On TV.com: Vote for your favorite SEINFELD Scenes
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Feb 27, 2006 12:00:00 PM

Apple Computer fans have long loved to point out the safety of using Mac OS X, which has mostly been left alone by hackers. But the recent arrival of three threats has some asking: Is the software's charmed security life over?

In the past two weeks, a pair of worms that target Mac OS X have been discovered, along with an easily exploitable, severe security flaw. The vulnerability exposes Mac users to risks that are more familiar to Windows owners: the installation of malicious code through a bad Web site or e-mail.

While these threats represent a sea change, there is no need for Mac owners to worry, experts said, as the published attacks are still mainly theoretical and not widespread. But they caution that Apple fans should not be smug: Now that it's been done, other malicious code writers are likely to turn their attention to the operating system.

It's a "small step in malicious code development for OS X," said Kevin Long, an analyst at security specialist Cybertrust and a Mac user for 11 years. "The message we need to get out there is that Mac users should not be complacent."

While Microsoft Windows users have grown accustomed to a seemingly incessant stream of computer worms, viruses and security vulnerabilities, the same is not true for Mac owners. Going by forum postings, many Apple customers believe their systems are much better protected against cyberattacks than the average Windows PC.

"Mac malware is not a myth. It is very real," said Kevin Finisterre, a security researcher at Digital Munition. Finisterre created the Inqtana worm, which targets Mac OS X and spreads using an 8-month-old vulnerability in Apple's Bluetooth software. "My point with Inqtana was to say, 'Hey! Wake up!'" he said.

Finisterre did not release his worm into the wild. He created Inqtana only to prove a point and to encourage antivirus makers to update their products against malicious software using the same method of attack, he said. Furthermore, Inqtana was programmed so that it could never spread far.

"Go buy yourself some antivirus software, keep your Apple updates current and stop pretending that you are invincible, because you are not," Finisterre advised Mac users.

The risk for Apple system users grows slightly every day, Long said. The number of people using Macs is growing, which makes attacks more likely, he said. Some have suggested that Mac OS X's previous immunity to threats is due partly to malicious coders focusing on Microsoft products, which have a much larger user base and so bring a much bigger scope for impact.

"Many think that the Macintosh operating system is impervious to viruses or these kind of security threats. It is not that they are impervious; they are targeted less," said Craig Schmugar, virus research manager at McAfee.

'Don't freak out'
The events of the last two weeks could change that. Hackers have had their interest in Apple piqued, Finisterre said. "It is a semi-new frontier, so to speak," he said.

Even so, the incidents likely won't have any significant fallout, Long said. "Hopefully, the end result is that people are a little more careful. They don't need to freak out about this," he said.

Many Mac users seem unfazed.

"I don't see myself changing any habits or panicking and running out to grab antivirus," CNET News.com reader Shane Walker wrote in an e-mail. "I am concerned, but not overly so. You just need to take the right precautions, watch your e-mail attachments and what you download like a hawk, and try to avoid known or seemingly questionable sites."

Another CNET News.com reader, using the initials J.G., said the three incidents don't bother him. "They are 'proof of concept,' not actual malware loose in the wild," the reader wrote in an e-mail. "I think much of the attention now being focused on Macs and OS X will dissipate in a few months."

So far, there have been no reports of any Mac systems infected with the Inqtana worm. The other OS X security incidents have had little impact on people either, experts said. Leap.A, considered to be the first first Mac operating system worm, was publicly posted on an online Mac message board, but did not make it onto many computers.

The most serious incident was perhaps the public disclosure of a serious and easily exploitable flaw in the Apple operating system, which could be a conduit for intruders to install malicious code on computers running the software. Exploit code that takes advantage of the security hole was quickly posted on the Internet.

The problem lies in the way Mac OS X associates files with applications, and it could be exploited to hit a Mac via the Safari Web browser or Apple Mail, experts said. Apple has said it is working on a fix for the flaw. So far, no actual attacks that take advantage of the flaw have been reported as hitting users.

Easier to hit?
Overall, only a few currently known worms, viruses and Trojans target the Mac, McAfee's Schmugar said. Nevertheless, people should not ignore the danger. "There does not have to be more than 150,000 threats for Macs before it's a security concern," he said, referring to the number of known Windows pests.

A machine running Apple's operating system might actually be easier to hit than a Windows PC, Schmugar said. "There are fewer and less evolved defenses around a Mac, because there have been fewer threats against it," he said. "The success rate for getting malicious code to run is probably greater."

The Mac maker is taking measures to sew up the latest hole in its operating system. "Apple takes security very seriously," a company representative said. "We're working on a fix so that this doesn't become something that could affect customers." The representative could not say when the patch would be ready.

Long recommends two tweaks to the OS X settings to make it more secure: enabling the firewall and disabling the "open safe files after downloading" option in the Safari preferences. That last option, if not locked up, could be exploited to trick people into downloading malicious code onto their Macs, he said.

All in all, this is not significant enough to dent user confidence in Mac OS X as a secure operating system, said Ray Wagner, an analyst at Gartner. "Given that the most recent vulnerability does not spawn an attack before being patched--an unknown--there is not enough impact on the average user to cause a significant change in behavior," he said.

Apple is advising its customers to consult its online safety guide and to be cautious when surfing the Web. "Apple always advises Mac users to only accept files from vendors and Web sites that they know and trust," the company representative said.

Asked if the Mac, compared with Windows, is still the obvious safer choice for people on the Internet, Gartner's Wagner simply replied: "Yes."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 137 Talkback(s)
Same mechanism as Klez and Sircam on Windows
Those viruses took advantage of Windows equivalent of "open safe files after downloading". They renamed files like "foo.exe" to "bar.mp3". This vulnerability requires *A COMBINATION OF* identifying f... (Read the rest)
Posted by: Knorthern Knight Posted on: 11/28/06 You are currently: a Guest | | Terms of Use
It's Just a Matter of Time...  jpr75_z | 02/27/06
Safe no more.  Mr. Roboto | 02/27/06
Being targetted by virus-writers is one thing...  Zogg | 02/27/06
If you Knoppix..  cashaww | 02/28/06
Brings smug Mac users down a peg...  aurora7795 | 02/27/06
Nothing has changed, this all FUD.  olePigeon | 02/27/06
there is one flaw  doh123 | 02/27/06
Is it? Yes it is , its all user side.  crampy20 | 02/27/06
Don't under estimate  Loverock Davidson | 02/27/06
How can I infect your Mac?  Uncle Buck | 02/27/06
How can I infect your mac?  Uncle Buck | 02/27/06
Exactly, but this doesn't change OS X's security.  olePigeon | 02/27/06
its not all user side.  doh123 | 02/27/06
Wow  IT Scion | 02/27/06
lol  crampy20 | 02/28/06
Is Mac OS as safe as ever?  Loverock Davidson | 02/27/06
What me worry?  Laff | 02/27/06
You are the audience that this article ...  ShadeTree | 02/27/06
Don't be completely worry free  Loverock Davidson | 02/27/06
As a general rule I NEVER trust.....:)  Laff | 02/27/06
Then what is OSX's advantage?  NonZealot | 02/27/06
Hmmmmm let's do some math shall we?  Laff | 02/27/06
Math doesn't look good for OSX!  NonZealot | 02/27/06
Three in one  baggins_z | 02/27/06
First of all not being a trusing soul is a lifestyle policy  Laff | 02/27/06
NZ--be realistic  tic swayback | 02/27/06
Flawed Argument  SquishyParts | 02/27/06
You are confused  NonZealot | 02/28/06
Do not get a Mac...  Anon_ymous | 02/27/06
I think I will  Loverock Davidson | 02/27/06
Riiiight...  BitTwiddler | 02/27/06
Right  Loverock Davidson | 02/27/06
The "Same"  SquishyParts | 02/27/06
How do we know the score?  Uncle Buck | 02/27/06
Why waste your money?  tic swayback | 02/27/06
problems in paradise  Amberhawk | 02/27/06
Fetish for file types  LittleGuy | 02/27/06
No need  baggins_z | 02/27/06
No need for file extensions  thunderdome1 | 02/28/06
Same mechanism as Klez and Sircam on Windows  Knorthern Knight | 11/28/06
Yes, Mac has been very safe, really about zero exploits of any  DonnieBoy | 02/27/06
I still play it safe.  ben.kreeger | 02/27/06
Clam  Bill4 | 02/27/06
No OS is safe.  theace18 | 02/27/06
You're a genius.  A_Pickle | 02/27/06
Regardless...NEVER USE SYMANTEC! for protection.  Anon_ymous | 02/27/06
Symantec Norton AV  Bill4 | 02/27/06
Although you really don't need AV protection on a Mac...  IT_Guy_z | 02/27/06
"Although you really don't need AV protection on a Mac..."  IT_Guy_z | 02/27/06
PC & Mac  Bill4 | 02/27/06
I use a Mac (and am my own IT person) BECAUSE I'm clueless  labarker | 02/27/06
It's the fundies  thunderdome1 | 02/28/06
NEVER USE SYMANTEC?  woodymiller | 02/27/06
Opposite experience here...  ajole | 02/27/06
So far, there have been no reports...  Uncle Buck | 02/27/06
Easy  bpick_z | 02/27/06
You would know  tic swayback | 02/27/06
Seriously underestimating...  NonZealot | 02/27/06
is it a worm?  doh123 | 02/27/06
It's not a worm  tic swayback | 02/27/06
Yes, the hackers and crackers are more interested in it  Boot_Agnostic | 02/27/06
The completely safe computer  the_doge | 02/27/06
Exactly!  ajole | 02/27/06
Mac OS is not safer now  bidemytime | 02/27/06
This reads like a Press Release  tic swayback | 02/27/06
Is this apple's problem?  crampy20 | 02/27/06
MAC OS X Security  alanrbriggs | 02/27/06
Are you sure about this?  ajole | 02/27/06
No OS is invulnerable!  georgep_z | 02/27/06
Of course they are vulnerable  richdave | 02/27/06
Is Mac OS as safe as ever?  richdave | 02/27/06
"Is Mac OS as safe as ever?" The answer is YES!  Laff | 02/27/06
RE: "Is Mac OS as safe as ever?" The answer is YES!  richdave | 02/27/06
And the ansers are still yes and obviously you....:)  Laff | 02/28/06
Sigh  Shelendrea | 02/27/06
"Where the numbers may be concerned"  tic swayback | 02/27/06
Your post is not accurate  NonZealot | 02/27/06
Your post is not accurate  NonZealot | 02/27/06
How so?  tic swayback | 02/27/06
Here's how so  NonZealot | 02/27/06
Still some vulnerabilities  thunderdome1 | 02/28/06
Name them  NonZealot | 02/28/06
Windows Update shows it  thunderdome1 | 03/01/06
Define "easy"  tic swayback | 02/28/06
Long reply!!  NonZealot | 02/28/06
Privilege Escalation  tic swayback | 02/28/06
Yes, it is a problem on all OSs  NonZealot | 02/28/06
my point being  Shelendrea | 02/27/06
Just ingore the extremes then  tic swayback | 02/27/06
Bad Logic  ajole | 02/27/06
Really bad analogy  tic swayback | 02/28/06
It's not the number of flaws, it's the attacks.  ajole | 02/28/06
How can you be so sure  tic swayback | 02/28/06
I agree, its not 100%  ajole | 03/01/06
Just thought of another possible reason...  ajole | 03/01/06
You accuse him of making a bad analogy?  NonZealot | 02/28/06
It's about numbers  thunderdome1 | 02/28/06
No, you don't read!  NonZealot | 02/28/06
Speaking of not reading...  tic swayback | 02/28/06
Yes, speaking of not reading!!  NonZealot | 02/28/06
I apologize, I missed your last statement  NonZealot | 02/28/06
NZ--you're not the only one here  tic swayback | 02/28/06
It wouldn't be fun if I was!!  NonZealot | 02/28/06
Arbitrary rules  tic swayback | 02/28/06
I read, and understand  thunderdome1 | 03/01/06
Don't try to speak for the rest of us  tic swayback | 02/28/06
My logic? Uh oh  NonZealot | 02/28/06
Again, you're trying to speak for others  tic swayback | 02/28/06
Nope, you are speaking for others  NonZealot | 02/28/06
Wherever did you get this idea?  tic swayback | 02/28/06
tic: merging 2 threads  NonZealot | 02/28/06
Ooh, good argument  tic swayback | 02/28/06
Lousy Reporting  joe_coder | 02/27/06
Not sure I agree in this case  tic swayback | 02/27/06
it is an OS problem  doh123 | 02/27/06
But in the media world, its good enough  ajole | 03/01/06
Incorrect use of zealot  thunderdome1 | 02/28/06
This is acceptable???  richdave | 02/27/06
Troll Alert  joe_coder | 02/27/06
There is a patch  MacGeek2121 | 02/27/06
Don't be silly, it's probably closer to 95,  ajole | 02/27/06
You're an idiot  thunderdome1 | 02/28/06
Is Windows OS as vulnerable as ever?  georgep_z | 02/27/06
Dude  Shelendrea | 02/27/06
The proof is in the pudding.  papatator | 02/27/06
Faster processors equal more popular OS?  ajole | 02/27/06
This is what PC users have always said...  ajole | 02/27/06
reasons  SquishyParts | 02/27/06
this is not a worm if you have any common...  BW1977 | 02/27/06
Securing OSX despite threats  Alex Santos | 02/28/06
MacO/S merely SMALL POTATOES for hackers  Feldwebel Wolfenstool | 02/28/06
Just keep telling yourself that.......:)  Laff | 02/28/06
Exactly. (NT)  NonZealot | 02/28/06
90%-95%  thunderdome1 | 02/28/06
Is OS/2 as dead as ever?  Boot_Agnostic | 02/28/06
It's Nice Being Alice, But Then...  bobhog | 03/01/06
Will they see the light?  zaphod@... | 03/02/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and