image
image

Go Back   macosx.com > Mac Help Forums > Mac OS X System & Mac Software

Reply
 
Thread Tools
  #1  
Old April 8th, 2004, 04:43 PM
bobw's Avatar
The Late: SuperMacMod
 
Join Date: Mar 2001
Location: Phila,PA
Posts: 8,835
Thanks: 0
Thanked 5 Times in 1 Post
bobw has a spectacular aura aboutbobw has a spectacular aura about
Os X Trojan

INTEGO SECURITY ALERT

Intego Announces Protection against the First Mac OS X Trojan Horse: MP3Concept

Paris, France: 4:15pm, April 8, 2004 – Intego, the Macintosh security specialist, has just released updated virus definitions for Intego VirusBarrier to protect Mac users against the first Trojan horse that affects Mac OS X. This Trojan horse, MP3Concept (MP3Virus.Gen), exploits a weakness in Mac OS X where applications can appear to be other types of files.

The Trojan horse's code is encapsulated in the ID3 tag of an MP3 (digital music) file. This code is in reality a hidden application that can run on any Macintosh computer running Mac OS X.

Mac OS X displays the icon of the MP3 file, with an .mp3 extension, rather than showing the file as an application, leading users to believe that they can double-click the file to listen to it. But double clicking the file launches the hidden code, which can damage or delete files on computers running Mac OS X, then iTunes to play the music contained in the file, to make users think that it is really an MP3 file . While the first versions of this Trojan horse that Intego has isolated are benign, this technique opens the door to more serious risks.

This Trojan horse has the potential to do any of the following:
- Delete all of a user's personal files
- Send an e-mail message containing a copy of itself to other users
- Infect other MP3, JPEG, GIF or QuickTime files

Due to the use of this technique, users can no longer safely double-click MP3 files in Mac OS X. This same technique could be used with JPEG and GIF files, though no such cases of infected graphic files have yet been seen.

Intego VirusBarrier eradicates this Trojan horse, and Intego remains diligent to ensure that VirusBarrier will also eradicate any future viruses that may try to exploit this same technique. All Intego VirusBarrier users should make sure that their virus definitions are up to date by using the NetUpdate preference pane in the Mac OS X System Preferences.

http://www.intego.com/news/pr40.html
__________________

Reply With Quote
  #2  
Old April 8th, 2004, 05:00 PM
brianleahy's Avatar
Colonel Panic
 
Join Date: Sep 2000
Location: Northern Ohio
Posts: 1,579
Thanks: 0
Thanked 0 Times in 0 Posts
brianleahy is on a distinguished road
It was only a matter of time, sad to say.
__________________
OS X 10.4
G5 Dual 2GHZ / 160GB / 1GB RAM / Superdrive
Apple 20" Cinema Display
SmartDrive 120GB Firewire HD
Maxtor 250GB SATA


Visit my wife's eBay store !!

http://stores.ebay.com/Catchy-Creations-by-brendaonline

Now pining for a MacBook Pro...
Reply With Quote
  #3  
Old April 8th, 2004, 05:04 PM
Giaguara's Avatar
Chmod 760
 
Join Date: Nov 2002
Location: ~
Posts: 7,734
Thanks: 2
Thanked 22 Times in 22 Posts
Giaguara is a jewel in the roughGiaguara is a jewel in the roughGiaguara is a jewel in the rough
I wonder if RIAA paid to develop that trojan. It would suit RIAA's needs .. making people scared of downloading [unpaid] music.
__________________
MacBook Pro + Mac mini | Newton 2000 | @Work : Dell D620 & 2x20" + a lot of Macs | Workstation, VC & Fusion
Twenty years from now you will be more disappointed by the things that you didn't do than by the ones you did do.
~ Samuel Clemens | Rants | Photos
Reply With Quote
  #4  
Old April 8th, 2004, 05:06 PM
chevy's Avatar
Leopardo Da Vinci
 
Join Date: Nov 2001
Location: Inside the black box, CH
Posts: 3,829
Thanks: 0
Thanked 0 Times in 0 Posts
chevy is on a distinguished road
This is a real stupid troyan ! But if it works... It's like the .pif files of PCs.
__________________
My current machine is an iMac Core 2 Duo 2.16 GHz 24" with MacOS X 10.5. My Apples are here. My oldest Apple was born in 1977.
GS/P/>SS d-(++) s+: a+ C+(C) U* P L+ E--- W++ N- o+ K? w O-- M++ V PS+ PE+ Y- PGP t+ 5 X+ R tv-- b+++ DI++ D+ G e+++ h---- r+++ y?
Time is not changing, I'm just traveling through time.
Reply With Quote
  #5  
Old April 8th, 2004, 05:07 PM
Giaguara's Avatar
Chmod 760
 
Join Date: Nov 2002
Location: ~
Posts: 7,734
Thanks: 2
Thanked 22 Times in 22 Posts
Giaguara is a jewel in the roughGiaguara is a jewel in the roughGiaguara is a jewel in the rough
Wow, google finds nothing with MP3Virus.Gen.
__________________
MacBook Pro + Mac mini | Newton 2000 | @Work : Dell D620 & 2x20" + a lot of Macs | Workstation, VC & Fusion
Twenty years from now you will be more disappointed by the things that you didn't do than by the ones you did do.
~ Samuel Clemens | Rants | Photos
Reply With Quote
  #6  
Old April 8th, 2004, 05:21 PM
Giaguara's Avatar
Chmod 760
 
Join Date: Nov 2002
Location: ~
Posts: 7,734
Thanks: 2
Thanked 22 Times in 22 Posts
Giaguara is a jewel in the roughGiaguara is a jewel in the roughGiaguara is a jewel in the rough
more: "First its an application that you must run by yourself. Second its a CFM application so it needs its resource fork, creater fork and file type to run.
You'd have to download this thing encoded in a format such as a Stuffit archive and the double click it to run. Basically you'd need to be pretty stupid."

http://groups.google.com/groups?hl=e...of.s%20e#link6 has some interesting stuff about the virus too.


http://apple.slashdot.org/comments.p...ad&cid=8808749 - one guy downloaded the file (link of google..) and tried to open it. panther (10.3) does not allow to open it anyway.

more on
__________________
MacBook Pro + Mac mini | Newton 2000 | @Work : Dell D620 & 2x20" + a lot of Macs | Workstation, VC & Fusion
Twenty years from now you will be more disappointed by the things that you didn't do than by the ones you did do.
~ Samuel Clemens | Rants | Photos

Last edited by Giaguara; April 8th, 2004 at 05:41 PM.
Reply With Quote
  #7  
Old April 8th, 2004, 06:29 PM
chevy's Avatar
Leopardo Da Vinci
 
Join Date: Nov 2001
Location: Inside the black box, CH
Posts: 3,829
Thanks: 0
Thanked 0 Times in 0 Posts
chevy is on a distinguished road
Other files can also be infected... this comes from www.macbidouille.com, the French reference site on mac.
Attached Images
File Type: jpg VirusBarrier.jpg (42.9 KB, 52 views)
__________________
My current machine is an iMac Core 2 Duo 2.16 GHz 24" with MacOS X 10.5. My Apples are here. My oldest Apple was born in 1977.
GS/P/>SS d-(++) s+: a+ C+(C) U* P L+ E--- W++ N- o+ K? w O-- M++ V PS+ PE+ Y- PGP t+ 5 X+ R tv-- b+++ DI++ D+ G e+++ h---- r+++ y?
Time is not changing, I'm just traveling through time.
Reply With Quote
  #8  
Old April 8th, 2004, 09:09 PM
andychrist's Avatar
devil's plaything
 
Join Date: Nov 2003
Location: E.Vil.
Posts: 781
Thanks: 0
Thanked 0 Times in 0 Posts
andychrist is on a distinguished road
"...It was discovered today by antivirus software company Intego, which manufactures VirusBarrier, a security suite for the Mac.... Luckily, this trojan hasn't been released into the wild... Intego offers its VirusBarrier Mac-security software for $59.95..."

Hmm... Now if this trojan hasn't actually been released, how did Intego "discover" it?

What a scam.

Last edited by andychrist; April 8th, 2004 at 11:14 PM.
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump


All times are GMT -5. The time now is 10:43 AM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.