First OSX based botnet spotted in the wild

Hey drop us a line about the show. Feel free to ask questions, provide feedback and criticism, or just ramble on about anything your little heart desires.

Moderators: snarkout, Patrick, dann

Post Reply
User avatar
Patrick
Site Admin
Posts: 2519
Joined: Tue Apr 27, 2004 11:38 am
Location: Easton, PA
Contact:

First OSX based botnet spotted in the wild

Post by Patrick » Thu Apr 16, 2009 11:25 am

http://digg.com/apple/First_OSX_based_b ... n_the_wild

Can't wait to hear how the Apple Kool Aid drinkers spin this one.
Ego contemno licentia

User avatar
dann
Site Admin
Posts: 1132
Joined: Mon Apr 26, 2004 10:55 pm
Location: Hampton, Va, USA
Contact:

Re: First OSX based botnet spotted in the wild

Post by dann » Thu Apr 16, 2009 1:47 pm

Well, at the risk of defending apple, how can you claim lack of security when a person purposefully installs questionable software, illegally mind you, and infects their machine. To install this software requires one to enter their password (equivalvent to sudo). Essentially they are purposefully installing these malicious code. The only exploit is the stupid user, and really, at this point this is no way to protect the system from that hole.

User avatar
Claudio
Posts: 249
Joined: Fri Sep 19, 2008 11:43 am
Location: Miami, FL

Re: First OSX based botnet spotted in the wild

Post by Claudio » Thu Apr 16, 2009 6:30 pm

dann wrote:Well, at the risk of defending apple, how can you claim lack of security when a person purposefully installs questionable software, illegally mind you, and infects their machine. To install this software requires one to enter their password (equivalvent to sudo). Essentially they are purposefully installing these malicious code. The only exploit is the stupid user, and really, at this point this is no way to protect the system from that hole.
While true, what's to prevent the use of this through a website that looks legitimate and acts as though it requires your password to install a supposed "plugin" to access the site? Not many people are privy to a site that they consider reputable to actually be some sort of phishing site or a legit site that was compromised. I personally see this as only the beginning. Of course, this could easily happen to a careless user in any desktop GNU/Linux distribution in much the same manner. The only difference is that Ubuntu doesn't make it easy to be root, while OS X basically defaults a user account to administrative rights upon initial configuration if I'm not mistaken. Not that far off from running as root IMO.
Image Image

User avatar
dann
Site Admin
Posts: 1132
Joined: Mon Apr 26, 2004 10:55 pm
Location: Hampton, Va, USA
Contact:

Re: First OSX based botnet spotted in the wild

Post by dann » Thu Apr 16, 2009 9:12 pm

The OS X user has the same rights as the Ubuntu user. Both require you to put in a password to do any administrative tasks and at that point all bets are off. The OS X user does not run at any other elevated privileges compared to the default ubuntu user.

Post Reply