Re: [botnets] mac trojan in-the-wild

2007-11-04 Thread Åsk Wäppling
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --I've been out looking for this trojan to see if I can find it, but have had no luck so far. Has anyone here seen it? I'd like a copy to dissect. cheers åsk ___ To report a botnet

Re: [botnets] mac trojan in-the-wild

2007-11-04 Thread PinkFreud
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --I've analyzed two variants of this trojan, procoded1000.dmg and ultracodec1000.dmg, provided to me by Chris (thanks, Chris!). These trojans basically consist of three scripts and a browser plugin (used by Safari / Firefox?

Re: [botnets] mac trojan in-the-wild

2007-11-04 Thread PinkFreud
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --Gadi already made the point that the significance of this lies in professional malware authors taking notice of Apple. If this trojan was written for, say, NetBSD, or perhaps ReactOS, I know *my* reaction would be the same -

Re: [botnets] mac trojan in-the-wild

2007-11-04 Thread Kyle Lutze
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- PinkFreud wrote: Gadi already made the point that the significance of this lies in professional malware authors taking notice of Apple. If this trojan was written for, say, NetBSD, or perhaps ReactOS, I know *my* reaction

Re: [botnets] mac trojan in-the-wild

2007-11-04 Thread James Pleger
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --You are beating a dead horse here. The point of this whole thing was to say that HEY, they are targeting a new platform other than windows. Not that it requires user interaction to install it. Honestly, think about it... this

Re: [botnets] mac trojan in-the-wild

2007-11-04 Thread Kyle Lutze
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- James Pleger wrote: You are beating a dead horse here. yeah, I just noticed while going through more e-mails that there is another thread where this topic was being beaten. Not much more need for discussion on this trojan

Re: [botnets] mac trojan in-the-wild

2007-11-04 Thread Jim O'Gorman
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --On 11/4/07, Kyle Lutze [EMAIL PROTECTED] wrote: What makes me unhappy is that people are using an SE exploit as a way to say here's proof that a mac is as insecure as a windows box or gadi saying the itw barrier has been

Re: [botnets] mac trojan in-the-wild

2007-11-04 Thread Tom
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- At 9:35 AM -0500 11/3/07, Dave Ellingsberg wrote: This is not so much a SE issue as it is a pure of heart issue. For way too long the Mac has been invincible, I can click on anything, you can not hurt me! This adds to the

Re: [botnets] mac trojan in-the-wild

2007-11-04 Thread Steven Adair
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- On Sat, 3 Nov 2007 13:54:44 -0400, Mr. X [EMAIL PROTECTED] wrote: To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Dude, you gotta get over yourself. The fact that the mac os x operating system

Re: [botnets] mac trojan in-the-wild

2007-11-04 Thread Gadi Evron
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- On Sun, 4 Nov 2007, Steven Adair wrote: On Sat, 3 Nov 2007 13:54:44 -0400, Mr. X [EMAIL PROTECTED] wrote: To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Dude, you gotta get over yourself. The fact

Re: [botnets] mac trojan in-the-wild

2007-11-03 Thread Tom
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- (Sorry on Digest) Hey all give it a break. You want to discuss this/ make a big deal about it then categorize it as a social engineering issue that occurs against not only any software platform but in most real life scams

Re: [botnets] mac trojan in-the-wild

2007-11-03 Thread Gadi Evron
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- On Sat, 3 Nov 2007, Tom wrote: To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- (Sorry on Digest) Hey all give it a break. You want to discuss this/ make a big deal about it then categorize it as

Re: [botnets] mac trojan in-the-wild

2007-11-03 Thread Tom
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- At 8:50 AM -0500 11/3/07, Gadi Evron wrote: On Sat, 3 Nov 2007, Tom wrote: To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- (Sorry on Digest) Hey all give it a break. You want to discuss this/ make a

Re: [botnets] mac trojan in-the-wild

2007-11-03 Thread Dave Ellingsberg
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- This is not so much a SE issue as it is a pure of heart issue. For way too long the Mac has been invincible, I can click on anything, you can not hurt me! This adds to the newbie issue as those buying into the gullible mac

Re: [botnets] mac trojan in-the-wild

2007-11-03 Thread Mr. X
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Dude, you gotta get over yourself. The fact that the mac os x operating system has no viruses is not the fault of the user base. And the tirades of the told-you-so's are petty and so OT let's just get back to info on

Re: [botnets] mac trojan in-the-wild

2007-11-03 Thread Jim O'Gorman
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --On 11/3/07, Gadi Evron [EMAIL PROTECTED] wrote: You really think a criminal group with revenue goals targets the mac to make some mac users feel unhappy? What is amusing about this whole situation is the Mac Defender

Re: [botnets] mac trojan in-the-wild

2007-11-03 Thread Randy Mueller
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Hey, Mac's just work! Right? It's going to get ugly. ___ To report a botnet PRIVATELY please email: [EMAIL PROTECTED] All list and server information are public and available to law

Re: [botnets] mac trojan in-the-wild

2007-11-01 Thread Jeremy Chatfield
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --Hi Gadi, I think you've gone a bit over the top here. I use Macs in preference to Windows because it reduces my system administration demands to tiny levels. I can focus on my business, not a blizzard of meaningless messages,

Re: [botnets] mac trojan in-the-wild

2007-11-01 Thread Gadi Evron
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- On Thu, 1 Nov 2007, Jeremy Chatfield wrote: snip correct stuff And this has, so far, little to do with botnets... Unless this SE attack is installing a bot. Is it? What does the bot do? Is there a signature? That'd be

Re: [botnets] mac trojan in-the-wild

2007-10-31 Thread Gadi Evron
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- On Wed, 31 Oct 2007, Joel Esler wrote: Um. Not only do you have to purposefully go download it, agree to accept the download, them agree to give the software admin priviledges. That's 3 accept dialogues and a password

Re: [botnets] mac trojan in-the-wild

2007-10-31 Thread Joel Esler
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- This is the dns thing right? -- Joel Esler Sent from the road. On Oct 31, 2007, at 10:06 PM, Gadi Evron [EMAIL PROTECTED] wrote: On Wed, 31 Oct 2007, Joel Esler wrote: Btw, not only is this the third peice of malware in

Re: [botnets] mac trojan in-the-wild

2007-10-31 Thread Eduardo Tongson
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- This is an SE type of malware. Codecs require installation so it needs root/admin privileges. On 11/1/07, Joel Esler [EMAIL PROTECTED] wrote: To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Btw, not

Re: [botnets] mac trojan in-the-wild

2007-10-31 Thread Hanz Makmur
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Yap. Social Engineering type of program is hard to deal with. I dont see this as big as the subject would like it to be. mac trojan in-the-wild. 'Wild' imho means out of control. SE program requires many clicks. To tame

Re: [botnets] mac trojan in-the-wild

2007-10-31 Thread g.rees-jones
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- but what if a user configured osx so that the administrator password does not need to be entered each time? Gadi Evron mailto:[EMAIL PROTECTED] wrote: To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --

Re: [botnets] mac trojan in-the-wild

2007-10-31 Thread Eduardo Tongson
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Comparing apples and oranges. If you want an equivalent Tiger and XP setup you have to run as a limited user in XP. If it is not obvious, SE type malware also requires Administrator privileges in XP. On 11/1/07, Hanz Makmur

Re: [botnets] mac trojan in-the-wild

2007-10-31 Thread Eduardo Tongson
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Then you have an OS X setup that is equivalent to a default XP setup where the user is running as Computer Administrator. Trojan slips through happily. On 11/1/07, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: To report a