Technical Discussion
  >> Apple Issues


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | 2 | 3 | 4 | 5 | >> (show all)   Print Thread
Standard User deleted
(deleted) Thu 19-May-11 20:28:04
Print Post

Fake MacDefender Warning.


[link to this post]
 
Fake MacDefender / Mac Security.

ALL SAFE HERE. wink

Edited by deleted (Thu 19-May-11 20:34:31)

Standard User deleted
(deleted) Thu 19-May-11 21:09:26
Print Post

Re: Fake MacDefender Warning.


[re: deleted] [link to this post]
 
Gullible people will install anything. Doesn't matter what computer they own.
Standard User ian_c
(eat-sleep-adslguide) Fri 20-May-11 00:05:50
Print Post

Re: Fake MacDefender Warning.


[re: deleted] [link to this post]
 
Although I see Ed Bott is really determined to make a name for himself.


Register (or login) on our website and you will not see this ad.

Standard User deleted
(deleted) Fri 20-May-11 12:34:50
Print Post

Re: Fake MacDefender Warning.


[re: ian_c] [link to this post]
 
Yup. ooo
Standard User deleted
(deleted) Fri 20-May-11 12:43:06
Print Post

Re: Fake MacDefender Warning.


[re: ian_c] [link to this post]
 
Quite ironic given his blog seems to be mostly about fixing up Windows to get it to run properly.
Standard User ian_c
(eat-sleep-adslguide) Fri 20-May-11 23:21:51
Print Post

Re: Fake MacDefender Warning.


[re: deleted] [link to this post]
 
Excellent write-up from Ars:

http://arstechnica.com/apple/news/2011/05/malware-on...

Standard User deleted
(deleted) Wed 25-May-11 14:00:10
Print Post

Re: Fake MacDefender Warning.


[re: deleted] [link to this post]
 
http://www.theregister.co.uk/2011/05/25/apple_acknow...
Standard User deleted
(deleted) Wed 25-May-11 14:38:27
Print Post

Re: MacDefender Warning.


[re: deleted] [link to this post]
 
Ooh-Err.. ooo

Subject line duly changed. Thanks for the update John.
Standard User ian_c
(eat-sleep-adslguide) Wed 25-May-11 14:55:58
Print Post

Re: MacDefender Warning.


[re: deleted] [link to this post]
 
http://support.apple.com/kb/HT4650

From the horses mouth.

Standard User deleted
(deleted) Wed 25-May-11 20:50:46
Print Post

Re: MacDefender Warning.


[re: ian_c] [link to this post]
 
If the malware has been installed, we recommend the following actions:

- Do not provide your credit card information under any circumstances.
laugh
Standard User deleted
(deleted) Thu 26-May-11 11:23:33
Print Post

Re: Fake MacDefender Warning.


[re: deleted] [link to this post]
 
Now it doesn't require an Administrator password. It looks like OS X is beginning to catch up with Windows.
Standard User ian_c
(eat-sleep-adslguide) Thu 26-May-11 19:51:20
Print Post

Re: Fake MacDefender Warning.


[re: deleted] [link to this post]
 
In reply to a post by AEP:
Now it doesn't require an Administrator password. It looks like OS X is beginning to catch up with Windows.
God lord. You really don't mind making yourself look retarded. Seriously, don't you dare play the "getting personal" card - that really was spectacularly dimwitted thing to post. Trolling, pure and simple.

Lets see what an actual security expert says:

Miller noted that Microsoft recently pointed out that 1 in 14 downloads on Windows are malicious. And the fact that there is just one piece of Mac malware being widely discussed illustrates how rare malware still is on the Mac platform, he said...."Mac malware is still relatively rare, but is getting worse," Miller said. "At some point soon, the scales will tip to installing antivirus, but at this point, I don't think it's worth it yet for most people."


Standard User deleted
(deleted) Thu 26-May-11 20:20:06
Print Post

Re: Fake MacDefender Warning.


[re: ian_c] [link to this post]
 
I'm merely repeating what an article in Ars Technica reported. I made no comment of my own about it.
You really don't mind making yourself look retarded.
Why do you always have to resort to these pathetic insults? Are you so unable to take part in rational discussion? You really shouldn't take it so personally that there is now malware in the wild for OS X.

Lets see what an actual security expert says:
Mac malware is still relatively rare, but is getting worse.
Comparisons with Windows are irrelevant; we're talking about OS X here, not Windows. The fact is that, as the "actual security expert" says, malware is now a reality on OS X and is only going to get worse. Welcome to the real world.

Now, can we please try to keep the discussion on a sensible level and avoid the childish insults please.
Standard User stniuk
(committed) Sat 28-May-11 11:47:27
Print Post

Re: Fake MacDefender Warning.


[re: deleted] [link to this post]
 
Mac Malware was always a reality, there just was very little of it about. Anyone that can programme a computer can produce an application that pretends to be anything and because people are naive they may install it.
It's up people to be very careful what they download and what they install and it's up to Apple to help prevent people from doing this by educating them and stopping the worse effects of Malware in osx.

This is not like a virus were people unknowingly in most cases contract a virus from an email or web site this needs to have the user install or at least download and run the programme. There is a huge difference.

The security software industry is busting for a mac virus or malware. They make millions or even billions each year from the mess Microsoft has created and the market is saturated, they need new markets....
Standard User deleted
(deleted) Wed 01-Jun-11 08:23:45
Print Post

Re: Fake MacDefender Warning.


[re: stniuk] [link to this post]
 
Security Update 2011-003 now available via software Update, see http://support.apple.com/kb/HT4657

Quick install, no restart
Moderator billford
(moderator) Wed 01-Jun-11 08:37:40
Print Post

Re: Fake MacDefender Warning.


[re: deleted] [link to this post]
 
It also adds an extra item under SysPrefs => Security on the General tab:

Automatically update safe downloads list

Checked by default.

~~~~~~~~~~~~
Bill

[email protected] _______________Planes and Cars and ..._______________BQM & Speed
The author of the above post is a thinkbroadband moderator but it does not constitute an official statement on behalf of thinkbroadband.
Standard User goldenoldie
(knowledge is power) Wed 01-Jun-11 08:54:18
Print Post

Re: Fake MacDefender Warning.


[re: billford] [link to this post]
 
This is not a good thing surely Bill ?

-------x-------x-------x-------x-------x-------x-------x-------x-------x-------x
If a thing ain't broke --- DON'T FIX IT
Experienced in making a mess of things smile
2 x MacBook Pro on OSX 10.6.4 ,Belkin N Wireless Router , [ sssh - and a PC wired lappy using XP Pro ] all on Virginmedia 20meg
Moderator billford
(moderator) Wed 01-Jun-11 09:04:01
Print Post

Re: Fake MacDefender Warning.


[re: goldenoldie] [link to this post]
 
I'm not sure... there's some more information about it here:

http://support.apple.com/kb/HT4651

I've left it checked for the moment, if it gets in my way I'll uncheck it.

~~~~~~~~~~~~
Bill

[email protected] _______________Planes and Cars and ..._______________BQM & Speed
The author of the above post is a thinkbroadband moderator but it does not constitute an official statement on behalf of thinkbroadband.
Standard User ian_c
(eat-sleep-adslguide) Wed 01-Jun-11 09:53:45
Print Post

Re: Fake MacDefender Warning.


[re: billford] [link to this post]
 
I believe the safe list is just a text file - can't imagine it getting in the way of anything. Haven't checked but I imagine updates to whatever engine is used will still come via Software Update.

I can think of no compelling reason to uncheck it.

Standard User ian_c
(eat-sleep-adslguide) Wed 01-Jun-11 09:54:36
Print Post

Re: Fake MacDefender Warning.


[re: deleted] [link to this post]
 
Comparisons with Windows are irrelevant;
Yet, oddly, you felt the need to make one.

Moderator billford
(moderator) Wed 01-Jun-11 09:59:36
Print Post

Re: Fake MacDefender Warning.


[re: ian_c] [link to this post]
 
In reply to a post by ian_c:
I imagine updates to whatever engine is used will still come via Software Update.
The support document I linked to suggests that it's just for Safari, iChat, Mail etc, not any of the virus scanners, and the implication is that it's automatic and daily whereas Software Update can be configured. Not that it matters much smile
I can think of no compelling reason to uncheck it.
Nor can I really, I just don't like computers doing something without asking first tongue

~~~~~~~~~~~~
Bill

[email protected] _______________Planes and Cars and ..._______________BQM & Speed
The author of the above post is a thinkbroadband moderator but it does not constitute an official statement on behalf of thinkbroadband.
Standard User ian_c
(eat-sleep-adslguide) Wed 01-Jun-11 10:21:41
Print Post

Re: Fake MacDefender Warning.


[re: billford] [link to this post]
 
The support document I linked to suggests that it's just for Safari, iChat, Mail etc, not any of the virus scanners

Well, yeah - it's checking for Trojans and that tends to be where they come via. A text file will have the defs and needs routine updating (a tweak of MacDefender would be easy enough to add, say).

Whatever bit of OSX does the processing will need less regular patching, as new *approaches* to malware are discovered.

Standard User goldenoldie
(knowledge is power) Wed 01-Jun-11 10:22:35
Print Post

Re: Fake MacDefender Warning.


[re: billford] [link to this post]
 
Bill - you are the same as me - I prefer to see what's there before I actually download/ install it .

Mousing over it shows << checks daily for updates to the safe downloads malware detection signature list and installs new signatures if they are available >>

Looks as if it should be OK - but does anyone have any real knowledge of it ?

-------x-------x-------x-------x-------x-------x-------x-------x-------x-------x
If a thing ain't broke --- DON'T FIX IT
Experienced in making a mess of things smile
2 x MacBook Pro on OSX 10.6.4 ,Belkin N Wireless Router , [ sssh - and a PC wired lappy using XP Pro ] all on Virginmedia 20meg
Standard User ian_c
(eat-sleep-adslguide) Wed 01-Jun-11 10:29:16
Print Post

Re: Fake MacDefender Warning.


[re: goldenoldie] [link to this post]
 
You realise this list has been in OSX since Leopard?

The only change is that it gets updated as needed, rather than when Apple gets round to it.

Moderator billford
(moderator) Wed 01-Jun-11 10:32:27
Print Post

Re: Fake MacDefender Warning.


[re: goldenoldie] [link to this post]
 
In reply to a post by goldenoldie:
Bill - you are the same as me - I prefer to see what's there before I actually download/ install it .
To be fair it's usually a matter of "when" rather than "what"- I don't think I've ever declined an update, for example1.

But I've delayed quite a few until a more convenient time, especially those that require a restart!



1 eta- not for the OS anyway, I've declined a few for 3rd party applications if they weren't useful to me.

~~~~~~~~~~~~
Bill

[email protected] _______________Planes and Cars and ..._______________BQM & Speed

Edited by billford (Wed 01-Jun-11 10:42:10)

The author of the above post is a thinkbroadband moderator but it does not constitute an official statement on behalf of thinkbroadband.
Standard User deleted
(deleted) Wed 01-Jun-11 13:20:58
Print Post

Re: Fake MacDefender Warning.


[re: deleted] [link to this post]
 
There's a long way to go before it catches up with Windows.

I believe much of the problem is due to people logging in with an admin account. That's pretty dumb on any OS.

I don't think Apple marketing has ever claimed OSX was impossible to write a virus for, they just listed the amount of viruses known for each platform. On Windows it was in the tens of thousands.

I guess the criminals have realised that Mac owners have more money to steal.
Standard User deleted
(deleted) Thu 02-Jun-11 11:54:28
Print Post

That didn't take long!


[re: deleted] [link to this post]
 
Link.
Standard User deleted
(deleted) Thu 02-Jun-11 11:56:29
Print Post

Re: Fake MacDefender Warning.


[re: ian_c] [link to this post]
 
No I didn't. Your "actual security expert" did.
Moderator billford
(moderator) Thu 02-Jun-11 11:59:57
Print Post

Re: That didn't take long!


[re: deleted] [link to this post]
 
In reply to a post by AEP:
Link.
Good grief, a malware author modifies his product to evade detection... what is the world coming to frown

~~~~~~~~~~~~
Bill

[email protected] _______________Planes and Cars and ..._______________BQM & Speed
The author of the above post is a thinkbroadband moderator but it does not constitute an official statement on behalf of thinkbroadband.
Standard User deleted
(deleted) Thu 02-Jun-11 12:04:13
Print Post

Re: That didn't take long!


[re: billford] [link to this post]
 
Exactly.

What will be more interesting is to see how quickly Apple respond. That's the game nowadays.
Moderator billford
(moderator) Thu 02-Jun-11 12:12:53
Print Post

Re: That didn't take long!


[re: deleted] [link to this post]
 
"Quickly" is a comparative term... what would you use for your reference?

~~~~~~~~~~~~
Bill

[email protected] _______________Planes and Cars and ..._______________BQM & Speed
The author of the above post is a thinkbroadband moderator but it does not constitute an official statement on behalf of thinkbroadband.
Standard User deleted
(deleted) Thu 02-Jun-11 12:19:42
Print Post

Re: That didn't take long!


[re: billford] [link to this post]
 
Microsoft would be a good reference point. Or any of the big anti-virus firms. The one that we used to use at work (F-Secure) typically took about 12 hours maximum to publish a data fix for a new piece of malware - we used to update the central definition file from them every two hours.

Still not quick enough - I've seen new malware reach our systems before the definitions were updated, but other more generic features of the software were sufficient to block them.
Standard User ian_c
(eat-sleep-adslguide) Thu 02-Jun-11 13:29:31
Print Post

Re: Fake MacDefender Warning.


[re: deleted] [link to this post]
 
In reply to a post by AEP:
No I didn't. Your "actual security expert" did.
Read your own posts, muppet:

http://forums.thinkbroadband.com/mac/t/4005566-re-fa...

Standard User ian_c
(eat-sleep-adslguide) Thu 02-Jun-11 14:36:11
Print Post

Re: That didn't take long!


[re: billford] [link to this post]
 
In reply to a post by billford:
"Quickly" is a comparative term... what would you use for your reference?
How about "by now" (patch out - will be picked up in next safe download check (or last one, depending on when yours runs).

Moderator billford
(moderator) Thu 02-Jun-11 14:45:02
Print Post

Re: That didn't take long!


[re: ian_c] [link to this post]
 
Seems quick enough to me, though some may beg to differ.

Any idea how can you check when/whether an update has been collected? Software update shows nothing, and I can't see anything in the system log.

~~~~~~~~~~~~
Bill

[email protected] _______________Planes and Cars and ..._______________BQM & Speed
The author of the above post is a thinkbroadband moderator but it does not constitute an official statement on behalf of thinkbroadband.
Standard User ian_c
(eat-sleep-adslguide) Thu 02-Jun-11 17:59:19
Print Post

Re: That didn't take long!


[re: billford] [link to this post]
 
Nothing obvious. I think Apple's policy is to be non-drama-queeny about it.

A process called xProtect runs and phones Apple Towers, but the only reason I know is Little Snitch alerting me. If the check box is checked, it is automatic. Basically, as long as you are on the Net you will be up-to-date within 24 hours max.

After a bit I will just tell LS to let it through, but I like to watch stuff for a few iterations before I do that (that approach also showed just how often Google s/w phones home!).

Moderator billford
(moderator) Thu 02-Jun-11 18:15:17
Print Post

Re: That didn't take long!


[re: ian_c] [link to this post]
 
Thanks smile

I found an entry for xProtect in the system log at just before 9am, but unfortunately it was an "Unable to connect" error- it had chosen to phone home whilst I was re-booting the router crazy

Sod's Law rules...

I'll have another look tomorrow.

~~~~~~~~~~~~
Bill

[email protected] _______________Planes and Cars and ..._______________BQM & Speed
The author of the above post is a thinkbroadband moderator but it does not constitute an official statement on behalf of thinkbroadband.
Standard User ian_c
(eat-sleep-adslguide) Thu 02-Jun-11 21:32:28
Print Post

Re: That didn't take long!


[re: billford] [link to this post]
 
it had chosen to phone home whilst I was re-booting the router

Ha ha! Typical.

Standard User ian_c
(eat-sleep-adslguide) Fri 03-Jun-11 18:38:05
Print Post

Re: That didn't take long!


[re: billford] [link to this post]
 
And this, if you wish to force an update:

http://www.tuaw.com/2011/06/03/force-your-mac-to-upd...

(As far as I can see, a simple uncheck and re-check forces it.)

Standard User deleted
(deleted) Fri 03-Jun-11 18:44:30
Print Post

Re: That didn't take long!


[re: ian_c] [link to this post]
 
Mine says it last updated at 00:13:07 GMT today, and it's at version 3.
Standard User TheHorseman
(knowledge is power) Fri 03-Jun-11 20:20:30
Print Post

Re: That didn't take long!


[re: ian_c] [link to this post]
 
In reply to a post by ian_c:
A process called xProtect runs and phones Apple Towers, but the only reason I know is Little Snitch alerting me. If the check box is checked, it is automatic. Basically, as long as you are on the Net you will be up-to-date within 24 hours max.

Can you see xProtect running in Activity Monitor? or from a 'ps ax' in the terminal as I can't see any such process (...and yes I have installed the update).

BT -> Zen -> F2S -> Bulldog -> Be* -> BT Infinity
Far too many computers, 1 Wife, 3 Maine Coons and too many horses smile
Moderator billford
(moderator) Fri 03-Jun-11 20:46:56
Print Post

Re: That didn't take long!


[re: ian_c] [link to this post]
 
In reply to a post by ian_c:
(As far as I can see, a simple uncheck and re-check forces it.)
Yes, so will a re-start.

I discovered one thing- if the computer is in sleep mode when update time comes around, it won't try again when it wakes up.

Could be a nuisance if you somehow get the update time set to the wee small hours!

~~~~~~~~~~~~
Bill

[email protected] _______________Planes and Cars and ..._______________BQM & Speed
The author of the above post is a thinkbroadband moderator but it does not constitute an official statement on behalf of thinkbroadband.
Standard User deleted
(deleted) Fri 03-Jun-11 21:03:44
Print Post

Re: That didn't take long!


[re: TheHorseman] [link to this post]
 
XProtect operates by modifying the file type detection process, deep in the file system itself. See http://ithreats.net/2010/06/19/about-mac-os-x-v10-6-...

Basically, each file that is written by the OS is checked to see if it meets certain criteria. If it does, its metadata is tagged with a corresponding file type. Most file types are just those that relate files to specific applications, but the XProtect extension adds tags for files that should be quarantined.

Note the comment at the end of the above post. Since XProtect is only triggered by a file save action, it will not detect a pre-existing copy of a malware file, already running on your system. Apple may have moved forward on this since the post was written a year ago, since they need to deal with users with MacDefender already installed. But that may use a different process from XProtect itself.

So you won't see a separate process running, because it's done by the file I/O kernel itself.

XProtectUpdater is the process that calls home and gets the new version of the protection system signatures. It is called by launchctl - the Apple replacement for cron - and the entry that controls it is at /System/Library/LaunchDaemons/com.apple.xprotectupdater.plist, which runs /usr/libexec/XProtectUpdater when it is first installed, and then every 86400 seconds thereafter, (24 hours). So it is launched on a schedule, updates the signature file, and then shuts down again.
Standard User deleted
(deleted) Fri 03-Jun-11 21:06:06
Print Post

Re: That didn't take long!


[re: billford] [link to this post]
 
In reply to a post by billford:
I discovered one thing- if the computer is in sleep mode when update time comes around, it won't try again when it wakes up.

Could be a nuisance if you somehow get the update time set to the wee small hours!

I'm surprised. Normally, a process controlled by launchctl will run the next time it can if the computer is asleep at the scheduled time. That's how all the other routine maintenance processes operate to rotate logs etc.
Moderator billford
(moderator) Fri 03-Jun-11 21:09:24
Print Post

Re: That didn't take long!


[re: deleted] [link to this post]
 
In reply to a post by AlanH:
I'm surprised.
I was too, but that's what (didn't) happen this morning, or tonight when I got back home.

It's only one instance so maybe something else interfered, but it might be worth keeping an eye on.

~~~~~~~~~~~~
Bill

[email protected] _______________Planes and Cars and ..._______________BQM & Speed
The author of the above post is a thinkbroadband moderator but it does not constitute an official statement on behalf of thinkbroadband.
Standard User TheHorseman
(knowledge is power) Fri 03-Jun-11 21:23:43
Print Post

Re: That didn't take long!


[re: deleted] [link to this post]
 
Ta, I was curious as I can see no mention of xProtect in the system log file and it had not updated itself today. I did the check/uncheck in the system prefs to prod it. The iMac is left on so I would have expected it to get the update.

BT -> Zen -> F2S -> Bulldog -> Be* -> BT Infinity
Far too many computers, 1 Wife, 3 Maine Coons and too many horses smile
Pages in this thread: 1 | 2 | 3 | 4 | 5 | >> (show all)   Print Thread

Jump to