Warning this article may contain opinions of the author that you and iTWire don't agree with.
Visit the last page to have your say in our forum.

No. 1 Story

Mobile operators get fixed price spectrum renewal in $3b Government windfall

The Government has offered Australia's three mobile operators, and vividwireless, renewal of their existing spectrum allocated on 15 year licences in the late 90s and early 2000s at set prices, while the Government expects to rake in $3 billion.

read more

Check that authentication dialog!

Opinion and Analysis

This trick isn't merely of academic interest - Pesoli went down this track after discovering that the recent Iservice (iWork Service) malware calls on the authorisation mechanism.

"The author of OSX.Iservice.B didn't go this far in that implementation, but the fact that the program already uses Authorization Services could mean he or she is already headed down this path," he noted.

So what's Symantec's recommendation? Cynical readers may be surprised, but there's no mention of running security software and keeping it up to date.

Instead, "From now on, we advise that Mac OS X users don't rely simply on familiar icons or messages from the authentication dialog box, but take an extra little step in order to verify the execution path of the program that is asking for the password. Furthermore, if we are prompted for a password by any Apple/clean/trusted application when we're not really expecting it, checking for any suspicious running processes would certainly help."

Mac malware seems to be on the increase, but it seems to rely on social engineering rather than silently exploiting underlying vulnerabilities.

Pesoli has shown how easy it is for the bad guys to incorporate real authentication dialogs to trick the unwary into granting rights to malware, so his call for extra care seems well-founded.

Fortunately, authentication dialogs don't normally appear very often, so there's no excuse for not stopping and thinking before you click OK.

Loading comments ...



Latest Listings - Australian IT Directory

  • Spotty Dog Computer Services
    We are located in Morayfield near Caboolture, halfway between Brisbane...
  • Boom
    We are Boom. We put our pants on just like the...
  • Network Overdrive
    Network Overdrive is the leading provider of Australia-wide Managed IT...
- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more