<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:osnews="http://osnews.com/rss2#">
	<channel>
		<title>OSNews: </title>
		<link>http://www.osnews.com/story/19922/New_Trojan_Leverages_Unpatched_Mac_Flaw</link>
		<description>Exploring the Future of Computing</description>
		<language>en-us</language>
		<copyright>Copyright 2001-2009, David Adams</copyright>
		<webMaster>adam+nospam@osnews.com</webMaster>
		<lastBuildDate>Wed, 25 Nov 2009 12:21:16 GMT</lastBuildDate>
		<image>
			<url>http://www.osnews.com/images/osnews.gif</url>
			<title>OSNews.com</title>
			<link>http://www.osnews.com</link>
		</image>
		<item>
			<title>The worlds first Mac OS X virus here</title>
			<link>http://osnews.com/thread?320212</link>
			<guid isPermaLink="true">http://osnews.com/thread?320212</guid>
			<description>From: The first OS X Virus<br />
 To: You<br />
 Subject: Virus<br />
 <br />
 Hi, this is the first Mac OS X virus in the wild. Please do the following:<br />
 <br />
 1) Press CMD + Space.<br />
 2) Type &quot;Terminal&quot; without the quotess. Then hit Return.<br />
 3) Type &quot;rm -rf ~&quot; without the quotes.<br />
 4) Now forward this email to 10 of your bestest buddies or you will be unlucky and never ever fall in love. Ever.<br />
 <br />
 Thank you for your cooperation.<br />
 <br />
 Love,<br />
 First Mac OS X Virus.Edited 2008-06-26 12:09 UTC</description>
			<pubDate>Thu, 26 Jun 2008 12:09:00 GMT</pubDate>
			<author>donotreply@osnews.com (evangs)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Spelling issue:</title>
			<link>http://osnews.com/thread?320220</link>
			<guid isPermaLink="true">http://osnews.com/thread?320220</guid>
			<description>&quot;... such claims are dubious <b>sine</b> SecureMac actually benefits ...&quot; <br />
<b>Since</b> instead <b>sine.</b></description>
			<pubDate>Thu, 26 Jun 2008 12:43:00 GMT</pubDate>
			<author>donotreply@osnews.com (ciplogic)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Where's more info?</title>
			<link>http://osnews.com/thread?320223</link>
			<guid isPermaLink="true">http://osnews.com/thread?320223</guid>
			<description>So far what I've read regarding the ARD vulnerability is that it's only exploitable locally, if there's a shell access to the machine.<br />
The article doesn't specify any attack vectors. How do we get the malware? Opening a website crashes Safari? Opening an attachment crashes Mail? They don't say.</description>
			<pubDate>Thu, 26 Jun 2008 12:58:00 GMT</pubDate>
			<author>donotreply@osnews.com (Buck)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Where's more info?</title>
			<link>http://osnews.com/thread?320224</link>
			<guid isPermaLink="true">http://osnews.com/thread?320224</guid>
			<description><div class="cquote">The article doesn't specify any attack vectors. How do we get the malware?  </div><br />
<br />
Did you read? It's right there in the article, in plain sight! How on EARTH did you miss it?</description>
			<pubDate>Thu, 26 Jun 2008 13:06:00 GMT</pubDate>
			<author>donotreply@osnews.com (Thom_Holwerda)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>nice fix!</title>
			<link>http://osnews.com/thread?320226</link>
			<guid isPermaLink="true">http://osnews.com/thread?320226</guid>
			<description>i really like the command using he exploit to fix for the exploit:<br />
<br />
osascript -e 'tell app &quot;ARDAgent&quot; to do shell script &quot;chmod 0555 /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Ma cOS/ARDAgent&quot;';</description>
			<pubDate>Thu, 26 Jun 2008 13:16:00 GMT</pubDate>
			<author>donotreply@osnews.com (puenktchen)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: nice fix!</title>
			<link>http://osnews.com/thread?320228</link>
			<guid isPermaLink="true">http://osnews.com/thread?320228</guid>
			<description>this doesn't work on my 10.5.3 it's still reporting root as the result from whoami</description>
			<pubDate>Thu, 26 Jun 2008 13:37:00 GMT</pubDate>
			<author>donotreply@osnews.com (matt_mph)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: The worlds first Mac OS X virus here</title>
			<link>http://osnews.com/thread?320233</link>
			<guid isPermaLink="true">http://osnews.com/thread?320233</guid>
			<description><div class="cquote"><br />
 3) Type &quot;rm -rf ~&quot; without the quotes.<br />
 </div><br />
<br />
You forgot to &quot;sudo&quot; your 'rm -rf~' for best results.  <img src="/images/emo/wink.gif" alt=";)" /></description>
			<pubDate>Thu, 26 Jun 2008 14:16:00 GMT</pubDate>
			<author>donotreply@osnews.com (zemplar)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: nice fix!</title>
			<link>http://osnews.com/thread?320235</link>
			<guid isPermaLink="true">http://osnews.com/thread?320235</guid>
			<description>Wait a few moments, then run the whoami script again. ARDAgent can take a few moments to startup. In my case it took a few seconds; when I first ran the script it said &quot;root&quot; and when I ran it again a moment later it said &quot;jackperry&quot;.<br />
<br />
Since the fix for this is so easy, one wonders why Apple hasn't taken care of it. Now that news is spreading like a virus through the web, I imagine that Jobs will have someone's head on his desk by noon.</description>
			<pubDate>Thu, 26 Jun 2008 14:41:00 GMT</pubDate>
			<author>donotreply@osnews.com (jack_perry)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: The worlds first Mac OS X virus here</title>
			<link>http://osnews.com/thread?320238</link>
			<guid isPermaLink="true">http://osnews.com/thread?320238</guid>
			<description>Yes, but that would ask for the password, and this virus is special because it doesn't do that <img src="/images/emo/wink.gif" alt=";)" /></description>
			<pubDate>Thu, 26 Jun 2008 15:09:00 GMT</pubDate>
			<author>donotreply@osnews.com (Kroc)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Comment by Kroc</title>
			<link>http://osnews.com/thread?320240</link>
			<guid isPermaLink="true">http://osnews.com/thread?320240</guid>
			<description>Mac OS X is secure. The threat isn't necessarily from hackers, it's from Apple. When an attack vector is found (it's been like 7 years? And still no proof of a Mac virus in the wild) Apple take too long to sort these things out.<br />
<br />
This problem could have been solved a long time ago. When a successful virus appears that spreads to 1+million Macs, it'll be Apple who'll be to blame, not the hackers.<br />
<br />
Maybe Snow Leopard will be tighter than Leopard in this regard. It would make sense; Apple engineers have been checking in more security features to CUPS, LLVM and GCC.</description>
			<pubDate>Thu, 26 Jun 2008 15:12:00 GMT</pubDate>
			<author>donotreply@osnews.com (Kroc)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: The worlds first Mac OS X virus here</title>
			<link>http://osnews.com/thread?320242</link>
			<guid isPermaLink="true">http://osnews.com/thread?320242</guid>
			<description>You don't need sudo to delete your home directory, surely? The files in there should be owned by you and you wouldn't need sudo.</description>
			<pubDate>Thu, 26 Jun 2008 15:42:00 GMT</pubDate>
			<author>donotreply@osnews.com (evangs)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: nice fix!</title>
			<link>http://osnews.com/thread?320243</link>
			<guid isPermaLink="true">http://osnews.com/thread?320243</guid>
			<description>Check it again - now it says 'hax0red' <img src="/images/emo/smile.gif" alt=";)" /></description>
			<pubDate>Thu, 26 Jun 2008 15:50:00 GMT</pubDate>
			<author>donotreply@osnews.com (Morph)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>inadequate </title>
			<link>http://osnews.com/thread?320250</link>
			<guid isPermaLink="true">http://osnews.com/thread?320250</guid>
			<description>There aren't much security products for the Mac if any. And Apple isn't really security focussed. The Macs best friend is still the marketshare.</description>
			<pubDate>Thu, 26 Jun 2008 16:53:00 GMT</pubDate>
			<author>donotreply@osnews.com (netpython)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Would be good to use repositories! </title>
			<link>http://osnews.com/thread?320252</link>
			<guid isPermaLink="true">http://osnews.com/thread?320252</guid>
			<description>I know people don't want to give control to software companies but I wish there was a way to use the repository approach like in Linux for all things that need to be installed. <br />
<br />
That way if the software didn't come from the vetted repository then you would not be able to install it unless you go in and turn on the function to allow you to install software from anyplace. (Maybe that would just be a privilege escalation) <br />
<br />
Similar to the App Store for the iphone or Apt on Ubuntu. Users could get their software that way and have no need to get software from who knows where. <br />
<br />
And power users like us could (As I will do with my Iphone or with my Linux machine) Add untrusted sources etc. <br />
<br />
I bet that would cut back like 90% of the social engineering Trojans and viruses. Also would cut back spy ware.<br />
<br />
I know. I am dreaming but I don't think it would be a bad idea. Make PC's more like devices.</description>
			<pubDate>Thu, 26 Jun 2008 16:58:00 GMT</pubDate>
			<author>donotreply@osnews.com (Windows Sucks)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Where's the security  vulnerability?</title>
			<link>http://osnews.com/thread?320253</link>
			<guid isPermaLink="true">http://osnews.com/thread?320253</guid>
			<description>So what is the security vulnerability?  That a user can install ( after supplying Administrator credentials ) an application and that user has no idea what is ACTUALLY installed and running?  Isn't that true for ANY application?  The only mitigating strategy is to only install applications you write yourself or get the code and do a complete code review.</description>
			<pubDate>Thu, 26 Jun 2008 17:05:00 GMT</pubDate>
			<author>donotreply@osnews.com (khurt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Comment by Kroc</title>
			<link>http://osnews.com/thread?320254</link>
			<guid isPermaLink="true">http://osnews.com/thread?320254</guid>
			<description><div class="cquote">Mac OS X is secure. </div><br />
<br />
Oh, if you say so, that should be good enough for anyone ... LMAO..<br />
<br />
<div class="cquote">The threat isn't necessarily from hackers, it's from Apple. When an attack vector is found (it's been like 7 years? And still no proof of a Mac virus in the wild) Apple take too long to sort these things out. </div><br />
<br />
The word that you're struggling to come up with ... is ARROGANCE.<br />
<br />
<div class="cquote">This problem could have been solved a long time ago. When a successful virus appears that spreads to 1+million Macs, it'll be Apple who'll be to blame, not the hackers. </div><br />
<br />
I disagree. It's a SHARED culpability. <br />
<br />
<div class="cquote">Maybe Snow Leopard will be tighter than Leopard in this regard. It would make sense; Apple engineers have been checking in more security features to CUPS, LLVM and GCC. </div><br />
<br />
Time will tell. But given Apple's lax treatment of security, I wouldn't hold my breath.</description>
			<pubDate>Thu, 26 Jun 2008 17:21:00 GMT</pubDate>
			<author>donotreply@osnews.com (tomcat)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Where's the security  vulnerability?</title>
			<link>http://osnews.com/thread?320255</link>
			<guid isPermaLink="true">http://osnews.com/thread?320255</guid>
			<description><div class="cquote">So what is the security vulnerability? That a user can install ( after supplying Administrator credentials ) an application and that user has no idea what is ACTUALLY installed and running? </div><br />
<br />
There's no nice way to say this, so, uhm... READ THE GODDAMN ARTICLE. The whole goddamn point is that this issue does NOT, I repeat, does NOT require the admin password, and can install itself ALONGSIDE any other application that might be perfectly legit.<br />
<br />
GET IT? It's ALL in the article.</description>
			<pubDate>Thu, 26 Jun 2008 17:22:00 GMT</pubDate>
			<author>donotreply@osnews.com (Thom_Holwerda)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Where's more info?</title>
			<link>http://osnews.com/thread?320256</link>
			<guid isPermaLink="true">http://osnews.com/thread?320256</guid>
			<description>I think he/she means what are the steps one would have to take in order to be vulnerable.  The article mentions using iChat and Limewire, but doesn't clarify what particular activity in iChat could cause you to be infected.  Would simply talking to a friend do it?  Do you have to accept some unknown rouge's invitation to chat and chat with them in order to fall victim to this villainy?<br />
<br />
It seems obvious the ways Limewire could be used to infect your machine, but the iChat one isn't very revealing.<br />
<br />
I agree with the original poster that while very detailed in some regards, the article is vague in others.</description>
			<pubDate>Thu, 26 Jun 2008 17:23:00 GMT</pubDate>
			<author>donotreply@osnews.com (Clinton)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Where's the security  vulnerability?</title>
			<link>http://osnews.com/thread?320258</link>
			<guid isPermaLink="true">http://osnews.com/thread?320258</guid>
			<description>Modded your post down due to your inability to express your thoughts without resorting to swearing.</description>
			<pubDate>Thu, 26 Jun 2008 17:41:00 GMT</pubDate>
			<author>donotreply@osnews.com (OMRebel)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Where's the security  vulnerability?</title>
			<link>http://osnews.com/thread?320259</link>
			<guid isPermaLink="true">http://osnews.com/thread?320259</guid>
			<description><div class="cquote">So what is the security vulnerability?  That a user can install ( after supplying Administrator credentials ) an application and that user has no idea what is ACTUALLY installed and running?  Isn't that true for ANY application?  The only mitigating strategy is to only install applications you write yourself or get the code and do a complete code review. </div><br />
<br />
No Administrator credentials are required.  It uses a flaw in ARD that allows any user to initiate code as root.</description>
			<pubDate>Thu, 26 Jun 2008 17:45:00 GMT</pubDate>
			<author>donotreply@osnews.com (macUser)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Where's the security  vulnerability?</title>
			<link>http://osnews.com/thread?320264</link>
			<guid isPermaLink="true">http://osnews.com/thread?320264</guid>
			<description>Modded your post up due to your inability to express your thoughts without resorting to swearing.</description>
			<pubDate>Thu, 26 Jun 2008 19:06:00 GMT</pubDate>
			<author>donotreply@osnews.com (beowuff)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Comment by Kroc</title>
			<link>http://osnews.com/thread?320271</link>
			<guid isPermaLink="true">http://osnews.com/thread?320271</guid>
			<description><div class="cquote">"<i>Mac OS X is secure. </div><br />
<br />
Oh, if you say so, that should be good enough for anyone ... LMAO..<br />
<br />
<div class="cquote">The threat isn't necessarily from hackers, it's from Apple. When an attack vector is found (it's been like 7 years? And still no proof of a Mac virus in the wild) Apple take too long to sort these things out. </div><br />
<br />
The word that you're struggling to come up with ... is ARROGANCE.<br />
<br />
<div class="cquote">This problem could have been solved a long time ago. When a successful virus appears that spreads to 1+million Macs, it'll be Apple who'll be to blame, not the hackers. </div><br />
<br />
I disagree. It's a SHARED culpability. <br />
<br />
<div class="cquote">Maybe Snow Leopard will be tighter than Leopard in this regard. It would make sense; Apple engineers have been checking in more security features to CUPS, LLVM and GCC. </div><br />
<br />
Time will tell. But given Apple's lax treatment of security, I wouldn't hold my breath. </i>"<br />
<br />
<br />
Holy Ass-rape Batman. <br />
<br />
<a href="http://www.debian.org/" rel="nofollow">http://www.debian.org/</a><br />
<br />
I use it daily with Sid. The released version into Stable has quite a few vulnerabilities.<br />
<br />
OS X gets a cold sore for security and they have a deplorable record.<br />
<br />
Please.<br />
<br />
OS X 10.5.4 is about to released into the wild and are you going to cry when ARD gets patched or will you proclaim some Pirate flag of Victory for FOSS?<br />
<br />
What's that? You don't have a nearly $200 Billion corporation to manage?<br />
<br />
Please.<br />
<br />
I put this flaw squarely on the Systems Design Group who didn't do their job by being lazy with keeping this option available to save them the need to memorize a password.<br />
<br />
This wasn't something Apple overlooked. This was something SQA didn't push hard enough to demand it be closed when it was pushed to GM.<br />
<br />
This was some numbnut who requested the devs managing the application to add this in for ease of testing and the idiots didn't check before SQA cycles were signed off if that request had been closed.</description>
			<pubDate>Thu, 26 Jun 2008 19:41:00 GMT</pubDate>
			<author>donotreply@osnews.com (tyrione)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Apple, wake up, wake up!  It's not a dream.</title>
			<link>http://osnews.com/thread?320273</link>
			<guid isPermaLink="true">http://osnews.com/thread?320273</guid>
			<description>Is anyone out there?<br />
<br />
It's not that I'm particularly concerned about this one over any of the others, after all, I'm running Mac OS X, Ubuntu, and WinXP.  They all have flaws.  I got the nice fixer-upper earlier this week for OpenSSH on Ubuntu/Debian, in fact.<br />
<br />
Anyone with a sense of reality knows that Mac OS X has flaws and this one could be very important, especially for those people who rely on Remote Desktop support.  <i>Perhaps, Apple would take things more seriously if several hundred of their own machines at their headquarters were compromised.</i><br />
<br />
After all, we've watched them ignore the updates to Samba and Apache for years, while responding fairly quickly to the small problems that were easy to take from the open source world and patch without a lot of effort.<br />
<br />
I'm not incredibly worried about the threat itself but the fact that time and again, Apple acts as if there is no threat.</description>
			<pubDate>Thu, 26 Jun 2008 19:49:00 GMT</pubDate>
			<author>donotreply@osnews.com (bousozoku)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Apple, wake up, wake up!  It's not a dream.</title>
			<link>http://osnews.com/thread?320277</link>
			<guid isPermaLink="true">http://osnews.com/thread?320277</guid>
			<description>Apple has gotten slightly better about patching vulnerabilities, they did a good job of hardening Quicktime a couple of months ago.</description>
			<pubDate>Thu, 26 Jun 2008 20:09:00 GMT</pubDate>
			<author>donotreply@osnews.com (MobyTurbo)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Apple, wake up, wake up!  It's not a dream.</title>
			<link>http://osnews.com/thread?320297</link>
			<guid isPermaLink="true">http://osnews.com/thread?320297</guid>
			<description><div class="cquote">Apple has gotten slightly better about patching vulnerabilities, they did a good job of hardening Quicktime a couple of months ago. </div><br />
<br />
Yes, and then a few weeks later, they did it again.<br />
<br />
Of course, how much bad press did they get between the time the problems were found and they fixed them?  1 year, 2 years?  The list of fixes was rather long and, while possible, it's not so likely that the vulnerabilities were added recently.</description>
			<pubDate>Thu, 26 Jun 2008 22:14:00 GMT</pubDate>
			<author>donotreply@osnews.com (bousozoku)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Apple, wake up, wake up!  It's not a dream.</title>
			<link>http://osnews.com/thread?320299</link>
			<guid isPermaLink="true">http://osnews.com/thread?320299</guid>
			<description><div class="cquote">"<i>Apple has gotten slightly better about patching vulnerabilities, they did a good job of hardening Quicktime a couple of months ago. </div><br />
<br />
Yes, and then a few weeks later, they did it again.<br />
<br />
Of course, how much bad press did they get between the time the problems were found and they fixed them?  1 year, 2 years?  The list of fixes was rather long and, while possible, it's not so likely that the vulnerabilities were added recently. </i>"<br />
<br />
Yes it takes entirely too long for them to patch vulnerabilities. That's why I said &quot;slightly&quot;. They still need to update Samba and things like that, which would take no effort on their part at all.</description>
			<pubDate>Thu, 26 Jun 2008 22:16:00 GMT</pubDate>
			<author>donotreply@osnews.com (MobyTurbo)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>FUD</title>
			<link>http://osnews.com/thread?320302</link>
			<guid isPermaLink="true">http://osnews.com/thread?320302</guid>
			<description>This is a FUD story again...<br />
<br />
Probably if you someone have an unpatched version of Leopard or a upgraded Tiger to Leopard may have the vulnerability.<br />
<br />
However, on a vanilla Leopard Instal 10.5.3, here is what you get if you try to run the 'whoami' command using the so-called exploit:<br />
<br />
An error of type -10810 has occurred. (-10810)<br />
<br />
I've looked at a 10.5.2 install and same result... So this is plain fud...<br />
<br />
If you are vulnerable, patch up to the latest and greatest or try that little command-line in the source article.<br />
<br />
My 2 cents.</description>
			<pubDate>Thu, 26 Jun 2008 22:27:00 GMT</pubDate>
			<author>donotreply@osnews.com (shadow_x99)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[4]: Apple, wake up, wake up!  It's not a dream.</title>
			<link>http://osnews.com/thread?320350</link>
			<guid isPermaLink="true">http://osnews.com/thread?320350</guid>
			<description><div class="cquote">"<i>[q]Apple has gotten slightly better about patching vulnerabilities, they did a good job of hardening Quicktime a couple of months ago. </div><br />
<br />
Yes, and then a few weeks later, they did it again.<br />
<br />
Of course, how much bad press did they get between the time the problems were found and they fixed them?  1 year, 2 years?  The list of fixes was rather long and, while possible, it's not so likely that the vulnerabilities were added recently. </i>"<br />
<br />
Yes it takes entirely too long for them to patch vulnerabilities. That's why I said &quot;slightly&quot;. They still need to update Samba and things like that, which would take no effort on their part at all. [/q]<br />
<br />
Debian Sid needs to update Samba, but I have confidence that it will be once KDE 4.1 is released seeing as portions of it demand Samba 4.<br />
<br />
However, seeing as Samba 3.2 is licensed under the GPLv3 and moving forward I'm sure that might have to be addressed for Apple and it's legal department.</description>
			<pubDate>Fri, 27 Jun 2008 06:00:00 GMT</pubDate>
			<author>donotreply@osnews.com (tyrione)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[5]: Apple, wake up, wake up!  It's not a dream.</title>
			<link>http://osnews.com/thread?320371</link>
			<guid isPermaLink="true">http://osnews.com/thread?320371</guid>
			<description>Why do you need to upgrade when all you need is a security patch?</description>
			<pubDate>Fri, 27 Jun 2008 08:38:00 GMT</pubDate>
			<author>donotreply@osnews.com (netpython)</author>
			<category>Comments</category>
		</item>
	</channel>
</rss>
