i Caramba!
By Davey Winder in Editorial
Posted in Uncategorized on
My Finnish friends at F-Secure have told me that their security research labs have taken delivery of a proof-of-concept sample for an AdWare application. Nothing particularly exciting or unusual about that, you might think, but if I tell you that it is an AdWare application that targets Mac OS X would you perhaps change your mind?
Bearing in mind, as a proof-of-concept code sample this is still in the realms of theoretical threat, there is no danger out in the wild. Yet. But given that it exploits a combination of the ease of use of a Mac and no Administrator rights in order to attach itself to your user account and then subsequently every application you use, that danger could be very real unless Apple do something drastic to fix the underlying weaknesses in OS X that allow a System Library to be installed without prompting the end user.
Sensibly, F-Secure are not revealing the precise methods used by the iAdware code, after all they are in the prevention not scare-mongering business (although it can often be a close call as far as security firms are concerned.) However, F-Secure did tell me that an Administrator could easily install iAdware globally for every user, as all it requires to do its stuff is Copy permissions. In their testing, the guys at the lab say the code sample managed to launch the Mac web browser client successfully for every application they used.
File under interesting rather than highly risky for now, but let it at least wipe the smug grin off the faces of the Apple Advocates who insist that their platform is impenetrable when it comes to such things. AdWare may not be a Windows based problem alone for very much longer…
Make a comment
Tag cloud
Archives
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
- August 2006
Most commented posts
- 80 percent of viruses love Windows 7
165 comments
- Has Microsoft gone mental?
- Has the US Army declared war on Windows 7?
- Cuil frozen out: market share drops to next to nothing
- Xbox 360 FAIL
- The 24GB RAM Desktop is born
- Use old version of Windows instead of Linux, says teacher
- Microsoft reveals time-based licensing model
- How Marblecake Hacked Time
- Nexus Two - The Next Generation
Highest Rated Blog Posts
- Why ecommerce fails (100%)
- Google Chrome stands alone at PWN2OWN (100%)
- Betting on Hubdub technology (100%)
- Has Google gone insane as GMail goes back to beta? (100%)
- Chinese whispers as government implicated in UK hack attacks (100%)
- Crimeware toolkit targets 10,000 trusted sites (100%)
- Black Hat risk to migrating VMs (100%)
- Tough on cyber crime, tough on the causes of cyber crime (100%)
- Firefox 3, Beta 4, Enhancements 900, Tested 5 (100%)
- Has the US Army declared war on Windows 7? (100%)

