Apple Rumors and Reports Discuss what's going on with Apple in this forum

Flashback trojan reportedly controls half a million Macs and counting


Post Reply New Thread Subscribe

 
Thread Tools
Doug b

 
Doug b's Avatar
 
Member Since: Jun 22, 2008
Location: Forest Hills, NYC
Posts: 3,339
Doug b has a reputation beyond reputeDoug b has a reputation beyond reputeDoug b has a reputation beyond reputeDoug b has a reputation beyond reputeDoug b has a reputation beyond reputeDoug b has a reputation beyond reputeDoug b has a reputation beyond reputeDoug b has a reputation beyond reputeDoug b has a reputation beyond reputeDoug b has a reputation beyond reputeDoug b has a reputation beyond repute
Mac Specs: 15-inch Early 2008; Processor 2.4 GHz Intel Core 2 Duo; Memory 4 GB 667 MHz DDR2 SDRAM; 10.7.5

Doug b is offline
Well, Dogbreath.. (I really like calling someone that) the thing is that I don't think anyone has actually seen or experienced the consequences of said "infection", so one shouldn't assume what the outcome would be. That said, everyone and their mom should be backing up their data (not just via Time Machine) redundantly, and on a regular basis.

Which reminds me, I need to buy a new external!

Doug
QUOTE Thanks
RavingMac

 
RavingMac's Avatar
 
Member Since: Jan 07, 2008
Location: In Denial
Posts: 6,779
RavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond repute
Mac Specs: 4GB Mac Mini, 13" MacBook, 15" MacBook Pro OSX 10.7, 32 GB iPhone 3GS, iPad2 64gb 3G

RavingMac is offline
Quote:
Originally Posted by Doug b View Post
Well, Dogbreath.. (I really like calling someone that) the thing is that I don't think anyone has actually seen or experienced the consequences of said "infection", so one shouldn't assume what the outcome would be. That said, everyone and their mom should be backing up their data (not just via Time Machine) redundantly, and on a regular basis.

Which reminds me, I need to buy a new external!

Doug
I was just going to post the question, "Has anybody on this Forum seen the infection, or even know someone who has?"

Just curious now.

Of course, I know everything . . . I just can't remember it all at once.
QUOTE Thanks
Stretch

 
Stretch's Avatar
 
Member Since: Jan 13, 2007
Location: Central New York
Posts: 4,614
Stretch has much to be proud ofStretch has much to be proud ofStretch has much to be proud ofStretch has much to be proud ofStretch has much to be proud ofStretch has much to be proud ofStretch has much to be proud ofStretch has much to be proud ofStretch has much to be proud of
Mac Specs: 15in i7 MacBook Pro, 8GB RAM, 60GB SSD, 500GB HD

Stretch is offline
I did the check, just for the heck of it. Didn't really need to since I have Little Snitch installed. Came back clean.

Blog and Photo Gallery: http://philolin.me/

Currently running OS X 10.8.2
QUOTE Thanks
McBie

 
McBie's Avatar
 
Member Since: Apr 26, 2008
Location: Belgium
Posts: 1,836
McBie is a name known to allMcBie is a name known to allMcBie is a name known to allMcBie is a name known to allMcBie is a name known to allMcBie is a name known to allMcBie is a name known to all
Mac Specs: 2008 MBP 17" - 10.8.2 & iPad - iOS 5.1

McBie is offline
Quote:
Originally Posted by Razormac View Post
I was just going to post the question, "Has anybody on this Forum seen the infection, or even know someone who has?"

Just curious now.
That is why I posted earlier on that the results of the malware are not clear and as far as I can tell, there are no results.
That is why I called this a proof of concept ... a step by step approach and see how far they can get.
That is also why the articles in the press and magazines made me smile ..... 600000 infections ... right .... what does that mean then ..... how many of those actually yielded any results .... and where does the 600000 comes from ?
Is someone counting numbers ?

In my mind, there is not so much to worry about, only that people now understand that the OS X platform is not only on the radar, it is now also a chosen target.

A few simple behaviors will keep the risk level actually low. ( The vulnerabilities are outside of our control )

Cheers ... McBie

" Everything should be made as simple as possible, but not one bit simpler. " A. Einstein
The problem is not the problem. The problem is your attitude towards the problem. You understand ?
QUOTE Thanks
ursus262

 
Member Since: Dec 27, 2011
Posts: 22
ursus262 is an unknown at this point

ursus262 is offline
I'm clean
QUOTE Thanks
mattg3

 
Member Since: Dec 05, 2010
Posts: 50
mattg3 is on a distinguished road

mattg3 is offline
Im clean.Just told me files do not exist but did not say anything like domain/default pair of does not exist
QUOTE Thanks
vansmith

 
vansmith's Avatar
 
Member Since: Oct 19, 2008
Location: Ottawa
Posts: 15,279
vansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond repute
Mac Specs: 2012 13" MBP (2.5 i5, 8GB)

vansmith is offline
I think I may have noticed a flaw in the F-Secure article (here). I noticed that in the Ars article (here) covering the malware, they check the Safari and Firefox app bundles which made me think that this malware modifies the app bundle for the browser used by the user and not necessarily Safari itself. I never use Safari so I imagine that checking the Safari app bundle is utterly useless if this is the case.

Does anyone know if the malware modifies Safari and/or Firefox regardless or does it modify the browser used when the malware was installed on the machine?

Important Links: Community Guidelines : Use the reputation system if you've been helped.
M-F Blog :: Write for the blog :: M-F IRC Channel - Chats every Sunday at 8PM EST.
QUOTE Thanks
RavingMac

 
RavingMac's Avatar
 
Member Since: Jan 07, 2008
Location: In Denial
Posts: 6,779
RavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond reputeRavingMac has a reputation beyond repute
Mac Specs: 4GB Mac Mini, 13" MacBook, 15" MacBook Pro OSX 10.7, 32 GB iPhone 3GS, iPad2 64gb 3G

RavingMac is offline
Okay, I just checked Firefox on all three Macs (my browser of choice) and still clean.

Of course, I know everything . . . I just can't remember it all at once.
QUOTE Thanks
mattg3

 
Member Since: Dec 05, 2010
Posts: 50
mattg3 is on a distinguished road

mattg3 is offline
Did you type in a different command in terminal to check firefox or just the two that have already been listed in this thread?
QUOTE Thanks
alexsd123

 
Member Since: Jul 18, 2009
Posts: 473
alexsd123 has a spectacular aura about
Mac Specs: Macbook Pro 13"

alexsd123 is offline
I am clean, but I have to now check up on the less wary Mac users that I know. I have a feeling I know someone who caught this--same person that caught the Mac Defender or whatever it was called.
QUOTE Thanks
vansmith

 
vansmith's Avatar
 
Member Since: Oct 19, 2008
Location: Ottawa
Posts: 15,279
vansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond reputevansmith has a reputation beyond repute
Mac Specs: 2012 13" MBP (2.5 i5, 8GB)

vansmith is offline
Quote:
Originally Posted by mattg3 View Post
Did you type in a different command in terminal to check firefox or just the two that have already been listed in this thread?
Replace:
Code:
defaults read /Applications/Safari.app/Contents/Info LSEnvironment
in the steps above to check your machine with the following:
Code:
defaults read /Applications/Firefox.app/Contents/Info LSEnvironment

Important Links: Community Guidelines : Use the reputation system if you've been helped.
M-F Blog :: Write for the blog :: M-F IRC Channel - Chats every Sunday at 8PM EST.
QUOTE Thanks
mattg3

 
Member Since: Dec 05, 2010
Posts: 50
mattg3 is on a distinguished road

mattg3 is offline
thanks,Firefox is clean
QUOTE Thanks
Semanon

 
Member Since: Mar 04, 2012
Posts: 12
Semanon is on a distinguished road

Semanon is offline
All the comments I am sure make sense to sophisticated MAC users. I am a new MACBookPro user. There is no way I can make sense of any of the comments above. How will I know if my MACBook has been infected? I have no idea how to use the terminal or what not.

Many of us are not expert MAC users.
QUOTE Thanks
Semanon

 
Member Since: Mar 04, 2012
Posts: 12
Semanon is on a distinguished road

Semanon is offline
How does one use the terminal? I opened it up, and it says:

Last login: Sun Apr 8 01:44:07 on ttys000
MYName-MacBook-Pro:~ mynames$ ..



Now what do I do?


I also see members writing that they checked their browsers, ie Firefox. How would I do that?

Do you think it might be better for me to call Apple and talk to a tech?
QUOTE Thanks
madwolfe

 
madwolfe's Avatar
 
Member Since: Nov 24, 2011
Posts: 89
madwolfe is an unknown at this point
Mac Specs: 20" iMac, Late 2007, 2.4GHz (Dual Core), 1GB RAM, Radeon 2600HD OSX 10.6.8

madwolfe is offline
Quote:
Originally Posted by Semanon View Post
All the comments I am sure make sense to sophisticated MAC users. I am a new MACBookPro user. There is no way I can make sense of any of the comments above. How will I know if my MACBook has been infected? I have no idea how to use the terminal or what not.

Many of us are not expert MAC users.
It is kind of like one of those make your own adventure books, if you follow the article here
To run commands in Terminal, open up Terminal (Applications/Utilities or a Spotlight search) and then it is merely a case of copying and pasting. So first we run
Code:
defaults read /Applications/Safari.app/Contents/Info LSEnvironment
by using cmd+c and then cmd+v into Terminal.
If you get an error message, you can skip straight to step 8 (Hope that you get one).
All you have to do is follow the instructions on the websitr linked.

I use Terminal all the time but I must admit to you that I understand very little.

You should be clean if you don't willy-nilly put in the admin password for everything that asks for it however if you do find you are infected, ask here for a walkthrough if you need.
QUOTE Thanks

Post Reply New Thread Subscribe


« Apple CEO Tim Cook spotted at video game designer Valve's headquarters | Reuters: Justice Department ready to sue Apple over ebook price fixing (Updated) »
Thread Tools

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off
Forum Jump

All times are GMT -4. The time now is 08:43 AM.

Powered by vBulletin
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
X

Welcome to Mac-Forums.com

Create your username to jump into the discussion!

New members like you have made this community the ultimate source for your Mac since 2003!


(4 digit year)

Already a member?