Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.
At least three unofficial fixes have been suggested. The idea that starting the Remote Management service (via the Sharing system preference) would provide protection was short lived, as it is too easy for an exploit to disable remote management and then restart it.
Removing the setuid bit for ARDAgent does block the exploit, but stops Remote Management working. This is therefore a simple way of avoiding the problem for machines that are never remotely administered (which is probably the majority of Macs in homes and small businesses).
Kou Man Tong, a Hong Kong based software developer, has suggested disabling AppleScript support in ARDAgent by editing its plist (property list).
He claims this prevents the exploit from working whether or not Remote Management is active, but without interfering with the normal use of Apple Remote Desktop for remote administration. However, the legitimate use of AppleScripts via Remote Management would also be blocked.
But if the privilege escalation exploit fails, the Trojan poses as a software update and asks the user to provide administrative login credentials, Sophos senior technology consultant Sean Richmond told iTWire.
So while cautious and sophisticated Mac users will no doubt feel as secure as they did before the discovery of the latest Trojans, those who manage computers used by colleagues or family members who take a more cavalier attitude to browsing and downloading may think again about the need for security software that can detect such malware.
David Bass
| For the fourth year in a row, IDC has placed content security provider Websense (NASDAQ: WBSN) at the top of the IDC Worldwide Web Security 2011 –…
How to Make Business Discovery Work for Your Business
Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more
Try an easy-to-use set of web-enabled
tools for business-class productivity services. Office 365 provides
anywhere-access to email, important documents, contacts, and calendars
on almost any device.