BetaONE will rise again!


 
Prev Previous Post   Next Post Next
  #1  
Old 22nd Oct 04, 11:00 PM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 31,188
NewsBot will become famous soon enough
OS X and Malware
There's now a real virus out there for Mac OS X that can do some real damage. It doesn't seem to be too destructive although it does delete some UNIX commands and modifies prefs for a couple of others. It will gather all password info on your machine. For now, lets call it "Opener." My system was a responding a bit slowly and a check of my /var/log files showed that they were _all_ empty and had the same mod date. The Activity Monitor showed a process called "john" eating almost an entire processor.

Some further looking showed an unknown startupitem in /Library/StartupItems/ called "opener". The executable file is a well-commented bash program. It scans for passwords for every user, processes the hashed info using your own Mac, turns on file sharing, and puts all this stuff into an invisible folder called .info on each users Public folder. It does much, much more but it's important that a warning get out quickly.

Dave Taylor: You might notify people that the fastest way for them to see if they've had this little bugger show up is to run:
$ sudo ls -l /Users/*/Public/.infoA good result is:
ls: /Users/*/Public/.info: No such file or directoryIf you get anything else, it's time to pop into /Library/StartupItems and see what's in there.

News source: Neowin
Full story: View Here
Reply With Quote
 


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
OS X Malware? NewsBot NeoWin News 0 22nd Oct 04 10:00 PM


All times are GMT +1. The time now is 07:42 AM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.