security blog, I will be providing a list of my favorite Mac security information sources.
--

Wednesday, April 4, 2012

CRITICAL Java Updates: Mac OS X 10.6 Update 7 and 10.7 Update 2012-002 (formerly 001)

--
[Updated 2012-04-06:
For users of Mac OS X 10.7, Java update 2012-002 has been released today to correct an error in the .DMG installation file for 2012-001. The 2012-001 installer has been withdrawn. I interpret this to mean that the flaw in 001 was critical. Therefore, please install Java for OS X 2012-002 IMMEDIATELY! It has been reported that over 600,000 (not a typo) Macs are now infected with the Flashback Trojan horse / botnet malware! This is unprecedented in Mac history. This Java update kills off a Drive-By method of Mac infection by the Flashback malware.]

If you haven't already installed the latest Java update for Mac OS X 10.6 Snow Leopard and 10.7 Lion, INSTALL IT NOW. No excuses. The best method of installation in this case is via Software Update, available under the Apple menu. There is currently a problem with the direct download version for 10.7 whereby it FAILs the fsck check the OS runs during DMG file verification. See details below.

This particular update is CRITICAL because there is an active exploit against the older version of Java that results in Drive-By infection of Mac machines without requiring the user to provide a password. This is unheard of on Macs. It is specifically a Java problem, NOT a Mac OS X problem. Don't blame Apple. Blame the lazy crapcoders at ORACLE.

Windows users have had this particular Java update for MONTHS. Supposedly Apple and Oracle have an arrangement whereby Oracle are now writing Mac updates for Java. But that arrangement is FAILing.

Earlier today I posted reviews of this update at both VersionTracker/CNET and MacUpdate. I have provided a somewhat redundant summary below which with details about how to turn OFF Java, which I highly recommend, as well as some rant action.

∞ ∞ ∞ ∞ ∞ ∞ ∞ ∞ ∞ ∞ ∞ ∞

Good: This CRUCIAL Java update patches an active exploit against Macs. Better a late update than never. Java is occasionally useful.

Bad: Java is now one of the most INSECURE Internet technologies. If you don't use Java, TURN IT OFF! Oracle and Apple are NOT providing Mac Java updates in a timely manner. This Java update for Mac provides an update that Windows users have had for months. For over a week, there has been an active malware exploit against Mac users with the unpatched version of Java.

It is terrific that Apple jumped on this exploit so quickly. However, Apple users MUST be provided with Java patches at the same time as Windows users. Delaying Java patches for Mac users is NOT acceptable.

I have verified that the direct download file of the 10.7 version of Java for OS X 2012-001,  FAILs the Mac OS X fsck check during file verification. This is evident in the Console. This is BAD. If you used this downloaded installer, IMMEDIATELY update to the Java for OS X 2012-002 installer!

The BEST way to install this update is from Software Update. You will find it under your Mac's Apple menu. This installation works perfectly.



Now For My Rant:


Java has become a BANE of the Internet. I have turned it OFF. I am sick of the recent Java exploits against Mac users. I don't deal with it. I suggest you turn Java OFF as well, unless you use it regularly.

HOW TO TURN OFF JAVA: 

If you use multiple web browsers (I use six) then the best and simplest way to turn Java OFF is via the Java Preferences app found in your Mac's Utilities folder. Follow these steps:

1) Open the Java Preferences app.


2) Under the 'General' tab, check OFF "Enable applet plug-in and Web Start applications". (Mac OS X 10.6 users: Instead uncheck the plugins for Java SE 6 in the box inside the window).

3) Quit the Java Preferences app.

4) VERIFY IT'S OFF: Open the Java Preferences app, again. Verify that the "Enable..." checkbox remains OFF. If you find it on again, check the damned thing OFF again. Quit Java Preferences. Verify AGAIN as required.

I add this VERIFY step because I personally have seen this checkbox turn on again. If you want to be extra-special certain the box doesn't turn on again, you can go down to the box under the 'General' tab and turn OFF both 64 and 32-bit "Java SE 6", then turn off "Enable". That definitely does the trick.

My #2 Rant: 


SHAME ON ORACLE. That company has RUINED OpenOffice. The LibreOffice branch is now off and running and far superior, leaving the source OpenOffice project irrelevant. Oracle has been just as obtuse with Java, which is now a DETRIMENT to the Internet.

Maybe Java will be made open source, at long last. That would help. Perhaps great developers like those on the LibreOffice team will grab it and make Java seriously great. Until then, BEWARE OF JAVA. I fully expect more Java exploit malware to come. (o_0) 



Now I go all sentimental: 

Remember when Java was supposed to be 100% secure, never able to access your computer directly, entirely safe in its sandboxed little Just-In-Time runtime machine? Remember 'write once, run anywhere'? Remember 'secure memory management'? Fun times in Fantasy Land. 
:-P

Thursday, February 16, 2012

Apple's Gatekeeper in Mac OS X 10.8 Mountain Lion

--
[Revised 2012-02-20 @11:30 pm]

Let's get happy! Apple has set up a new approach to nailing Trojan horse malware for the upcoming new version of Mac OS X, code named Mountain Lion, aka 10.8. AND! Apple did it right! It uses both and application blacklisting and whitelisting.  It also uses application security certificates (aka digital signing). Only Apple gets to provide them, as opposed to the ongoing SSL certificate highjacking mess with hundreds of certificate providers.

If this concept sounds familiar, it's because Microsoft started doing it with 64-bit Windows Vista, where it was a profound failure. Why a failure? Because Microsoft GOUGED their developers with punishing fees per security certificate. Developers ignored it. This resulted in, among other things, a lack of hardware drivers for 64-bit Vista. Profound OOPS factor! Eventually Microsoft got the clue and relented on their fees. Therefore, the 64-bit 7ista release received far better developer support.

Apple's approach builds upon Mac OS X Snow Leopard and Lion's XProtect anti-malware system by providing users with new Security & Privacy Preferences accessible options and warnings:



1) Allow applications downloaded from: Anywhere. You can choose to keep things the way they are now. However, Apple provides WARNINGS about potential problems known about specific programs found on their current blacklist. Similar to XProtect, the blacklist is updated over the Internet every day. Apple will also be daily revoking bad app developer security certificates.

Example:
You download an app off a random site off the Internet and Apple pops up a message warning you that this particular app is known to upload your entire Address Book to their server. That's dangerous! It could mean the developer could take that list and perpetrate a SPAM ATTACK! That SPAM could include links to Phishing sites, further malware, etc. Your friends will not be pleased.

This feature alone is going to infuriate the malware rats. Users cannot turn it OFF as long as you are the administrator for your account. I like it! The result is a great short-circuiting of most social engineering malware.

The drawback is more popup boxes on the screen that you have to dismiss, IOW an increased safety factor as well as an increased annoyance factor.

2) Allow applications downloaded from: Mac App Store. You can choose to only download software from Apple's Mac Store. This provides maximum security because as of Mountain Lion's release date ALL Mac Store provided apps will be sandboxedwhereby every app is limited to accessing only the Apple APIs it requires and the apps run within a restricted memory space. Think of all the memory corruption vulnerabilities constantly being patched in applications. Now the damage they can do will be severely limited.

Example:
You download a crappy xhumans-style app that plays you videos about moths. The app will not be able to rifle through your Address Book for suckers to SPAM. All developers will have to justify every API their app accesses as being critical to its functions.

This remarkable approach for protecting users from malware already gives malware rats painful anxiety hemorrhoids. The result for users is very similar to the wonderful 'walled garden' available to all iPhone / iPod Touch / iPad users. This is the ideal setting to lock into place for all the 'LUSERS' in our midst. It will be nearly impossible for them to infect their Mac. They cannot turn this off, as long as you don't provide them with the administrator password.

The drawbacks here are:
  • Paranoia about Apple ruling the software world.
  • The profit loss to developers by selling their apps via Apple's Mac Store.
  • The sense of losing our freedom to do as we like with our computers. 
But keep in mind that you can turn this feature OFF and continue to enjoy your freedom-filled life as a positive anarchist. (^_^)

3) Allow applications downloaded from: Mac App Store and identified developers. You can choose the compromise setting of using both the Apple Mac Store and make use of Apple's blacklist of dangerous apps, whitelist of safe apps and app security certificates. In other words, you can download whatever you like off the Internet, but Apple's lists will not only warn you of potentially bad software, it will prevent you from being able to install it at all.

Example:
You got this really kewl email telling you about an incredible application that will remind all your friends of your upcoming birthday, maximizing your receipt of birthday cards, congratulation messages and presents. You click the link to go to the website, which actually automatically downloads the software directly to your computer, like it or not. But then BAM! Apple's Gatekeeper STOPS the installation because this app is on their blacklist as potential scamware. Apple warns in a popup box that this app will not only grab your Address Book, but will PWN your Twitter account, Google+ account and Facebook account then grab all your friend contacts. The result could be a major scale SPAM, Phishing and linked malware attack on every single person you know.

This is a great default setting for everyone for every day use. You could be temporarily brain compromised, clicking on every link on the Internet, downloading goodness knows what, and the computer will stop you. And again keep in mind that you can turn this OFF, as long as you are your account administrator.

Meanwhile, malware rats will be restricted to only short term mass infection of suckers. Once Apple catches up with new malware on its blacklist, the malware rats will be ripping their hair out with consternation. What fun!

The Time and Sharing Problems:


It is difficult to keep Apple's XProtect perfectly up-to-date. On occasion it has taken Apple a number of days to provide malware signatures. We can expect a similar lag with their application blacklist and security certificate revocation.

Note that this is not entirely Apple's fault! Knowing the anti-malware community as well as I do, I can verify that it can be extremely hard to get a copy of the latest malware for analysis, signature creation and infection prevention. The anti-malware community is outrageously unprofessional in many respects. Therefore, there is almost NO SHARING of malware between anti-malware companies and providers. That includes sharing malware with Apple. If at some point the anti-malware community grows up and becomes serious, standardized and scientific in its approaches, all this competitive rubbish will go away. But don't hold your breath. We're still living in a metaphorical Wild West of computer security. Thankfully, Apple is taking the role as the new sheriff in town.

There is a wonderfully detailed article about Mountain Lion's Gatekeeper by Rich Mogull. You can find it on the TidBITS website:

Gatekeeper Slams the Door on Mac Malware Epidemics

Rich Mogull has also provided a follow up article with more technical details, available at his Securosis blog:


Meanwhile, Macworld has been providing a series of articles about Mountain Lion, including coverage of Gatekeeper that goes into further detail:

Mountain Lion: Hands on with Gatekeeper


No doubt, further details and analysis will be provided as Mountain Lion approaches. Please tell us about further information in the comments!
--

Wednesday, February 15, 2012

Adobe Flash Player: Critical Security Update to v11.1.102.62

--
And then Adobe released a critical security update for their Flash Player! Be sure to update ASAP to Adobe Flash Player version 11.1.102.62. You can 1-step download the update from here:

http://get.adobe.com/flashplayer/?promoid=BUIGP

The update includes six security patches relevant to Mac OS X users. You can read Adobe's provided details here:


For those interested, three of the security patches involve memory corruption. Two of the patches repair security bypass vulnerabilities. One of the patches is for a cross-site scripting vulnerability.

Don't forget to update to yesterday's new critical security update version of Adobe Shockwave Player as well!
--

Tuesday, February 14, 2012

Adobe Shockwave Player: Critical Security Update to v11.6.4.634

--
Adobe has again done the right thing and ignored their own idiotic quarterly updates schedule. I'm glad someone over there has a brain in their head. This time the problem is with Adobe Shockwave Player. Adobe says:
These vulnerabilities could allow an attacker, who successfully exploits these vulnerabilities, to run malicious code on the affected system.
Update Adobe Shockwave Player to version 11.6.4.634 immediately. You can download it here:


http://get.adobe.com/shockwave/otherversions/


A good article about the many dangerous security flaws in the previous version is available at ZDNet:


You can read Adobe's detailed explanation of the critical security issues here:


And for those interested: 
ALL the critical security flaws are due to poor memory management, still the bane of modern code engineering. (o_0)
--

Thursday, February 9, 2012

Hacked iTunes Accounts Resulting In Robberies

--
*Updated 2012-02-09 4:22 pm*


This issue in the UK came to my attention today. I wanted to make sure all iTunes users were aware of it. The depth and details of this hacking problem have not yet been revealed. It is useful that everyone with iTunes accounts read about this problem and consider whether they may be affected. Apple consider the problem to be limited to isolated incidents and has responded by stating:

“Apple takes precautions to safeguard your personal information against loss, theft and misuse.”

Below is a link to a source article about this problem provided by DailyMail.co.uk:


I've been reading other, possibly exaggerated accounts of this situation. One such account is the original article at the website The Global Mail. (Please note that this website is poorly formatted for many users, uses incorrect security terminology, and that the article may have been sensationalized. It does however offer some useful data).


If you would like direct information about the problem, there is lengthy related thread at Apple's Support Communities board entitled "iTunes store account hacked".
--