Sunday | 7 September, 2008
Computerworld
Are we about to witness a real OS X virus?
Intego might have stumbled across an OS X specific virus being offered for auction that targets a previously unknown ZIP archive vulnerability.
Carl Jongsma 24/07/2008 14:27:59

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Your World. . . Hacked 02/10/2007 10:51:23

    As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to compete
    The call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Mac antivirus maker, Intego, have published an interesting alert about a potential OS X virus that an enterprising individual is trying to sell through auction. With absolutely no technical information to go on, the antivirus maker is treating the announcement with caution.

Based on the rate and type of vulnerabilities identified by projects like the Month of Apple Bugs it isn't too far fetched to expect that there are dozens or even hundreds of OS X specific viruses/malware creations that are sitting on the systems of their developers but which do not have many opportunities for widespread distribution.

Some of the more successful OS X-specific pieces of malware have been distributed through file sharing sites and P2P applications, usually claiming to be for highly desirable software. A 5-10MB download for an application suite that should be 500-600MB generally leaves clues as to something not being quite right. More common, though, are exploit attempts against QuickTime and popular OS X web browsers, with US developer Sunbelt Software having identified and tracked a number of these types of vulnerability, though their effectiveness at infecting OS X targets in the wild isn't known. The exploits used in these types of attack will compromise a victim's system, but there aren't any readily available figures as to how many victims have actually been affected by them.

From Intego's posting, it appears that the enterprising auctioneer seems determined to make sure that his name is one that is not forgotten when it comes to Apple security, claiming that his exploit is a poisoned ZIP archive that will "KO the system and Hard Drive" when unarchived. He may not be operating on the scale of David Maynor, Tom Ferris, or Kevin Finisterre, and there might not even be the kernel of truth that InfoSec Sellout had with their claimed OS X malware, but it is feasible that there is something in the OS X Archive Utility that lends itself to exploitation and system control like the recent ARDAgent vulnerability did.

From appearing on July 21, to disappearing soon after Intego's post, there is more mystery than substance about the hacker, the claimed vulnerability and the site itself. There are plenty of ways to take an OS X system to its knees by manually launching malicious software or content, there just aren't very many that have demonstrated a capability of being set up for malicious use (despite their potential) and there are even fewer that demonstrate any sort of viability for (semi-)autonomous spreading.

Time will tell, but it's possible that Intego has stumbled across something that could cause as much interest as last year's InfoSec Sellout soap opera.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

Dude! You Say I Need an Application-Layer Firewall?!

Proxy firewall technologies have proven time and again to be more secure than “stateful” firewalls. They will also prove to be more secure than “deep inspection” firewalls. High-performance proxy firewalls are available today which are easily capable of handling gigabit-level traffic. Discover more by reading on.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links