Friday, January 11, 2013

Apple Disables Java 7
In Response To New Malware

--
GO Apple! I like it... EXCEPT! There's a problem.

First the good news:

What a day. Check out this article at MacRumors:

As noted by ZDNet, a major security vulnerability in Java 7 has been discovered, with the vulnerability currently being exploited in the wild by malicious parties. In response to threat, the U.S. Department of Homeland Security has recommended that users disable the Java 7 browser plug-in entirely until a patch is made available by Oracle.
So Apple, paying attention to the situation, did THIS:

Apple used its built-in XProtect system to disable ALL versions of Java 7. No versions of Java 7 will be allowed to run until Oracle provides an update. MacRumors lists the XProtect XML code that blacklists the Java 7 Internet plug-in.

XProtect will NOT allow a Java 7 plug-in to work until Oracle update past the current version, Java 1.7 update 10 beta 18 (AKA 7u10b18).

How to verify you have the updated Xprotect.plist file:

Navigate in the Finder to here:

/System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/

There you will find the file "XProtect.plist". Do a Get Info on the file to discover its 'Created' date. You'll want to see either today's date (Friday, January 11, 2012...) or later. If you see a date circa "December 13, 2012..." you do NOT have the update. You are looking at the previous version of the .plist file, NOT the updated version.

NOT what you want.
A NOT updated XProtect.plist file.


How to force an update of your XProtect.plist file:

Navigate in the Finder (using the menu command Go/Go to Folder...) to here:

/usr/libexec/

There you will find the file "XProtectUpdater". If you have Administrator privileges on your Mac, you can simply double-click this file to run it. You'll see the Terminal app open. It will then perform the UNIX process built into XProtectUpdater.


Now for the PROBLEM:

At the moment, I can't get XProtectUpdater to update my XProtect.plist file on a Mac running 10.7.5. That's not good.

(We're into the realm of super geeky, nasty CLI, character line interface, hell here. I despise CLIs and the associated geekiness that goes with them. That's MY problem. YOUR results will no doubt vary).

Here is what I am consistently seeing in the Terminal after I invoke XProtectUpdater:
2013-01-11 15:29:30.053 XProtectUpdater[91712:707] Unable to verify signature: Error Domain=com.apple.security Code=-20044 "The operation couldn’t be completed. (com.apple.security error -20044.)" UserInfo=0x7ff2ba606f60 {FailingMethod=SecManifestVerifySignature}
I get these same results if I:

A) Double-click XProtectUpdater
-OR-
B) Drop XProtectUpdater on the Terminal window and invoke it
-OR-
C) Use 'sudo', space, then invoke XProtectUpdater

This is apparently a security problem over at Apple.com, NOT on my machine UNLESS Apple has only provided the XProtect.plist update for OS X 10.8, which is a distinct possibility.

If other folks have further insights into this problem, please post a comment.

Today's Java BS has burned me out. But tomorrow I will be checking for new information as well as testing XProtectUpdater on my 10.8.x systems. If you run into this same problem updating your XProtect.plist file, stick to the mantra:

Just Turn Java OFF.

If you don't know how, travel on down the blog to my previous articles about Java 7.

:-Derek


Mal/JavaJar-B,
That New Java 7 Malware
You've Been Waiting For!

--
[Updated 2012-01-28]

That didn't take long! Sophos has reported the name of the new in-the-wild Java 7 exploit is:



Translated into the official malware naming system (that nearly everyone ignores), the name would be:

OSX.Trojan.JavaJar.B

Naming such malware as a 'Trojan horse' is debatable as it is a drive-by infection not requiring anything more than a user visiting a website with the Java plug-in left insecure. I suspect this is why Sophos reports the malware as 'Mal'. I personally would advocate for calling it:

OSX.DriveBy.JavaJar.B

In any case, the malware is here and dangerous.

Just Turn Java OFF.

--> UPDATE NOTE from 2013-01-28:
It has been found that the "Very High" Security Level setting is INEFFECTIVE! It does NOT block malware. Consider it USELESS! Read ahead to my article:

Just Turn Java Off: 'Very High' Security Setting NOT EFFECTIVE!

Or if you must use Java, at least get used to keeping its Security setting at 'Very High' as of Java v1.7 update 10, aka 7u10. 


Sophos provides a picture that indicates using the 'High' setting. That's baloney. Just leave it on 'Very High' until you're at a trusted web page. Don't forget to turn it back to 'Very High' BEFORE you leave that web page. And yes kids, this is a big PITA. Blame Oracle.

Also, Sophos made an error when they stated:
A single check-box can be used to disable the web plugin entirely...



That continues to NOT be true on the OS X version of the Java 7u10 'Control Panel'. Oracle know about it. They attempted to provide a workaround that was specific to OS X 10.8.x. But from my experience, Oracle's workaround was a FAIL. Hopefully Oracle will figure out how to allow mere humans to uncheck a checkbox in their next rendition of Java 7. 

Sheesh. :-P


--

New Java 7 Exploit In The Wild,
Coming Soon To A Mac Near You!

--
Just Turn Java OFF.

Oracle's Java 7, ALL versions (v1.7 update 10, aka 7u10, on down), has a newly discovered security hole that is being exploited in-the-wild on Linux, Windows and UNIX. That 'UNIX' exploit means malware will immediately be coming to Mac.

Surprised? Not me!

CVE-2013-0422 describes the security hole as:
Unspecified vulnerability in Oracle Java 7 Update 10 and earlier allows remote attackers to execute arbitrary code via unknown vectors, possibly related to "permissions of certain Java classes," as exploited in the wild in January 2013, and as demonstrated by Blackhole and Nuclear Pack.
SecurityTracker provides further details:
A remote user can create specially crafted Java content that, when loaded by the target user, will execute arbitrary code on the target user's system. The code will run with the privileges of the target user. 
This vulnerability is being actively exploited. 
Several exploit kits include an exploit for this vulnerability....  
No solution was available at the time of this entry.
The source report about in-the-wild exploit malware can be found here:


Quoting the article:
Hundreds of thousands of hits daily where i found it. This could be a mayhem. I think it's better to make some noise about it.
I'll post when the 'mayhem' hits the Mac community, which will likely be any minute now...
--


Wednesday, January 9, 2013

Adobe Updates:
Flash Player v11.5.502.146,
Reader and Acrobat v11.0.01,
Air v3.5.0.1060


Adobe provided updates on January 7th, 2013 for Reader, Acrobat, AIR and Flash Player. ALL of these updates include security patches. LOTS of security patches!

THE DOWNLOAD LINKS:

Adobe Flash Player v11.5.502.146: http://www.adobe.com/support/downloads/thankyou.jsp?ftpID=5540&fileID=5553

Adobe AIR v3.5.0.1060: http://get.adobe.com/air/thankyou/?installer=Adobe_AIR_3.5_for_MacOS_X


Adobe Reader v11.0.01: http://www.adobe.com/support/downloads/detail.jsp?ftpID=5540


Adobe Acrobat v11.0.01: http://www.adobe.com/support/downloads/detail.jsp?ftpID=5538


LATEST VERSION INSTALLED VERIFICATION:

Adobe Flash Player: 
Visit this web page:
http://www.adobe.com/software/flash/about/

Adobe AIR: 

Visit this web page for instructions: 
http://helpx.adobe.com/air/kb/determine-version-air-runtime.html

Adobe Reader: 

Within Reader, choose Help > Check for Updates.

Adobe Acrobat:

Within Acrobat, choose Help > Check for Updates.


SECURITY BULLETINS:


Adobe Flash Player v11.5.502.146 and Adobe Air v3.5.0.160, Security Bulletin APSB13-01

Adobe Reader and Acrobat v11.0.01, Security Bulletin APSB13-02

The security bulletin for Flash Player and Air is listed as being only for Flash Player. And yet it's not. (0_o) It's about BOTH. So be sure you update both. Get your act together Adobe!


SECURITY HOLE SUMMARIES:

Adobe Flash Player and AIR:
These updates address a vulnerability that could cause a crash and potentially allow an attacker to take control of the affected system.
Details about this security hole can be found in CVE-2013-0630, which has not yet been detailed as of today. SecurityFocus lists the CVE as a "Remote Buffer Overflow Vulnerability", IOW the usual.

Adobe Reader and Acrobat:
CVE numbers: CVE-2012-1530, CVE-2013-0601, CVE-2013-0602, CVE-2013-0603, CVE-2013-0604, CVE-2013-0605, CVE-2013-0606, CVE-2013-0607, CVE-2013-0608, CVE-2013-0609, CVE-2013-0610, CVE-2013-0611, CVE-2013-0612, CVE-2013-0613, CVE-2013-0614, CVE-2013-0615, CVE-2013-0616, CVE-2013-0617, CVE-2013-0618, CVE-2013-0619, CVE-2013-0620, CVE-2013-0621, CVE-2013-0622, CVE-2013-0623, CVE-2013-0624, CVE-2013-0626, CVE-2013-0627
The total is 27 security holes. Adobe is listing them all as 'Priority 2', which they describe as:
This update resolves vulnerabilities in a product that has historically been at elevated risk. There are currently no known exploits. Based on previous experience, we do not anticipate exploits are imminent. As a best practice, Adobe recommends administrators install the update soon (for instance, within 30 days).
Again, none of these CVE reports yet offer any details as of today. If you use a search engine and input each CVE number you can find some dirt on them from various sources. Feeling in a magnanimous masochistic mood, I dug up some general descriptions of the CVEs. 

SecurityTracker describes all but the first CVE here:

Adobe Acrobat/Reader Multiple Flaws Lets Remote Users Execute Arbitrary Code and Local Users Gain Elevated Privileges
Description:   Multiple vulnerabilities were reported in Adobe Acrobat/Reader. A remote user can cause arbitrary code to be executed on the target user's system. A local user can obtain elevated privileges on the target system. A user can bypass security restrictions. 
A remote user can create specially crafted content that, when loaded by the target user, will execute arbitrary code on the target system. The code will run with the privileges of the target user.
The security problems involve the usual memory overflow problems, a "use-after-free" [which is new to me], local errors, elevated privileges and security restriction bypasses. Oh dear. Not pretty.

IOW: There is no indication of Reader or Acrobat settling into safe and secure mode. The security flaws just keep on coming! Avoid both Adobe Reader and Acrobat as much as possible. 

Apple's Preview app is adequate for most reading and annotation purposes, and it hasn't demonstrated any of Adobe's circus of security holes.

There is also a plethora of alternatives to Adobe Acrobat available for Mac. The alternatives include, in no particular order:

Share and Enjoy!
:-Derek
--

Tuesday, December 11, 2012

Java 1.7 Update 10 (AKA Java 7u10)
Is Available From Oracle

--
On November 29, 2012, Oracle released Java 7u10 (v1.7 Update 10) for Mac. I discovered it by accident. Apparently, inevitably, suitably, few Mac users now bother with Java.

Here is where you can get the latest version of Java 7:

http://www.oracle.com/technetwork/java/javase/downloads/jre7-downloads-1880261.html

Venture back through my previous posts for rants about how much Java sucks, how it's the most dangerous software you can install on your Mac, how a drive-by Java malware infection zombied ~600,000 Macs this past summer and how you should never run it except on specific trusted websites. If you don't need Java, either turn it OFF in your web browsers or uninstall it.


WHAT'S NEW IN JAVA 7u10

I) Release Notes

Oracle buried its 7u10 release notes under three layers of links. But I have spared you frustration and provided it here:

http://www.oracle.com/technetwork/java/javase/7u10-relnotes-1880995.html

Mac Relevant Highlights:
This update release contains the following enhancements:
- Additional Certified System Configurations
- Security Feature Enhancements
. . .
 
For JDK 7u10 release, the following additional system configurations have been certified: 
Mac OS X 10.8
. . . 
The JDK 7u10 release includes the following enhancements: 
The ability to disable any Java application from running in the browser. This mode can be set in the Java Control Panel.... 
The ability to select the desired level of security for unsigned applets, Java Web Start applications, and embedded JavaFX applications that run in a browser. Four levels of security are supported. This feature can be set in the Java Control Panel or (on Microsoft Windows platform only) using a command-line install argument. 
New dialogs to warn you when the JRE is insecure (either expired or below the security baseline) and needs to be updated.
. . .
 
Known Issues. . . 
Area: deploy
Synopsis: System level disable switch does not work on Mac OS_X (10.8) platform. 
On some systems running Mac OS X Mountain Lion (version 10.8), applying system level switch from the Java Control Panel to enable or disable Java does not work even though the correct credentials have been provided. 
The workaround is to delete the file /Library/Application Support/Oracle/Java/Info.plist and then reinstall the JRE. . . 

II) Visible changes in this version:

The Java System Preferences pane is still Mac illiterate, opening its own separate 'Java Control Panel' application. What is Oracle's problem?! (0_o)

1) The 'General' tab now has an 'About...' button.

2) The 'Security' tab has a new GUI. Sadly, it is reminiscent of Windows. But at least it's simple. Here is a screenshot:



As you can see, I recommend setting the 'Security Level' on 'Very High'. 

Do NOT use the 'Medium (recommended)' setting unless your web browser is specifically at a trusted website. When you're done with that website, REMEMBER to set Security back to 'Very High' and just leave it there. I also recommend turning Java OFF in all your web browsers. This is the only way to stay verifiably safe from Java drive-by malware.

Stay safe!
--

Monday, December 10, 2012

Passwords
Versus The Limits of Human Comprehension
Versus The Anti-Security Rats

--
This past week I listened to a US NPR (National Public Radio) program on the Diane Rehm Show entitled 'The Illusion of Online Security'. Despite the fact that the program featured terrific security expert Kevin Mitnick, among others, it was worthless garbage chatter. I personally sent off two simple and direct email questions to the program in order to get the discussion above the level of coffee talk, but both were ignored. I asked about multi-factor authentication, specifically the concept of using something we KNOW, such as a password, and something we HAVE, such as a Yubikey. But apparently, from what little was said about multi-factor authentication, the subject flew far over the heads of everyone in the discussion but Kevin. I felt sorry for Kevin, as he reiterated several times the key problems with today's Internet security, and not once did I have any sense he had penetrated the skulls of the others speaking. I wished I had been there to help Kevin speak to the issues on something closer to the level of their comprehension. But I realized they were simply not going to understand.

The concept of technology being beyond the comprehension of average people is very old. I remember the 1970 book 'Future Shock' by Alvin Tofler. It was a fanciful adventure in FUD, mixed with some bits of actual futurism, designed to sell books. It was also made into TV special to add illustration to its sensation. One thing it did manage to portray well has been the inability of the human mind to comprehend the full complexity of our world. As we watch the ramifications of the damage our species wreaks upon our miracle planet, how can any of us comprehend a solution beyond our individual lives? It is too much for any one mind to grasp. Similarly, today's technology is well beyond the comprehension of most human beings. Understanding it all is simply NOT going to happen among the average populace. There is no solution any of us can comprehend beyond making certain we are safe and secure within our individual lives.

For those of us who can and wish to understand the issue of passwords on the Internet, I want to pass along a nicely concise article entitled "How Attackers Steal Passwords" by Joe Golton. It is well worth a good read to both yourself and anyone willing to listen. I'll be reading it to the local PC user group where I often teach.

I must add to Joe's list of 9 methods of stealing passwords Number 10: Illegal government surveillance in violation of your personal privacy rights. In the USA this pertains specifically to violation of the Fourth Amendment of the US Constitution. We might as well be realistic. Illegal US government surveillance of US citizens on US soil is a constant, ongoing event at this time. This isn't the place to discuss the politics of why. It is simply a fact we must consider. It is also one reason I will be discussing tools for encryption of personal data in future articles.

Related articles by Joe Golton are:

'A Guide to Using Passwords Without Distraction.'

'Which Password Manager?'

:-Derek
---

Wednesday, December 5, 2012

Mac Security Information Resource List
2012-12

--
[Updated 2012-12-05 7:43 pm]
--
The purpose of this list is to point out Mac security information resources we can all use. I am adding the most directly useful of the Mac security web locations to my "Friends Of Mac-Security" list on the right of the blog page for your convenience. Please do NOT count on my blog as a summary of any of these resources. I have neither time nor ambition to meet that expectation. Instead please visit these all of these sites directly.

NOTE: Please add to my list via your comments. I will be updating this article with your suggests, giving you credit for your contributions. They are always appreciated.

This list is in no order of priority. I'll leave that to you. But I will start with my net friend Thomas Reed, with whom I collaborate. Together, with a group of writers, developers and others who work with malware, we attempt to keep a complete list of active Mac malware which we present on our perspective websites.

I) Thomas' Tech Corner

Thomas's terrifically useful website, like this blog, is entirely an act of altruism to the Mac community. He attempts to keep track of all the currently active Mac malware, as do I. We will be collaborating in the future to share our collected list of malware with out via both our websites. Thomas is also involved with anti-malware software analysis. I highly recommend his interesting article Mac anti-virus detection rates.
altruism
    n. The quality of unselfish concern for the welfare of others.
II) Brian Krebs: Kreb on Security

Brian wrote about computers for the Washington Post through 2009. We benefit from his, again altruistic, contributions to the computer security community via his terrific web blog. His work has been exemplary. He does not focus on Mac security. However, he's one of the very best independent resources on computer security issues, many of which are directly applicable to Mac users.

Brian also, like myself, has had a run-in with the Red Hacker Alliance as they used to be called. This Chinese hacker group is now simply called the Chinese government. Brian also points out that one of the former RHA members is now involved with, ironically and ominously, an Chinese 'anti'-malware company called 'Anvisoft'. Here's his article on the subject: Infamous Hacker Heading Chinese Antivirus Firm?
philanthropy
   n. An active effort to promote human welfare; humanitarianactivity. In this sense, it is an action, not merely a state of mind. [PJC]

Rich is the Mac security expert at venerable TidBITS. His correspondence has personally helped me learn a great deal about Mac computer security. He's a terrific fellow and great resource. Rich is not the only contributor to his Securosis Blog. Nor is his blog specific only to Mac computers. Like Brian Krebs, Rich is extremely knowledgable about the entire field of computer security and highly recommended for general knowledge.

Rich's Mac security specific articles typically turn up at the TidBITS website and in the weekly TidBITs newsletter, available for sign up HERE.

Rich is also a contributor to the Macworld Mac Security Superguide, available through TidBITS Publishing.

IV) MacWorld Security

I've been a paying subscriber to MacWorld magazine for nearly two decades (electronic version preferred). I very much enjoy other Mac magazines and websites. But I consistently come back to MacWorld as my best general Mac resource. Their writing is excellent. The magazine itself still lags a full month behind reality. But the website is terrifically up-to-date. Recently their website has gone through a hellish beta period of revision. However, it appears to have settled into usefulness again, including its Security website area. I would never count on MacWorld as any sort of definitive source of Mac security news. Much of it is second hand. None of it is provocative or particularly insightful. However, they keep track of the big issues and write about them effectively.

V) Topher Kessler at MacFixIt

Topher is another member of the Mac security interest group to which I belong. I used to be a paying member at MacFixIt and have been reading Topher's terrific articles for years. He frequently writes about Mac malware and Mac security strategies. I've found his insights to be extremely valuable.

VI) Intego's Mac Security Blog

I've had a very positive relationship with the folks at Intego. I still prefer their VirusBarrier X6 to the alternatives I've tested and continue to be a paying user. Their Mac Security Blog has been the best commercial source of Mac Security news I've found. Lately the blog has been expanding in some odd directions that have concerned me. You may find my comments there stating so. Nonetheless, their Mac security reports have consistently been on target, timely and insightful.

I continue to wish Intego would publish a list of known active Mac malware! They won't, sigh. No one will. It's the usual 'secret malware', 'go get your own' competition within the commercial anti-malware industry that irks me to no end. And yet, Intego have gone out of their way to help me whenever I've had specific malware questions. I am extremely grateful for their work within the Mac community and look forward to their supporting them in the future.

V) The NakedSecurity blog at Sophos

The Sophos blog covers a lot of computer security news and issues. As such, you're likely to find their articles to be slightly more obscure for the average Mac user. Nonetheless, I find their articles to be timely and interesting. They dive deep into what's going on in computer security today. For example, they're a great place to keep up with the latest DIY malware kits, aka Exploit Kits and Hacker Tools. All of this is increasingly relevant to Mac users as the cyber criminals in China, Russia, Iran and elsewhere become more Mac literate and more desperate to abuse both users and LUSERS alike.

~~~~~~~~~~

That's it for my quick Mac Security Information Resource List. Here are links to additional resources I recommend for those who wish to know more about computer security:

Steve Gibson's 'Security Now' podcast @TwIT.TV
Secunia
SANS
The Ed Bott Report
Jeremiah Grossman's Whitehat Security Blog
• The Fishbowl: Dr. Charlie Miller's Weblog
Trail of Bits: Dino Dai Zovi's Blog
Adobe's PSIRT Blog

If you have other great computer security information resources, please post them in the comments!

Share and Enjoy,

:-Derek