The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Wild trojan found

    Discussion in 'Apple and Mac OS X' started by gms238, Jun 20, 2008.

  1. gms238

    gms238 Notebook Consultant

    Reputations:
    8
    Messages:
    133
    Likes Received:
    0
    Trophy Points:
    30
  2. cdnalsi

    cdnalsi Food for the funky people

    Reputations:
    433
    Messages:
    1,605
    Likes Received:
    0
    Trophy Points:
    55
    Again we're talking about:

     
  3. Thibault

    Thibault Banned

    Reputations:
    1,079
    Messages:
    1,319
    Likes Received:
    2
    Trophy Points:
    55
    Regardless, it's still a threat and it's out there.
    So thanks to the OP for the news.
     
  4. Chrysaor

    Chrysaor Notebook Consultant

    Reputations:
    36
    Messages:
    172
    Likes Received:
    0
    Trophy Points:
    30
    This exploit can be placed in any installers preflight script to run, and you wouldn't even be aware of it. It is a serious vulnerability.

    To test if your system is vulnerable:
    Code:
    osascript -e 'tell app "ARDAgent" to do shell script "whoami"';
    Workaround fix for this is by removing the setuid bit in the ardagent.
     
  5. swarmer

    swarmer beep beep

    Reputations:
    2,071
    Messages:
    5,234
    Likes Received:
    0
    Trophy Points:
    205
    Well, yeah, that's what "trojan" means... something people are tricked into running.
     
  6. saturnotaku

    saturnotaku Notebook Nobel Laureate

    Reputations:
    4,879
    Messages:
    8,926
    Likes Received:
    4,707
    Trophy Points:
    431
    Can you provide more detailed instructions for doing this?
     
  7. Chrysaor

    Chrysaor Notebook Consultant

    Reputations:
    36
    Messages:
    172
    Likes Received:
    0
    Trophy Points:
    30
    Code:
    sudo chmod u-s /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent
    This removes the setuid bit in ardagent, that means it can't elevate permissions to root. If you execute the command I gave before it should return your username instead of root.
     
  8. saturnotaku

    saturnotaku Notebook Nobel Laureate

    Reputations:
    4,879
    Messages:
    8,926
    Likes Received:
    4,707
    Trophy Points:
    431
    Much obliged. Thanks.

    +rep
     
  9. jjahshik32

    jjahshik32 Notebook Deity

    Reputations:
    78
    Messages:
    1,333
    Likes Received:
    0
    Trophy Points:
    55
    Lol, this is old news. I remember this trojan back 2 years ago. Just dont use limewire and dont accept suspicious files via ichat from people you dont know and dont open it.
     
  10. Deifiic

    Deifiic Notebook Guru

    Reputations:
    16
    Messages:
    55
    Likes Received:
    0
    Trophy Points:
    15
    Well.. looks like it's time to jump ship. How's linux doing these days =p?

    /end sarcasm.

    Seriously though, thanks for the heads up.
     
  11. Gintoki

    Gintoki Notebook Prophet

    Reputations:
    2,886
    Messages:
    6,566
    Likes Received:
    0
    Trophy Points:
    205
    Linux is pretty alright, we don't really have any problems but it depends on what you want/need. ;)
     
  12. bmwrob

    bmwrob Notebook Virtuoso

    Reputations:
    4,591
    Messages:
    2,128
    Likes Received:
    0
    Trophy Points:
    55
    My guess is that Linux and OSX are about on an even level concerning malware. Neither system is popular enough in comparison with Windows for most hackers and thieves to bother wasting their time. Sooner or later though, both will probably be hit with crap from the jerks out there, unfortunately.
     
  13. Gintoki

    Gintoki Notebook Prophet

    Reputations:
    2,886
    Messages:
    6,566
    Likes Received:
    0
    Trophy Points:
    205
    But the difference is that Linux is open source, so as soon as a vulnerability is found there will be a fix as soon as possible. I'm not sure how well this goes for OSX though but i'm pretty sure it's about the same.
     
  14. masterchef341

    masterchef341 The guy from The Notebook

    Reputations:
    3,047
    Messages:
    8,636
    Likes Received:
    4
    Trophy Points:
    206
    i dont know.

    open source is great, but it doesn't necessarily mean that everything is going to get fixed immediately.

    in fact, open source development tends to be slower. the final products are usually high quality because the people who are making them do it out of their own enjoyment...

    but you can't spend every second of your life working on your hobby that generates nothing for you... i'm not sure how speedy the responses will be to security issues with linux...

    still- unix and linux are both designed around the concept of securing the kernal, so i think even in the long run they will be better off.
     
  15. talin

    talin Notebook Prophet

    Reputations:
    4,694
    Messages:
    5,343
    Likes Received:
    2
    Trophy Points:
    205
    I sincerely hope it stays that way. That would be my luck, finally switch to Mac, and have it become a haven for virii. :rolleyes:
     
  16. Gintoki

    Gintoki Notebook Prophet

    Reputations:
    2,886
    Messages:
    6,566
    Likes Received:
    0
    Trophy Points:
    205
    I'll have to disagree with you on this one and link to Linus's Law. It took a few days to patch the SSL security bug Debian had, try finding that same level of dedication with a Windows bug (i haven't used OSX so i don't have much experience with it besides what i read). With Windows you have to wait until SP1 or until MS decides to patch the flaw, I've heard that OSX is pretty fast but you can only pay a certain amount of people. While Apple may have 5,000 employees, Linux has over 1,000,000 developers who take the time to work on it.