Mostrar mensagens com a etiqueta Mac OS X. Mostrar todas as mensagens
Mostrar mensagens com a etiqueta Mac OS X. Mostrar todas as mensagens

sábado, 3 de dezembro de 2011

Update Java to thwart active cross-platform exploit


There is a rather serious vulnerability in Java version 1.6.0_26 that is apparently being actively pursued by hackers, one that is easy to implement and allows hackers to compromise systems without being detected.
The exploit was found a couple of months ago and was addressed in the latest round of Java updates both from Oracle and from Apple for OS X users; however, many people have not yet updated their systems and hackers are working to take advantage of this flaw on these systems.
The vulnerability allows a maliciously crafted Java applet to run undetected on many browsers and allows code to execute outside of the Java sandbox with the privileges of the current user. This means that malicious code in the applet can have access to any system feature your account has access to. For standard user accounts that's restricted to the user's home folder and attached disks, but for administrators it includes the Applications folder and parts of the global library and system folders.
This behavior is not particularly new for vulnerabilities; however, this one is a bit different in that the exploit is easy to perform, does not require authentication or other user input to run, and remains hidden on most browsers.
Beyond all of these details is the real issue here, which is that packaged versions of the exploit are apparently being actively sold and distributed among hackers on underground cybercrime networks, meaning that it is very likely to be implemented on many sites. If by chance a Google search results in you clicking a site that has this exploit, then if you have Java installed, your computer could be quickly compromised. All you have to do is visit a compromised Web site with a malicious Java applet, and most browsers will not even indicate the exploit is running.
OS X Java Preferences
In OS X, check the Java Preferences utility to see what version of Java you are running. You can use the preferences to disable Java applets as well.
(Credit: Screenshot by Topher Kessler)
Security community Metasploit took a recent look at this vulnerability, and found that the exploit, described as "a big one," is run completely and successfully on all systems running Java prior to version 1.6.0_29-b11, including Windows XP, Windows 7, Ubuntu Linux, and Apple's OS X.
On all platforms, only Google's Chrome browser gave any notification that a Java applet was running; other browsers like Safari, Internet Explorer, and Firefox gave no indication at all. Regardless of this difference, the malicious applet ran easily and successfully in all browsers.
According to Krebs on Security, the exploit "should not be taken lightly by any computer user," since Java is installed on more than 3 billion computing devices worldwide. Krebs cites Microsoft's Tim Rains as mentioning that Java-based exploits were the most common ones seen on computer systems in the first half of 2011, suggesting that hackers would be eager to get their hands on this current exploit.
Safari's Java options
Safari's preferences have an option for disabling Java.
(Credit: Screenshot by Topher Kessler)
This is a serious issue, but luckily the last update to Java distributed by Oracle, Apple, and other companies for their operating systems includes a fix for this problem. If you keep your system fully updated and if applied the Java patch when it was released then you have nothing to worry about; however, many times people ignore updates to software that they do not use, with Java being one of them.
To see what version of Java you are running on your system, launch your Java configuration tool or runtime environment and check the version there. For Mac users, Apple has stopped including Java with OS X but has it readily available to download if you run Java applications on your system. If you have not installed Java then you are in the clear. If you have, then go to your /Applicatons/Utilities/ folder and open the Java Preferences application. In here if you see the Java SE 6 version listed as being anything below 1.6.0_29-b11, then it is highly recommended that you update Java on your system.
The latest Java update is available via software update tools, so be sure to run them on your system (Apple's is available by selecting Software Update in the Apple menu). However, you can also download the updates directly from sites like Apple's Java Update 6 for Mac OS X 10.6, and the Java Update 1 for OS X 10.7. Non-Mac users can download the update directly from Oracle.
Firefox Add-on manager
Firefox's Java handling can be disabled through its Add-ons manager.
(Credit: Screenshot by Topher Kessler)
In addition to updating Java, there are some other steps you can take to help secure your system, especially if you do not regularly use Java Web applets when browsing the Internet (and especially since most common Web scripting is done in JavaScript and PHP, or uses Flash). In the Java preferences, uncheck the option to enable applet plug-in and Web Start applications, which will prevent downloaded applets from launching. Additionally, in Safari's preferences uncheck the security option for enabling Java.
If you use Firefox, then to disable Java go to the Tools menu and select the Add-ons option to open the Add-ons Manager window. In here, click the Plugins section to the left, and locate the Java Applet Plug-in. Then click the "Disable" button next to the plug-in to prevent Java applets from running.
Again, this threat was addressed over a month ago, so while it is only now being found to be a serious issue, the fix for it has been available and ready for a while. However, as it's a recent update many people may not have yet installed it, so again, be sure to check your system and apply the update if you are not running the latest version of Java.


Read more: http://reviews.cnet.com/8301-13727_7-57335639-263/update-java-to-thwart-active-cross-platform-exploit/#ixzz1fQjmo45O

Enhanced by Zemanta

sexta-feira, 23 de setembro de 2011

New OS X trojan horse sends screenshots, files to remote servers


These days when people think of malware and OS X the first name that comes to mind is likely MacDefender or one of its variants, which were rogue utilities designed to trick users into giving up personal and financial information. As the Mac gains in popularity there will 
undoubtedly be more attempts like this, and recently a new trojan horse attempt for OS X has surfaced that tries to steal users' personal information.
The malware was first seen in late July of this year, and has been identified by security firms F-Secure and Sophos as "trojan dropper" and "backdoor" utilities that both work in tandem to install on the system.
trojan-dropper.OSX.Revir.A PDF file
The Trojan downloader will display this PDF file that contains offensive political statements in Chinese (click for larger view).
(Credit: F-Secure)
This trojan downloader is the initial phase of the attack, and is a program that when run will install a backdoor utility called "BackDoor:OSX/Imuler.A" onto the system. The downloader will also download and continually open a Chinese PDF document (aptly named "trojan.pdf") that contains offensive political statements, which apparently is an attempt to distract the user and disguise the installation of the backdoor malware.
When the backdoor is installed, it will set up a launch agent on the system that is used to continually keep the malware active on the system. It will then connect to a remote server and send the system's current username and MAC address to the server, after which the server will instruct it to either archive files and upload them, or take screenshots and upload them to the server.
According to F-Secure, the malware does not appear to work very well (if at all) at this time since it does not receive instructions from the remote server, but the malware may still be capable of performing its malicious activities. Currently the server seems to be a crude Apache implementation that is likely in a testing phase, but has the potential to be active and properly interact with the malware.
Both F-secure and Sophos have issued malware definition updates to address this new threat, and it is very likely that other malware scanners will soon follow suit, so be sure you keep your malware scanners up to date.
If you do not have a malware scanner, then you can check for the presence of this trojan horse by opening Activity Monitor, ensure you are viewing all processes, and then look for a process called "checkvir" (sort the processes by name to make locating it easier). If you see this process running, then select it and click the red stop sign button to quit it using Activity Monitor, followed by removing it from the following directory on your system:
/username/Library/LaunchAgents/
If you are running OS X Lion, you can get to the user library by holding the Option key and selecting "Library" from the Finder's Go menu, but in prior versions of the OS the Library should be visible in your home directory. Inside the LaunchAgents directory, remove the files "checkvir" and "checkfir.plist" which are the malware and its launcher agent, respectively. After this the malware should be removed from your system.
Overall while this is a new threat to OS X users, the threat level is relatively minor. The program is easily detectable and removable, and does not seem to be widespread. It also currently does not seem to work properly as it does not yet receive instructions from the remote server.
Unfortunately so far there is no information on exactly how the malware is distributed, but as with other malware it may be distributed via spam e-mails and underground Web sites. If you see an unknown PDF launch automatically on your system, then that is a very good sign the malware is running. As with other malware on OS X, this will need to be explicitly run by the user in order to install, so be aware of any programs that you have downloaded, especially if they show odd behavior like opening unknown documents, are in unexpected languages, or have obviously poor grammar and spelling.
Besides the use of malware scanners, OS X itself has a few guards against these types of trojans. The system flags every application that is downloaded, and warns you that it is the first time you've run that file, which can help you determine if you want to open the program. In addition, while it has not yet been updated Apple has its XProtect malware detection system that may acquire definitions to this new malware and detect it if, and when, it is downloaded.