--
When I was a computer newbie, what I heard repeatedly was "The Number One Rule Of Computing is Make A Backup!" I've been working on an extended list beyond one item in order to help newer newbies consider further aspects of their computer experience that can help save them in a crisis. I don't consider my list definitive or even finished. But I like the list enough to publish it as a starting guide. So here I go:
The Rules Of Computing
1) Make a backup. Have two backup strategies. One strategy regularly backs up your crucial data to local external media away from your computer. The other strategy backup up this same data to an off-site location, such as in 'the cloud' or onto external media you take to a separate location each day. The idea is to have an off-site backup in case your computer site burns to the ground. Backups are also your first and best defense against malware damage and hardware failures. If you don't back up your data, you get what you deserve.
2) Verify all software before installing it. Verify your software source is reliable and that the software itself is reliable. Look up the software title on the Internet using a search engine to discover if it has been reported as problematic. Download software from reliable sources such as VersionTracker, MacUpdate, Major Geeks, etc. Don’t ever blindly install emailed software. It could be malware.
3) Verify that websites you visit are legitimate. This third rule is difficult to implement on your own. Use tools provided inside web browsers, as well as add-on browser extensions, that help you check websites you visit against a blacklist of known bad websites. One of the most popular ways of spreading malware at this time is via 'drive-by' infections via JavaScript and Java. Don't ever blindly click on web links in email. The could be sending you to a malware infection or identity phishing website.
4) Keep your computer up-to-date with the most recent security updates. Apple provide security updates on a regular basis. Security Preferences, built into Mac OS X, should let you know when an update is available. You can also open Security Preferences yourself and have it check for you.
5) Use a 'Standard' account when surfing the Internet or using your Mac on any network. Do NOT use an 'Administrator' account in these situations. This is not a cure all to prevent your Mac from becoming hacked or malware infected. But it adds a terrific layer of security to help prevent malicious root access to your computer.
6) Password protect your user account. Make sure your account password is not a dictionary word or you'll be hacked in no time flat. Use something long and obscure that you can remember but that you expect no one could guess. To this day I run into people who tell me 'But I'm the only one who uses my computer!'. Cure your ignorance please. There is NO excuse for not protecting your computer with a password. If you don't protect your user account, you get what you deserve.
Yes, I'm that mean and cruel when it comes to computer security. There are wonderful security strategies and tools that Apple provide, such as Time Machine, Disk Utility, Standard user accounts and password protection. If you don't put them to use, I have no sympathy! If you have questions about how to make them work for you, write to me, talk to Mac users you know, contact users on the Internet or at your local Mac user group. These tools are not difficult. They are important and they are FREE.
A Few Further Strategies:
I'm only going to list these strategies as they are more complicated and involved to install and get running. What's important is that they are available, they are also FREE, and they may well save you from giving away data to the bad guys.
A) FileVault. You will find it inside the Security System Preferences. It lets you transparently encrypt your entire user account folder so no one can ever get to your data without knowing the decryption password. This is rock solid encryption you can rely upon. Apple will be providing an option for encrypting your ENTIRE computer hard drive in Mac OS X 10.7 Lion. I personally consider whold drive encryption to be overkill. But it is considered to be critical in Enterprise business situations. Note that there are some minor dysfunctions that result from encrypting your user account. But if you have critical data, it is an excellent security tool.
B) Firmware Password. Apple provide a utility to set their Firmware Password Utility on all Mac OS X installation DVDs. It adds another layer of security to keep the bad guys out of your computer. Sadly, it is not fool proof. A tech savvy bad guy can work around it. Encryption is a much more effective tool. Also note that you lose some minor computer functionality when you use a firmware password.
C) GnuPG, aka GNU Privacy Guard. I have been using GPG for many years at this point. I'm a fairly infamous critic of the bugs that have should up in the related tools from time to time. Also note that GnuPG has a steep learning curve and can be a bit frustrating. However, it is a FREE and brilliant tool with many users. You can encrypt and password protect anything you like. The Apple Mail tool lets you digitally sign all your email in order to verify exactly who you are to those who receive your email. You can encrypt your email such that no one can read it in transit over the Internet. It lets you create any number of encryption keys as well as collect public keys from your friends and acquaintances. And more! If you want to be serious about encryption, GPG is excellent. These days it also has a terrific group of developers dedicated to keeping it bug free and up-to-date.
D) Disk Utility. Among the many features of the Mac OS X Disk Utility application is the ability to create encrypted, password protected .sparseimage files. I absolutely love this feature and use a sparseimage I created all day, every day. I have my sparseimage open every time I log into my user account. I provide the decryption password and it sits on my desktop like a disk volume. Anything I put into it is encrypted and unavailable to anyone but me as soon as I close the disk image. Because its a sparseimage, it can grow to as large a size as you choose as you add more into it. Recently the DropBox application and server have become notorious because nothing-at-all is encrypted when you use it. That can be very bad. However, I work around this problem by putting only my sparseimage file into my drop box. No one has any access to anything I have in my DropBox ever, thanks to this great tool.
E) Anti-Malware applications. I own, use and love Intego's VirusBarrier X6 ($50). There aren't any better anti-malware applications, period. But I have to pay for malware signatures every year. If you are a professional user, VirusBarrier is well worth the cost.
If you're a casual computer user, paying for anti-malware is a bit less critical. I've worked fairly closely with Mark Allan and friends who develop and support the FREE program ClamXav. There was a time when I had quite the run-in with the ClamAV Open Source project because most volunteers there cared not-a-whit about Mac OS X. But gradually Mark and I managed to turn a few heads and encourage them to get up-to-date with current Mac malware. At this point in time I can tell you that just about all current Mac malware is being detected by ClamAV. Therefore, I highly recommend downloading, installing and running ClamXav from time to time if you are concerned about malware. The GUI Mark provides is excellent.
Also, if you own Snow Leopard Cache Cleaner ($15) you will find that it includes its own implementation of ClamAV, also highly recommended. I no longer recommend free iAntiVirus as it is now out-of-date and less effective than the ClamAV alternatives.
There are plenty more security tools and strategies, both free and for a fee. But the above is a good start with reasonable coverage.
For the extra security conscious, as ever I highly recommend the TWiT.tv podcast 'Security Now' with the most excellent Steve Gibson. It gets highly technical but is wonderfully presented and very contemporary. You can look up the podcast in iTunes or visit its dedicated webpage at:
http://GRC.com/SecurityNow
:-Derek
--
Showing posts with label Intego. Show all posts
Showing posts with label Intego. Show all posts
Thursday, May 19, 2011
Thursday, May 5, 2011
"Mac Security" Scamware:
Variations on a Fake
How I love the hunt!
Today's prey is an Internet rat known as species 'Scamware stupidicus'.
The rats who brought you the scamware (rogueware) "MAC Defender" (see my previous blog post) have now tweaked their code slightly and renamed the thing "Mac Security" with an installer entitled "BestMacAntivirus2011.mpkg.zip" which expands to the installer file "MacSecurity.mpkg". Expect there to be other name variations.
Good old Intego discovered this new variation, posting an article and a "How It Works" video here:
Intego Discovers New Variants of Mac Defender Fake Antivirus
You can directly watch the video on YouTube HERE.
Intego have updated their Virus Barrier malware signatures to detect this new rodent excrement.
What is hilarious about this scamware is the LAZINESS of the hacker rats who wrote it. The interface for the scamware is that of Microsoft WINDOWS!!! Hardy har. If you've used Windows in the last decade, you'll spot it immediately as BOGUS.
At this time the dangers are:
A) You fork out $money$ to buy useless garbage.
B) You give away your CREDIT CARD to criminals. It's a good as posting your card publicly on the Internet.
C) You give away your computer's PASSWORD. (This is now clearly evident from Intego's provided video). Consider yourself as good as PWNed (i.e. botted, i.e. zombied, i.e. no longer in control of your computer). So far the Trojan horse software is 'empty', containing nothing dangerous. But it could! Most likely, future variations will.
As with all current Mac malware, this POS relies upon social engineering, aka LUSER behavior, to entice the user to install it. Don't do that!
To keep ourselves safe, let's chant the mantra of...
The Top Two Rules Of Computing:
I) Make A Backup.
II) Verify All Software Before Installing It Or Running It.
(I'm considering using the following as Rule III:
III) Verify all links before clicking them).
Happy shooting!
--
Today's prey is an Internet rat known as species 'Scamware stupidicus'.
The rats who brought you the scamware (rogueware) "MAC Defender" (see my previous blog post) have now tweaked their code slightly and renamed the thing "Mac Security" with an installer entitled "BestMacAntivirus2011.mpkg.zip" which expands to the installer file "MacSecurity.mpkg". Expect there to be other name variations.
Good old Intego discovered this new variation, posting an article and a "How It Works" video here:
Intego Discovers New Variants of Mac Defender Fake Antivirus
You can directly watch the video on YouTube HERE.
Intego have updated their Virus Barrier malware signatures to detect this new rodent excrement.
What is hilarious about this scamware is the LAZINESS of the hacker rats who wrote it. The interface for the scamware is that of Microsoft WINDOWS!!! Hardy har. If you've used Windows in the last decade, you'll spot it immediately as BOGUS.
At this time the dangers are:
A) You fork out $money$ to buy useless garbage.
B) You give away your CREDIT CARD to criminals. It's a good as posting your card publicly on the Internet.
C) You give away your computer's PASSWORD. (This is now clearly evident from Intego's provided video). Consider yourself as good as PWNed (i.e. botted, i.e. zombied, i.e. no longer in control of your computer). So far the Trojan horse software is 'empty', containing nothing dangerous. But it could! Most likely, future variations will.
As with all current Mac malware, this POS relies upon social engineering, aka LUSER behavior, to entice the user to install it. Don't do that!
To keep ourselves safe, let's chant the mantra of...
The Top Two Rules Of Computing:
I) Make A Backup.
II) Verify All Software Before Installing It Or Running It.
(I'm considering using the following as Rule III:
III) Verify all links before clicking them).
Happy shooting!
--
Monday, February 28, 2011
New Baby Trojan: Trojan.OSX.MusMinim.a
aka Blackhole RAT
(aka darkComet, aka MusMinim)
A new baby Trojan has arrived on the Mac OS X platform, as discovered by Sophos. It is the 28th currently known active malware for Mac OS X (according to my counting). Transforming the Sophos name for the Trojan into the proper naming convention, its official name is 'supposed' to be:
Trojan.OSX.MusMinim.a
But of course it has a bunch of other names, in keeping with the chaotic nature of the computer security community, which has agreed upon a malware naming convention but rarely bothers with it because of the vast array of competitive egos in the business as well as a general lack of professionalism. As for me, I'm going to use its proper name, I expect Intego also will, and I hope you will too.
[Update: Intego are only calling the Trojan 'Black Hole RAT'. Sigh.... But at least Intego have indicated this is only a hacking tool, (as is the 'Hellraiser' malware), not much of a threat. You can read their analysis HERE. Intego point out a further description of the Trojan HERE.]
Sophos provide their take onTrojan.OSX.MusMinim.a in this article:
Mac OS X backdoor Trojan, now in beta?
RAT stands for Remote Administration Tool, (NOT 'Remote Access Trojan' as Sophos calls it; Thank you to Intego for the correction). In other words it creates a back door into the infected computer. Because it is strictly a Trojan horse (as is technically all Mac malware at this point in time), it requires user failure in order to be installed.
Therefore, the Number 2 Rule of Computing:
Always verify the validity of software you install.
And what is the Number 1 Rule of Computing?

Always make a backup.
That way you always have a fall back in case your machine becomes infected or dies.
I'll be writing more about Trojan.OSX.MusMinim.a in an upcoming summary of the 28 current Mac OS X malware.
--
Trojan.OSX.MusMinim.a
But of course it has a bunch of other names, in keeping with the chaotic nature of the computer security community, which has agreed upon a malware naming convention but rarely bothers with it because of the vast array of competitive egos in the business as well as a general lack of professionalism. As for me, I'm going to use its proper name, I expect Intego also will, and I hope you will too.
[Update: Intego are only calling the Trojan 'Black Hole RAT'. Sigh.... But at least Intego have indicated this is only a hacking tool, (as is the 'Hellraiser' malware), not much of a threat. You can read their analysis HERE. Intego point out a further description of the Trojan HERE.]
Sophos provide their take onTrojan.OSX.MusMinim.a in this article:
Mac OS X backdoor Trojan, now in beta?
RAT stands for Remote Administration Tool, (NOT 'Remote Access Trojan' as Sophos calls it; Thank you to Intego for the correction). In other words it creates a back door into the infected computer. Because it is strictly a Trojan horse (as is technically all Mac malware at this point in time), it requires user failure in order to be installed.
Therefore, the Number 2 Rule of Computing:
Always verify the validity of software you install.
And what is the Number 1 Rule of Computing?

Always make a backup.
That way you always have a fall back in case your machine becomes infected or dies.
I'll be writing more about Trojan.OSX.MusMinim.a in an upcoming summary of the 28 current Mac OS X malware.
--
Saturday, January 29, 2011
Little Snitch $14.99,
(Regular Price $$29.95)
This Weekend
--
MacUpdate is offering Little Snitch from Objective Development, a beloved 'reverse firewall' for Mac OS X, at almost HALF-PRICE this weekend. That's $14.99. (Regular price is $29.95) Go get it here:
http://www.mupromo.com/deal/1421/7024/little-snitch
I use it non-stop and love the thing. It has gotten consistently easier to use over time. I also have an older version running on my FTP server 24/7. If you're worried about being pwned, this will stop all communication from malware back to the Bot Wrangler. No botnet for you! It's also perfect for stopping all 'phoning home' by pesky applications.
MUPromo's offer drops dead at midnight on Sunday, January 30, 2011. But you may be able to get it for a lower discount during the following week. Check the MUPromo website for details.
Note: If you use the 'reverse firewall' in Intego's VirusBarrier v10.6, you don't need Little Snitch.
--
MacUpdate is offering Little Snitch from Objective Development, a beloved 'reverse firewall' for Mac OS X, at almost HALF-PRICE this weekend. That's $14.99. (Regular price is $29.95) Go get it here:http://www.mupromo.com/deal/1421/7024/little-snitch
I use it non-stop and love the thing. It has gotten consistently easier to use over time. I also have an older version running on my FTP server 24/7. If you're worried about being pwned, this will stop all communication from malware back to the Bot Wrangler. No botnet for you! It's also perfect for stopping all 'phoning home' by pesky applications.MUPromo's offer drops dead at midnight on Sunday, January 30, 2011. But you may be able to get it for a lower discount during the following week. Check the MUPromo website for details.
Note: If you use the 'reverse firewall' in Intego's VirusBarrier v10.6, you don't need Little Snitch.
--
Saturday, July 24, 2010
Desperate Propaganda,
aka FUD,
in the Anti-Malware Community
--
We are living not only the 'The Age of Triva' as I call it, but 'The Age of the Marketing Moron'. Marketing Morons treat the customers and clients as worthless scum only valuable for their money.
Lately I have been wondering if biznizz skoolz deliberately teach their MBA candidates how to be effective psychopaths. Who is better at abusing other humans than a psychopath? I read this past week that an estimated 10% of biznizz executivez are psychopaths because it is such an in-demand mental illness for the creation and execution of biznizz ambitions. Imagine that. Variations of Bernie Madoff may be running your company. No wonder we're in a lingering economic depression.
[Note: I use the terms 'biznizz', 'executivez', 'skoolz' etc. whenever discussing deceitful aberrations from respectable forms of the subject. Deliberately distorted spelling is an enjoyable method of both sarcasm and laughter.]
Last week Intego pulled a FUD (Fear, Uncertainty and Doubt) move with their monstrosity 'Learn About Mac Malware'. This week it is being reported, by PC World, that Secunia have joined the anti-Apple security FUD circus. I'll decide that for myself in a future article. For now, it's of interest to take a look at the utter bullshite perpetrated by PC World. It doesn't get much more stooopid:
Security Firm: Apple Has More Security Holes Than Microsoft
The first sentence in this article gives away the show. This is FUD:
Here is a ticked-off post I made over at MacDailyNews regarding this FUD:
Secunia Half Year Report 2010
Seeing as PC World has no interest in factual Macintosh security information, and may well be spinning FUD regarding Secunia, I'm going to give the report a read myself. If I find anything of interest to Mac users, I'll post.
Share and Enjoy!
--
We are living not only the 'The Age of Triva' as I call it, but 'The Age of the Marketing Moron'. Marketing Morons treat the customers and clients as worthless scum only valuable for their money.
Lately I have been wondering if biznizz skoolz deliberately teach their MBA candidates how to be effective psychopaths. Who is better at abusing other humans than a psychopath? I read this past week that an estimated 10% of biznizz executivez are psychopaths because it is such an in-demand mental illness for the creation and execution of biznizz ambitions. Imagine that. Variations of Bernie Madoff may be running your company. No wonder we're in a lingering economic depression.
[Note: I use the terms 'biznizz', 'executivez', 'skoolz' etc. whenever discussing deceitful aberrations from respectable forms of the subject. Deliberately distorted spelling is an enjoyable method of both sarcasm and laughter.]
Last week Intego pulled a FUD (Fear, Uncertainty and Doubt) move with their monstrosity 'Learn About Mac Malware'. This week it is being reported, by PC World, that Secunia have joined the anti-Apple security FUD circus. I'll decide that for myself in a future article. For now, it's of interest to take a look at the utter bullshite perpetrated by PC World. It doesn't get much more stooopid:
Security Firm: Apple Has More Security Holes Than Microsoft
The first sentence in this article gives away the show. This is FUD:
Here's another blow to those insist that Apple products are rock solid and unhackableAs I wrote to PC World:
No one says "Apple products are rock solid and unhackable" except YOU PC World. It is an invented club with which to slam and abuse Mac users. It's called desperate propaganda, aka FUDI also wrote to PC World, and posted at FaceBook:
Facts (vs FUD) regarding Macintosh security:
Number of Mac OS X viruses: 0
Number of Mac OS X worms: 0
Number of illegal Mac OS X spyware: 1
Number of Mac OS X Trojan horses: 23
Compare that to the number for Windows and decide for yourself.
No one ever said Mac OS X was perfect (except trolls). But it remains the single most secure GUI operating system available. The only operating systems that are more secure:
- OpenBSD
- FreeBSD
And Mac OS X contains elements of both these operating systems. No coincidence.
Suggestion: Do your homework before posting about Mac OS X.
Here is a ticked-off post I made over at MacDailyNews regarding this FUD:
ANTI-FUD:Meanwhile, you can take a look at the Secunia report that inspired the FUD. It is a PDF file:
I receive EVERY Secunia report they publish via eMail.
Want to know what they publish every week? A GIGANTIC PILE of Windows vulnerabilities and extremely few Mac OS X vulnerabilities, as in about 1 (ONE) per month, at a guess.
This FUD attack 'by Secunia' [by PC World!] is made utterly hilarious by their own publications. Don't believe me. Go look for yourself:
http://secunia.com
Examine the home page. What do you see Highlighted there? Today:
- Microsoft Windows Shell Shortcut Parsing Vulnerability
- Apple iTunes "itpc:" Handling Buffer Overflow [That is SPECIFIC to WINDOWS ONLY]
- Microsoft Windows MFC Document Title Updating Buffer Overflow
Is there ANYTHING there related to Mac OS X? NO!
So what's with the FUD?
--> The fact that nearly the entire Anti-Malware Community lives off the security FAILures of Windows. Therefore, obviously, everyone MUST USE WINDOWS in order to keep them all employed!
∑ = Pure Adulterated PROPAGANDA
And no folks. There is nothing perfect about Mac OS X security. It just happens to be the most reliable of any GUI OS on the market. The only OSes with better security reputations are:
- OpenBSD
- FreeBSD
And oh look. Mac OS X contains elements of BOTH these OSes.
Hey FUD mongers: GET BENT.
Secunia Half Year Report 2010
Seeing as PC World has no interest in factual Macintosh security information, and may well be spinning FUD regarding Secunia, I'm going to give the report a read myself. If I find anything of interest to Mac users, I'll post.
Share and Enjoy!
--
Tuesday, July 13, 2010
Intego Errors!
Marketing Vs Fact,
Money Vs Reality
--
Kids. Didn't I tell you the computer anti-malware community was 'unprofessional'? Here we go again.
For shame Intego! Publishing FUD to sell your anti-malware software. For shame!
I like the folks at Intego a lot. But this is the SECOND time they have outright FUDed the public for the sake of making sales of their indeed superior anti-malware software. Note that this is entirely in line with our current era of PROPAGANDA at the expense of both facts and reality. I DESPISE FUD! I DESPISE PROPAGANDA! If you check out my zunipus blog you'll see I'm well versed on the subject.
This very WRONG page of information was posted at the Intego website this week. It makes me want to gag. It's crap like this that inspires me to keep writing my own, independent, 'hey look at me I have a brain in my head', Mac-Security blog:
Intego: Learn About Mac Malware
The Post-Mortum:
I) This page claims to provide a "clear explanation of what types of viruses and malware are a danger for Mac OS X."
Bullshit.
There is nothing 'clear' about FUDing customers and confusing them with ignorant information. If you haven't already spotted the garbage on this page, read on.
II) The Mac picture provided on the page, with its arrows to various malware, includes the word "Botnet". This is WRONG. There is no such thing as a 'botnet' form of malware. A 'botnet' is the result of having many computers infected with BOT malware. The software that infects your computer is called a 'bot.' Not a 'botnet'. A BOT!
III) The paragraph entitled "MAC VIRUS" is WRONG. There are NO viruses for Mac OS X. There never have been any viruses for Mac OS X. So this paragraph must be proceeded with the word:
NO
The description of viruses by Intego in this wrongful paragraph is entirely inadequate. Read these instead:
Computer Virus
or
What is virus?
In fact there are dozens of pages on the Internet that have superior descriptions of computer viruses. Google "What is a computer virus?"
IV) Examining the wrongful "MAC VIRUS" paragraph we see two wrongful examples. They are NOT viruses. Here is what they REALLY are: PROOF OF CONCEPT malware. Did you see 'Proof Of Concept' listed as a type of malware in Intego's illustration? No. Why? Because they are only demonstration malware that are NOT released into the wild, cannot replicate in the wild, and are only created to prove a software security problem. They are HARMLESS to one and all except on test machines used for EXPERIMENTATION. Anyone telling you that Proof of Concept malware will ever appear on your machine at any time, except within an experimentation situation, are FUDing you. FUD = a classic form of propaganda known as FEAR, UNCERTAINTY and DOUBT.
You can read about FUD here:
Fear, uncertainty and doubt (FUD) is a tactic of rhetoric and fallacy used in sales, marketing, public relations, politics and propaganda.
If you'd like to read about Proof Of Concept malware, check these out:
Proof of concept
Prototype
What is proof-of-concept virus?
And for fun, here is what these two Proof of Concept malware actually do:
A) OSX.MacArena.A - Here is a quotation from 2006 from Kaspersky's Securelist.com:
B) "OSX/Oomp-A or Leap.A" - First off, note use of two different names for the exact same thing, AND the total lack of conformity to the published malware naming standard. I'd be ticked off, except this is again harmless proof of concept malware, so who cares. Here is an article from Macworld, published in 2006, about what is ACTUALLY called the "Oompa-Loompa Trojan" by the first person to publicly describe it, Andrew Welch of Ambrosia Software:
Reports emerge of Mac OS X Trojan horse or worm
But I thought proof of concept OSX.MacArena.A was "the first attempt to create a virus"!!!
Are you getting the idea of how chaotic the anti-malware community can be?
And guess what folks. Ooompa-Loompa was made entirely INERT with the next Apple revision of iChat. So be scared. Be VERY scared!
And no, it's NOT a virus. No, it CANNOT replicate itself in-the-wild. This thing can only replicate via iChat within a LAN. That means it hasn't even got a clue what the Internet is. Got that? NOT-IN-THE-WILD at all. It can't get there. There was only ever ONE place it was ever found on the Internet, at that was in a forum at a Mac rumor website.
V) Then we move along to the wrongful paragraph about BOTs. I'm perfectly happy to ALSO call them by other malware names. But the ONLY bots for Macs exist in the form of Trojan horses. There are three of them: Trojan.OSX.iServices.A - C, which is to say that there are versions A, B and C. They have only ever been found, as Intego indicate, within the installers of pirated software. These include pirated copies of Apple iWork and Adobe Photoshop CS4.
Once Macs were infected, via these pirated installers, with the bots, the computers were then 'zombied' or 'botted'. Via communication over the Internet, these machines then joined into what is called a 'botnet'. In early 2009 there was a guestimate that the resulting botnet contained over 10,000 Macs, which indicates the popularity of pirated software. The only published attack carried out by this botnet that I am aware of was a DDOS, or Distributed Denial of Service attack. I've never heard or read about it again. But note that this malware is indeed still in-the-wild and can infect you.
VI) Then we get to the WORM section: Note how Intego don't list any for Mac. That's because THERE AREN'T ANY for Mac, except as Proof of Concept malware. Yawn. Therefore, this section also requires the removal of the 'YES' to be replaced with:
NO
The description of worms here is poor. Reading this stuff you'd think they were the same thing as viruses. They aren't. Read this from Wikipedia.org:
Computer worm
~~~~~~
I know Intego are not going to be pleased that I've ripped apart this blatant propaganda / FUD piece. To be honest, I'm really miffed that I, a non-professional in the Mac malware field, end up having to point out these ERRORS and FUD. If dimwit security amateur me knows full well the bullshit in this Intego article, why the hell are the 'professionals' at Intego publishing it?!
My proposal:
--
Kids. Didn't I tell you the computer anti-malware community was 'unprofessional'? Here we go again.
For shame Intego! Publishing FUD to sell your anti-malware software. For shame!
I like the folks at Intego a lot. But this is the SECOND time they have outright FUDed the public for the sake of making sales of their indeed superior anti-malware software. Note that this is entirely in line with our current era of PROPAGANDA at the expense of both facts and reality. I DESPISE FUD! I DESPISE PROPAGANDA! If you check out my zunipus blog you'll see I'm well versed on the subject.
This very WRONG page of information was posted at the Intego website this week. It makes me want to gag. It's crap like this that inspires me to keep writing my own, independent, 'hey look at me I have a brain in my head', Mac-Security blog:
Intego: Learn About Mac Malware
The Post-Mortum:
I) This page claims to provide a "clear explanation of what types of viruses and malware are a danger for Mac OS X."
Bullshit.
There is nothing 'clear' about FUDing customers and confusing them with ignorant information. If you haven't already spotted the garbage on this page, read on.
II) The Mac picture provided on the page, with its arrows to various malware, includes the word "Botnet". This is WRONG. There is no such thing as a 'botnet' form of malware. A 'botnet' is the result of having many computers infected with BOT malware. The software that infects your computer is called a 'bot.' Not a 'botnet'. A BOT!
III) The paragraph entitled "MAC VIRUS" is WRONG. There are NO viruses for Mac OS X. There never have been any viruses for Mac OS X. So this paragraph must be proceeded with the word:
NO
The description of viruses by Intego in this wrongful paragraph is entirely inadequate. Read these instead:
Computer Virus
or
What is virus?
In fact there are dozens of pages on the Internet that have superior descriptions of computer viruses. Google "What is a computer virus?"
IV) Examining the wrongful "MAC VIRUS" paragraph we see two wrongful examples. They are NOT viruses. Here is what they REALLY are: PROOF OF CONCEPT malware. Did you see 'Proof Of Concept' listed as a type of malware in Intego's illustration? No. Why? Because they are only demonstration malware that are NOT released into the wild, cannot replicate in the wild, and are only created to prove a software security problem. They are HARMLESS to one and all except on test machines used for EXPERIMENTATION. Anyone telling you that Proof of Concept malware will ever appear on your machine at any time, except within an experimentation situation, are FUDing you. FUD = a classic form of propaganda known as FEAR, UNCERTAINTY and DOUBT.
You can read about FUD here:
Fear, uncertainty and doubt (FUD) is a tactic of rhetoric and fallacy used in sales, marketing, public relations, politics and propaganda.
If you'd like to read about Proof Of Concept malware, check these out:
Proof of concept
Prototype
What is proof-of-concept virus?
And for fun, here is what these two Proof of Concept malware actually do:
A) OSX.MacArena.A - Here is a quotation from 2006 from Kaspersky's Securelist.com:
"Macarena was the first attempt to create a virus for Mac OS X that infects mach-o format executable files. The virus only infects files in the current directory and only runs on Intel platforms, i.e. it does not pose a threat to machines with ppc architecture. These malicious programs are purely proof of concept code, i.e. they demonstrate that such programs can be created."Darn. This thing can only self-propagate within its own current directory. Wow. So scary. It is NOT in the wild. It does NOTHING to harm your computer. Not-a-thing.
B) "OSX/Oomp-A or Leap.A" - First off, note use of two different names for the exact same thing, AND the total lack of conformity to the published malware naming standard. I'd be ticked off, except this is again harmless proof of concept malware, so who cares. Here is an article from Macworld, published in 2006, about what is ACTUALLY called the "Oompa-Loompa Trojan" by the first person to publicly describe it, Andrew Welch of Ambrosia Software:
Reports emerge of Mac OS X Trojan horse or worm
"Reports indicate that someone has let loose a “Trojan horse” or worm for Mac OS X users. The program is hidden within a package that purportedly contains screenshots of Apple’s as-yet unannounced next major revision to Mac OS X. Whether it’s a Trojan horse or worm seems to vary depending on the source of the information."Do you see the word 'virus' in this description? NO.
"So-called Trojan horses are differentiated from viruses because they masquerade as a regular application or file and do not replicate themselves arbitrarily."Ah! So NOT a virus!
"Anti-virus software maker Sophos takes issue with this description claiming this is the “first ever virus for Mac OS X.”Traveling over to the Sophos page, what do we see in the TITLE of their article?
"First ever virus for Mac OS X discoveredSo it's a 'worm', and NOT actually a virus. That's what Sophos are actually saying.
OSX/Leap-A worm spreads via iChat instant messaging software"
But I thought proof of concept OSX.MacArena.A was "the first attempt to create a virus"!!!
Are you getting the idea of how chaotic the anti-malware community can be?
And guess what folks. Ooompa-Loompa was made entirely INERT with the next Apple revision of iChat. So be scared. Be VERY scared!
And no, it's NOT a virus. No, it CANNOT replicate itself in-the-wild. This thing can only replicate via iChat within a LAN. That means it hasn't even got a clue what the Internet is. Got that? NOT-IN-THE-WILD at all. It can't get there. There was only ever ONE place it was ever found on the Internet, at that was in a forum at a Mac rumor website.
V) Then we move along to the wrongful paragraph about BOTs. I'm perfectly happy to ALSO call them by other malware names. But the ONLY bots for Macs exist in the form of Trojan horses. There are three of them: Trojan.OSX.iServices.A - C, which is to say that there are versions A, B and C. They have only ever been found, as Intego indicate, within the installers of pirated software. These include pirated copies of Apple iWork and Adobe Photoshop CS4.
Once Macs were infected, via these pirated installers, with the bots, the computers were then 'zombied' or 'botted'. Via communication over the Internet, these machines then joined into what is called a 'botnet'. In early 2009 there was a guestimate that the resulting botnet contained over 10,000 Macs, which indicates the popularity of pirated software. The only published attack carried out by this botnet that I am aware of was a DDOS, or Distributed Denial of Service attack. I've never heard or read about it again. But note that this malware is indeed still in-the-wild and can infect you.
VI) Then we get to the WORM section: Note how Intego don't list any for Mac. That's because THERE AREN'T ANY for Mac, except as Proof of Concept malware. Yawn. Therefore, this section also requires the removal of the 'YES' to be replaced with:
NO
The description of worms here is poor. Reading this stuff you'd think they were the same thing as viruses. They aren't. Read this from Wikipedia.org:
Computer worm
"Unlike a virus, it does not need to attach itself to an existing program. Worms almost always cause at least some harm to the network, if only by consuming bandwidth, whereas viruses almost always corrupt or modify files on a targeted computer."The main, if not only, point of a worm is self-replication. Whereas, the point of a virus is not merely to replicate but to DAMAGE.
~~~~~~
I know Intego are not going to be pleased that I've ripped apart this blatant propaganda / FUD piece. To be honest, I'm really miffed that I, a non-professional in the Mac malware field, end up having to point out these ERRORS and FUD. If dimwit security amateur me knows full well the bullshit in this Intego article, why the hell are the 'professionals' at Intego publishing it?!
My proposal:
Dear Intego,Where's my aspirin?
FIRE your Marketing Manager. Dishonest marketing damages your company's reputation. Witness Adobe.
And please don't bother writing to me to attempt to explain the bullshit in your article! Just take the article down, remove it, kill it. Then get a serious professional at Intego, (I know they exist! I've talked to them!), to write a seriously HELPFUL, HONEST and INFORMATIVE article that misleads no one and educates everyone. THAT will bolster your reputation and sales. Not this FUD crap.
--
Labels:
bot,
botnet,
Error,
FUD,
Intego,
iServices,
MacArena,
Oompa-loompa,
Proof of Concept malware,
Trojan horse,
virus,
worm,
zombie
Windows Users ONLY:
Adobe Screw Up Yet-Again!
Acrobat & Reader Updates
DON'T Fix PDF Security Hole
--
For Frack's sake! Adobe = Idiotic Security.
I'm patience counting again: 1 - 2 - 3 . . .
NOTE: This is ONLY a Windows user problem. We Mac OS X users can sit back and gasp. But we are NOT affected (as far as we can tell at this time).
We know Adobe security is bad. We know their attitude toward their security problems is bad. But now we can verify that Adobe are indeed idiots at security. This incident throws their security incompetence into a whole other ballpark.
Enough ranting from me. Windows Users, read and weap this message from Intego:
Last Adobe Reader and Acrobat Update Doesn’t Fix PDF Bug
"... It turns out that Adobe’s fix was not enough. Adobe is aware of the issue and will be issuing an update to the update soon."
Keep in mind, Mac users, that if you use Windows you ARE affected. This means if you load Windows via virtualization or natively via Boot Camp. This PDF exploit is active in-the-wild. Beware.
Again, only Acrobat 8 and Reader 8 are safe. You can roll back to those versions and you're fine. It's Windows versions 9.x that are being exploited. Do NOT use them at this time on the Internet. Do NOT use them with any PDF file that you have not verified as 100% authentic and safe.
And of course, if you're affected, write Adobe a great big 'Thank You' note for being so kind, caring and conscientious toward their customers. /s
[Newbies: "/s" designates sarcasm]
--
For Frack's sake! Adobe = Idiotic Security.
I'm patience counting again: 1 - 2 - 3 . . .
NOTE: This is ONLY a Windows user problem. We Mac OS X users can sit back and gasp. But we are NOT affected (as far as we can tell at this time).
We know Adobe security is bad. We know their attitude toward their security problems is bad. But now we can verify that Adobe are indeed idiots at security. This incident throws their security incompetence into a whole other ballpark.
Enough ranting from me. Windows Users, read and weap this message from Intego:
Last Adobe Reader and Acrobat Update Doesn’t Fix PDF Bug
"... It turns out that Adobe’s fix was not enough. Adobe is aware of the issue and will be issuing an update to the update soon."
Keep in mind, Mac users, that if you use Windows you ARE affected. This means if you load Windows via virtualization or natively via Boot Camp. This PDF exploit is active in-the-wild. Beware.
Again, only Acrobat 8 and Reader 8 are safe. You can roll back to those versions and you're fine. It's Windows versions 9.x that are being exploited. Do NOT use them at this time on the Internet. Do NOT use them with any PDF file that you have not verified as 100% authentic and safe.
And of course, if you're affected, write Adobe a great big 'Thank You' note for being so kind, caring and conscientious toward their customers. /s
[Newbies: "/s" designates sarcasm]
--
Wednesday, June 2, 2010
OSX/OpinionSpy:
Mac's First Illegal Spyware
Part I
--
RISK: HIGH
--
RISK: HIGH
--

Introduction:
Up to this point in time, Mac OS X has only had 'legal', publicly available 'spyware'. The most common kind has been keyloggers installed by Mac network administrators into client accounts to keep track of what the client user is doing on the computer and on the Internet. You can grab a list of known 'legal' spyware over at the MacScan website. You can also search for them (using the terms 'spyware' and 'keylogger') at any of the shareware sites, such as VersionTracker.com and MacUpdate.com.
Ten years into the life of Mac OS X we now have our very first actual malware version of spyware. And it's a nasty one.
OSX/OpinionSpy:
I seriously doubt OSX/OpinionSpy is going to be the official name of this spyware. Using the current malware naming standard, my best guess is that it will end up being called Trojan.OSX.OpinionSpy.A. But don't quote me. I am calling it a Trojan horse form of spyware because of its method of infection. It requires you, the user, to install it by providing it with your administrator password. Once it has the admin password it can do what it likes, as is typical with the current crop of Mac Trojans. For now, I will stick with the name Intego have given it.
Thanks to Intego's vigilance in detecting and studying malware for the Mac, we now have some reasonable details about this spyware. We know what it does and we know a lot about where it comes from. At the time of this posting, Intego have two articles in their series on OSX/OpinionSpy:
Intego Security Alert: OSX/OpinionSpy Spyware Installed by Freely Distributed Mac Applications
Further Information about the OSX/OpinionSpy Spyware
NetworkWorld has joined in the research efforts and has come up with a preliminary list of applications that include OSX/OpinionSpy with their installation:
Intego updates Mac users on OSX/OpinionSpy Spyware threat
It might be useful to repeatedly check the article above for further additions to the list. I will also be publishing a continually updating list here in Part II of my own blog series on this malware.
What OSX/OpinionSpy Does:
Read the Intego articles for full details. Below is a very brief summary of what they have discovered:
1) At this time, the infected installers are downloadable from any of the shareware sites as well as from the source developer sites.
2) The download website or the installer may or may not tell you know that the spyware, calling itself a 'market research' program, is included in the installer. If you are warned, obviously don't install the software. I personally cannot abide any form or marketing research data collection on my computers. Sadly, the field of marketing is too full of parasites, aka what I call Marketing Morons (versus beneficial Marketing Mavens) to ever trust your data with anyone.
3) Once the Trojan horse is installed, it takes over your computer with full Root access. At that point it can do anything-at-all to your computer.
4) The basic behavior of OSX/OpinionSpy is that of most spyware applications. It collects masses of data about your computer and sends it off to a collection hub for evaluation and potential distribution to others. This can include all your account IDs and passwords, all your web surfing history, bookmarks, address book data, email addresses, literally everything about you that exists on your computer and on your local network. This is a very thorough method of Phishing you, aka stealing your identity. Plenty of criminals would gladly put your identity to work for nefarious purposes.
HOWEVER, that is not where this spyware stops.
5) It is capable of restarting itself if its process is stopped on your Mac. It is also capable of reinfecting your Mac despite you having deleted any one of the applications it has infected.
6) It opens an HTTP backdoor into your Mac using port 8254.
7) It upgrades itself with new variants of itself, or any other malware it chooses to install. So far one new variant called 'PremierOpinion' has already been discovered.
8) It eats your CPU cycles while it scans your computer files and sends out files and data to the 'bot wrangler' hub. (Typically these hubs are anonymous IRC rooms setup by the bot wrangler).
9) It intercepts and analyzes all data packets coming into and going out of your Mac.
10) It injects code, aka infects itself into the RAM space used by running applications. It also gathers data from application memory space, such as IDs, passwords, credit card numbers, PINs, etc.
11) It occasionally provides an interface for asking users for information it would like to learn, essentially Phishing for your identity via bogus surveys.
12) It is capable of crashing or stopping Macs it has infected, requiring the user to Force-Reboot their computer. Potentially it has corrupted your boot drive.
No doubt, further details about its behavior will be discovered. Considering that this spyware runs with Root authority, you might as well describe it has having botted, zombied or pwned your Mac. This is the worst possible infection situation.
Detection And Prevention:
Intego today provided a 'threat filter' (aka malware signature) update for active versions of VirusBarrier versions 10.5 and 10.6.
As with any Trojan horse, only install software on your Mac that you have verified to be legitimate and malware free. Intego recommend having 'real time scanning' running in their anti-malware application. Another option is to individually scan all application installers you download before you install them. If you fail to use either of these precautions, you should perform a full scan of your Mac.
Using a reverse firewall is also extremely helpful. I use Little Snitch. Intego also include a reverse firewall in VirusBarrier v10.6. In particular, keep an eye out for any application accessing ports 80, 443 and 8254. Personally, I set up a denial rule for 'All Applications' attempting to send data out of port 8254. This is unlikely to entirely block the actions of the spyware, but it can't hurt. This port is very rarely used.
Reverse firewalls also make it easy to scan down a list of applications with rules you have set for accessing your network or the Internet. This can help you identify whether you have some odd or foreign application making connections. If you find one, it is likely useful for you to scan your Mac for all instances of the spyware.
It is also useful to delete mysterious applications from your reverse firewall rules list in order to keep an eye on their further requests for network and Internet access.
Other Anti-Malware applications:
At the moment, only Intego VirusBarrier is able to detect and fully remove this malware. As usual, VirusBarrier is the only commercial anti-malware application I can recommend.
I'm going to keep an eye out for detection and removal by other anti-malware apps. Of the free options it is doubtful that ClamAV (via ClamXav) will detect this malware in the near future. iAntiVirus so far not does detect OSX/OpinionSpy, but I expect they shortly will.
A blog at Sophos describes the experience of running one of the screensaver spyware installers from 7art:
Mac OS X OpinionSpy – same old, same old
In keeping with the chaotic nature of the anti-malware community, Sophos are ignoring the published malware naming standard, calling this malware simply "OpinionSpy". They are also describing it as "monitorware" as opposed to spyware. Yeah, whatever guys.
(o_0)
[Patience requires that I start counting to 10, again...]
Infected Installers:
With time I will be posting a periodically updating list of dangerous installers that will infect your Mac. This will constitute Part II of my blog series on OSX/OpinionSpy. For the moment, the general shortlist is:
A) ANY screensaver installer from 7art-screensavers.com, version 2.6 or above. So far, 29 of their screensavers have been found to be vectors for installing this spyware.
B) The installer for 'MishInc FLV to MP3' available from the MishInc.info website.
I don't know if Intego have contacted VersionTracker or MacUpdate about these dangerous application installers. I will be writing to both of them tomorrow to make certain they know what is going on. If you are a fan of other shareware download sites, please contact them as well.
Stay safe. Stay secure.
:-Derek
:-Derek
Wednesday, April 28, 2010
HellRTS,
The Not Quite In-The-Wild
Hacker Tool "Trojan"

"Take a deep breath and count to ten. One, two, three..."
This past couple weeks the incoherent, or should I say incompetent, nature of the anti-malware community has become evident yet-again through the discovery and discussion about a new variation of a hacker tool called 'OSX.HellRTS.D'. I am going to use that name because my best estimation is that it was first described by Intego, and that is their chosen name. It also follows the published malware naming protocol.
As per usual, other anti-malware companies could not bother to stick to the source name and have proliferated the usual WHATEVER of their own names, those being 'Hellraiser' and 'Pinhead'. Further confusion includes the addition of '.D' at the end of Intego's name. I have no idea why it is there. It indicates that this is supposed to be the FOURTH variant of this 'malware', and yet no one, including Intego of course, provides any reference to variants ".A", ".B" or ".C". I am going to toss out a wild guess that ".D" only means that this hacker tool has three previous versions known well only within the hacker community.
UPDATE: I have verified that 'Hellraiser' is the actual name of the source hacker tool of which HellRTS.D is the fourth variation.
Why I'm counting to ten: Because there are no signs of improvement in the chaotic nature of the anti-malware community. Anti-malware is supposed to be a 'professional' endeavor. The only reliably professional thing I have found so far in the community is that people make money in it. Otherwise, as a trained and experienced scientist, I find the community to be nothing more than 'A Pack Of Cards', as Lewis Carroll put it. That is to say it is a bunch of playing card characters disagreeing with one another over nonsense.

Which is to say quite bluntly:
The anti-malware community is not entirely scientific in nature.
The anti-malware community is not entirely scientific in nature.
(I am so itching to have someone disagree with my statement above. I dare you.)
Of course, enough of my own injection of subjective emotion into what should be an objective, scientific subject. Here's the lowdown on this new 'Trojan':
So far OSX.HellRTS is entirely ignorable. It is being distributed as a hacker tool out on the Internet, but has NOT been utilized as malware 'in-the-wild'. Instead it is being described as capable of being used as malware in-the-wild. When or if OSX.HellRTS becomes anything more than a hacker tool, I'll provide more detailed information.
In the meantime, here are some links for those who would like to dig around in the details:
David Harley has written a series of articles about HellRTS at his poorly named "Mac Virus" blog. David provides some very useful information through his professional work for the Mac community, which I very much appreciate. However, David also often makes his own contributions to the chaotic nature of the anti-malware community, fitting my fittingly harsh appraisal. Therefore, when you read his articles, "Take a deep breath and count to ten...."
Hellish Mac Malware
More on that hellish Mac malware...
OSX/HellRTS - more info
Here are Intego's source articles about OSX.HellRTS:
INTEGO SECURITY MEMO – April 16, 2010
HellRTS Backdoor Can Allow Malicious Remote Users to Control Macs
Intego Security Memo: HellRTS Backdoor Can Allow Malicious Remote Users to Control Macs
Now for the firing squad:
These are reports from other anti-malware companies that chose to use their own WHATEVER name for OSX.HellRTS. They should be lined up against a wall. As you click each of the links below, think to yourself:
"BOOM! HEADSHOT!"
Sophos: "OSX/Pinhead-B"
CA: "OSX/HellRTS"
iAntiVirus (PC Tools): "Backdoor.OSX.Hellraiser" <- Search on this page for 'Hellraiser' to read its description.

As usual I'm not going to bother with references to Symantec or MacScan articles. Why? Why bother.
If there are hackers who'd like to share the history of the Hellraiser hacking tool, please let us know via the comments! I'd be most interested.
Labels:
backdoor,
hacker tool,
Hellraiser,
HellRTS,
Intego,
Pinhead
Friday, March 19, 2010
Intego VirusBarrier Review Part II
--
My friend and former employer Michael Flaminio posted a very nice video review of Intego VirusBarrier version 10.6 over at Insanely-Great Mac. You can also access it at YouTube. I could not provide any improvement over Michael's review, so please give it a viewing! VirusBarrier is the only Mac OS X anti-malware program I can recommend for individual users. See my Part I review for further details and opinions regarding the program.
This past week someone told me that FUD mongers Symantec have finally gotten their act together, allowing their Norton Anti-Virus program to work properly without damaging your hard drive. Imagine that! I am seeking verification that this is indeed the case, if anyone would please let me know. Much obliged. If I get enough happy shiny smiley stories I may dare to perform some testing on the latest version myself.
Happy spring to the northern hemisphere! Happy fall to the southern hemisphere. (-_^)
--
My friend and former employer Michael Flaminio posted a very nice video review of Intego VirusBarrier version 10.6 over at Insanely-Great Mac. You can also access it at YouTube. I could not provide any improvement over Michael's review, so please give it a viewing! VirusBarrier is the only Mac OS X anti-malware program I can recommend for individual users. See my Part I review for further details and opinions regarding the program.
This past week someone told me that FUD mongers Symantec have finally gotten their act together, allowing their Norton Anti-Virus program to work properly without damaging your hard drive. Imagine that! I am seeking verification that this is indeed the case, if anyone would please let me know. Much obliged. If I get enough happy shiny smiley stories I may dare to perform some testing on the latest version myself.
Happy spring to the northern hemisphere! Happy fall to the southern hemisphere. (-_^)
--
Friday, January 15, 2010
Intego VirusBarrier Version 10.6 Review:
Part I
--
Let's start with the GOOD NEWS:

Intego VirusBarrier is the only anti-malware program I can recommend for Mac OS X. Its interface and features are unmatched by any similar program. The signature updates are regular and reliable. Intego stay right up-to-date with all Mac OS X malware. The program is 100% compatible with Snow Leopard. Ignore all reports to the contrary. For Mac users who want a top notch single-user anti-malware program, this is the only one. Nothing compares, except perhaps Sophos, which is only designed for network users.
The new VirusBarrier 10.6 version adds a bunch of new security features worth the upgrade price. Some features are redundant to those already in Safari and FireFox. The reverse firewall is the only new feature I care about. Reverse Firewalls stop dead any way to zombie your Mac. They also stop all software from 'phoning home'. I've been using Little Snitch for years and love it. The reverse firewall in VirusBarrier 10.6 is not as good as Little Snitch. But it's there and it's useful.

A new single user license for VirusBarrier costs $49.95 and protects two Macs. A new family license is $69.95 and protects five Macs.The 10.6 upgrade is potentially free for those who purchased VirusBarrier 10.5 on or after November 25, 2009 through April 13, 2010. See Intego for details. Otherwise, the upgrade is $34.95 for single users. A family pack upgrade is $59.95 for protecting five Macs. Every new or upgrade license includes a year's subscription of malware signatures.
Intego also provide an occasionally useful and intelligent Mac Security Blog.
Now the BAD NEWS:

1) Accompanying the 10.6 update is a new advertising campaign that makes several wrong and ridiculous claims consisting of what is traditionally called BULL SHITE or FUD. Enjoy:

I hope Intego have brains enough to dump the false advertising before they get sued. I despise FUD and would hate to have to put Intego on a par with Symantec, the renowned masters of anti-Mac security FUD and makers of easily the worst anti-malware for Mac.
2) Yearly malware subscriptions for VirusBarrier are required and expensive. $29.95 for one year. Yikes! A two year subscription is 50% off the second year at $44.90. If you're up for renewal and are using version 10.5, you might as well upgrade to 10.6 at $34.95 and get the included one year subscription, saving yourself $25.
3) Intego outright refuse to provide a list of malware detected and removed by VirusBarrier. That's idiotic and I've directly told them so. They don't care. Instead, I follow the imperfect but useful Threats Database provided by the PC Tools site, the makers of the up and coming competitor program iAntiVirus.
4) And of course, if you turn on the Real-Time Scanner feature, expect VirusBarrier to eat your CPU. So turn it off. You don't need it unless you're dealing with LUSERs, in which case all you have to do is prevent them from having access to an administrator account and password. It's seriously that simple.
CONCLUSION:
So what is VirusBarrier for? It protects you from LUSER behavior and lets you find and wipe out Windows malware you may be passing along to Windows users.
If you're a conscientious Mac user who checks the validity of all software you install, you don't need VirusBarrier to protect your Mac. There are less reliable free alternatives if you want to try them out, such as ClamXav and iAntiVirus. (Avoid MacScan, which is ultra-lame).
I'll be posting a detailed feature review in Part II after I test the new VirusBarrier 10.6.3 update.
--
Let's start with the GOOD NEWS:

Intego VirusBarrier is the only anti-malware program I can recommend for Mac OS X. Its interface and features are unmatched by any similar program. The signature updates are regular and reliable. Intego stay right up-to-date with all Mac OS X malware. The program is 100% compatible with Snow Leopard. Ignore all reports to the contrary. For Mac users who want a top notch single-user anti-malware program, this is the only one. Nothing compares, except perhaps Sophos, which is only designed for network users.
The new VirusBarrier 10.6 version adds a bunch of new security features worth the upgrade price. Some features are redundant to those already in Safari and FireFox. The reverse firewall is the only new feature I care about. Reverse Firewalls stop dead any way to zombie your Mac. They also stop all software from 'phoning home'. I've been using Little Snitch for years and love it. The reverse firewall in VirusBarrier 10.6 is not as good as Little Snitch. But it's there and it's useful.

A new single user license for VirusBarrier costs $49.95 and protects two Macs. A new family license is $69.95 and protects five Macs.The 10.6 upgrade is potentially free for those who purchased VirusBarrier 10.5 on or after November 25, 2009 through April 13, 2010. See Intego for details. Otherwise, the upgrade is $34.95 for single users. A family pack upgrade is $59.95 for protecting five Macs. Every new or upgrade license includes a year's subscription of malware signatures.
Intego also provide an occasionally useful and intelligent Mac Security Blog.
Now the BAD NEWS:

1) Accompanying the 10.6 update is a new advertising campaign that makes several wrong and ridiculous claims consisting of what is traditionally called BULL SHITE or FUD. Enjoy:
"More and more malware is discovered every day. Macintosh computers face threats from viruses, Trojan horses, worms and more."Incorrect! There are ONLY Trojan horses for Mac OS X. Period. The End. If you believe otherwise, you've been duped.
"VirusBarrier X6, the Lowest-Priced Mac Antivirus"No. FREE would be 'The Lowest-Priced Mac Antivirus', and there are a few of those to choose from. See below.
"... simply visiting a booby-trapped web page can compromise your Mac."This has never happened on Mac OS X in the wild or in a 'Crack A Mac' competition without an account user providing deliberate sabotage assistance. However it 'could' happen if a JavaScript or Java security hole wasn't patched in your web browser or operating system. (Readers of my posts know what contempt I have for the state of JavaScript).

I hope Intego have brains enough to dump the false advertising before they get sued. I despise FUD and would hate to have to put Intego on a par with Symantec, the renowned masters of anti-Mac security FUD and makers of easily the worst anti-malware for Mac.
2) Yearly malware subscriptions for VirusBarrier are required and expensive. $29.95 for one year. Yikes! A two year subscription is 50% off the second year at $44.90. If you're up for renewal and are using version 10.5, you might as well upgrade to 10.6 at $34.95 and get the included one year subscription, saving yourself $25.
3) Intego outright refuse to provide a list of malware detected and removed by VirusBarrier. That's idiotic and I've directly told them so. They don't care. Instead, I follow the imperfect but useful Threats Database provided by the PC Tools site, the makers of the up and coming competitor program iAntiVirus.
4) And of course, if you turn on the Real-Time Scanner feature, expect VirusBarrier to eat your CPU. So turn it off. You don't need it unless you're dealing with LUSERs, in which case all you have to do is prevent them from having access to an administrator account and password. It's seriously that simple.
CONCLUSION:
So what is VirusBarrier for? It protects you from LUSER behavior and lets you find and wipe out Windows malware you may be passing along to Windows users.
If you're a conscientious Mac user who checks the validity of all software you install, you don't need VirusBarrier to protect your Mac. There are less reliable free alternatives if you want to try them out, such as ClamXav and iAntiVirus. (Avoid MacScan, which is ultra-lame).
I'll be posting a detailed feature review in Part II after I test the new VirusBarrier 10.6.3 update.
--
Monday, July 6, 2009
Quickie Reviews of ClamXav, iAntiVirus and MacScan
--
Recently, I've been testing the free anti-malware options for Mac. At the moment, none of them are perfect. But there is progress! Below are posts I made this week over at the VersionTracker.com sites regarding iAntiVirus, ClamXav and MacScan:
I) MacScan Is Unreliable:
III) ClamXav: Progress! But Still Waiting For Full Mac Malware Detection:
Recently, I've been testing the free anti-malware options for Mac. At the moment, none of them are perfect. But there is progress! Below are posts I made this week over at the VersionTracker.com sites regarding iAntiVirus, ClamXav and MacScan:
I) MacScan Is Unreliable:
I've tested MacScan several times over the course of several versions. The results are consistently flaky. It is impossible to get it to detect items reliably. Instead you have to run it over and over and over and over to get the thing to pick up everything.II) iAntiVirus Is Basic, Not Perfect, Mostly Works:
For some purposes, like detecting the full raft of 'legal' Mac Spyware and Tracking Cookies, this is the only show in town. But OMG does it suck. IMHO MacScan requires an entire rewrite in order get a rating better than one star. The developers have done some nice things like providing some sort-of working removal tools for current Trojans. So they aren't evil. They're just lousy programmers.
Keep in mind that this thing is FREE:Addendum: I should note that iAntiVirus also fails to detect RSPlug.I and .L.
Despite some outright dishonest flame reviews of iAntiVirus here at VT, it actually does work, mostly. I let it loose on a folder full of Trojans a friend shared with me and it successfully found MOST of them:
Trojan.OSX.RSPlug.C, D & F
Trojan.OSX.iServices.A & B
Problems:
1) It did NOT find Trojan.OSX.RSPlug.E, of which I had a number of copies in my folder-full-of-Trojans. That is upsetting.
2) It also uses wrong names for the iServices Trojans. But sadly, despite a clear naming convention for malware, hardly anyone bothers, which is of course pathetic.
3) The app only gives you two choices when it finds malware: Either remove the malware or nothing. There is no sophistication to this app whatsoever.
Maybe the 'Pro' version is way better. I don't know. The PC Tools website certainly 'claims' iAntiVirus detects all the current Mac malware. Judging from the free version, it only finds some Mac malware. Maybe I'll test the Pro version some time.
In the meantime, I own Intego VirusBarrier, which frankly is the ONLY anti-malware app for Macs I can recommend. It works great, detects everything, is updated daily, is entirely reliable, is never a CPU hog, and has all the bells and whistles you could want.
If you want to stick with free stuff, the best idea is to use BOTH iAntiVirus AND ClamXav. Between the two of them you're probably just fine. This is thanks to the fact that the excellent author of ClamXav went out of his way to convince the ClamAV project to accept contemporary Mac malware sample definitions. *Applause*
III) ClamXav: Progress! But Still Waiting For Full Mac Malware Detection:
Recently, ClamXav developer Mark Allen went out of his way to convince the ClamAV project to accept contemporary Mac malware samples for definition integration. *Applause*--
However, my testing today shows only partial progress from the ClamAV project.
MY TEST: A friend provided me with a large collection of recent Mac Trojan horses including all the iServices and RSPlug malware. There were 18 samples in all. I used them as my testing ground.
RESULTS: ClamXav, via the latest engine and definitions of ClamAV, found 10 of them and successfully put them into my quarantine folder.
As my control, I used Intego VirusBarrier, latest version with current definitions. It found all but one of the malware. (The undetected malware was a .pkg with the payload inside a .bom file).
What ClamXav, via ClamAV, didn't detect:
DMG files containing:
RSPlug.D
RSPlug.E
RSPlug.F
RSPlug.I
RSPlug.L
I'm testing iAntiVirus, (runs on Mac OS X Leopard only). But it too is unable to detect RSPlug.E [as well as .I and .L].
CONCLUSIONS:
1) ClamXav is the best of the free anti-malware application options. But the ClamAV database of current Mac malware is still not completely up to date. However, it is far better than it was a couple months ago thanks to Mark Allen's work.
2) Even with the combination of ClamXav and iAntiVirus, it is still possible to have a current Mac Trojan sneak by. But then again, Intego VirusBarrier missed one as well, possibly due to the way the Trojan was packaged.
A high quality paid anti-malware application remains the best way to go for professional use. But for casual use, ClamXav is the best, despite remaining ClamAV deficiencies. I would combine it with iAntiVirus as well if you are running Mac OS X Leopard.
Labels:
ClamXav,
iAntiVirus,
Intego,
iServices,
MacScan,
Mark Allan,
RSPlug,
Trojan,
VirusBarrier
Friday, May 29, 2009
Microsoft Senior Security Architect Said WHAT?!
Someone needs a good spanking and a time out for bad behavior. He's considered to be a professional computer security expert, (so it's not me!).
This afternoon I was checking out the Intego Mac Security Blog and read about interviews ZDNet Australia had done with security specialists regarding the question "Do Mac Users Need Antivirus Software?" (They got the software category wrong as usual. It's anti-malware, not 'anti-virus'. I'll go down in history as the curmudgeon who chanted this fact to the grave, and nobody cared. Poor me). So I clicked over to ZDNet OZ, read their article and watched the video, found HERE.
In the video, note the fellow in the white shirt with a British accent. That's Greg Singh from RSA. As Intego point out, Singh is incorrect to say Mac users will have to get used to the degradation in performance caused by anti-malware applications. He could be talking specifically about Symantec's Norton Antivirus for Mac, in which case no one could argue with him. He also insinuates that Apple have said Mac OS X is not susceptible to 'viruses'. Oops, I think he got his Apples mixed up. He must have meant Apple Corps, the folks who make Beatles CDs. Yeah, I'd agree that Beatles recordings are not susceptible to viruses. **snicker**
Then there's the guy in the black t-shirt and hat reading 'ULTIMATE-DEFENCE". That's Rocky Heckman from Microsoft. He has the title of "Microsoft Senior Security Architect". I was freaked at what was coming out of his mouth. First he thinks BSD is something new to Mac OS X Tiger. He was born yesterday. Then he says that because BSD is part of Mac OS X, hackers are now realizing they can write 'viruses' for it, "and there have been a couple out there." He's from the Bizarro World. There are no viruses for Mac OS X. There are only Trojans, and he knows the difference. I wrote a ripping comment about Mr. Heckman over at the ZDNet OZ site. See below.
Then there's an Australian fellow in a white striped shirt with a big pad and marker hanging around his neck. I don't know his name, sorry. His odd statement, if you listen carefully, is that anti-malware products for Mac OS X are 'immature'. Based on what information? Based on ignorance. Very strange.
OK, so where were all these incorrect people when they were interviewed? The AusCERT 2009 IT Security Conference. The mind boggles.
Here is the concerned comment I wrote to ZDNet Australia regarding the statements of Mr. Heckman from Microsoft:
This afternoon I was checking out the Intego Mac Security Blog and read about interviews ZDNet Australia had done with security specialists regarding the question "Do Mac Users Need Antivirus Software?" (They got the software category wrong as usual. It's anti-malware, not 'anti-virus'. I'll go down in history as the curmudgeon who chanted this fact to the grave, and nobody cared. Poor me). So I clicked over to ZDNet OZ, read their article and watched the video, found HERE.
In the video, note the fellow in the white shirt with a British accent. That's Greg Singh from RSA. As Intego point out, Singh is incorrect to say Mac users will have to get used to the degradation in performance caused by anti-malware applications. He could be talking specifically about Symantec's Norton Antivirus for Mac, in which case no one could argue with him. He also insinuates that Apple have said Mac OS X is not susceptible to 'viruses'. Oops, I think he got his Apples mixed up. He must have meant Apple Corps, the folks who make Beatles CDs. Yeah, I'd agree that Beatles recordings are not susceptible to viruses. **snicker**
Then there's the guy in the black t-shirt and hat reading 'ULTIMATE-DEFENCE". That's Rocky Heckman from Microsoft. He has the title of "Microsoft Senior Security Architect". I was freaked at what was coming out of his mouth. First he thinks BSD is something new to Mac OS X Tiger. He was born yesterday. Then he says that because BSD is part of Mac OS X, hackers are now realizing they can write 'viruses' for it, "and there have been a couple out there." He's from the Bizarro World. There are no viruses for Mac OS X. There are only Trojans, and he knows the difference. I wrote a ripping comment about Mr. Heckman over at the ZDNet OZ site. See below.
Then there's an Australian fellow in a white striped shirt with a big pad and marker hanging around his neck. I don't know his name, sorry. His odd statement, if you listen carefully, is that anti-malware products for Mac OS X are 'immature'. Based on what information? Based on ignorance. Very strange.
OK, so where were all these incorrect people when they were interviewed? The AusCERT 2009 IT Security Conference. The mind boggles.
Here is the concerned comment I wrote to ZDNet Australia regarding the statements of Mr. Heckman from Microsoft:
Microsoft Senior Security Architect Said WHAT?!--
"Microsoft senior security architect Rocky Heckman said AV became necessary when Apple in 2001 decided to underpin OS X Tiger with the BSD operating system because it made Macs an easier platform to write malicious code for."
Why did anyone ask Mr. Heckman his opinion? We certainly have no reason to care. Windows is the single LEAST secure operating system, commercial or Open Source, available on the planet.
Why Heckman's opinion is lunatic:
1) Apple didn't decide to underpin Tiger with BSD. NeXT decided to underpin NeXTStep with BSD decades ago! Mac OS X inherited it when Apple decided to make NeXTStep/OpenStep the foundation for Rhapsody, which was then developed into Mac OS X.
2) The three most secure operating systems on the planet have been repeatedly proven to be:
A) OpenBSD
B) FreeBSD
C) Mac OS X
Mac OS X incorporates elements of both OpenBSD and FreeBSD into it's core OS called Darwin OS. So what Mr. Heckman it talking about is incomprehensible. He is either a blithering idiot or is pulling a FUD manoeuvre by telling the opposite of the truth in order to fool the public that black is white, war is peace, hate is love, the usual doublespeak routine from the book '1984'. Shame on Mr. Heckman.
This has to be one of the most dishonest statements from a Microsoft executive of all time. It's running neck-and-neck with Bill Gates' moronic statement that Mac OS X is exploited everyday, when it fact it is HIS operating system that is exploited every day.
Or maybe there's lead in the water over at Redmond. (o_0)
Thursday, May 21, 2009
Java is DANGER! Apple is SLOW POKE!
--
One of my favorite jabs at the anti-Mac security FUD mongers is to point out that their FUD attack party, ongoing since it was started by Symantec way back in August 2005, has happily prodded Apple to get serious about Mac OS X security updates. I then extend them a hearty handshake and gleefully, maniacally, laugh.
However, Mac security mavens point out that Apple is still a slow poke. Damned right! There are a couple short articles over at Intego about an ongoing security hole in the current implementation of Java in Mac OS X:
-> Apple Hasn’t Updated Java to Protect Mac Users from Critical Vulnerabilities
-> Intego Security Memo: Java Vulnerability
To defenders of the faith, such as myself, this is annoying. First off, we get to be poked by the FUD mongers with the 'see, I told you' routine. Second off, I am so sick of the corrosion that has happened to the great and shiny image in the sky of Java being this ultra-safe, can't break into your computer, can't hurt you, technology. Yeah, and Sun is now no more. Justice is served. But we're stuck with the mess as a web standard.
*rolling eyes*
--
One of my favorite jabs at the anti-Mac security FUD mongers is to point out that their FUD attack party, ongoing since it was started by Symantec way back in August 2005, has happily prodded Apple to get serious about Mac OS X security updates. I then extend them a hearty handshake and gleefully, maniacally, laugh.
However, Mac security mavens point out that Apple is still a slow poke. Damned right! There are a couple short articles over at Intego about an ongoing security hole in the current implementation of Java in Mac OS X:
-> Apple Hasn’t Updated Java to Protect Mac Users from Critical Vulnerabilities
-> Intego Security Memo: Java Vulnerability
To defenders of the faith, such as myself, this is annoying. First off, we get to be poked by the FUD mongers with the 'see, I told you' routine. Second off, I am so sick of the corrosion that has happened to the great and shiny image in the sky of Java being this ultra-safe, can't break into your computer, can't hurt you, technology. Yeah, and Sun is now no more. Justice is served. But we're stuck with the mess as a web standard.
*rolling eyes*
--
Wednesday, April 29, 2009
Dump Adobe Reader? Yeah, why not.
--
Intro: I never like articles with a title ending in a question mark. You know what you're going to get: no answer to the question. Therefore, they are typically filler. Yawn on that. So here is my question and answer title. Let's get to the point right off the bat: Adobe Reader is a security risk.
The chatter on the net this past week has come to the conclusion that the long line of security holes in Adobe Reader over the past two years is enough already. Dump the thing. It's like my conclusion from decades past that Windows, among its many disappointments, is too much of a security risk to use professionally. That any business or any government uses it greatly concerns me. But it's not Microsoft bashing day. It's Adobe bashing day. If you don't need Adobe Reader, don't use it. Thankfully, Mac OS X users have Apple's Preview application, which has not got the JavaScript vulnerabilities of Adobe Reader. So use Preview instead. It's not totally immune to infected PDF files, but it's much safer than Adobe Reader.
OK, it's not like anyone's Mac got pwned by using Adobe Reader. There is no malware targeting Macs that I know of that weasels its way in via holes in Adobe Reader. So really there is no major alarm going off telling us to kick Adobe Reader off the bus for having cooties. But considering that Mac OS X is the safest professional operating system on the planet (not that I'm dissing Linux mind you), avoiding Adobe Reader at this time is a very good idea.
Personally, I've been a fan of PDF since Adobe Acrobat version 3. It's brilliant and has only become better over time. Thank you Adobe, and especially thank you for making it an open standard. Its integration into the core of Mac OS X is incredible. However, Adobe allowed in some poor code, including support for the catastrophe oddly known as JavaScript. I'll skip my usual lecture on how it got its misnomer and how it was ruined as a standard by Microsoft. Simply know that it is a security holey mess. Apple has gotten burned by JavaScript in QuickTime since 2006. The same JavaScript insecurities are equally plaguing Adobe Reader. Apple got control of their JavaScript problems. Adobe are still playing catch up.
Me, I'll still continue to use Acrobat. I'll still keep Reader around for when I absolutely need it. And there are indeed times when I require Reader. But I'm also going to keep an eye on the latest Reader problems and continue to update it (manually!) when updates are offered.
--
Intro: I never like articles with a title ending in a question mark. You know what you're going to get: no answer to the question. Therefore, they are typically filler. Yawn on that. So here is my question and answer title. Let's get to the point right off the bat: Adobe Reader is a security risk.
The chatter on the net this past week has come to the conclusion that the long line of security holes in Adobe Reader over the past two years is enough already. Dump the thing. It's like my conclusion from decades past that Windows, among its many disappointments, is too much of a security risk to use professionally. That any business or any government uses it greatly concerns me. But it's not Microsoft bashing day. It's Adobe bashing day. If you don't need Adobe Reader, don't use it. Thankfully, Mac OS X users have Apple's Preview application, which has not got the JavaScript vulnerabilities of Adobe Reader. So use Preview instead. It's not totally immune to infected PDF files, but it's much safer than Adobe Reader.
OK, it's not like anyone's Mac got pwned by using Adobe Reader. There is no malware targeting Macs that I know of that weasels its way in via holes in Adobe Reader. So really there is no major alarm going off telling us to kick Adobe Reader off the bus for having cooties. But considering that Mac OS X is the safest professional operating system on the planet (not that I'm dissing Linux mind you), avoiding Adobe Reader at this time is a very good idea.
Personally, I've been a fan of PDF since Adobe Acrobat version 3. It's brilliant and has only become better over time. Thank you Adobe, and especially thank you for making it an open standard. Its integration into the core of Mac OS X is incredible. However, Adobe allowed in some poor code, including support for the catastrophe oddly known as JavaScript. I'll skip my usual lecture on how it got its misnomer and how it was ruined as a standard by Microsoft. Simply know that it is a security holey mess. Apple has gotten burned by JavaScript in QuickTime since 2006. The same JavaScript insecurities are equally plaguing Adobe Reader. Apple got control of their JavaScript problems. Adobe are still playing catch up.
Me, I'll still continue to use Acrobat. I'll still keep Reader around for when I absolutely need it. And there are indeed times when I require Reader. But I'm also going to keep an eye on the latest Reader problems and continue to update it (manually!) when updates are offered.
--
Saturday, April 18, 2009
The First Reported Mac BOTNET
--
Let me first share news from SANS Institute, then provide a brief perspective on the situation.
Below is a quote from SANS NewsBites Volume 1, Number 30, released last night. (I added some bolding for emphasis). You can sign up for the SANS newsletters HERE.
While all the FUD mongers have a sadism party at our expense, (and they will), keep in mind that NONE of the current Mac malware is able in penetrate any Mac unless the user (often called the 'luser') deliberately installs a Trojan horse on their computer. This happens specifically because the user has been conned by what is called Social Engineering, or in this case, the luser is using pirating software that has had the Trojan carefully placed in the installer to go along for the ride. What do you call it when a dirty deed is done to someone pulling a dirty deed? How about 'Dishonor Among Thieves'. It is more like poetic justice, parasite chewing on parasite.
Anyway, Mac Botnets have arrived. What is done with them will be of interest. Typically these days they are used for money making schemes. Go read all the news about the Windows Conficker worm scare of April 1st and beyond. Once created via infection, a botnet can pull off just about anything you can do over the Internet except in mass numbers at one time.
OK! You're a luser and maybe you did something that could have gotten you infected. Now what?
What NOT to use:
ClamAV. Worthless for Macs. I've covered this disappointment several times.
MacScan. The botnet Trojans are out of its league. It's clunky unreliable software anyway.
Symantec Norton Whatever. I consistently get reports that Norton Anti-Virus continues to be one of the single most buggy and CPU hogging applications you can buy for Macintosh. Symantec also invented the anti-Mac security FUD campaign back in 2005. Save your money and your patience. Avoid. Run away. Just my opinion.
Freeware:
iAntiVirus from PC Tools. It can detect and remove all current Mac malware. You don't have to pay for the application unless you are a business or are running a large network. The paid version offers technical support. Note that it only runs on Leopard. I use it and find it to be very simple and unobtrusive.
Shareware / Commercial-ware:
Sophos Anti-Virus. It is designed for companies and networks of computers.
Intego VirusBarrier. I find them to be the best-in-class for single users. I'm disappointed at their disorganization as a company. But the program is top notch. Just be prepared to shell out money year after year. Bleh. Nonetheless, I own it, use it and like it.
I used to use Virex X, now called McAfee Virus Scan. But it got clunky. Many people downright hate it. I don't know why. These days it is designed for companies and networks, not single users. I would have shoveled McAfee into the grave along side Symantec for having FUDed the Mac. But oddly, their CEO ended up stating that the single best way to escape computer malware was to "buy a Mac." So they can't be entirely stupid over there.
There is other stuff around, but it makes me yawn. You can get a listing of it all at the download sites by searching for 'virus'.
DEFENSE!
If you are in charge of a home computer shared by others, or you are an IT manager, stop the luser users from installing Trojans by giving them Mac OS X accounts that Do Not Allow Program Installation! If a user wants a program installed, let them ask you to do it for them in YOUR account. Then give them access to the program.
But of course this means that YOU, the boss of the machines, have to be careful too. Always verify that what you install has specifically been tested somewhere. I always use the download sites like VersionTracker or MacUpdate. There are many others. Be sure that either the site itself has tested that version of the program and given it an OK, or that a lot of users have tested it and OKed it. Buy commercial-ware directly from the company, and make certain they are entirely, unquestionably reputable. Adobe.com = reliable. Jake's Super Deluxe Fly-By-Nite Site.com ≠ reliable. You get the idea.
And just to tick off the FUD mongers:
A) There is no such thing as a 'virus' for Mac OS X.
B) There is no such thing as a 'worm' for Mac OS X.
C) There is no such thing as illicit 'spyware' for Mac OS X. All Mac spyware is sold legally for the purpose of surveillance of network machines.
D) There is no such thing as 'security by obscurity' for Mac OS X. If you know how to do math, you can prove this for yourself. Go backwards in my blog if you want to read the gravestone I wrote for this mythological absurdity form of FUD.
E) As a Mac user you must keep computer security in mind. Follow the basic rules:
And of course, don't ever pirate software. Now it's extra dangerous. If that gets you excited, welcome to the botnet.
:-Derek
--
Let me first share news from SANS Institute, then provide a brief perspective on the situation.
Below is a quote from SANS NewsBites Volume 1, Number 30, released last night. (I added some bolding for emphasis). You can sign up for the SANS newsletters HERE.
--Trojan in Pirated Mac Software Helped Create First Mac BotnetIndeed it has. "Several Thousand Computers." This is incredibly sad, but also inevitable.
(April 15, 2009)
Malware embedded in pirated versions of Apple's iWork and Adobe Photoshop CS4 for Mac that were available over a peer-to-peer network in January is responsible for what appears to be the first known Mac botnet. The zombie network attempted to launch a distributed denial-of-service (DDoS) attack against an unidentified website. The malware had spread to several thousand computers before it was identified.
http://www.cbc.ca/technology/story/2009/04/15/ibotnet-trojan.html
http://blogs.zdnet.com/security/?p=3157
[Editor's Note (Honan, Schultz): Looks like the Mac platform is an increasingly fruitful target for cyber criminals. ]
While all the FUD mongers have a sadism party at our expense, (and they will), keep in mind that NONE of the current Mac malware is able in penetrate any Mac unless the user (often called the 'luser') deliberately installs a Trojan horse on their computer. This happens specifically because the user has been conned by what is called Social Engineering, or in this case, the luser is using pirating software that has had the Trojan carefully placed in the installer to go along for the ride. What do you call it when a dirty deed is done to someone pulling a dirty deed? How about 'Dishonor Among Thieves'. It is more like poetic justice, parasite chewing on parasite.
Anyway, Mac Botnets have arrived. What is done with them will be of interest. Typically these days they are used for money making schemes. Go read all the news about the Windows Conficker worm scare of April 1st and beyond. Once created via infection, a botnet can pull off just about anything you can do over the Internet except in mass numbers at one time.
OK! You're a luser and maybe you did something that could have gotten you infected. Now what?
What NOT to use:
ClamAV. Worthless for Macs. I've covered this disappointment several times.
MacScan. The botnet Trojans are out of its league. It's clunky unreliable software anyway.
Symantec Norton Whatever. I consistently get reports that Norton Anti-Virus continues to be one of the single most buggy and CPU hogging applications you can buy for Macintosh. Symantec also invented the anti-Mac security FUD campaign back in 2005. Save your money and your patience. Avoid. Run away. Just my opinion.
Freeware:
iAntiVirus from PC Tools. It can detect and remove all current Mac malware. You don't have to pay for the application unless you are a business or are running a large network. The paid version offers technical support. Note that it only runs on Leopard. I use it and find it to be very simple and unobtrusive.
Shareware / Commercial-ware:
Sophos Anti-Virus. It is designed for companies and networks of computers.
Intego VirusBarrier. I find them to be the best-in-class for single users. I'm disappointed at their disorganization as a company. But the program is top notch. Just be prepared to shell out money year after year. Bleh. Nonetheless, I own it, use it and like it.
I used to use Virex X, now called McAfee Virus Scan. But it got clunky. Many people downright hate it. I don't know why. These days it is designed for companies and networks, not single users. I would have shoveled McAfee into the grave along side Symantec for having FUDed the Mac. But oddly, their CEO ended up stating that the single best way to escape computer malware was to "buy a Mac." So they can't be entirely stupid over there.
There is other stuff around, but it makes me yawn. You can get a listing of it all at the download sites by searching for 'virus'.
DEFENSE!
If you are in charge of a home computer shared by others, or you are an IT manager, stop the luser users from installing Trojans by giving them Mac OS X accounts that Do Not Allow Program Installation! If a user wants a program installed, let them ask you to do it for them in YOUR account. Then give them access to the program.
But of course this means that YOU, the boss of the machines, have to be careful too. Always verify that what you install has specifically been tested somewhere. I always use the download sites like VersionTracker or MacUpdate. There are many others. Be sure that either the site itself has tested that version of the program and given it an OK, or that a lot of users have tested it and OKed it. Buy commercial-ware directly from the company, and make certain they are entirely, unquestionably reputable. Adobe.com = reliable. Jake's Super Deluxe Fly-By-Nite Site.com ≠ reliable. You get the idea.
And just to tick off the FUD mongers:
A) There is no such thing as a 'virus' for Mac OS X.
B) There is no such thing as a 'worm' for Mac OS X.
C) There is no such thing as illicit 'spyware' for Mac OS X. All Mac spyware is sold legally for the purpose of surveillance of network machines.
D) There is no such thing as 'security by obscurity' for Mac OS X. If you know how to do math, you can prove this for yourself. Go backwards in my blog if you want to read the gravestone I wrote for this mythological absurdity form of FUD.
E) As a Mac user you must keep computer security in mind. Follow the basic rules:
- Make regular backups. This is the #1 Rule Of Computing.
- Learn how to use your router's firewall and use it.
- Learn how to use Mac OS X's built-in firewall and use it.
- Always use password protected accounts. Make very sure your password is strong, obscure, unintuitive and plain old nasty. Be sure you remember it. Don't give anyone else access to it.
And of course, don't ever pirate software. Now it's extra dangerous. If that gets you excited, welcome to the botnet.
:-Derek
--
Subscribe to:
Posts (Atom)











