Warning this article may contain opinions of the author that you and iTWire don't agree with.
Visit the last page to have your say in our forum.

No. 1 Story

Telstra adds one million mobile services, but Sensis plummets

Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.

read more

Dastardly duo of Mac OS X Trojan threats on the loose in the wild

Opinion and Analysis

The other Trojan is known as Astht, short for AppleScriptTHT. The problem here is that the Apple Remote Desktop software (part of Mac OS X) can be tricked into executing code as root.

This works by telling ARDAgent to run an AppleScript that contains a shell script. Since ARDAgent runs as root, the shell script does too, so there's nothing to limit what it can do.

At least two variations of Astht have been detected in the wild. Their capabilities include keystroke logging, activating the iSight camera, taking screen shots, and turning on file sharing.

Symantec and other security vendors have issued advisories about Astht without describing its purported function.

An unofficial workaround to protect against Astht is to remove setuid from ARDAgent (eg,
sudo chmod -s /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent
), although this could interfere with legitimate use of Apple Remote Desktop for remote system administration.

Although these threats are Trojans and therefore rely on users running them (as opposed to nastier forms of malware that exploit software vulnerabilities to get their hooks into systems without user involvement),
they show that Mac OS X is getting more attention from the malware merchants. Sensible users will take these developments as a wake-up call, and review their security practices.

Loading comments ...



- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more