New OS X “Trojan” In the Wild
By Daniel Miessler on November 1st, 2007: Tagged as Apple | OS X | Security

A new “trojan” has been identified by Intego that enables phishing attacks to take place against Mac users. But before you get too worried, let’s take a look at how it works.
- Go to a malicious site.
- Get prompted to install software.
- Choose to install it.
- Put in your admin password when it asks for it.
- Get pwned.
So basically a hostile, unknown website asks you to install software on your system with elevated privileges, and if you willfully go through the entire install process (including entering your administrator password) something bad will happen.
Scary.
In other news, if someone sends you an email that says to run sudo rm -rf / on the command line (and enter your admin password when it asks you to) — don’t do it. Interesting attack method — send someone malicious software and ask them to install it as administrator. The defense? Don’t install it.
Make no mistake — this is not the same kind of threat that we’ve faced in Windows over the years. That threat is very specifically the drive-by installation of software without the user knowing or having a chance to stop it.
In summary, this social-engineering-based attack requires a high level of interaction and it will have very little impact on the Mac user community.:
Related Content
- Vista’s Security Hobbled By Microsoft’s Own Insecure Past
- Installing the Latest Version of Nmap Using Subversion
- Vista Security A Joke? : Executables Install As Administrator Because It’s More Convenient
- Bruce On Two-Factor Authentication — And Why I Disagree
- From Password Reset Mechanisms to OpenID: A Brief Discussion of Online Password Security
Pingback: dblog-Tech News And Other Humorous And Frightening Things From Around The Web
Pingback: in medias res » The first OS X virus?