Monday, April 27, 2009

Multiple Symantec Software Vulnerabilities Found

--
This isn't so much a useful article as a thumb in the eye of my least favorite anti-Mac security FUD monger, Symantec. Have an *evil laugh* along with me if you like:

Digging around at the F-Secure site tonight I happened up on this article from a few days back:

Symantec Brightmail Gateway Control Center Multiple Vulnerabilities

Summary

Some vulnerabilities have been reported in Symantec Brightmail Gateway, which can be exploited by malicious people to conduct cross-site scripting attacks and by malicious users to bypass certain security restrictions.

Detailed Description

Some vulnerabilities have been reported in Symantec Brightmail Gateway, which can be exploited by malicious people to conduct cross-site scripting attacks and by malicious users to bypass certain security restrictions.

1) Certain unspecified input passed to the Control Center is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

2) An error when processing unspecified console functions can be exploited by a Control Center user to gain administrative privileges.

The vulnerabilities are reported in versions prior to 8.0.1.
The vulnerabilities were discovered by Secunia.

They were NOT discovered by Symantec.

So next time Symantec strike one of their Overlords Of Security poses, just laugh at them.

;-D
--

Saturday, April 18, 2009

The First Reported Mac BOTNET

--
Let me first share news from SANS Institute, then provide a brief perspective on the situation.

Below is a quote from SANS NewsBites Volume 1, Number 30, released last night. (I added some bolding for emphasis). You can sign up for the SANS newsletters HERE.
--Trojan in Pirated Mac Software Helped Create First Mac Botnet
(April 15, 2009)

Malware embedded in pirated versions of Apple's iWork and Adobe Photoshop CS4 for Mac that were available over a peer-to-peer network in January is responsible for what appears to be the first known Mac botnet. The zombie network attempted to launch a distributed denial-of-service (DDoS) attack against an unidentified website. The malware had spread to several thousand computers before it was identified.

http://www.cbc.ca/technology/story/2009/04/15/ibotnet-trojan.html

http://blogs.zdnet.com/security/?p=3157

[Editor's Note (Honan, Schultz): Looks like the Mac platform is an increasingly fruitful target for cyber criminals. ]
Indeed it has. "Several Thousand Computers." This is incredibly sad, but also inevitable.

While all the FUD mongers have a sadism party at our expense, (and they will), keep in mind that NONE of the current Mac malware is able in penetrate any Mac unless the user (often called the 'luser') deliberately installs a Trojan horse on their computer. This happens specifically because the user has been conned by what is called Social Engineering, or in this case, the luser is using pirating software that has had the Trojan carefully placed in the installer to go along for the ride. What do you call it when a dirty deed is done to someone pulling a dirty deed? How about 'Dishonor Among Thieves'. It is more like poetic justice, parasite chewing on parasite.

Anyway, Mac Botnets have arrived. What is done with them will be of interest. Typically these days they are used for money making schemes. Go read all the news about the Windows Conficker worm scare of April 1st and beyond. Once created via infection, a botnet can pull off just about anything you can do over the Internet except in mass numbers at one time.

OK! You're a luser and maybe you did something that could have gotten you infected. Now what?

What NOT to use:

ClamAV. Worthless for Macs. I've covered this disappointment several times.

MacScan. The botnet Trojans are out of its league. It's clunky unreliable software anyway.

Symantec Norton Whatever. I consistently get reports that Norton Anti-Virus continues to be one of the single most buggy and CPU hogging applications you can buy for Macintosh. Symantec also invented the anti-Mac security FUD campaign back in 2005. Save your money and your patience. Avoid. Run away. Just my opinion.

Freeware:

iAntiVirus from PC Tools. It can detect and remove all current Mac malware. You don't have to pay for the application unless you are a business or are running a large network. The paid version offers technical support. Note that it only runs on Leopard. I use it and find it to be very simple and unobtrusive.

Shareware / Commercial-ware:

Sophos Anti-Virus. It is designed for companies and networks of computers.

Intego VirusBarrier. I find them to be the best-in-class for single users. I'm disappointed at their disorganization as a company. But the program is top notch. Just be prepared to shell out money year after year. Bleh. Nonetheless, I own it, use it and like it.

I used to use Virex X, now called McAfee Virus Scan. But it got clunky. Many people downright hate it. I don't know why. These days it is designed for companies and networks, not single users. I would have shoveled McAfee into the grave along side Symantec for having FUDed the Mac. But oddly, their CEO ended up stating that the single best way to escape computer malware was to "buy a Mac." So they can't be entirely stupid over there.

There is other stuff around, but it makes me yawn. You can get a listing of it all at the download sites by searching for 'virus'.

DEFENSE!

If you are in charge of a home computer shared by others, or you are an IT manager, stop the luser users from installing Trojans by giving them Mac OS X accounts that Do Not Allow Program Installation! If a user wants a program installed, let them ask you to do it for them in YOUR account. Then give them access to the program.

But of course this means that YOU, the boss of the machines, have to be careful too. Always verify that what you install has specifically been tested somewhere. I always use the download sites like VersionTracker or MacUpdate. There are many others. Be sure that either the site itself has tested that version of the program and given it an OK, or that a lot of users have tested it and OKed it. Buy commercial-ware directly from the company, and make certain they are entirely, unquestionably reputable. Adobe.com = reliable. Jake's Super Deluxe Fly-By-Nite Site.com ≠ reliable. You get the idea.

And just to tick off the FUD mongers:

A) There is no such thing as a 'virus' for Mac OS X.
B) There is no such thing as a 'worm' for Mac OS X.
C) There is no such thing as illicit 'spyware' for Mac OS X. All Mac spyware is sold legally for the purpose of surveillance of network machines.
D) There is no such thing as 'security by obscurity' for Mac OS X. If you know how to do math, you can prove this for yourself. Go backwards in my blog if you want to read the gravestone I wrote for this mythological absurdity form of FUD.
E) As a Mac user you must keep computer security in mind. Follow the basic rules:
  1. Make regular backups. This is the #1 Rule Of Computing.
  2. Learn how to use your router's firewall and use it.
  3. Learn how to use Mac OS X's built-in firewall and use it.
  4. Always use password protected accounts. Make very sure your password is strong, obscure, unintuitive and plain old nasty. Be sure you remember it. Don't give anyone else access to it.
I've gone into greater detail about add-on measures in previous posts. The list above covers the essential basics.

And of course, don't ever pirate software. Now it's extra dangerous. If that gets you excited, welcome to the botnet.

:-Derek
--

Wednesday, April 15, 2009

Attack of the Black Hats 2009

--
Intego's Mac Security Blog pointed out that the Black Hat Europe 2009 security conference starts tomorrow, April 16th. Two of my most un-favorite Mac crackers will be presenting a paper entitled "Fun and Games with Mac OS X and iPhone Payloads". The point of their presentation will be introduce "advanced payloads which help to avoid detection, avoid forensics, and avoid countermeasures used by the operating system for both Mac OS X and iPhone."

White Hats are hackers who try to keep the computer world in order. Black Hats are hackers who try to put the computer world into disorder. The entire point of the Black Hat movement is beyond my comprehension. My opinion is that it is all a matter of human personality. Some centered people relish being helpful to others. Some lost people relish hurting other people. Obviously this is a simplistic description, but I find it to be entirely parallel to the humane versus troll warz on the Internet. The point of trolling is sadomasochistic induction of suffering in others. IOW trolls are mentally deranged. I can't help but think of Black Hats in the same black light. They will never gain my respect, and they like it that way.

But then there is my Angst Theory: Creativity is proportional to angst. When angst is introduced into any living system, the typical reaction is creativity if only to maintain survival or to reach a new steady state. Obviously, too much angst = breakdown of the system. But there are those who believe that contained and defined units of angst are good for a system and keeps it in a state of evolution. Stagnation leads to devolution, aka status quo. For me this explains the revolution imperative in all teenage kids. Teens aren't just trying to establish their own authority and territory. They are in their limited way, with their limited perspective, trying to topple the stagnant and irrational status quo in favor of a system they believe to be more contemporary and sane. This is one reason I enjoy championing creative obnoxiousness in kids and why I believe the entire anti-ADD, ADHD movement is, in and of itself, an illness of our culture. Diversity rules in any natural system. Drugging kids to smash them into status quo molds, conforming them to the spirit of the old age, is demented.

Those who know me can attest to the fact that I am not at all like the persona I typically portray on the Internet. Why do I deliberately induce angst in my readers? I am a change agent. That is part of my personal manifesto within my culture. I am very deliberate about it and know I am doing my job when I upset people whom I believe require upsetting. I also have a fearless rational mind. If I believe my purpose is just, I'll induce angst into anyone. I have no sense of class system or authority. Instead I am what I call a positive anarchist. To put it simply: I believe in maximum choice and maximum responsibility for the consequences of one's choices.

Having now blethered at you my personal POV, perhaps you can understand how I analyze Black Hat hackers. Are they inducing angst into the status quo? That could be excellent! Are they taking responsibility for the consequences? To know that you would have to know each individual involved, and I certainly don't. I can only read the stuff they publish and analyze their words from my personal inner world POV.

Here is my quick analysis of the abstract Dr. Charlie Miller and Vincenzo Iozzo provide for their 'Fun and Games...' paper:
Mac OS X continues to spread among users...
Obviously the word 'spread' was carefully chosen to infer Mac OS X is equivalent to a spreading disease. It has no positive connotations in this context. Sadly, there is no indication of what OS Charlie and Vincenzo would prefer. They're out of their minds if it's Windows, that's all I know. I like to assume they are Linux freaks. There is some basis to this assumption: Linux is rarely bashed, as far as I am aware, at Black Hat tribal rituals. The fact that Linus Torvalds is himself a rebel and that Linux is Open Source freeware tends to lend credibility to the tribals. Or the two of them may simply be UNIX freaks, which explains why they bother with Mac OS X, which is UNIX to the core.
... with this increased market share comes more scrutinization of the security of the operating system.
That has been the history, and I like it.
The topics of vulnerability analysis and exploit techniques have been discussed at length. However, most of these findings stop once a shell has been achieved. This paper introduces advanced payloads which help to avoid detection...
IOW, Charlie and Vincenzo are going to be particularly vicious dickheads this time around. No more water-boarding for them. It's time for flaying and evisceration. I always did enjoy reading Clive Barker, so this could get interesting. But I believe the point here is to make the victim, Mac OS X, suffer for its failings. This is IMHO irresponsible and therefore stupid. It is little kids playing with blasting caps. Charlie and Vincenzo might get their hands blown off or lose an eye. Darn. Worse yet, Mac OS X security might be damaged.

Or will it? If Charlie and Vincenzo are skilled, their coding scalpels will reveal security tumors in Mac OS X that require removal and replacement. Apple will of course respond and Mac OS X could end up more secure. From my positive POV, that is the goal. But from a Black Hat's point of view, what is the point? Self-aggrandizement? Some other form of psychopathic mental orgasm? Again, you have to know the people to know their personal problems.

If you'd like some insight into Charlie Miller, have a read of his recent book "The Mac Hacker's Handbook", written with Dino Dai Zoni, ISBN 978-0-470-39536-3. One of these days I'll be posting a review. He publishes articles at the Independent Security Evaluators website. You can also hear him speak in the Black Hat Briefings podcasts via iTunes. I am willing to bet he also plays the persona game, acting the angst inducing change agent while being a nice guy behind the scene. But you figure him out for yourself.
--

Derek's Minor Intego Adventure

--
Intego VirusBarrier remains my favorite Mac anti-malware application. Yeah, like many of it's competitors, it's named incorrectly, (should be 'MalwareBarrier'). And yeah, they don't publish a list of their malware definitions, but I still... WHAT? No malware list?!

So I contacted Intego and had an email chat with a nice fellow at their Support Team. My question: Where is your malware list? Their reply:
We do not provide a list of every virus that VirusBarrier X5 protects against. If you have a question about a particular virus threat, please let us know and we will be more than happy to answer the question for you. You can also find information on our security blog about new threats:

The Mac Security Blog
This is actually a very good blog. However, it does not cover all Mac malware. So I persisted in my conversation with Intego. It turns out that there is a disconnect between their blog and their news releases; Therefore, you have to keep track of both:
Intego Press Releases
I found it is indeed possible to scavenge together a list of Mac OS X malware detected by VirusBarrier. I was also pleased to find the list is complete.

(The possible exception is Trojan.OSX.RSPlug.G, which for all I know is mythological. Only PCTools' iAntiVirus program notes it having been found in the wild. Or, on the other hand, Intego may include the G variant with the F variant. It's hard to tell thanks to the industry's insistent lack of conformity to malware description and naming standards).

So why doesn't Intego provide a simple list of detected malware with descriptions of each malware family and variant, like you know, everyone else does? I call it disorganization, which is a shame since they easily have the most organized and best written anti-malware program for Mac.

Until Intego get better organized, I suggest keeping track of the Mac OS X Threat List provided at the PCTools iAntiVirus site page. It contains a lot of baloney proof-of-concept, inert and ancient Mac OS (not X) malware. Otherwise I find it very useful. Yes, it has the same old problem of not adhering to malware naming standards resulting in the same old comprehension chaos. And yeah, this list has some incomprehensible duplication of malware, like DNSChanger and RSPlug being listed separately when in fact they are the same thing. *rolling eyes* But so far, it's the most complete, literate and up-to-date list I have found:
iAntiVirus Threat List
[I continue to ask: Why do I have to write this blog? Why isn't there a nice, up-to-date, simple, complete, sane, standards compliant site dedicated to Mac OS X malware? Until one appears, I'll continue trying to fill the void.]
--

Monday, March 23, 2009

Before: My current POV on Mac security

--
Before what? Before I read this article on Mac security:

Mac OS Xploitation
by Dino A. Dai Zovi

When (more likely than 'if') I have changed my POV after reading it, I'll post an 'After'. I find this sort of thing amusing. Consider me eccentric.

One of the places I hang out on the net is the MacEnterprise list. It is run by the Mac OS X Enterprise Deployment Project. I've cross-posted between here and there previously. Here is my post this evening to the list:

On Mar 16, 2009, at 03/16, 2:12 PM, Allan Marcus wrote:

This paper is from the author of the Mac Hacker's Handbook . It's rather scary and concludes . . .

The conclusions were fairly standard "Mac OS X is scary insecure!" stuff. Before reading the article, here was my reply:

I'm going to give it a read through as I am interested in Mac security.

But I have to give a few bits of perspective from my current POV. I know I'll get contentious arguments to the contrary, but here goes anyway:

1) This sort of article, in part, amounts to FUD (Fear, Uncertainty and Doubt). It is extremely rare to find articles with a full explorative comparison between UNIX (which is what Mac OS X actually is, legally, officially, etc), Mac OS X (meaning the other stuff Apple put on top of UNIX), Linux and Windows. Empirically, Windows is the single least secure commercially available operating system on the planet. There are plenty of people who have a stake in its success, despite this blatant problem. Therefore, it is extremely popular among them and the people who believe their con-job to FUD every other OS at every opportunity. The result is chaotic disinformation leading to stagnation, aka the status quo. I don't believe you have to take a 'political' or 'religious' stance to understand that this is the case.

2) And yet the seemingly endless barrage of FUD, initiated in August 2005 by none other than Symantec, has done nothing but *GOOD* for Mac OS X. All the FUD mongers and earnest, honest security experts out in the field have driven Apple out of their security slumber. Apple's resulting attention to Mac OS X security has increased exponentially. This is one reason I value competition in the marketplace. It keeps the competitors awake and innovative. Does this mean Apple is in high gear to make Mac OS X security impenetrable? I don't think so. But I do believe they are now serious and alert.

3) Apple's most insecure program is QuickTime. Mac OS X has its problems, but QuickTime has been Apple's security bane. If you go through the list of security fixes since December 2006, when this problem became blatantly clear over at MySpace, you'll find this assertion to be correct. Microsoft has gotten slammed for its poor multimedia code. But QuickTime has had its share of very similar problems, without getting nearly as much attention.

4) I don't care what OS you talk about. Buffer overrun problems are consistently the horror of programming to this day. I like to slam Microsoft for still using ye olde DOS memory management under the hood. But programmed memory management messes are just as prevalent everywhere else. From my limited coding education, I have to point to the now antiquated programming languages we have to use. Remember how Java was supposed to have solid memory management, among other miraculous safety features? Forget it.

5) Despite what gets thrown about in the FUD mongering chronicles, the fact remains that Microsoft have perpetrated some outrageously insecure code. Examples: JScript remains one big reason 'JavaScript' is insecure these days. ActiveX scripting is another Microsoft 'Welcome Hackers!' security hole made for the Internet. Vista is not entirely immune to either of these lousy technologies.

6) There never was such a thing as 'Security By Obscurity' for Mac. It's a total myth, and no one foisting the myth has ever presented a sane argument in their favor. Anyone can do the math. We currently have eight (8) Mac OS X Trojan horses. That is the full extent of Mac OS X malware in the wild at this moment. We have a market share that is maybe 1/10th that of Windows. So how come Windows has a massively disproportionate number of malware in the hundreds of thousands, with thousands more every year? There is something more going on here than Macs having 1/10th or less market share. That's a big 'DUH' in my estimation.


So I say, Bring On The FUD!

Despite the fact that every single piece of current Mac OS X malware requires social engineering methods to break into a Mac, that does not mean other methods are not possible. There is plenty of evidence to the contrary. There is no harm to the Mac platform whatsoever by striking fear of security breaches into hearts of its users. It just makes the platform that much stronger. Just don't go out and buy rubbish anti-malware programs from the FUD meisters. Equally, don't count on the freeware to cover your butt. For example, I've totally given up on Clam providing any relevant protection for Mac OS X. It's not happening. Instead we currently have to train users to not fall for social engineering tricks, while keeping up with security updates and watching Mac OS X relevant security news. If a time comes to use anti-malware programs for particular situations, so be it. Right now I'd turn to Sophos and Intego for the best quality solutions.

Please remember, this is just my personal limited POV. Obviously, gather in many more perspectives and make the best educated security decisions you can for your situation.

Thank you for reading my blether-fest,

:-Derek

--

Friday, March 20, 2009

Pwn2Own Browsers Hacked: IE 8, "Safari" and "Firefox"

--
This time of year is now one of traditional contention. It's time for Pwn2Own at CanSecWest. It is a fun contest held among security experts to crack the chosen subjects for each year. This year a selection of web browsers was used.

Of course after the contest there is lots of snickering and gossip. But for better or worse, what exactly happened at the contest is rarely revealed, meaning that the specific cracks used are not allowed to be published so they can be provided to the programmers of the cracked software for consideration and patching.

Questionable aspect of this year's contest: Windows 7ista was used in PC testing. It's in beta.

Losers so far this year:

1) "Safari" for Mac. I use quotes as I have not been able to find what version was used. Presumably it is the latest public release, and not the version 4 beta. It was cracked within 2 minutes. How cracked? Unstated. My speculation: That hell hole known as "JavaScript" which these days includes JScript, a holey mess perpetrated by Microsoft. Apple have consistently had JavaScript security problems, starting with QuickTime in 2006 over at MySpace.

2) "Firefox". Again I use quotes as I have not found the version number. Neither do I know which platform, which may well mean both Mac and PC. How cracked? Unstated.

3) Internet Explorer 8.0. This browser was JUST released. Oops. It should have stayed in beta. Again, specifics of the crack have not been made public.

For further details, keep an eye on the Security Watch blog at PC Magazine and the TippingPoint DVLabs blog. You can also follow TippingPoint's Twittering. The contest will conclude later today (Friday, 2009-03-20).
--

Thursday, March 12, 2009

Mostly Harmless: Adobe Updater Requests Administrative Privileges!!!

--
Consider me profoundly ticked off at Adobe. This is the last straw for me regarding their Adobe Updater program. It has now been DELETED off my computer, and I suggest you do the same.

I really hope I am being alarmist about what Adobe just tried to pull on me and I get lots of letters ranting at me about my foolishness. But I believe what I just witnessed on my Mac has tipped Adobe into the Evil Zone.

Back Story:

For the last several years it has been at times hell-on-Earth updating Adobe programs via the Internet. I have never, ever seen a more diabolically BAD system for updating programs. I've written to them about it several times as have hundreds of other people.

So this past year Adobe figured out they had a PR problem and offered professionals the opportunity to describe the problems with Adobe's update system. Hundreds of people again contacted Adobe. So everything is going to get all better now. Right?

Adobe wants to rule your Mac:

Tonight I got notification from good old VersionTracker.com that Adobe Reader version 9.1 had been released. It is a critical update that plugs some very bad security holes. Everyone should update ASAP. So of course I did the update.

As per usual, stupid Adobe couldn't do just one simple update, they had to ask me again and again for permission to install stuff. Among the added rubbish was yet another version of Adobe Updater. Clearly, nothing has been improved in Adobe's idiotic updating system over the Internet.

Then came the very-very last step: A box requesting my password, for a SECOND TIME, allowing Adobe Updater to have ADMINISTRATIVE PRIVILEGES, forever!

Stop and consider that a second. An application asked me if it could always have administrative privileges to do whatever it wanted to my computer at any time. IOW Adobe Updater was asking if it could rule my computer. This is called evil. (OK, now you can tell me I'm paranoid. But I don't think so!)

My response:

I canceled the request.

And for good measure I DELETED Adobe Updater from my computer.

Then I wrote the following to Adobe:

I just installed Adobe Reader 9.1 for Mac OS X.

Why did Adobe Updater ask me for my password so it could run, at will, with Administrative Privileges?

This is profoundly insecure, DANGEROUS and a bad idea in ALL situations.

As a result I CANCELED this privileges request. I also took Adobe Updater and ERASED IT from my computer. Adobe Updater will remain erased from my Macintosh computer until such time as Adobe explains itself regarding this DANGEROUS request. It had better be good. I will be publishing my disgust regarding your privileges request on the Internet and in computer user group newsletters this coming week.
And so I have. And if (a big if) Adobe get off the arrogance kick and actually respond, I'll let you know and share what they say. You can start holding your breath . . . NOW.

Until then:

Clutch your Mac firmly to your breast. Adobe are coming to take it away.
--