Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Tuesday, June 29, 2010

They're Here!
Adobe CRITICAL Updates:
Acrobat & Reader & Flash Player

--
As promised, Adobe skipped their dopey 'quarterly' security update schedule and pushed out updates to Adobe Acrobat, Reader and Flash Player before the end of June. Gee thanks. Let's hope this incident puts the 'quarterly' security update stooopidity in the grave where it belongs.

Before I send you to the sources, I get to be a grumbling curmudgeon. Be warned that Adobe made the process of updating Adobe Acrobat, Reader and Flash Player yet-another PITA with a number of pages to click through to just download the things. So apparently, whoever made Adobe updating the most heinous process in the entire computer community, has not yet been fired from the company.
What A Shame.

For your pleasure, I have dug through the pages of Adobe bureaucratic garbage for you in order to provide direct download URLs:

Acrobat 9.3.3 Pro update

Adobe Reader 9.3.3 update for Intel Macs

Adobe Reader 9.3.3 update for PPC Macs

Adobe Flash Player 10.1.53.64

The simple URL for Flash Player is courtesy of my pals at VersionTracker.com

REMINDER: If you have installed the Mac OS X 10.6.4 update and/or Apple Security Update 2010-004, you have NOT NOT NOT updated to this CRITICAL latest version of Flash Player. Apple only included the old dangerous version. Thankfully, Apple's updater does not remove the newer version if you already installed it.

THEREFORE: If you haven't already, you must DIY install the Adobe Flash Player version 10.1.53.64. Apple won't do it for you. I don't know why! They just won't.
--

Thursday, December 4, 2008

Update: The State Of Trojan OSX.RSPlug, aka the 'Porno Trojan'

The net-cracker effort to bring the 'RSPlug' Trojan horse from Windows over to Mac OS X continues apace. As of this week we are now up to version E, aka Trojan OSX.RSPlug.E. Again, this Trojan is showing up at scam pornography websites.

The difference with variants D and E, however, are particularly nefarious. Instead of the Trojan itself being the full payload of malware, it downloads the actual payload from the Internet. This means the Trojan can install literally anything into your system. It's not just for DNS forwarding phishing scams any more.

Of course, it will be possible to kill off the payload Internet sites one by one as sub-variants of D & E pop up. But once infected, a Mac could theoretically become zombied, which these days is the prime goal of net-crackers. Botnets can make big money. As was popularly reported last week, the taking down of one particular bot wrangler killed off as much as 70% of SPAM distribution for a few days. That's a massive botnet. Imagine the profit the bot wrangler was pulling in. Sadly, the botnet involved remained intact and another bot-wrangler stepped in to take advantage of it, restoring SPAM to its usual blasting volume.

You can read the details about Trojan OSX.RSPlug.E over at Intego's website.

One hilarious flagging giveaway of this Trojan is the continued laziness of the developers' social engineering method. Instead of altering their tease line to potential wetware victims, they left it exactly the same as the Windows version. This means that anyone who is both Mac and Windows savvy will realize immediately that something screwy is going on. The blunder is the tease line "Video ActiveX Object Error". For those who don't know, ActiveX is a scripting monstrosity perpetrated by Microsoft several years back. Yeah, it was another of their attempts to make the Internet proprietary. ActiveX is entirely irrelevant on Mac OS X, thank goodness, as it is a gigantic, wide open door for malware infection on Windows. The only web browser on Mac capable of running ActiveX rubbish is FireFox, and you have to specifically install an ActiveX extension. Therefore, for the moment, if you run into a "Video ActiveX Object Error" on a website, you have just run into an attempt to infect you with the Trojan OSX.RSPlug.
--

Tuesday, December 2, 2008

Trojan OSX.Lamzev.A

As of last week, Mac OS X has a second piece of malware. It is a Trojan horse officially called OSX.Lamzev.A. (It is also erroneously known as OSX.TrojanKit.Malez).

Detection and removal of this malware is built into the latest versions of the FREEWARE anti-malware programs ClamXav and iAnti-Virus.

So what is the strategy this time? To quote ZDNet:
OSX.Lamzev.A is a hacker tool designed primarily to allow attackers to install backdoors in a user's system, according to Intego. However, the company dismissed the tool as a serious threat because a potential hacker has to have physical access to a system to install the backdoor.
. . .
Other antivirus vendors noted that Lamzev could be disguised as a piece of legitimate software and used to trick users into creating the backdoor themselves.
Theoretically, this will become another piece of social engineering / wetware error malware where the user is tricked into installing it. Therefore, as usual, always verify that anything you install is legitimate software. Check it out at any of the well known shareware distribution sites like VersionTracker.com, MacUpdate.com, TuCows.com or MajorGeeks.com. All of these sites have human users and reviewers who can tell you what's legitimate. If you can't verify an application, don't install it! Also, if you want to be extra safe, work only inside a 'Standard' Mac OS X account, not an Administrator account.

I'm going to keep an eye on this Trojan to see what damage it can do. If it is a true 'backdoor' to Mac OS X, a cracker can do anything they like with your Mac. We'll see with time if this becomes a problem. For now, the anti-malware distributors consider it only a minor threat. Just run your usual FREEWARE anti-malware apps once a week, at least, to clean it out if somehow you've installed it.
--

Wednesday, June 11, 2008

Mac Security Advise For Enterprise Users


One of the useful email lists I belong to is the 'Mac OS X enterprise deployment project.' You can join the list and view archives at:

http://lists.psu.edu/archives/macenterprise.html

In April I wrote up a quick article in response to someone's question about preventative maintenance for Mac OS X Server. Interest was expressed in my publishing the article formally on the Internet, so it is provided below. The information is a bit high end, directed specifically to enterprise users of Mac systems. But serious Mac security newbies will find a lot of useful references as well.


:-Derek

===============

From: Derek Currie
Date: April 15, 2008 10:57:25 PM EDT
To: Mac OS X enterprise deployment project
Subject: Re: Apple's guidelines for preventative maintenance for XServes and/or OS X Server.


On Apr 15, 2008, at 04/15, 4:19 PM, Rich Trouton wrote:
"Does anyone know if Apple has posted specifications or guidelines for preventative maintenance for XServes and/or OS X Server? We're doing our regular security re-certification, and one of the things we're being asked for is documentation of how we're doing routine and preventative maintenance "in accordance with manufacturer or vendor specifications and/or organizational requirements." Right now, we don't have organizational requirements, so I'm trying to find Apple's specifications and I'm not finding them. Tempting as it may be, I don't think our re-certification folks are going to accept "there aren't any specifications, so I guess I don't have to do anything" as an valid answer."


Actually, Apple do provide some relevant documentation. See #6 ahead. But first let me provide a long winded brain storm:


1) Detail your backup strategy. I consider making backups the #1 rule of computing and the first step in computer security. Apple provide TimeMachine in Leopard Server.

2) Talk about KeyChain for storing and protecting passwords. I also use 1Password, and excellent shareware program.

3) Discuss what encryption you are using to protect critical data. You can use FileVault or use encrypted disk images created in Disk Utility. (Personally I use an encrypted .sparseimage for storing my database of server clients and other critical odds and ends I would never want stolen). Leopard server offers 256 bit encryption. You shouldn't need anything stronger. As long as you use a ridiculously un-guessable password, theoretically it would take the length of the life of the universe to crack.


==============
Sideline Rant:

If you're not using encryption, start using it already. I know you know this, but for everyone else: Federal servers are now notorious for having been cracked by the Red Hacker Alliance in China, among others. If the data is seriously encrypted, they're wasting their time. Many businesses now demand encryption. Here is a blurb from the SANS Institute's security newsletter NewsBites Vol. 10 Num. 28 regarding some incredible ignorance at the NIH:

On Apr 8, 2008, at 04/08, 5:00 PM, The SANS Institute wrote:

-- NIH Workers May Not Store Sensitive Data on MacBooks
(April 4 & 7, 2008)

A National Institutes of Health (NIH) agency memo forbids employees from storing sensitive data on MacBook laptop computers. As of April 4, all NIH laptops running Windows or Linux operating systems must have the Pointsec encryption tool; Windows Vista users may also use that operating system's BitLocker disk encryption tool. There is presently a beta version of Pointsec for MacBooks, but not an approved version. The ban on MacBooks holding sensitive data applies to contractors as well as in-house employees.


http://www.informationweek.com/shared/printableArticle.jhtml?articleID=207001840
http://www.fcw.com/online/news/152173-1.html

[Editor's Note
(Schultz): As said so many previous times, nothing serves as a wake-up call for security as much as a serious security-related incident.
(Liston): Note: The issue here is the lack of an approved version of whole-disk encryption, not with OSX itself. Apple Fanboys: Return to standby. Nothing to see here-- you may safely return to caressing your MacBooks and iPhones.]


Obviously FileVault would be 'approved' if they bothered to notice it was there in Mac OS X.

(Also note that I pointed out Mr. Liston's lack of professionalism in an email I sent all over SANS. I got into a friendly back and forth with the President of SANS, a very nice fellow. He assured me of Mr. Liston's skills and privately told me that he pulls troll manoeuvres such as the above as a way of blowing off steam during a long boring day of security analysis, wink wink. Hopefully my efforts will shut the guy up in the future).
==============


4) Discuss the fact that Mac OS X uses the PDF document format as part of its foundation, and that any PDF can be locked such that only a user with its password can open it. Discuss how locked PDFs are used in the work environment.
http://docs.info.apple.com/article.html?path=Mac/10.5/en/8152.html

5) Discuss your implementation of PGP or GPG (the free Open Source version of PGP) in your work environment. Sources:
http://www.pgp.com/
http://www.gnupg.org/

6) Apple has some security documents relevant to Mac OS X Server:

a) Mac OS X Server - Security Configuration - For Version 10.4 or Later - Second Edition
http://manuals.info.apple.com/en/Tiger_Server_Security_Config_021507.pdf

- If an update is provided specific to Leopard Server, it will be posted on the Security Configuration Guides page:
http://www.apple.com/support/security/guides/

b) Mac OS X, Mac OS X Server: Protection for sensitive files when using Apache on an HFS+ volume
http://docs.info.apple.com/article.html?artnum=300422

c) Mac OS X: How to keep network computers secure
http://docs.info.apple.com/article.html?artnum=61534

d) Mac OS X Leopard - Features - Security
http://www.apple.com/macosx/features/300.html#security

7) Apple also offer their Security-Announce mailing list. You can get it via email or via RSS:
http://lists.apple.com/
http://lists.apple.com/mailman/listinfo/security-announce
feed://rss.lists.apple.com/security-announce.rss


----------------
Bonus Points:

1) Some nifty security statistics from March 2008 to quote in defense of Mac OS X's excellent security record:

http://www.insanely-great.com/news.php?id=8665
http://www.zone-h.org/content/view/14928/30/

An excerpt from the Zone-H Statistics Report 2005-2007, the number of registered computer attacks:

OS ________ | Year 2005 | Year 2006 | Year 2007
------------------------------------------------
MacOSX ________ 2.139 _____ 2.247 _____ 1.488
Windows 2003 _ 72.377 ___ 183.953 ___ 114.137

To quote M. Sharp from Insanely-Great Mac:
"Assuming that the Mac's server market share is growing—the most-recent data on Apple sales I could find (Q2 of last year) had unit volume up 78 percent—then the above figures indicate that attacks are declining absolutely even as the number of servers increases proportionately and absolutely."

2) Apple provide references to security related software from third-party vendors at their 'Macintosh Products Guide' pages:
http://guide.apple.com/

Examples:
a) Go to the Mac Software/Products and Utilities page. In the 'Sub-category' popup menu choose "Security" and hit the Search button. Today there are 135 security related apps listed.

b) Go to the Mac Software/Servers, Networking & Communications page. In the 'Sub-category' popup menu choose "Security" and hit the Search button. Today there are 20 related apps listed.

You could also search for software firewalls, hardware firewalls, etc.
----------------

That should get you going!

:-Derek

===================
Derek Currie
derekcurrie@mac.com.invalid
===================
http://Mac-Security.blogspot.com
http://MacSmarticles.blogspot.com
http://zunipus.blogspot.com
http://movies.groups.yahoo.com/group/dwaynecameronfanclub
http://groups.yahoo.com/group/ymorare

© 2008-04-15 Derek Gordon Currie