Featured Content
Posted Jul 03, 2006 at 05:36AM by Alaric S. Listed in: Apple Tags: Trojan, Mac OS X, Exploit, Trojan Horse
Ó

symantecSymantec the Virus Slayer reported sighting a Trojan horse that exploits the Apple Mac OS X LaunchD Local Format String Vulnerability. It provides root access on the Macintosh OSX version 10.4.6 or earlier.

When OSX.Exploit.Launchd is executed, the malicious bug performs the following actions:
  1. Exploits the Apple Mac OS X LaunchD Local Format String Vulnerability which may elevate the privileges of a remote attacker's local account on an Apple Mac OS X computer.
  2. Uses a crafted .plist configuration file for LaunchD service. In order to exploit LaunchD the attacker must execute the command: launchctl load [MALICIOUS FILE NAME]
  3. Runs inside the process of LaunchD which runs with root privileges.
  4. Opens a shell with full root privileges which is controllable by the attacker.
However the company also said the Apple Trojan as a minor threat as it has not spread widely and easily removed. To help minimize attacks Symantec gave the following recommendations:
  • Always keep virus protection program up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services (for example, all Windows-based computers should have the current Service Pack installed.).
  • Enforce password policy to prevent or limit damage when a computer is compromised.
  • Configure email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.
  • Isolate infected computers quickly.
  • Train employees not to open attachments unless they are expecting them.
If your Mac is already infected, you may download the removal tools from Symnatec.

Email this  |  Digg It!   |   Comments [0] read more ...
  Page 1   
QJ.NET Blog Network RSS Feeds
MyQJ Feed / PDA
MyQJ RSS / PDA
Blog of Blogs Feed / PDA
QJ.NET RSS / PDA
Gaming Consoles Feed / PDA
Nintendo DS RSS / PDA
PlayStation 3 RSS / PDA
PSP Updates RSS / PDA
Wii RSS / PDA
Xbox 360 RSS / PDA
PC Gaming Feed / PDA
Age of Conan RSS / PDA
Games for Windows RSS / PDA
MMORPG RSS / PDA
Tabula Rasa RSS / PDA
World of Warcraft RSS / PDA
Science Feed / PDA
Science RSS / PDA
Technology Feed / PDA
Apple RSS / PDA
Gadgets RSS / PDA
iPhone RSS / PDA
Mobile RSS / PDA
Photography RSS / PDA
Tech RSS / PDA
Add QJ.NET
Add to My Yahoo!
Google Reader Subscribe with Bloglines
Add  to your Kinja digest Subscribe in NewsGator Online
Subscribe with Pluck RSS reader Add 'www.qj.net' to Newsburst from CNET News.com
Subscribe with SearchFox RSS del.icio.us www.qj.net
Add to Technorati Favorite! Add to My AOL
furl! it Stumble for Treehugger!