Friday, January 30, 2009

Re: "The Mac Malware Myth"

--
I'm a Daniel Eran Dilger fan. I've enjoyed bantering with him in the past over at ye olde Mac Advocacy Usenet newsgroup for many years. He writes one of my favorite blogs called RoughlyDrafted Magazine.

Yesterday Dan posted a great article called "The Mac Malware Myth". Being my notorious self, I posted a few replies to the article. Seeing as the replies are directly applicable to Mac Security, I decided to toss them here as well. My replies are a bit redundant of previous stuff I have written, but I also find them to be nice little summaries of useful information. So here goes:

Reply #1:

HISTORY: ‘The Sky Is Falling’ FUD started in August of 2005. The first perpetrator was our old pal Symantec. Who else. McAfee fell in line by the end of the year. But oddly, the CEO of McAfee was then quoted as saying the single best way to avoid malware on computers was to, you guessed it, use a Mac.

In the following three years there was an actually wonderful event: The FUD got to Apple and they got seriously serious about Mac OS X security. Believe me, Apple had NOT been serious about it previously. As a result there was an exponential increase in Apple Security updates. There was also one enormous revelation: Apple QuickTime was a massive security hole. If you review the security improvements in Quicktime over the last year you’ll realize this is a fact. The problems first became obvious in December 2006 when one of its vulnerabilities was exploited by hackers at MySpace who managed to use a cross site scripting hole in Quicktime to hack thousands of MySpace pages. Apple rapidly provided a fix and got to work cleaning up the rest of their messed up code.

In October 2007, the very very very first Mac OS X malware in-the-wild showed up in the form of a porn site Trojan horse masquerading as a Quicktime component you were supposed to install in order to watch a website porn video. That was over TWO YEARS after ‘The Sky Is Falling’ FUD began. Then over the last year a horrifying TRICKLE happened. While Windows was flooded with thousands of new malware, including real life viruses, Mac OS X was made slightly damp with another seven Trojan horses. Did I feel a drop?


Reply #2:

“Security By Obscurity”
… Is a joke, always was, and I suspect always will be. I wrote a shocking article, over at my Mac-Security blog, about how to prove it is a joke to all but the most dimwitted among us. It uses mathematics, which apparently confuses dunderheads and trolls.

Why is there no such thing as ‘Security By Obscurity’ for Mac OS X?

Because Mac OS X is UNIX. It’s certified! Look it up! UNIX was built from day one to be profoundly secure. Windows never was. That’s why Microsoft, to this day, have the single least secure operating system commercially available. Very sad. Very true.

Do not ever expect Mac OS X, even if it becomes as popular as Windows, to have any amount of malware as massive as Windows. Mac OS X is, here’s that word again, PROFOUNDLY more secure than Windows. There is no such thing as perfect security. Mac users have no excuse for not paying attention to security. But never let any joker, dimwit or troll fool you that there is such a thing as ‘Security By Obscurity.’ What really exists is solid state Mac OS X security that prevents hacking and cracking far better than anything Microsoft will ever come up with. That is literally why they have 99.99999999% of the malware and Mac OS X users statistically have next to nothing. And yes, they’ll hate you for telling them the truth. Just smile back.

;-Derek


Reply #3:

OK, so you want to be a responsible Mac OS X user, and want to be prepared for any Mac malware lingering out there in the wild. What do you do?

1) Never install anything that you have not verified as 100% legitimate software. That means specifically two things:

A) Never believe any notice anywhere that says you must install something being offered to you. Go check it out and download it from a reputable site that checks out software and provides user reviews. These include Versiontracker, MacUpdate, Download.com, TuCows, etc.

B) Never install pirated software. The most recent Trojan for Mac OS X specifically hides inside pirated software installers, pretending to be an installer package, installed right along side the legitimate installer packages.

2) Go get a decent free anti-malware program. (The term ‘anti-virus’ is out of date). My only recommendation for a FREE program is ‘iAntiVirus’ free edition from PC Tools. It is up to date. Do NOT bother with ClamXav. It is well over a year out of date regarding Mac malware. (I have personally attempted to improve this situation but found it fruitless).

Of the commercial/shareware anti-malware programs, the only one I recommend is Intego’s VirusBarrier. It works great. I own it. Got a nice deal on it too. Downside: You have to pay every year for updated malware definitions. Not worth it! See #1 above. Go get iAntiVirus.

3) Keep up with security updates. Always install Apple Security Updates when they are provided via Software Update for your Mac. Always install updates to applications and plugins. Quicktime has security holes. Adobe Flash has security holes. RealPlayer has security holes. Etc.

4) Use security tools and techniques. This includes working as a ‘Standard User’ on any network, not as an Administrator. You can also encrypt your account using Apple’s provided File Vault. You can also lock down your Mac using a Firmware password. There are loads of other security utilities on the net. Three I like are 1Password, Little Snitch and Gnu Privacy Gaurd (which is free!)

5) The #1 Rule of Computing, repeat after me:

Make
A
Backup.

If you don’t, you get what you deserve. Cruel. Reality.

That’s my list!

The end.
--

Friday, January 23, 2009

Mac Malware #8: OSX.Trojan.iServices.A

--
Intego, makers of VirusBarrier, posted an alert on Thursday 2009-01-22 regarding a newly discovered Trojan horse specific to Mac OS X. They have designated it "OSX.Trojan.iServices.A". It was found in torrented/pirated copies of Apple's iWork 09 installer.

Conclusion: If you have torrented, downloaded or been given any pirated copy of iWork 09, do not install it! Throw it away!

Cures: Intego of course has provided a removal method in the latest malware definitions file for VirusBarrier. The folks at MacScan have also provided a FREE removal tool here.

A MacRumors article about the Trojan can be found here.

How does it work?

1) Included with the iWorks 09 package is an added bogus Trojan package entitled "iWorkServices.pkg". When you install iWork 09, the Trojan is installed along with the legitimate program packages. It is specifically installed as a startup item within your system.

2) According to Intego: "The malicious software connects to a remote server over the Internet; this means that a malicious user will be alerted that this Trojan horse is installed on different Macs, and will have the ability to connect to them and perform various actions remotely. The Trojan horse may also download additional components to an infected Mac."

Essentially, you've been zombied. The cracker controlling the program can do anything with your computer. Examples include money making schemes such as stealing your identity, spamming the net or using your machine in a denial of service attack.

For Mac users, this method of infection is entirely new. It can also be used in any other similarly pirated program installer, not just iWorks 09. The only things specific to iWork 09 about this Trojan are the name of the package used and its placement along side all the other installer packages for iWorks 09.

In other words, pirated Mac program installers are now all suspect. Pirates beware.
--

Tuesday, December 16, 2008

Apple Security Update 008

-
10.5.6 was released Monday afternoon in combination with Apple Security Update 008. The security update is also available separately for Tiger, 10.4. You grab them via Software Update within Mac OS X or download them from Apple's website.

Here are some highlights:

- ATS (Apple Type Services) bug/security update. 10.5 only.

- BOM (Bill of Materials) security update.

- CoreGraphics security update.

- CoreServices security update to prevent web hijacking of a user's credentials.

- CoreTypes security update. Adds further file types to its Internet download warning list. 10.5 only.

- FlashPlayer Plug-in security update.

- Kernel security update. 10.5 only.

- LibSystem:
  • - Security update to the inet_net_pton API.
  • - Security update to the strptime API.
  • - Security update to the strfmon API.
- Managed Client bug/security update. 10.5 only.

- network_cmds bug/security update.

- Podcast Producer security update. 10.5 Server only.

- UDF (Universal Disk Format) ISO (International Standards Organization disk image) handling bug/security update.

Details regarding 10.5.6 can be found over at my MacSmarticles blog.
--

Thursday, December 11, 2008

Trojan OSX.RSPlug DNS Confusion Solution

-
Earlier in the year I posted an article questioning whether Apple had patched Mac OS X Server versions 4 and 5 to prevent the actions of Trojan OSX.RSPlug.A, which hijacks a Mac's DNS server settings in order to divert users to Phishing sites. Misinformation galore was available on the Internet, and of course there was no one in the Mac community I could find with any kind of clear discussion of the issue. If there were such folks around I would send you to them for better information than I can provide.

Thankfully this past week, during my investigation of Clamav's effectiveness against Mac malware, Adam Engst was kind enough to get me in touch with Rich Mogull. Rich provided me with a very helpful answer, quoted below:
Hi Derek,

Yes- that family of trojans makes DNS changes on your system, but not because of any vulnerability or problems with the OS X implementation of DNS. The trojan only works if you manually install it and enter you administrative password. It then changes settings just as you can do yourself under normal circumstances. On occasion, these trojans (and others) may be able to take advantage of other vulnerabilities on the Mac to make changes without an administrative password, or install itself automatically due to a browser weakness, but there are currently no known open vulnerabilities like these being used by bad guys. Right now, you still need to install it and manually enter your admin password- there's not much Apple can do to prevent that.
As a result, I chopped out my early Trojan OSX.RSPlug.A article and corrected a related sentence in my recent article "Update: The State Of Trojan OSX.RSPlug..." in order to remove my own confusion.

The confusion on the Internet regarding Apple Security Update 005 came from the fact that it repaired a very old DNS technology vulnerability. The fact that DNS was involved in both this vulnerability and the RSPlug Trojan was coincidental. I have never covered the DNS technology vulnerability here, called DNS cache poisoning, as it has not been of serious consequence to Mac users. If you are interested, coverage of the problem at the SANS Institute is adequate and provides references.
--

Wednesday, December 10, 2008

Off Topic: How to meet trolls and play S&M games

-
The Internet of course reflects humanity at large. The difference is, on the Internet cowards can come out of their hiding holes and swat you with their widdle hands. You say 'ouch' and they get all orgasmic. These lost little souls are referred to as trolls.

In the process of researching an upcoming article about Clamav, the cross platform Open Source anti-malware program, I ran over the biggest concentration of trolls of 2008. It's the Clamav Users email list. If you'd like to meet trolls and play S&M games, here is where to sign up:

Clamav Abusers

Tell them Derek sent you. Enjoy a laugh at my expense. ;-D
I guarantee you'll learn utter nonsense about malware while you're there. And who doesn't find nonsense amusing.
**Sarcasm**
--

Thursday, December 4, 2008

Update: The State Of Trojan OSX.RSPlug, aka the 'Porno Trojan'

The net-cracker effort to bring the 'RSPlug' Trojan horse from Windows over to Mac OS X continues apace. As of this week we are now up to version E, aka Trojan OSX.RSPlug.E. Again, this Trojan is showing up at scam pornography websites.

The difference with variants D and E, however, are particularly nefarious. Instead of the Trojan itself being the full payload of malware, it downloads the actual payload from the Internet. This means the Trojan can install literally anything into your system. It's not just for DNS forwarding phishing scams any more.

Of course, it will be possible to kill off the payload Internet sites one by one as sub-variants of D & E pop up. But once infected, a Mac could theoretically become zombied, which these days is the prime goal of net-crackers. Botnets can make big money. As was popularly reported last week, the taking down of one particular bot wrangler killed off as much as 70% of SPAM distribution for a few days. That's a massive botnet. Imagine the profit the bot wrangler was pulling in. Sadly, the botnet involved remained intact and another bot-wrangler stepped in to take advantage of it, restoring SPAM to its usual blasting volume.

You can read the details about Trojan OSX.RSPlug.E over at Intego's website.

One hilarious flagging giveaway of this Trojan is the continued laziness of the developers' social engineering method. Instead of altering their tease line to potential wetware victims, they left it exactly the same as the Windows version. This means that anyone who is both Mac and Windows savvy will realize immediately that something screwy is going on. The blunder is the tease line "Video ActiveX Object Error". For those who don't know, ActiveX is a scripting monstrosity perpetrated by Microsoft several years back. Yeah, it was another of their attempts to make the Internet proprietary. ActiveX is entirely irrelevant on Mac OS X, thank goodness, as it is a gigantic, wide open door for malware infection on Windows. The only web browser on Mac capable of running ActiveX rubbish is FireFox, and you have to specifically install an ActiveX extension. Therefore, for the moment, if you run into a "Video ActiveX Object Error" on a website, you have just run into an attempt to infect you with the Trojan OSX.RSPlug.
--

Tuesday, December 2, 2008

Trojan OSX.Lamzev.A

As of last week, Mac OS X has a second piece of malware. It is a Trojan horse officially called OSX.Lamzev.A. (It is also erroneously known as OSX.TrojanKit.Malez).

Detection and removal of this malware is built into the latest versions of the FREEWARE anti-malware programs ClamXav and iAnti-Virus.

So what is the strategy this time? To quote ZDNet:
OSX.Lamzev.A is a hacker tool designed primarily to allow attackers to install backdoors in a user's system, according to Intego. However, the company dismissed the tool as a serious threat because a potential hacker has to have physical access to a system to install the backdoor.
. . .
Other antivirus vendors noted that Lamzev could be disguised as a piece of legitimate software and used to trick users into creating the backdoor themselves.
Theoretically, this will become another piece of social engineering / wetware error malware where the user is tricked into installing it. Therefore, as usual, always verify that anything you install is legitimate software. Check it out at any of the well known shareware distribution sites like VersionTracker.com, MacUpdate.com, TuCows.com or MajorGeeks.com. All of these sites have human users and reviewers who can tell you what's legitimate. If you can't verify an application, don't install it! Also, if you want to be extra safe, work only inside a 'Standard' Mac OS X account, not an Administrator account.

I'm going to keep an eye on this Trojan to see what damage it can do. If it is a true 'backdoor' to Mac OS X, a cracker can do anything they like with your Mac. We'll see with time if this becomes a problem. For now, the anti-malware distributors consider it only a minor threat. Just run your usual FREEWARE anti-malware apps once a week, at least, to clean it out if somehow you've installed it.
--