Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » When is a NAT Router Not Enough? » Now that is
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« About time !!  
AuthorAll Replies


ThunderCorp

join:2002-03-11
Chula Vista, CA

reply to Sandman5
Re: Security through obscurity

McAfee's analysis of this so-called OS X Trojan:
The only mildly non-trivial discovery associated with this malware is that its author managed to combine a valid MP3 file and a PowerPC application in one file without violating any of the two file formats. That means the trojan is playable within iTunes as MP3 sound file and it can also be launched as a program by Finder. This works under MacOS 9 and OS X.
  However, dual personality of a file has little relevance to the malicious function. If a user is convinced to double click on an icon representing a file the program will run regardless of being a simple disguised application or dual-format file. Thus, the discovery of dual-format files does not really introduce any new penetration or propagation vector. It can only obfuscate a little the function of the disguised program, which will appear as a valid sound file and it can be played from iTunes.
  To achieve this dual personality of the file the PowerPC application (Type 'APPL', Creator = 'vMP3') is registered in the resource fork as 'cfrg' (code fragment) within the data fork. At the same time this data fork (with an ID3 record at the beginning of the MP3 file that holds the binary code) is a valid MP3 file image.
That, plus the fact that this "trojan" is easily killed just by sending it over the internet, which strips its executable code fork and renders it useless.
Forums » When is a NAT Router Not Enough?« About time !!  


Sunday, 08-Nov 13:49:18 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [156] Cable Uncapper Faces Criminal Charges
· [140] AT&T Sues Verizon Over 3G Ads
· [112] Why Run Fiber When You Can Run Ads That Pretend You Do?
· [108] Comcast Is Simply Getting Huge
· [92] Apple Cooking Up New $30 A Month TV Service?
· [82] Bits Of ACTA Agreement Leaking Out
· [80] Will 'Three Strikes' Come To The United States?
· [78] Verizon To Double Smartphone ETFs?
· [76] Verizon: Droid Tethering Will Cost $30 Extra
· [73] Comcast, NBC Deal Almost Complete
Most people now reading
· Hit and run [General Questions]
· [NFL] Week 9 Games Thread [Sports Chat]
· [Need Info] Looking for backup software... [Software]
· Odd Memory Issue [Computer Hardware Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· NO ONE knows what's wrong with my line! [TekSavvy]
· Know when to run! [Home Repair & Improvement]