Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » When is a NAT Router Not Enough? » Now that is
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« About time !!  
AuthorAll Replies


Sandman5
Premium
join:2002-07-10
Brookline, MO
clubs:

reply to Shamayim
Re: Security through obscurity

said by Shamayim See Profile:
said by Sandman5 See Profile:
S
Not sure if you knew, but just recently the first worm for OSX was released.

1. It's not a worm, it's a trojan.
2. Trojans are not self-replicating like worms.
3. It wasn't a real trojan even.. Just a 'proof of concept' ("see? theoretically it can be done.").
4. It wasn't "released." Nothing damaging to OSX was 'released.'
5. Classic case of FUD (Fear Uncertainty Doubt).


Yeah, thanks. That'll "learn" me to spout information that I didn't really read up on.

Though, I've always wondered what FUD meant.


Shamayim
I already have a Messiah.
Premium
join:2002-09-23

reply to Sandman5
said by Sandman5 See Profile:
S
Not sure if you knew, but just recently the first worm for OSX was released.

1. It's not a worm, it's a trojan.
2. Trojans are not self-replicating like worms.
3. It wasn't a real trojan even.. Just a 'proof of concept' ("see? theoretically it can be done.").
4. It wasn't "released." Nothing damaging to OSX was 'released.'
5. Classic case of FUD (Fear Uncertainty Doubt).

--
"tick...tick...tick..." »www.jtf.org/


wolfox
Gentle Wolfox

join:2002-11-27
Dunnellon, FL

reply to ThunderCorp
said by ThunderCorp See Profile:
i never believe in security by obscurity. i believe in security by inherent secure default settings (well written software + a good admin behind them).

Exactly. I run Outlook and MSIE and have never gotten an infection/system compromise via that vector. The *default* security settings are laughable at best. With a few well placed tweaks - problem solved. However, I did run one system overnight via a DMZ'd internal IP and it got whacked to shreds, it was running IIS FTP and some script kiddie tore it apart. That is another matter altogether, and a failed experiment.
--
Nothwest Arkansas' ONLY all Techno Radio Webcast, powered by SBC DSL!


ThunderCorp

join:2002-03-11
Chula Vista, CA

reply to Sandman5
McAfee's analysis of this so-called OS X Trojan:
The only mildly non-trivial discovery associated with this malware is that its author managed to combine a valid MP3 file and a PowerPC application in one file without violating any of the two file formats. That means the trojan is playable within iTunes as MP3 sound file and it can also be launched as a program by Finder. This works under MacOS 9 and OS X.
  However, dual personality of a file has little relevance to the malicious function. If a user is convinced to double click on an icon representing a file the program will run regardless of being a simple disguised application or dual-format file. Thus, the discovery of dual-format files does not really introduce any new penetration or propagation vector. It can only obfuscate a little the function of the disguised program, which will appear as a valid sound file and it can be played from iTunes.
  To achieve this dual personality of the file the PowerPC application (Type 'APPL', Creator = 'vMP3') is registered in the resource fork as 'cfrg' (code fragment) within the data fork. At the same time this data fork (with an ID3 record at the beginning of the MP3 file that holds the binary code) is a valid MP3 file image.
That, plus the fact that this "trojan" is easily killed just by sending it over the internet, which strips its executable code fork and renders it useless.


ThunderCorp

join:2002-03-11
Chula Vista, CA

reply to Sandman5
i never believe in security by obscurity. i believe in security by inherent secure default settings (well written software + a good admin behind them).

Oh, and to let you know, the OSX trojan isn't out in the wild and even if it was, it has an huge achilles heel that makes its existence a joke. Once you send it over the 'Net over any protocol its resource fork is stripped off, thereby making it useless. I guess you should know better than to trust an antivirus company about virus announcements (they're out to make money if they're losing it).

Even if the trojan got onto an OS X system intact, it can only affect the files in the current user's directory, since it cannot elevate to sudo permissions with a password. And, as you know, OS X ships with root OFF so even the admin users can't affect system files without sudo.


Sandman5
Premium
join:2002-07-10
Brookline, MO
clubs:
reply to ThunderCorp
So do you believe in security through obscurity or are those just your tools and you're pointing out that they are more secure?

Not sure if you knew, but just recently the first worm for OSX was released.
Forums » When is a NAT Router Not Enough?« About time !!  


Friday, 27-Nov 10:51:08 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [116] Time Warner Cable Fires Broadside At Broadcasters
· [109] New AT&T Ad Campaign Hits Back At Verizon
· [95] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [70] TiVo Sees Record Customer Losses
· [67] In-Flight Internet Headed For Bumpy Landing?
· [59] Thanksgiving Open Thread
· [38] ICANN Slams DNS Redirection
· [36] Senators Want ACTA Made Public
· [36] EFF Wages War On Fine Print
Most people now reading
· Newegg Black Friday Sale started [Users Find Hot Deals]
· Windows 7 boot manager editing questions [Microsoft Help]
· Not strictly "Home" related - but WOW anyways... [Home Repair & Improvement]
· SSD [Computer Hardware Discussion/Reviews]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Only firefox accesses Internet? [Security]
· Bell Response to PIPEDA Request [TekSavvy]
· Whats the big deal about being "Old School"....? [World of Warcraft]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]