OSX.Leap.A: a near miss for Mac users

“This week’s ‘Mac virus’ scare turned out to be nothing more than a worm for Mac OS X that propagates through iChat and infects local Mac applications. OSX/Leap.A is a wake up call to Mac users that we’re not immune to all the nasties floating around on the Web,” Jason D. O’Grady blogs for ZDNet. “There was a story circulating this week that The First Virus For Mac OS X had arrived, but it turned out to only be a relatively innocuous worm embedded in a file called “latestpics.tgz” promising pictures of ‘MacOS X Leopard.’ The worm required the user to download, decompress and execute the file then enter their admin password to cause any damage.”

O’Grady writes, “The first rule of software downloads is obvious: never open a file or attachment from someone that you don’t know. The second is that if it’s too good to be true it probably is. If a download promises you screen shots of Mac OS 10.5 “Leopard” don’t believe it (after all, why not just post the pics?) but never, ever enter your Mac OS X admin password to install something from an unknown source, especially if you downloaded it surreptitiously.”

Full article here.

MacDailyNews Take: Tsk, tsk. So much ado about nothing. The old rules still apply: do not enter your Mac OS X admin password to install anything from an unknown and/or untrusted source.

MacDailyNews Note: We have been affected by a widespread power outage as a result of Friday’s windstorms in the U.S. northeast. We lost power at approximately 9:30am EST yesterday along with approximately 250,000 others. The blackout is still affecting over 120,000 residences and businesses as of this post. Due to our backups currently being unavailable due to other circumstances, we have driven out of the affected area in order to resume posts. The power company curently reports that they expect power to be restored by “Sunday night at the latest.” Thank you for your patience.

Advertisements:
• MacBook Pro. The first Mac notebook built upon Intel Core Duo with iLife ’06, Front Row and built-in iSight. Starting at $1999. Free shipping.
• iMac. Twice as amazing — Intel Core Duo, iLife ’06, Front Row media experience, Apple Remote, built-in iSight. Starting at $1299. Free shipping.
• iMac and MacBook Pro owners: Apple USB Modem. Easily connect to the Internet using dial-up service. Only $49.
• iPod Radio Remote. Listen to FM radio on your iPod and control everything with a convenient wired remote. Just $49.
• iPod. 15,000 songs. 25,000 photos. 150 hours of video. The new iPod. 30GB and 60GB models start at just $299. Free shipping.
• Connect iPod to your television set with the iPod AV Cable. Just $19.

Related MacDailyNews articles:
Apple: ‘Leap-A’ not a virus; only accept files from vendors and Web sites that you know and trust – February 16, 2006
Incorrect reports of ‘Mac OS X virus’ begin to circulate – February 16, 2006
New Mac OS X Trojan warning – February 16, 2006

81 Comments

  1. We as Mac users need to trumpet this fact as far and as wide as we can. Don’t let these “news” organizations get away with posting these errors as news and then not having it thrown in their faces that they were WRONG!

    Post the truth everywhere. Forums, discussion boards, mailing lists. Even cite the “journalists” and their respective “news outlets” that got it wrong, I say. Don’t let them off the hook.

    Screw them.

  2. (after all, why not just post the pics?)

    Jason D. O’Grady is a moron, some sites don’t let people post pic’s and then you need a host as well.

    And since a link can go to a web page which immediatly starts a download or not, how are people supposed to know the difference before they click?

    Hang in there MDN!

    We lost some people too, they are A O fscking L

  3. “This week’s ‘Mac virus’ scare turned out to be nothing more than a worm for Mac OS X that propagates through iChat and infects local Mac applications

    Excuse me, a worm is a virus. Let me repeat that for those of you who missed it: a worm is a virus. The first virus for OS X has arrived. MDN, it’s time for you to admit the truth.

  4. MacDude, hosting pics is nothing. Safari warns you if a page downloads something dangerous.

    And if someone has pics of Leopard and it ain’t on Apple’s own site, AppleInsider, ThinkSecret, MacRumours, MacBidouille, MOSR, MacWorld, or MDN, then I’m already suspicious.

    However, as I got so roundly pounded a few weeks ago, someone has shown it is possible to create something like this, but to make it work you’ve got to target utter morons.

    Now, I’ll be happy to go back and be smug, because this story is utterly overblown and totally misreported.

  5. Look, the bugs in MS Office are more pervasive than this thing. Of course, the virus protection software guys are predicting the apocolypse….they have to somehow come up with a reason for us to buy virus protection software for a platform THAT DOESN’T HAVE VIRUSES. It’s like the guy who is selling snow-making machines in Fairbanks.

    The virus protection software guys are PRAYING for a mac virus – hell, if they were at all competent, they’d probably write one themselves, but since there just aren’t going to be any real ones, they are going to make something up. And the Windows IT guys administering Macs will buy it hook, line, and sinker…that is the reason that the IT dept. where I work insists on buying institutional licenses and loading and automatically enabling virus protection software on all the Macs distributed in our department. That is also the reason that I end up administering our Macs….the first thing I do is turn off the virus software and the second thing I do is enable ARD…it’s easier than explaining why they are wasting their money.

    MW: makes. As in, virus protection software on a Mac MAKES me laugh.

  6. Some teensy things have been overlooked:

    THIS SO-CALLED VIRUS IS NOT A WORM BECAUSE IT DOESN’T INFECT WITHOUT USER INTERVENTION!!!!

    THIS SO-CALLED VIRUS ONLY WORKS ON A LAN NOT OVER THE INTERNET!!!!

    THE DEFAULT CONFIG OF A MAC IS IMMUNE BECAUSE BONJOUR IS TURNED OFF!!!!

    How come only Mac World picked up that little factoid?
    http://www.macworld.com/news/2006/02/17/leapafollow/index.php

    Sing it! YOU CAN’T GET THIS VIRUS OVER THE INTERNET.

    ” width=”19″ height=”19″ alt=”smile” style=”border:0;” />

  7. What about the Inqtana ‘worm’? Where are MDN’s denials of that one? True, it’s more like just a soon-to-expire piece of proof that the Bluetooth vulnerability is there, but I expected to see something about it too.

    I have written a couple letters to the magazines and sites myself already… but as far as Leap/A is concerne, there isn’t much the Mac community can do when Sophos themselves adamantly classifies this as a virus. And MDN… a worm IS a virus, as many others have pointed out.

    True or not… utterly idiotic or not… say goodbye to the official “zero-viruses OS X.”

  8. Is this thing a virus/worm or a program? So someone wrote a program that does things I would want it to do? My goodness, my ENTOURAGE that came with my Office Suite does that!

    I’m sorry, but anythng that asks me if it can download, asks me if it can run, and then asks me for Administrator access before it does anything doesn’t seem like much of a threat, and certainly not the kind malicious of code found covertly targeting Windows on a weekly basis.

    I would be very upset if my Mac didn’t run a program as it was designed. The scandal would be if it didn’t.

  9. It amuses me how this community are happy to classify any malicious Windows program as a virus when trumpeting how many Windows viruses there are (despite the fact that most of these are trojans, worms, spyware, etc, all requiring user intervention to install) but when it comes to Mac malware they tie themselves in semantic knots in order to deny the possibility that there are potential weaknesses in MacOS. One standard for Apple, another for everything else.

  10. MacDude, hosting pics is nothing. Safari warns you if a page downloads something dangerous.

    Nope, it only warns you that your about to download a application.

    Malware has been attached to ordinary images and on web pages.

    Also Javascript malware

  11. You can classify this as a virus if it makes you feel better, but if this is indeed a virus, it has to be just about the lamest one ever written.

    And please tell us how can it be classified as a true worm/virus if it doesn’t have the ability to propagate itself over the internet?

  12. This is definitely the end of Apple computer. Apple fan boys thought that OSX was secure and now we know it is full of holes. It will be a matter of weeks before OSX is overrun with viruses and all Apple users will have to switch to windows to get work done. With the second security problem this week (bluetooth hole) it is obvious that this is the tip of the iceberg and that the tidal wave of viruses, malware, and trojan horses are on their way.

    Finally the computer world can unify behind Windows — a secure, fast, and reliable operating system. This will be the end of overpriced computers that are only sold to rich people that have virtually no software to run.

    Time to short Apple stock!

  13. No no. It certainly doesn’t make me feel better, and indeed it is one of the most lame ‘viruses’ ever written, because the fact remains that any malicious program must be given permission to run by the user. Not to mention the fact that it requires the most stringent of circumstances to work (including that it doesn’t spread over the internet).

    My point is that when Sophos classifies this thing as a virus, there is then very little we ‘mere mortals’ can do to combat that labeling. I am just as much of a Mac fan as the rest of you, I am just injecting a little reality into our combat attempts. 🙁

  14. I think we have two different ‘Reality Check’s.

    @ Reality Check #2: Despite the fact that I don’t label this as a virus if is requires administrator privileges… I was thinking the same thing. Just how drastically would the number of Windows “viruses” decrease if we put the stringent standards on them as we are putting on Leap/A? Just a thought. Double standards are very hypocritical.

    @ Obvious Man: I am fully aware that the Bluetooth vulnerability was patched shortly after Tiger’s release. Blaster, and countless other Windows viruses were patched (with SP2 and the countless security updates), but that doesn’t take away from the fact that they are viruses… because there are always those few who don’t update their systems. Ignorant and unwise, yes, but they are out there nonetheless.

    However,

    (1) In the Mac community, there seem to be far fewer people who don’t update their systems regularly and
    (2) Again, the highly specialized and difficult application where this Bluetooth vulnerability applies makes it a negligible threat, if any at all.

  15. Who the hell double clicks on a JPEG icon? And who computes “in the wild?” I’m in a mid-sized city, so I don’t have anything to worry about, not to mention that I’m using Panther. This is just for Tiger, isn’t it?

  16. To Caruso:

    The purpose of running anti-virus software on a Mac in a corporate network isn’t to keep the Mac from being infected, it’s to keep the Mac from being a carrier used propagate infected files.

    Mac’s may not get viruses but they can spread them.

  17. IT IS NOT A WORM IF IT REQUIRES USER INTERVENTION TO ACTIVATE AND PROPAGATE.

    One more time: IT IS NOT A WORM IF IT REQUIRES USER INTERVENTION TO ACTIVATE AND PROPAGATE!

    God I hate the mainstream tech press. Grrrrrrrr. I say we take a few lessons from our muslim brothers and burn down the Windows embassy.

  18. This is the dumbest “virus” I’ve ever heard of. If it requires the user to accept the incoming bluetooth transfer, and since bluetooth requires the devices to be within several feet of each other to make a connection, how practical is this? Not very. Even if it didn’t require user intervention, it wouldn’t spread very far, if at all. Everybody in the mainstream tech press has been jizzing all over themselves that they can finally say “MAC OS X HAS A VIRUS!! MAC USERS ARE JUST AS VULNERABLE AS WINDOWS USERS! FEAR!! PANIC!! DREAD!!!!!”

  19. This thing, whether it be virus or not, can still run without asking for an admin password if the account you use on a day-to-day basis is an admin itself. By default, the first user on a Mac when OSX is installed is an Admin. Therefore, this piece of malware has uncovered a problem in OSX. Now that one malware writer knows about it, there will be others that come up with variants.

    Until Apple figure out how to patch against this (and I’m sure it won’t be long until they do), you can either take extra caution on what you click on, or ensure that your day-to-day account is marked as standard.

    Although if you have been running as an admin and decide to demote yourself, please remember that any software you have installed into /Applications will still have you as the owner, meaning the admin password prompt will once again not appear if malware attempts to write to it. You will need to correct this by either using the chown and chgrp commands or from the GUI if you have the patience.

    I would recommend running your day-to-day account as standard anyway, but I can understand that some users find the restrictions it adds a bit of a chore. Each to their own.

  20. Wikipedia sez: “Trojan horse programs cannot operate autonomously, in contrast to some other types of malware, like viruses or worms. Just as the Greeks needed the Trojans to bring the horse inside for their plan to work, Trojan horse programs depend on actions by the intended victims. As such, if trojans replicate and even distribute themselves, each new victim must run the program/trojan. Therefore their virulence is of a different nature, depending on successful implementation of social engineering concepts rather than flaws in a computer system’s security design or configuration. …

    “Trojans of recent times also contain functions and strategies that enable their spreading. This moves them closer to the definition of computer viruses which operate by spreading on their own and infecting executable files, and it becomes difficult to clearly distinguish such mixed programs between Trojan horses and viruses. However, the defining characteristic of trojans is that they require some user action, and cannot function entirely on their own.”

  21. neomonkey

    Yes, apparently this is just for Tiger. Good job I’m not the panicky type, as I eBayed my Panther install disks together with my old iMac.

    As for that stupid flamebait above that everyone will now switch to Windows, I can’t see anyone who ditches a UNIX based platform going back to Redmond’s hacked together pile of steaming mess. Even if the Mac does find ourselves under a virus onslaught, it just means more Linux installations.

    Either way, crappy old Symantec isn’t going to get a penny.

  22. Tip of the iceberg my friends, tip of the freakin’ iceberg. As the Mac gains in popularity more will come. Obscurity a myth? Yeah, that’s why taggers put their stuff in little know hidden places, huh?

    These sick bastards write these things to have their handy work seen, and as the Mac OS becomes more and more prevalent it becomes a more tempting target.

    Storm clouds on the horizon, time to head for the storm cellar.

  23. goddammit…

    A worm is not a virus, unless someone has conveniently redefined “virus” in recent years (which wouldn’t surprise me).

    There are three major types of malware:

    Virus — a virus is code which propagates by inserting itself into files, which are then shared between computers. Very few true viruses exist anymore.

    Worm — a worm is malware which spreads automatically from computer to computer via a network. Internet worms and email worms are the two main types. Email worms require minor intervention by the user, but only in the form of opening an attachment. Most problem malware these days are worms, NOT viruses.

    Trojan — a trojan (horse) is an malicious application pretending to be something else. It requires the user to explicitly run it.

    Leap.A is most definitely NOT a virus. It does infect files, sort of, but not in a way that could be used for propagation. In fact, it’s stretching the definition a little to call it a worm. Yes, it propagates over a network, but it requires significant trojan-style user-interaction at each stop. It would best be classified as a “self-replicating trojan”.

    So please, stop with the arrogant “admit it” bull$#!+. You don’t know what you’re talking about.

    (I swear, the idea that people wouldn’t switch from Windows because of this makes me think of a man in a burning building who won’t leave because it’s hot outside.)

  24. Is Leap-A a virus or a Trojan?

    Some members of the Apple Macintosh community have claimed that OSX/Leap-A is a Trojan horse, and not a virus or worm, because it requires user interaction (the user has to receive a file via iChat, and manually choose to open and run the file contained inside).

    However, this is not the definition of a Trojan horse.

    A Trojan horse is a seemingly legitimate computer program that has been intentionally designed to disrupt and damage computer activity. Importantly, Trojan horses do not replicate or have any mechanism of spreading themselves. They have to be deliberately planted on a website, or accidentally shared with another user, or spammed out to email addresses. There is nothing inside a Trojan’s code to distribute themselves further to other victims.

    Trojan horses do not contain any code to distribute or spread themselves, viruses and worms do.

    OSX/Leap-A is programmed to use the iChat instant messaging system to spread itself to other users. As such, it is comparable to an email or instant messaging worm on the Windows platform. Worms are a sub category of the group of malware known as viruses.

    Therefore, it is correct to call OSX/Leap-A a virus or a worm. It is not correct to call OSX/Leap-A a Trojan horse.

  25. @ Sam City:

    Come on and please read the articles next time. We and the mainstream press are not talking about the Bluetooth vulnerability. That is very very very minor news which only garnered a passing mention from The Register.

    We are talking about the Leap/A piece of malware (I refuse to call it a virus or worm myself). Don’t start hyperventilating.

  26. Pathetic… when something shows up that runs without our knowledge and infects our osx then thats news. Look up the definition of virus. For your own pathetic sake, look it up. The lengths that one must go to for this to actually work is obsurd. These security companies number one priority is profit. Use some common sense. And please Windows users, be safe. Theres over 100,000 viruses out there for you, and as far as I’m concerned and most anybody with a bit of intelligence, theres are still no osx viruses. Period.

  27. For those that have obviously been too lazy to read up on this, here you go courtesy of Macworld online…

    It turns out that Leap-A will only send itself out via iChat under a very specific set of circumstances:

    You must be using Bonjour iChat, not Internet-based iChat. That’s right. If you’re using iChat in the way that probably 99 percent of us do, you’ll never see this file being sent from an infected buddy. Leap-A will only send itself to others on your Bonjour buddy list. This is why Kirk and I were never able to get the malware to do its thing—we were not conversing via Bonjour. It sounds amazingly simple, but we spent quite a bit of time trying to figure this out before someone at Intego pointed out that it was limited to Bonjour networks.

    Even on a Bonjour network, you have to work a bit to get the file to send itself. It requires one (or more) status changes on either (or both?) of the Macs involved. In my case, I tested this by activating Bonjour chat on my G5-based desktop. For me, this was the only status change required to activate the file transfer function. But for Kirk, who already had Bonjour running, he had to change his status message on the target machine a couple times before the infected Mac noticed and then tried to send him the file. However, Kirk’s son Perceval, not being warned that this dangerous activity was occurring on the home network, turned on his iBook, logging in to iChat automatically. Since he logs into both AIM and Bonjour, this triggered the “hot” machine to send files to both the iBook and Kirk’s iMac.

    You still have to manually accept the file (then expand it and then double-click it) to infect your machine. Clearly, this thing is not going to spread like wildfire via iChat.

    So it seems the “iChat transmission” aspect of the Leap-A malware has been greatly overstated—unless you use Bonjour iChat, you’ll never see it arriving on your machine in this manner.

  28. Why is everyone downplaying this whole thing and acting like it’s nothing?

    Yes, this is news… Call it what you want, trojan, virus, worm.. Whatever you call it, This is the first documented attack on OSX.. Sure, it’s only a level one threat and yes, it requires user interaction, but it CAN do harm… And on an infected machine it can anonymously pop up on every person in that users iChat friends list..

    No one is claiming that OSX is not any safer now than Windows, all these reports are saying is, there has been a first attack on our beloved platform.

    This is the FIRST, there will be more.. Accept it!

  29. This is the third time that I’ve seen news sources running headlines gleefully proclaiming that the first Mac virus has arrived.

    As nobody noticed this one either, they can have another go at running the ‘First Mac virus’ headline at some point in the future.

  30. All the MacHaters will be in our face – ad infinitum – bla bla bla bla bla.

    In THEIR world: 1 Mac malware = 100,000 Windows malwares

    –

    MacHater: Jeez, get a real PC. Why do you continue to use that Crapintosh, anyway?

    MacUser: Because it annoys people like you so much.

    –

    Apple Computer, going out of business since 1984. Annoyed yet?

  31. Like I said before, I’m tired of us Mac users being treated like second class citizens!

    How come Windows users get to have over 70,000 real, hardcore, trash-the-peecee and all files, crash the ATM, subvert the server type malware? While Mac users only get these lame, “concept”, can’t install or propagate without root/admin passwords, “is it a virus?”, nonsense code?

    I think I’ll switch to Windblows.

    ” width=”19″ height=”19″ alt=”raspberry” style=”border:0;” />

  32. “Excuse me, a worm is a virus. Let me repeat that for those of you who missed it: a worm is a virus. The first virus for OS X has arrived. MDN, it’s time for you to admit the truth.”

    Well, let me repeat it for you in case you missed it, this isn’t the “first virus for OS X.” It’s no different from MP3Concept, Opener, or any of the other worms/viruses that have been written for OS X over the years that OS X remains impervious to because of its built-in security.

    It’s time for YOU to admit the truth.

  33. To repeat again for the numbskull press–THIS ISN’T THE FIRST OS X VIRUS.

    Plenty have been written for the platform over the years, but they never spread because of the need for user intervention, a result of OS X’s inherent security. Christ, even Paul Thurrott at Wininformant got this part right.

  34. MDN – affected by a power outage?! – methinks someone wanted to have a look at those “Leopard” pics …

    I guess this proves that Mac users are not immune to the same kinds of social-engineering techniques that users of PCs are … Whatever this is, it’s great to see the spirit of the Mac community and the calm and rational way people are speaking about this.

    From what I gather, this program has to be launched to do any damage – this is a far cry from what our PC brethren have to contend with each day.

  35. Trojan, worm… whatever… the user MUST decompress and run an unknown file from an unknown sender and circumvent the Mac’s existing warnings in order to be “infected”. This is hardly a virus.

    All this proves is that after all of Apple’s intensive engineering and installed safeguards, the Mac is still vulnerable to idiot users. Some people just shouldn’t have a computer.

  36. …still has no INTERNET viruses.

    Which is what the masses worry about–with good reason.

    If you want a laugh, check out the size of the infection stated at Symantec. Less than 50!

    All the word play and trolling in the world won’t change the truth: there’s nothing to see here.

    If some ignorant people think this is a reason to fear Macs, then too bad for them. Have fun on Windows, and no skin off my nose ” width=”19″ height=”19″ alt=”smile” style=”border:0;” />

  37. Before anyone posts any more crap about malware, I’d thoroughly recommend people go read the highly informative article at:

    http://www.kernelthread.com/publications/security/

    which describes the issues of computer security in some detail, for all platforms, in a highly informed manner. Perhaps surprisingly for members of this forum, you’ll learn that MacOS is actually rather poor (relatively) in terms of its security against other UNIX variants and has no formal security accreditation. Even more surprisingly, Windows NT has the highest formal security accreditation of any operating system.

  38. And yet again people are in denial. A virus is “a self-replicating program that spreads by inserting copies of itself into other executable code or documents. ”

    That is exactly what this is. It’s a virus with Trojan and Worm like characteristics. I’d suggest that since Mac users have little to no real experience with malware that they stop talking as if they are experts on the subject.
    Continue to be in denial but facts are fact. The one greatest tool to avoid malware on Windows or the Mac is your brain. Think before you click. That and turn off hiding file extensions. My first Apple arrives this week. Having a virus on it or not isn’t going to make a single difference to me since I’ve had one and only one virus on Windows in the last 12 years. And that was a boot sector virus on 3.11. As long as you exercise a little caution viruses are nothing to worry about.

    Actually more then anything I hope this is a wake up call for Mac users. That more then anything is what scares me. If something highly virulent comes along Mac users are going to be ill prepared. Windows users deal with this **** day in and day out. We are use to this crap. (OK most are. OK some are.) we’ve been inoculated. Mac users continue to tool along without a care in the world secure in the belief that nothing can touch their system. That mentality leaves the door open for some very nice social engineered viruses. And that is where things get interesting: when viruses trick the end user into entering their administrative account password. The most secure system in the world is useless if the person running it can be tricked.

  39. To SiliconAddict: you missed one crucial and most important thing about virus. A virus propagates without user intervention. Your PC gets infected just because it is ON and ONLINE.

    If it does not replicate and spread and infect WITHOUT user intervention it is not a virus. A virus example is MSBLASTER where the number of infected PC grew exponentially with time. Why? Because it required NO USER INTERVENTION.

    Silicon, stop spreading FUD: yourself are no expert on the subject.
    No one ever have said in these forums OS X is 100% bulletproof, we always said that social engineered attacks, where the naive user has to play a part, where possible. Remember Opener? Pretty much the same thing. So not only this is not the first virus on OS X, it is not EVEN the first malware as that, and other concept-proof malware has already appeared many months ago.

    A virus is what happens on Windows where after few days tens of THOUSANDS of PC get infected till hundred of thousands become infected in the weeks to come. This does not happen if there is even the minimal required user intervention to spread the malware, the absence of which is what characterize a virus.

    The problem in Unix, hence OS X, is the automatic infection of computers. This is what is going to be extremely difficult to achieve. OS X has its roots in BSDUnix. A *real* virus in OS X has to find a way to automatically infect BSDUnix platform by exploiting the OS security flaws, not the user mental flaws sitting in front of the keyboard.

    To conclude: malware on OS X? Oh My! OF COURSE, you just need to convince the user to do a dumb suicidal job and BINGO.
    A virus? Automatic detection of OS weakness, installation, infection, replication, spread, all this without user intervention? This is tough on OS X as it is on Unix family of OSes. Mind, not impossible, but tough. It might come if Apple and the Open Source community stop being proactive in finding and patching security flaws on Unix.

    Now, from your *understanding* of a virus, if I was putting in a shell script something like: ” cd / && rm -rf *” and sending email around asking you to launch the script in that it optimizes bandwidth and DOUBLE YOUR DOWNLOAD SPEED from the internet, and you were gobbling it and naively doing, you would have hammered your computer and cried out loud that your computer was a security swiss cheese?

    If it does not spread by itself without user intervention it is not a virus. Other kind of malware, relying on user stupidity are possible on every and any OS. They do not exploit OS weaknesses but exploit the fact that the owner should not use a computer because it is too hard for him to grasp.

  40. More precisely, the Symantec site says the infection rate is 0-49.

    That means that, other than the guys deliberately trying to get infected for documentation purposes, there have been effectively ZERO infections.

    What’s more, considering how hard it is to get this virus and make it do its stuff, I have no doubt it was purposely engineered to be a castrated monster for the purpose of AV publicity.

    As I brainstormed, I thought, I’ve got 7 rooms in my house, including bathrooms. Suppose I have one Mac in each room, and all the Macs are on BONJOUR iChat. Even then, how does this thing get into my house? Via SNAIL MAIL ??

    C’mon guys. This is as much a proof of concept as anything before.

    Where’s the proof that this thing is actively attacking anybody’s Macintosh?? There is no proof.

    In the meantime, I have ClamXav’s Sentry on the job, so quit hollering about how ill-prepared Mac community is. This site is evidence enough of our awareness, despite the alleged “denial”.

  41. the infection rate 0-49 essentially means there is no infection rate possible to detect. Just few units here and there means the threat does not have spreading capabilities per se, but requires an uninformed, naive user – to the point of being stupid – in order to infect a machine.

    The 0 means actually that no such *true* infected machine has been reported so far but only from people having tried *on purpose* to get infected just to prove that it coud work.

    From our side: Symantec classes the worm is a low threat because it doesn’t automatically infect other’s machines. The company says it has infected less than 50 machines. *see above comment*

    “… this worm will not automatically infect, but will ask users to accept the file, giving potential victims a heads up and the opportunity to avoid infection. The important piece of advice for any iChat users running OSX 10.4 is not to accept file transfers, even if they come from someone on a buddy list.”

    but it has to be a Bonjour iChat session. Regular iChat is not affected.

    However the worm, or Trojan-Work, is a wake-up call for OS X users with a false sense of OS X’s invulnerability: “Now that Leap.A has been discovered in the wild, copycat media-craving individuals will likely launch similar attacks in 2006.”

    OS X is not invulnerable. It is very good, as all other Unices, but not invulnerable. Hence, do not be stupid and believe that whatever you do the OS will save you. If you are a moron and a stupid Mac user, OS X cannot save you from these kind of threats.

    Do not be the security weakest link nor undermine because of your behavior the OS X inherent security.

    Now, can we put it to rest: we need to put bacon on our tables, what do you expect? ” width=”19″ height=”19″ alt=”wink” style=”border:0;” />

  42. Ya gotta love Rob Griffith’s definition of this [insert malware term of your choice]…

    I quote:

    Is this a virus, a worm, malware, or a Trojan horse?

    Technically, it’s a bit of everything. It’s a virus, in the sense that it attaches itself to other executable code on your Mac. It’s a worm, in that it attempts to self-replicate and spread from machine to machine. It’s a piece of malware, because it can do bad things to your computer. Basically, it’s a piece of malware that’s delivered via a Trojan horse and then acts in both viral and wormy ways.

    OK? Are we done now? The debate about what kind of program this is has been settled. </judge’s gavel pounding> ” width=”19″ height=”19″ alt=”LOL” style=”border:0;” />

  43. Wikipedia sez: “Trojan horse programs cannot operate autonomously, in contrast to some other types of malware, like viruses or worms. Just as the Greeks needed the Trojans to bring the horse inside for their plan to work, Trojan horse programs depend on actions by the intended victims. As such, if trojans replicate and even distribute themselves, each new victim must run the program/trojan. Therefore their virulence is of a different nature, depending on successful implementation of social engineering concepts rather than flaws in a computer system’s security design or configuration. …

    “Trojans of recent times also contain functions and strategies that enable their spreading. This moves them closer to the definition of computer viruses which operate by spreading on their own and infecting executable files, and it becomes difficult to clearly distinguish such mixed programs between Trojan horses and viruses. However, the defining characteristic of trojans is that they require some user action, and cannot function entirely on their own.”

    That perfectly describes this little piece of malware. It is not a virus; it is a Trojan horse.

    Someday a true MacOS X virus may come along, but we have yet to see that day, in spite of the rabid desire of some on this list.

    Anyone here still insisting this is a virus or worm is just a troll, or M$ apologist spreading FUD, in my book.

  44. MK,

    I was talking to this guy, two weeks ago – at one of the Chinese food places I go to (this one being, not very good, but it is a block away).

    We started talking about computers, and inevitably we got talking about viruses and MARKETSHARE. I tried to explain to him, that the Mac doesn’t get loads of viruses because of low marketshare, but rather it’s inherent nature. Even briefly explaining the concept of Root, Admin, Standard users on both the Mac and Windows. He politely listened, tho’ it made his eyes glaze over. But, I could tell that he wasn’t having any of it.

    I printed out four essays describing the technical reasons for the Mac’s better security, and left them at the restaurant for him. If he gets them, AND reads them, It’ll be interesting to have a discussion with him in light of this latest development.

    I’m sure he’ll bring this up. But, as I’ve NEVER said to him or anyone that it was impossible for a Mac to get a ‘virus’, only much more difficult – and gave the ‘technical’ reasons why – then I don’t think that I’ve betrayed my own or the Mac community ethos.

    And again, I don’t care that he or anyone else doesn’t like the Mac or won’t use and doesn’t want anyone else using one. I get great satisfaction using the Macs that I’ve owned. If this annoys people, too freakin’ bad.

    [RainDay said: Someday a true MacOS X virus may come along, but we have yet to see that day, in spite of the rabid desire of some on this list.
    Anyone here still insisting this is a virus or worm is just a troll, or M$ apologist spreading FUD]

    I truly believe both of these comments.

  45. Still no viruses that have effected Macs to date and counting. If it can’t spread and propogate it’s not a virus. Viruses go from one machine to the next with no manual human interface and this leap crap is nothing more than a bad application trying to play out like a virus and of course all of the antivirus companies trumpeting there horns so they can get your money for NO REASON!

  46. John you’re wrong….

    Some members of the Apple Macintosh community have claimed that OSX/Leap-A is a Trojan horse, and not a virus or worm, because it requires user interaction (the user has to receive a file via iChat, and manually choose to open and run the file contained inside).

    However, this is not the definition of a Trojan horse.

    A Trojan horse is a seemingly legitimate computer program that has been intentionally designed to disrupt and damage computer activity. Importantly, Trojan horses do not replicate or have any mechanism of spreading themselves. They have to be deliberately planted on a website, or accidentally shared with another user, or spammed out to email addresses. There is nothing inside a Trojan’s code to distribute themselves further to other victims.

    Trojan horses do not contain any code to distribute or spread themselves, viruses and worms do.

    OSX/Leap-A is programmed to use the iChat instant messaging system to spread itself to other users. As such, it is comparable to an email or instant messaging worm on the Windows platform. Worms are a sub category of the group of malware known as viruses.

    Therefore, it is correct to call OSX/Leap-A a virus or a worm. It is not correct to call OSX/Leap-A a Trojan horse.

  47. I think that the whole point is that people are actively trying to create malware to discredit the “macs are safer” statements so often made.

    Any malware that relies on user stupidity works because, and I say this from considerable experience in IT support, the vast majority of users are that stupid!!!!

    As Robert A. Heinlein said “Never Underestimate the Power of Human Stupidity”

    It is Apple’s job to find ways to prevent this, perhaps through creating a quarantine folder for all downloads where they can be checked before moving into a home folder or apps folder. OSX is more secure than anything else but too often we forget the most unsecure part of the computer – the user.

  48. BILL GATES AND GM 

      For all of us who feel only the deepest love and affection for the way computers have enhanced our lives, read on. At a recent computer expo (COMDEX), Bill Gates reportedly compared the computer industry with the auto
    industry and stated, “If GM had kept up with technology like the computer industry has, we would all be driving $25.00 cars that got 1,000 miles to the gallon.” 

    In  response to Bill’s comments, General Motors issued a press release stating: If GM had developed technology like Microsoft, we would all be driving cars with the following characteristics (and I just love this part): 

    1.  For no reason whatsoever, your car would crash twice a  day. 

    2.  Every time they repainted the lines in the road, you would have to buy a new car. 

    3.  Occasionally your car would die on the freeway for no reason. You would have to pull to the side of the road, close all of the windows, shut off the car, restart it, and reopen the windows before you could continue. For some
    reason you would simply accept this. 

    4.  Occasionally, executing a maneuver such as a left turn would cause your car to shut down and refuse to restart, in which case you would have to reinstall the engine. 

    5.  Macintosh would make a car that was powered by the sun, was reliable, five  times as fast and twice as easy to drive – but would run on only five percent of the roads. 

    6.  The oil, water temperature, and alternator warning lights would all be replaced by a single “This Car Has Performed an Illegal Operation” warning light. 

    7.  The airbag system would ask “Are you sure?” before deploying. 

    8.  Occasionally, for no reason whatsoever, your car would lock you out and refuse to let you in until you simultaneously lifted the door handle, turned the key and grabbed hold of the radio antenna. 

    9.  Every time a new car was introduced car buyers would have to learn how to drive all over again because! None of the controls would operate in the same manner as the old car. 

    10.  You’d have to press the “Start” button to turn the engine off. 

  49. The headlines need to say:

    “MAC OSX REMAINS RESISTANT TO VIRUS ATTEMPT”

    Can ANYONE find someone who has been affected by this thing? Surprise surprise, no they can’t – the only people ‘affected’ were experimenting with it to take it apart…

  50. OK thanks for that Jason – I see it took about four minutes of the posting for the suspicions to have been raised. I count about 3 people affected and the same number of others that were suspicious enough not to have opened the file…

    It shows we need to be alert, but I agree with the the general view that this is proof of concept and not a real threat.

    I will continue to maintain that the ratio is still 100,000 to zero of Winbox viruses to Mac ones!

  51. Leap.A is a trojan, a virus, and a worm. The terms are not mutually exclusive.

    I read the Macworld article so don’t quote it at me. The fact is that once Leap.A has infected an app, if I take that app and drag-and-drop it (and Leap.A infects primarily drag-and-drop apps) onto a zip disk or a hard drive or burn it to a CD, and move that zip disk or HD or CD to another Mac and then run the app, it WILL infect that other Mac.

    That’s an old-school virus, pure and simple, from before the days of the internet. This thing spread JUST LIKE THE OLD MAC OS 6 AND 7 VIRUSES did. There is NO DIFFERENCE. Remember that. It’s a virus.

    It is also a worm. If my machine is infected and I connect to a particular type of network (Bonjour-enabled iChat), then it sends itself spontaneously without my intervention. Yes, the user on the other side has to accept the file, BUT THAT IS TRUE OF ALMOST ALL INTERNET WORMS. The point is, I do not have to send an infected file over the network. It sends itself spontaneously upon connection. THAT MY FRIENDS IS AN INTERNET WORM.

    And finally, it is of course a trojan horse since it is available for download and pretends to be something else.

    None of these terms are mutually exclusive, and many many specious arguments that assume they are have been made here. Leap.A is without a doubt a virus. By the definition of virus that a lot of you people are going by, there can’t have been any viruses before people were connected to the internet and THAT IS PATENTLY NOT TRUE. Read your history. The entire first and second generations of virus are simply malicious codes that gets transferred with a host file and replicates upon the launching or opening of that file. Leap.A DOES THIS! ONCE IT HAS INFECT YOUR MACHINE IT DOES NOT REQUIRE A PASSWORD TO INFECT OTHER FILES ON YOUR MACHINE AND THEN BE CARRIED WITH THOSE FILES TO OTHER MACHINES AND INFECT THEM, AGAIN, WITHOUT A PASSWORD.

    It’s a virus. Pack it in people.

    For the record I think the Mac is inherently FAR MORE SECURE than Windows and not just because of obscurity, but face the facts people. Virus. Worm. Trojan. This is all three.

    DB.

  52. Reading this discussion leads me to believe that the situation is much worse than we all believe. It seems clear to me that most of your macs have already been infected by a potent virus.

    It seems the virus is modifing the posts of reasonable and prudent people so that almost every other one is changed into a frenzied, emotional outburst devoid of rational thought and fact.

    The end result to someone like me, who is following this thread, is to see what appears to be normally intelligent people actually arguing over something so inane that it makes no difference who is ultimately correct.

    Now the GOOD NEWS! For all of you worried about your late model mac being infected with this virus, the Leap/A trojan, or the Bluetooth issue, I will do you a huge favor and take those infected macs off your hands for $100 each. That’s a hundred bucks whether your disease-ridden mac is a 17″ Powerbook, a Powermac Quad G5 or even a lowly G4 iBook. I’ll save you from all further security threats as well as the embarrassment of continuing in this discussion, and give you $100 too. You’ll never get such an offer from Apple. The line forms to the right…

    DbD

    p.s. Mr. or Ms. “Whatever”, The guy in the Chinese restaurant who you lectured on mac security and even printed him essays to read, I think it’s safe to say you won’t be seeing him again (if he can possibly help it). Nice job portraying the average mac user as a rabid, meal-spoiling nut. That’s how No Smoking started in restaurants!

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.