*DAMN R6
.:Navigation:| Home | Battle League | Forum | Mac Downloads | PC Downloads | Cocobolo Mods |:.

Welcome, Guest. Please login or register.
November 27, 2024, 03:40:27 am

Login with username, password and session length
Search:     Advanced search
One Worldwide Gaming Community since 13th June 2000
132955 Posts in 8693 Topics by 2294 Members
Latest Member: xoclipse2020
* Home Help Search Login Register
 Ads
+  *DAMN R6 Forum
|-+  *DAMN R6 Community
| |-+  General Gossip (Moderators: Grifter, cookie, *DAMN Hazard, c| Lone-Wolf, BTs_GhostSniper)
| | |-+  Just a Heads Up! Trojan Horse in Mac OSX
Pages: [1]   Go Down
Print
Author Topic: Just a Heads Up! Trojan Horse in Mac OSX  (Read 1733 times)
0 Members and 6 Guests are viewing this topic.
one login not workin
Guest
« on: April 09, 2004, 04:27:34 am »

Just a heads up to anyone who doesn't know...there's a Trojan Horse in OSX - the first one.

From Macnn:

This Trojan horse, MP3Concept (MP3Virus.Gen), exploits a weakness in Mac OS X where applications can appear to be other types of files: "The Trojan horse's code is encapsulated in the ID3 tag of an MP3 (digital music) file. This code is in reality a hidden application that can run on any Macintosh computer running Mac OS X. Intego says the malicious application can delete files, propogate itself by sending a message to other users, and also infect other MP3, JPEG, GIF or QuickTime files.                                    
                                     
                                     The company says that Mac OS X displays the icon of the MP3 file, with an .mp3 extension, rather than showing the file as an application, leading users to believe that they can double-click the file to listen to it. But double clicking the file launches the hidden code, which can damage or delete files on computers running Mac OS X, then iTunes to play the music contained in the file, to make users think that it is really an MP3 file . While the first versions of this Trojan horse that Intego has isolated are benign, this technique opens the door to more serious risks.  

"Due to the use of this technique, users can no longer safely double-click MP3 files in Mac OS X. This same technique could be used with JPEG and GIF files, though no such cases of infected graphic files have yet been seen."  


Update your virus definitions/software!
Logged
BTs_Mysterio
BL Staff
God save the Royal Whorealots
*****
Offline Offline

Gender: Male
Posts: 3676



WWW
« Reply #1 on: April 09, 2004, 04:42:23 am »

I would highly suggest that you read the comments on that story one.
Logged

"There's room at the top they are telling you still. But first you must learn how to smile as you kill"
John Lennon
Only suits they'll be wearing are body bags. • Your trial will be held at the city morgue. • I'll return your gun, one bullet at a time.
Mysterio is a registered trademark of Myster
BTs_GhostSniper
Moderator
God save the Royal Whorealots
*****
Offline Offline

Gender: Male
Posts: 3807


SUA SPONTE


WWW
« Reply #2 on: April 09, 2004, 04:48:15 am »

Well, since I currently do not, and probably never will, use mp3 files on my Mac, I don't think this will affect me.  I only use music files in the very rich AIFF format (the format they come in on a regular Music CD).
Logged

"On the fields of friendly strife are sown the seeds that on other days and other fields will bear the fruits of victory."

-General of the Army Douglas MacArthur
Mr. Lothario
Special Forces
God bless the freaks
*****
Offline Offline

Gender: Male
Posts: 1748


Suck mah nuts.


« Reply #3 on: April 09, 2004, 06:53:02 am »

     Well, without even reading the story, that sounds like a load of bullpuckey to me. I have "show all file extensions" enabled, and I renamed the app "VLC" (no .app suffix) to "VLC.mp3" and OS X renamed it to "VLC.mp3.app". It's not possible to remove the .app suffix in that case, since OS X replaces it when you delete it. Even when I turned off "show all file extensions", the .mp3.app renamed. Thus, horseshit.
Logged

"How is the world ruled and how do wars start? Diplomats tell lies to journalists and then believe what they read." - 19th-century Austrian press critic Karl Kraus

Rule 37: "There is no 'overkill'. There is only 'open fire' and 'I need to reload'". -- Schlock Mercenary
crypt
God bless the freaks
*****
Offline Offline

Gender: Male
Posts: 1631


Do or Die


WWW
« Reply #4 on: April 09, 2004, 07:20:54 am »

Still, until we hear more we should be careful.
Logged

Opinions are like assholes, everyone has one. Unfortunately, most of them go hand in hand.
one once again
Guest
« Reply #5 on: April 09, 2004, 03:42:54 pm »

It isn't a virus  Wink
Logged
Ace
Resident Ass
God bless the freaks
*****
Offline Offline

Gender: Male
Posts: 1700



« Reply #6 on: April 09, 2004, 06:55:00 pm »

Loth, from what I've read this proof of concept actually works. However, the code resides in the resource fork, so to get the trojan you would need to download a compressed version of it in a .sit or .dmg, decompress, then run it.
Logged

There are only 10 types of people in the world. Those who understand binary and those who don't.
Mr. Lothario
Special Forces
God bless the freaks
*****
Offline Offline

Gender: Male
Posts: 1748


Suck mah nuts.


« Reply #7 on: April 09, 2004, 07:56:12 pm »

     Yeah, when I looked into it, turns out it's a reasonable idea. Still, even if you are stupid enough to get caught by it now that it's known, it can only run its code with your permissions. Hardly a critical threat. Besides, I bet Apple will have a Security Update out by tomorrow.
Logged

"How is the world ruled and how do wars start? Diplomats tell lies to journalists and then believe what they read." - 19th-century Austrian press critic Karl Kraus

Rule 37: "There is no 'overkill'. There is only 'open fire' and 'I need to reload'". -- Schlock Mercenary
BTs_Mysterio
BL Staff
God save the Royal Whorealots
*****
Offline Offline

Gender: Male
Posts: 3676



WWW
« Reply #8 on: April 09, 2004, 09:24:56 pm »

Apple has officially stated that it is working on a solution.
Logged

"There's room at the top they are telling you still. But first you must learn how to smile as you kill"
John Lennon
Only suits they'll be wearing are body bags. • Your trial will be held at the city morgue. • I'll return your gun, one bullet at a time.
Mysterio is a registered trademark of Myster
crypt
God bless the freaks
*****
Offline Offline

Gender: Male
Posts: 1631


Do or Die


WWW
« Reply #9 on: April 10, 2004, 12:19:55 am »

I believe you can change the name and get rid of the .app by using "Get Info" and saving it.
Logged

Opinions are like assholes, everyone has one. Unfortunately, most of them go hand in hand.
Ssickboy
Full Member
**
Offline Offline

Gender: Male
Posts: 157



« Reply #10 on: April 10, 2004, 02:11:40 am »

would this affect mp3 files that are automatically run when downloaded through limewire or  acquisition?
Logged

Retire Bush
BTs_Mysterio
BL Staff
God save the Royal Whorealots
*****
Offline Offline

Gender: Male
Posts: 3676



WWW
« Reply #11 on: April 10, 2004, 03:32:01 am »

Update: Wired posts more information on the purported Trojan:

[Intego] gave the impression that this is a threat, but it isn't," said Dave Schroeder, a systems engineer with the University of Wisconsin. "It is a benign proof of concept that was posted to a newsgroup. It isn't in the wild, and can't be spread in the wild. It's a non-issue."

source www.macrumors.com (news section)
Logged

"There's room at the top they are telling you still. But first you must learn how to smile as you kill"
John Lennon
Only suits they'll be wearing are body bags. • Your trial will be held at the city morgue. • I'll return your gun, one bullet at a time.
Mysterio is a registered trademark of Myster
crypt
God bless the freaks
*****
Offline Offline

Gender: Male
Posts: 1631


Do or Die


WWW
« Reply #12 on: April 10, 2004, 06:52:41 am »

That's good to hear, but as of now LimeWire is removed from my computer to prevent my brother from downloading mp3's, and I banned the website, so until it's fixed and confirmed by apple as a bs threat, I'm gonna be careful.
Logged

Opinions are like assholes, everyone has one. Unfortunately, most of them go hand in hand.
kos.viper
Forum Whore
****
Offline Offline

Gender: Male
Posts: 746



« Reply #13 on: April 10, 2004, 07:43:03 am »

Crypt, your bro can download all the MP3's his little heart desires from Limewire.  In order for the trojan to work it needs to be decompressed from a sit file.  If you only transfer the mp3 apparently all you hear is someone laughing.
Logged

kos.viper
Xbox LIVE Gamertag: Brain 7
The box said "requires Windows 98 or better"... so I bought a Mac.
Pages: [1]   Go Up
Print
Jump to:  



 Ads
Powered by SMF 1.1.7 | SMF © 2006-2007, Simple Machines LLC
Page created in 0.074 seconds with 20 queries.