Become a part of the TranceAddict community!Frequently Asked Questions - Please read this if you haven'tSearch the forums
TranceAddict Forums > Local Scene Info / Discussion / EDM Event Listings > Canada > Canada - Toronto & Southern Ont. > The day has come ... AppleScript.THT: new virus for MAC OS X
  Last Thread   Next Thread
Share
Author
Thread    Post A Reply
E2EK1EL
Supreme tranceaddict



Registered: Nov 2001
Location: Toronto, Ontario
The day has come ... AppleScript.THT: new virus for MAC OS X

AppleScript.THT: new virus for MAC OS X

Posted on 22.06.2008 at 13:41 in Tech News by Martin

Security researchers reported last week that they’ve spotted a Mac Trojan horse in the wild that could compromise machines running Apple Inc.’s Mac OS X 10.4 or 10.5. SecureMac, a Mac-specific anti-virus vendor, posted an alert last Thursday that its researchers had found a Trojan horse, dubbed “AppleScript.THT,” being distributed from a hacker-operated site where discussions of spreading the malware via iChat, Apple’s instant messaging and video chat software, were also taking place. The company classified the threat posed by the Trojan as “critical.” The malware exploits a recently publicized vulnerability in the Apple Remote Desktop Agent (ARDAgent), part of Tiger’s and Leopard’s Remote Management component. Composed as a compiled AppleScript, or in another variant, script bundled into an application, the Trojan leverages the ARDAgent bug to gain full control of the victimized Mac.

“[It] allows a malicious user complete remote access to the system, can transmit system and user passwords, and can avoid detection by opening ports in the firewall and turning off system logging,” claimed SecureMac. “Additionally, the Trojan can log keystrokes, take pictures with the built-in Apple iSight camera, take screenshots, and turn on file sharing.” SecureMac’s warning came one day after an anonymous reader disclosed a few details of the ARDAgent vulnerability on Slashdot.org, and on the same day that rival security vendor Intego provided more information about the bug. Malicious AppleScript, said Intego, can call ARDAgent, which then gives that script full “root” access to the system. Like any Trojan horse, AppleScript.THT does not spread on its own but relies on user interaction, such as downloading and launching, to infect a machine. Trojans can also be silently introduced on a computer if it’s injected after a successful attack using another vulnerability, such as a browser bug.

Source: Computer World

Old Post Jun-29-2008 09:07  China
Click Here to See the Profile for E2EK1EL Click here to Send E2EK1EL a Private Message Add E2EK1EL to your buddy list Report this Post Reply w/Quote Edit/Delete Message
Prometheus Xex
Still alive.



Registered: Nov 2006
Location: The known universe.

Hmmm... according to Apple's commercials it's system is far too perfect for something like this to happen. Since they're always putting down every PC owner on the planet with those dam condescending commercials, then this report cannot be true... no?


___________________
GrooveENERGY Website
Me on Facebook

Old Post Jun-29-2008 19:42  Canada
Click Here to See the Profile for Prometheus Xex Click here to Send Prometheus Xex a Private Message Visit Prometheus Xex's homepage! Add Prometheus Xex to your buddy list Report this Post Reply w/Quote Edit/Delete Message
E2EK1EL
Supreme tranceaddict



Registered: Nov 2001
Location: Toronto, Ontario

Apple fixes 40 security holes in Mac OS X


Posted on 29.05.2008 at 10:45 in Tech News by Martin
Apple released a hefty security update for the Mac OS X and OS X Server on Wednesday that fixes more than 40 vulnerabilities, a number of which could be exploited to enable someone to run programs on the machine remotely or lead to the disclosure of sensitive data. Security Update 2008-003 is for Mac OS X v 10.4.11 and Mac OS X Server v 10.4.11. The fixes are included in the latest Leopard edition, Mac OS X v 10.5.3, which also was released on Wednesday. The software fixes vulnerabilities that could have led to arbitrary code execution and/or unexpected application termination related implemntaton of: AFP Server, AppKit, Apple Pixlet Video, ATS, CoreFoundation, CoreGraphics, Flash Player Plug-in, Help Viewer, and iCal. The iCal vulnerability was discovered by Core Security, which last week announced it had found three vulnerabilities in iCal.

It also fixes vulnerabilities that could have led to disclosure of sensitive information related to implementation of technologies including CUPS, International Components for Unicode, and CFNetwork when visiting a maliciously crafted Web site due to an issue in Safari’s SSL client certificate handling. In addition, the software fixes a vulnerability that could lead to information disclosure when viewing a maliciously crafted BMP or GIF image and lead to unexpected application termination or arbitrary code execution when viewing a maliciously crafted JPEG2000 image file. Security Update 2008-003 and Mac OS X v 10.5.3 are available from Apple’s Software Downloads Web site.

http://www.tranceaddict.com/forums/...threadid=476717

(All my sources are 100% confirmed)

Old Post Jun-29-2008 20:04  China
Click Here to See the Profile for E2EK1EL Click here to Send E2EK1EL a Private Message Add E2EK1EL to your buddy list Report this Post Reply w/Quote Edit/Delete Message
DigiNut
You kids get off my lawn!



Registered: Dec 2002
Location: Toronto, Self-proclaimed Centre of the Universe

We now turn to the angry mob gathering in front of us for comment. Sir, anything you'd like to add?

"LA LA LA LA LA I'M NOT LISTENING LA LA LA"

Uh huh, and how about you sir?

"Oh this is just such a crock of shit. You just know that Bill Gate$ wrote the stupid virus himself. FUCK YOU MICRO$OFT, YOU CAN'T FOOL US!"

According to Steve Jobs, an update is available that fixes the problem, available for $46,000 per processor, available in all Apple stores.

That's all for today.


___________________
My party schedule:
2009-02-21 - DJ Attention @ I'm So Popular
2009-06-18 - DJ Annoying @ People Need To Know Where I'll Be
2012-11-32 - DJ Insufferable ɸ Or At Least the Stalkers I Complain About
2048-06-66 - Spastic & Whocares Although I'm Actually Flattered
9999-45-81 - Tweaker Gimp I Probably Won't Even Go To This But I Have To Make Sure I Fill Up All The Available Space Here

Old Post Jun-29-2008 20:09  Canada
Click Here to See the Profile for DigiNut Click here to Send DigiNut a Private Message Add DigiNut to your buddy list Report this Post Reply w/Quote Edit/Delete Message

TranceAddict Forums > Local Scene Info / Discussion / EDM Event Listings > Canada > Canada - Toronto & Southern Ont. > The day has come ... AppleScript.THT: new virus for MAC OS X
Post New Thread    Post A Reply

 
Last Thread   Next Thread
Click here to listen to the sample!Pause playbackcome on guys, please ID this uplifting melody. will be easy for TAs! [2005] [0]

Click here to listen to the sample!Pause playbackY.A.G.O. - "Hard" [2002]

Show Printable Version | Subscribe to this Thread
Forum Jump:

All times are GMT. The time now is 22:25.

Forum Rules:
You may not post new threads
You may not post replies
You may not edit your posts
HTML code is ON
vB code is ON
[IMG] code is ON
 
Search this Thread:

 
Contact Us - return to tranceaddict

Powered by: Trance Music & vBulletin Forums
Copyright ©2000-2026, Jelsoft Enterprises Ltd.
Privacy Statement / DMCA
Support TA!