“A malicious program that could be the first Trojan in the wild to target Apple Computer’s Mac OS X operating system has been discovered, security experts confirmed Thursday. Apple and outside analysts said the program, referred to as Leap-A, is not a ‘virus,’ per se. Rather, it ‘requires a user to download the application and execute the resulting file,’ Apple said in a statement to CNET News.com. The company provided no further comment on the nature of the program,” Anne Broache reports for CNET News. “The malicious software, which has also been dubbed OSX/Oompa-A and the Ooompa Loompa Trojan Horse by other security experts, appears to have spread minimally so far and has achieved low-level threat classifications from McAfee and Symantec. But security experts cautioned Macintosh users to view the incident as a wake-up call that all operating systems have vulnerabilities.”
MacDailyNews Take: Did security experts also caution Macintosh users to view the incident as a wake-up call that all operating systems can run programs, too? Do not download “latestpics.tgz” and then uncompress it and then run it by giving Mac OS X your Admin password at the prompt. Also, do not drag files that you wish to keep on your hard drives to the Trash and then empty it.
“‘It’s not really news as far as threats go,’ said Ray Wagner, a senior vice president in Gartner’s information security group. ‘It is news because it targets OS X, and as far as I know, it’s certainly the first OS X malicious content in the wild that’s been noted at this point,'” Broache reports. “Apple directed customers to a safety guide at its site and said it ‘always advises Macintosh users to only accept files from vendors and Web sites that they know and trust.'”
Full article here.
Advertisements:
• MacBook Pro. The first Mac notebook built upon Intel Core Duo with iLife ’06, Front Row and built-in iSight. Starting at $1999. Free shipping.
• iMac. Twice as amazing — Intel Core Duo, iLife ’06, Front Row media experience, Apple Remote, built-in iSight. Starting at $1299. Free shipping.
• iMac and MacBook Pro owners: Apple USB Modem. Easily connect to the Internet using dial-up service. Only $49.
• iPod Radio Remote. Listen to FM radio on your iPod and control everything with a convenient wired remote. Just $49.
• iPod. 15,000 songs. 25,000 photos. 150 hours of video. The new iPod. 30GB and 60GB models start at just $299. Free shipping.
• Connect iPod to your television set with the iPod AV Cable. Just $19.
Related MacDailyNews articles:
Incorrect reports of ‘Mac OS X virus’ begin to circulate – February 16, 2006
New Mac OS X Trojan warning – February 16, 2006
Apple: ‘Opener’ is not a virus, Trojan horse, or worm – November 02, 2004
“‘It’s not really news as far as threats go,’ said Ray Wagner, a senior vice president in Gartner’s information security group. ‘It is news because it targets OS X, and as far as I know, it’s certainly the first OS X malicious content in the wild that’s been noted at this point,'”
Well Mr. Wagner… guess you haven’t been keeping track of OS X security information very well since you’ve never heard of the Opener script.
oh my god, all this over pretty much nothing, just think of the bad press when osx finally does get a real virus, itll happen one day !
In other words…have a lick of common sense and this particular issue won’t impact you.
Get the scoop here on Apple’s discussion boards
http://discussions.apple.com/thread.jspa?threadID=366230&tstart=60
Opener was virtually nothing more than a proof of concept script. There were no real confirmed sightings of it in the wild. As for Leap, the only ones that were infected were the dolts that downloaded and installed it from that rumor site’s message board. I’ve seen no confirmed reports of it actually propagating out in the wild.
Third party programs using root are installing “helper programs”
This is the email response I got back from a developer concerning the issue of secretly trying to install code in root when I was about to clone my drive using their software.
I’m sorry that xxx isn’t at your convenience.
Actually I must say, that I can’t agree with some of your critics. (Sorry, my english is not perfect.)
1. The “Helper Tool” is a tool to make xxx more secure. xxx authorizes the helper tool to do root privileged operations. The helper tool itself, doesn’t keep the authorization, and so can’t be used to do root operation by any other user (via shell…). xxx keeps the authorization for some minutes (then it expires), just as any other “safe” third party system utilities (some really unsafe utilities even save the admin password in the keychain, and keep the authorization active until quit.).
I decided to install the helper tool right at launch, to ensure that only admin users are able to use xxx (I confess, that this is uncommon, but in my opinion it provides further security. – other utilities does it “hidden” when starting the first admin priv. process). I also decided to install the helper tool (instead of using it in the app bundle) in a safe system location (just as most command-line tools are installed). A different method to execute admin commands is AppleScript (which is used by some other utilities), which is not at all safer than a proper helper tool. A helper tool is a common and “safe” way to do root privileged operations on Mac OS X, and the ADC (Apple Developer Connection) recommended me to build a helper tool, and not to execute via app or shell directly.
2. I confess that the updates provide a potential security whole, and maybe its not a good argument, but this is also a very common way to distribute updates. There are hundreds of utilities, which require root privileges, that are distributed like this, and even major software companies offer their updated on normal download mirrors. Anyway I will not ignore your advices, and will continue to make the update notification and download more secure.
3. I also confess, that I can’t deny that xxx is theoretically hackable, but I think not more or less than any common system utility. The authorization technology, I use in xxx, is a standard authorization technology provided by the ADC (Apple). Anyway I’m very concerned about the security of xxx and my customers, and will continue actualizing and improving its security.
Thanks much for your email. Actually I appreciate critic customer, even if I regret to lose you as customer.
The problem doesn’t sound bad, but it is, your using a program to do something as root, say offline for better security. The only problem is it leaves something behind for some other program to exploit it’s flaws.
Since flaws can go unfounded for months or even years, this gives the bad guys access to root.
I can’t find anything on the Apple Developer Connection recommending installing rootkits on peoples Mac’s.
http://homepage.mac.com/hogfish/Personal21.html
Good grief, why is the media feeding on this? Mac-aware security people are all saying that this is NOTHING to worry about. How come the media isn’t picking up on ThEIR side of the story?
[url=”http://blogs.ittoolbox.com/security/investigator/archives/007789.asp”]
Quote:Nothing to see here folks, move along![/url]
Discussions at MR have a pretty good handle on the whole non issue since that is where the link was first posted yesterday
http://forums.macrumors.com/showthread.php?t=180579
On the evening of the 13th, an unknown user posted a link to a file on MacRumors Forums claiming to be the latest Leopard Mac OS X 10.5 screenshots. The file was named “latestpics.tgz”
The resultant file decompresses into what appears to be a standard JPEG icon in Mac OS X but was actually a compiled Unix executable in disguise. An initial disassembly reveals evidence that the application is a virus or was designed to give that impression. Routines listed include:
_infect:
_infectApps:
_installHooks:
_copySelf:
The exact consequences of the application are unclear, but users who originally executed the application have noted that it appears to self propogate even after the original file has been deleted:
I left my front door unlocked. My computer was up and running. Someone came into the house and used it.
Oh My God! Macs are just as vulnerable as PC’s!!
For those idiots in the cheap seats, that was sarcasm.
Nostradomus
No BBCode here and the only HTML is Italic and perhaps bold (but I think it’s been turned off) so far I’ve gotten to work.
You can paste a url and it will turn into a link, but not <a href =”http://macdailynews.com”>Visit this site</a> links or downloads.
from Apple discussion board
Trojan Warning “latestpics.tgz”
Posted: Feb 16, 2006 6:50 AM
This file may be renamed to something else and provided in a link in a post, iChat or email, it requires your admin password to run.
It cannot get on your machine unannounced like a virus can. (no Mac OS X viruses so far) Although if your not paying attention it can appear on your desktop or downloads folder in a flash and you may wonder what it is and/or double click it by accident.
It requires social engineering to trick the user into downloading and providing a admin password.
As always guard that admin password and don’t give it out to any program you don’t trust 100%, and even then watch out as it may install something anyway as a “feature” or “helper” program, even make unknown internet connections or it’s code can be exploitable running as root. (such as the Sony/BMG rootkit or Norton AV rar files)
Clone your boot drive occasionally and backup your files regularly, so in case you do get tricked, you simply c boot off the Mac OS X Installer disk and use Disk Utility to erase the infected drives(s), boot off the clone and reverse clone. (don’t hook a clean write-able drive to a infected system)
More information about this Trojan can be found here.
http://www.ambrosiasw.com/forums/index.php?showtopic=102379
More info can be found how to clone your boot drive here
http://homepage.mac.com/hogfish/Personal6.html
Help cloning your boot drive can be found free of charge by visiting Carbon Copy Cloners forums.
I’m crazy
uuuuh, i am NOT scared! this is no virus… of course…if i tell you erase your hd and you do it… then this procedure “could” (eventually) be called a virus (but rather a virus of the sick mind than a computer virus)… falling asleep while standing… this is NONE-INFORMATION, since nothing new!!! get back to work!!!
d00de, I think I caught a cold from Mac OS X.
Actually the first Mac OS X trojan “in the wild” was program that looked like OfficeMac circulated via P2P networks and various posts, emails and such.
Except this wasn’t very nice, it wiped out the entire contents of a users/home.
Since then Apple has initated the “this is a program your downloading” warning to combat the “looks like a file” tricks, but nothing to combat downloading a malcious app.
I’m surprised the author of this malware didn’t just wipe the contents of user/home.
It doesn’t matter how hard it is to “run” this trojan ..
All the media needs are the words “virus” and Mac OSX and that’s all they care about ..
All your’re going to read and hear from now on in is that Macs are just as prone to viruses as pc’s
Mark my words … the PC guys will run with this ….
I hear that the intel Macs are more virus prone.
You’d think when Safari pops up and says you’re downloading a program, most people would not run the file. Ugh. Expect lots of bashing and raving from the Windows peanut gallery, even though OS X’s own safeguards require you to execute this yourself and give it permission–just as with any potentially malicious program.
Just so you know, most of the malware MDN uses to blast the security of Windows are also technically trojans.
MacDude writes: “Nostradomus
No BBCode here and the only HTML is Italic and perhaps bold (but I think it’s been turned off) so far I’ve gotten to work.
You can paste a url and it will turn into a link, but not <a href =”http://macdailynews.com”>Visit this site</a> links or downloads.”
How about this?: Visit this site
or this:
Quote:Nothing to see here folks, move along!
I think this is just a RUMER.
Nick –
Where did you hear that? Wherever / whoever it was has given you disinformation. As a matter of fact, Intel Macs are currently more secure than PPC variants because this trojan is designed to run only on PPC.
How about this?: Visit this site
or this:
Quote:Nothing to see here folks, move along!
Yep, seems I’m missing something.
Still going to HTML school I’m afraid, but then I’m old. Excuse me I need to have the nurse wipe my wrinkled butt again.
Well I haven’t seen anything like it yet.
I hear the new intel Macs make you impotent.
Now its on the DrudgeReport: Here is the (Reuters) title:
“Virus attacking APPLE Macintosh PCs found…”
MacDude- Hint: Nostradomus’ error was to use quotes (which of course you should use in HTML).
Winblows will always suck so keep on paying people to find something wrong with OSX all you want because we all know that it is superior in every aspect.
This is bullshit.
Nonetheless, the peecee fanbase and Mafiasoft lapdogs are getting moist and touching themselves over this “much ado about nothing”®
Use “common sense” folks. Why give your admin or root password to picture?
OMG, a trojan that requires 5 to 6* acknowledgments from an admin user to work! You never know, one might just download an unknown file from an unknown source, double-click the file to decompress, double-click to open, enter pw for first run of new app, and enter admin pw to enable. This could potentially cause at least a few dollars in global economic damage.
* if DLd from Safari with Open Safe Files disabled, the DL window will warn the user requiring a positive response to continue the DL.
That should be “click OK to allow first run of new app,” dammit.
I’m tired of us Mac users being treated like second class citizens. Why can’t we get a proper, hardcore, bag the whole fsking computer, network, servers and bank machines like Windows users have had for so many years.
It’s just not fare damn it!
Rainy Day
Can you tell me how to format URLS into words in your posts like you demonstrated above. Thanks.
Geez–
Can’t we get anything right? No self-propagating virrii. We should just give up. Seriously.
Give. Up.
The following html tags are allowed in Reader Feedback:
<b>bold</b> result: bold
<i>italics</i> result: italics
<u>underline</u> result: <u>underline</u>
<em>emphasis</em> result: emphasis
<strike>strikethru</strike> result: <strike>strikethru</strike>
<strong>strong<strong> result: strong
Also allowed:
<pre>pre-formatted text</pre>
<code>code</code>
Link format:
<a href=”http://www.macdailynews.com”>MacDailyNews</a> result: MacDailyNews
[This information has been added above the feedback box for future reference.]
It actually is a virus because it self-propagates, it was even classified as one. Who cares if it requires user interaction? Many Windows viruses require you to download and open attachments. This is exactly the same. Why is it so hard to admit the Mac OS X has one virus? It’s not like it does any damage, and it’s still 59,000 less than Windows has.
Ive been a windows user but mac fanboy for yrs and i have no viruses on my pc. You know why? cuz im not an idiot. Guess what else, I dont use virus protection, ive used virus detection software twice in 10 yrs… and only ever found one on my pc.
You have to be stupid to get a virus on windows, and EVEN MORE STUPID to get one on a mac, i think actually people who would get any sort of “malicious ware” on their mac should be shot because they delay human evolution… as long as i get their macs when they die.
Exactly – the days of Windows automatically installing and running virus code are long gone (about 5 years ago?). This Mac virus is identical in concept to current Windows viruses – the user must download it and then run it. Like all Windows viruses, it claims to be something interesting that you want to open.
It’s a virus folks. Get over it.
… when it’s on a Mac!
I can see a new Mac security phenomemon arriving. First we had “security by obscurity” and now we have “security by denial”. As long as we all redefine any Mac virus as something else involving “social engineering” the Mac will remain virus free! Excellent news!
Thanks for the formatting info!
<u>i</u> A<u>m</u>
cRaZy4 <u>m</u>Ac <u>Dai</u>LynEzzOk, we can go back to bashing Microsoft again, seems exploits for WMP are out and about.
<i>
The flaw, rated "critical" by Microsoft, could enable an attacker to seize control of a vulnerable computer system.<i>Now <u>that/u> sounds better don’t it?
No tricks url, just paste in your browser if your leary.
” width=”19″ height=”19″ alt=”wink” style=”border:0;” />
http://news.com.com/2100-1002_3-6040746.html?part=rss&tag=6040746&subj=news
“Exactly – the days of Windows automatically installing and running virus code are long gone (about 5 years ago?). “
I guess you missed the recent Windows WMF vulnerability which allowed for silent and automatic execution of code.
“It’s a virus folks. Get over it.”
An all-volunteer virus. What person would ignore Safari’s prompt of an executable being in the compressed file? Your attempt to align this with the insecure world of Windows doesn’t fly.
I’d like to mention, this is no different from past trojan proofs-of-concept that targeted OS X, like MP3Concept from 2004: http://securityresponse.symantec.com/avcenter/venc/data/mp3concept.html
MP3Concept even used the same icon swap technique. These things never end up spreading to any measurable degree, and when someone says Macs have no viruses and trojans, that’s what they’re referring to. Not that people haven’t written some and tried. Dozens have been written in the past five years. This isn’t the first trojan targeting OS X. The point is that they never go anywhere because OS X doesn’t have any exploitable mechanisms for automatically downloading and running the code.
This will be forgotten in a couple of weeks, just like the Safari widget auto-installation hooplah when Tiger first came out (which was an actual behavioral flaw). Basically, an isolated incident of some guy on a forum tricking some users into running his buggy executable before admins removed his post has now been picked up on the national newswire (Reuters, Drudge Report) as “The First OS X Virus!” Absolutely stunning.
I’m really disappointed with MacRumors right now for not only posting their announcement as “the first OS X trojan/virus” but for neglecting to mention that lots of trojans have targeted OS X (including MP3Concept which used the same icon trick), the point being that trojans on OS X never propogate to any measurable degree. Now the bigger tech sites have run their story, and misinformation is all over the place.
RC and others, sorry but you are all wrong. Exactly – the days of Windows automatically installing and running virus code are long gone (about 5 years ago?). This Mac virus is identical in concept to current Windows viruses – the user must download it and then run it. Like all Windows viruses, it claims to be something interesting that you want to open.
It’s a virus folks. Get over it.
What you describe above is not a virus, is a trojan horse. And it would be a trojan horse and not a virus also on Windows. If the user has to do ANYTHING it is not a virus. Same for Windows: if the user has to do ANYTHING is not a virus. A virus is like MSBlaster, you boot your PC, you do NOTHING, the PC gets infected just because it is on, and spread the same malware to other PCs. This is a virus: no user intervention, all automatic.
Trojan horses rely on the naive user to do their work, no OS can protect a naive user from himself. Not a single one. It can try to wake-up the naive user with “Are you sure?” “This is an application that wants to get installed” etc warnings, but if the user clicks ok, ok, ok, etc what can you do? So, if someone tells you that a new Windows virus is on the wild but you have to download and do something, please, next time just say: silly, this is not a virus, it is a naive-user catcher. In this case the weakness is not the OS, Windows or OS X, but the user. I could not blame Windows for being vulnerable to its users, as for a Mac.
The problem in Windows, and it is still there, sorry, is exploitable code that can take over your machine just because it is on.
In this case a user must first receive the malware file in question (either via download from a Web site, via e-mail, or via iChat file transfer), then double-click the file to expand it, then double-click the resulting file. Then the last file appears to be a JPEG graphic but is instead an executable file.
If you receive a file that doesn’t look like something you’d expect to receive, even if it’s ostensibly from someone you know, it’s pretty clear that you shouldn’t be launching the file.
I do not blame Windows for such problems. It is not an OS weakness if the user has to actively help the malware to do its job.
This isn’t really taking advantage of any holes in the OS security, instead, it’s taking advantage of the willingness of the user to open an unknown file. That’s not exactly a virus or worm. As was pointed out on the Apple OS X Server Admin mailing list, if I write an OS X user an e-mail message and say, “Hey, open the Terminal and type rm – rf *” it’s not really the fault of the OS if the user follows my instruction and a bunch of files get deleted. My e-mail isn’t a “virus,” and the inherent security of the system isn’t flawed.
Instead, it’s the fault of the user for believing me when I said the user should do something dumb.
There’s a somewhat technical discussion of what this file is and what it does here:
http://www.ambrosiasw.com/forums/index.php?showtopic=102379
RC and other windows users reaction to the “Get over it, it is a virus” clearly demonstrate the problem Microsoft faces with its users. If they do not know the difference between a virus and a trojan horse, how in the world Windows can rely on its users to help not get infected?
I said it many times already, one big problem in Windows is exactly that the ones that should be more aware of security issues and possible ways of attacking a computer are exactly the ones more in the dark. Devilish combination.
Follow-up
A good read is http://toxicsoftware.com/blog/index.php/weblog/entry/us_vs_them/
Why? because it describes Input Managers, what this trojan horse deals with as you have read in the link to ambrosia (you did read that, right?)
Personally I do not have any Input Manager myself. This particular malware also can act as a worm: it attempts to – if you give permission to install it – hijack InputManager to access iChat, then sends itself as an attachment to your iChat Buddys.
To a large extent, it does rely on user naivety: Safari at least will warn about it, and you need to manually extract the tgz and launch it.
Here’s a few things you can do. The first is valid no matter the OS you are running. Windows included:
a) Don’t download ANYTHING from anonymous sites
b) Heed Safari’s warnings about suspicious downloads
c) Don’t open attachments from Buddys without double check with them
d) Be *really* careful about authenticating as admin – you essentially tell the OS “don’t be paranoid, do it, I know what I am doing”. So the OS trusts you.
e) To disable Input Managers (if you don’t need them):
$ sudo chmod 755 /Library # so it requires explicit privileges to create
$ touch ~/Library/Input\ Managers
$ chmod 555 !$
With the above, the trojan will not be able to hijack Input Managers
It actually is a virus because it self-propagates, it was even classified as one. Who cares if it requires user interaction? Many Windows viruses require you to download and open attachments. This is exactly the same.<i> — Um
Amazing. Did you read yourself? A virus not only self-progate but installs without user intervention. A self-propagating malware is actually a worm, after the naive user has allowed itself to install.
<i>Many Windows viruses: Those are NOT Windows viruses.
As Seahawk said: how can you beat an enemy (the malware) if you do not even know it? Windows users, please, inform yourselves already!
Did anyone read the comments from the referring article?
One of them was absolute genius!
Take a few minutes and read this
MW: today, as it, today is the first day of the rest of y… I can’t do it.
Tried following my own link, didn’t work. Anyway, this is WELL WORTH THE TIME, head to the comments and look for the one titled “Well, DAVE…” attributed to Matthew Good — Feb 16 2006, 8:38 PM PST
You can delete files from a command prompt.
You can write a script that will delete files from a command prompt.
You can name that script HotSexyPicture.tgz, convince someone to uncompress it, give it their admin password, and run the script that deletes the files from a command prompt.
How is this new, and how is this a virus? I wouldn’t even call it a trojan because it requires so much work to make it happen.
However, if I wrote a one-line batch file that deletes the contents of “My Documents” on Windows, and named it HotSexyPicture.com or HotSexyPicture.bat, I could get that onto someone’s system with execute permissions without having to compress it first, and it would do its deed simply by double-clicking on it, no password needed.
So tell me again how Macs are “just as vulnerable as PCs”, corporate media. This case seems to prove the opposite.
Preston said:
>> “Exactly – the days of Windows automatically installing and running virus
>>code are long gone (about 5 years ago?). “
>I guess you missed the recent Windows WMF vulnerability which
>allowed for silent and automatic execution of code.
And I guessed you missed the almost identical vulnerability in Quicktime, patched about 3 weeks ago? This is not a virus – it has no means to replicate – it’s a buffer overflow exploit. Ironic how both WMF and Quicktime had almost identical issues eh?
SJR: “In other words…have a lick of common sense and this particular issue won’t impact you.”
That´s the same advice I give to windows users regarding viruses.
Something seldom mentioned is the extent of this “worm”. Symantec’s web site shows that the number of users affected by this trick are “0-49”.
So of all the 20 million (plus or minus) Mac users out there, less than 50 got taken in by this thing.
Wow. This should make headlines huh?
We macs don´t have viruses or trojan horses or anything bad can be put on our computers and even if we do we will never admit to it.
According to knowledgeable sites, the code combines traits of a worm, a trojan and a virus. Once it has been unleashed on one Mac, it self-propagates via iChat/AIM.
Furthermore, in most cases the code does NOT require, or ask for, an administrator password; it installs to folders that aren’t protected by such a requirement.
The code doesn’t exploit any weakness or bug in Mac OSX, though. It relies solely on human curiosity. Nevertheless, it is time to put semantics aside and accept that we as Mac users need to be more cautious / suspicious.
The problem isn’t with the software, it is in the fleshware. And since this file, and the successors that will inevitably follow, propagates itself via chat programs to contacts that are colleagues or friends – and therefore trust things that originate from you -, such caution is not just self-defence: it is a social and moral obligation.
So let us stop the name-calling and linguistic waffling and own up to the new truth. Networking means being responsible.
Peter J. Pedersen
MacDailyNewsWebMaster
will we ever be able to post images here?
We can host them off-site if that makes a difference.
OH, MY GOD! MY Mac sytem can run APPS! This is NOT the way a good operating should behave. A good OS should prevent the user from running third party apps so that no harm can ever be done to the system and the user’s files.
Hello!
HUGE!
LOOK AT ME!
[quote=”Mace”]Help! I’m trapped in BB Code!
echo "This is some code";
[list]
[*]Red
[*]Blue
[*]Yellow
[/list]
[list=a]
[*]The first possible answer
[*]The second possible answer
[*]The third possible answer
[/list]
no.one@domain.adr
mike k.: Did you want to post secret photos of Leopard? (j/k)
Hello!
Look at all the pretty colors
Hmmm.
This just proves how much more secure M$ Windblows is.
For $50/year M$ can make sure that Windblows users will only be able to run M$-approved programs. Therefore, there can be no inadvertant malware running on Windblows.
For the upgrade cost of Longdelayed, M$ will make sure that NO programs will run on your PC. Can’t get more secure than that!
<span style=”color:red;”>Testing in red</span>
I know I’m posting late in the game here, and maybe no one will read my post, but I just thought about this today.
What we are talking about here is a user that downloads or receives a file, opens the file without knowing what it does, then entering in an administrator password to allow that file to do damage. A virus? A worm? Not really. A trojan? Yes.
OK, so is this because OS X has a “security flaw”? Not at all. However, Apple can do something about this. They can set up an option, something like “Notification Options”, that allow users to get more verbose security messages. If you set it to “verbose”, you’d get a more detailed message rather than a prompt for your admin password.
Here’s an example:
Old Message
Username: Jimbo von Winskinheimer
Password:IAmNoDummy
(OK) (Cancel)
New Message:
Warning: You are now being prompted for your administrator password. This is because the file you are opening is going to install something on your system. If you are unsure of what is being installed, do not enter your password. Instead, cancel out of this and verify that what you just opened is really what you think it is.
Username: Jimbo von Winskinheimer
Password:
(OK) (Cancel)
This will not prevent people from still installing malware, but at least it will attempt to protect Grandma Beatrice when she goes to look at the pix that were sent to her.
So is it
Windows:60,000
Mac: 1 or 0?
This is the first of thousands of trojan horses that will attack OSX in the coming weeks. This will overwhelm Apple and they will not be able to keep up with the attacks. Now that the truth is out that OSX is riddled with security problems that have no solutions everyone will flock to Windows. Guess it doesn’t matter if you are rich…you still have stupid people that will click on anything.
Mac fan boys finally get their just deserts 😀
Time to short that Apple stock!
Just a sensless Google bomb
http://www.bkpfd.org
Get a life! Your really didn’t read all these posts, did you?
^^^ MORON ALERT!
“Now that the truth is out that OSX is riddled with security problems that have no solutions everyone will flock to Windows.”
Cite the OS X security flaw being exploited here. There is none. This trojan is no different from any of the others written in the past five years that never spread due to the inherent security of OS X, unlike in the Windows world where just viewing a webpage or an email will hit you with a WMF exploit. You actually have to download this one and run it yourself.
Will someone please explain how this code is “self-replicating”, when it can’t replicate until it has been decompressed and run? “Self-replicating” means “it can replicate all by itself”. This thing can’t do anything “by itself”.
Okay, okay. I guess technically, because the app contains code to send copies of itself to AIM users, that makes it “self-replicating”. But that’s not what you think of when you hear “self-replicating”. You think of something that can begin to spread the moment it hits a computer, with maybe one click from a user at most.
Correction:
Technically, you can’t classify it as a virus just because it trys to send itself to people in your buddy list (See definitions below). I would classify it as a Worm as it’s only purpose is to <u>SPREAD</u> itself (I am NOT in denial about viruses).
Leap.A is a trojan, a virus, and a worm. The terms are not mutually exclusive.
I read the Macworld article so don’t quote it at me. The fact is that once Leap.A has infected an app, if I take that app and drag-and-drop it (and Leap.A infects primarily drag-and-drop apps) onto a zip disk or a hard drive or burn it to a CD, and move that zip disk or HD or CD to another Mac and then run the app, it WILL infect that other Mac.
That’s an old-school virus, pure and simple, from before the days of the internet. This thing spread JUST LIKE THE OLD MAC OS 6 AND 7 VIRUSES did. There is NO DIFFERENCE. Remember that. It’s a virus.
It is also a worm. If my machine is infected and I connect to a particular type of network (Bonjour-enabled iChat), then it sends itself spontaneously without my intervention. Yes, the user on the other side has to accept the file, BUT THAT IS TRUE OF ALMOST ALL INTERNET WORMS. The point is, I do not have to send an infected file over the network. It sends itself spontaneously upon connection. THAT MY FRIENDS IS AN INTERNET WORM.
And finally, it is of course a trojan horse since it is available for download and pretends to be something else.
None of these terms are mutually exclusive, and many many specious arguments that assume they are have been made here. Leap.A is without a doubt a virus. By the definition of virus that a lot of you people are going by, there can’t have been any viruses before people were connected to the internet and THAT IS PATENTLY NOT TRUE. Read your history. The entire first and second generations of virus are simply malicious codes that gets transferred with a host file and replicates upon the launching or opening of that file. Leap.A DOES THIS! ONCE IT HAS INFECT YOUR MACHINE IT DOES NOT REQUIRE A PASSWORD TO INFECT OTHER FILES ON YOUR MACHINE AND THEN BE CARRIED WITH THOSE FILES TO OTHER MACHINES AND INFECT THEM, AGAIN, WITHOUT A PASSWORD.
It’s a virus.
For the record I think the Mac is inherently FAR MORE SECURE than Windows and not just because of obscurity, but face the facts people. Virus. Worm. Trojan. This is all three.
DB.