On CHOW: Can girls use the guys' bathroom?
BNET Business Network:
BNET
TechRepublic
ZDNet

By David Becker
Posted on ZDNet News: Apr 9, 2004 9:58:00 PM

Apple Computer was investigating a reported security flaw Friday in its OS X operating system that could allow vandals to trick Macs into opening dangerous files, such as Trojan horses and viruses.

The flaw was reported by Intego, a French security firm specializing in Apple systems. The company said in a statement that it had encountered a proof-of-concept Trojan horse for OS X disguised as an MP3 music file.

"Mac OS X displays the icon of the MP3 file, with an .mp3 extension, rather than showing the file as an application, leading users to believe that they can double-click the file to listen to it," according to Intego. "But double-clicking the file launches the hidden code, which can damage or delete files on computers running Mac OS X, then (launches) iTunes to play the music contained in the file, to make users think that it is really an MP3 file."

Proof-of-concept bugs are typically created by security researchers to prove the existence of a software flaw. They exploit the flaw but don't do any damage. The OS X Trojan began circulating last month via a newsgroup posting.

Apple said in a statement that it was looking into the matter. "We are aware of the potential issue identified by Intego and are working proactively to investigate it," the statement said. "While no operating system can be completely secure from all threats, Apple has an excellent track record of identifying and rapidly correcting potential vulnerabilities."

In a bulletin released on Friday, Security software and services company Symantec verified the bug but said it posed no immediate danger. "This Trojan does not contain any malicious code," the bulletin said. "MP3Concept is a proof-of-concept Trojan and is not currently seen 'in the wild'--it is not spreading and infecting Mac users."

An Intego researcher said that exploit works by embedding a file with code written for Carbon, the OS X component that allows older programs to be updated to run natively in the new operating system. OS X's Finder application, which associates file types with appropriate applications, doesn't see the Carbon code and launches the malicious file.

A number of such spoofing exploits have surfaced for Microsoft's Windows operating systems, but Macs have been relatively safe from such exploits and other types of attacks. Apple released a security update for the latest version of OS X earlier this week.

Christophe Guillemin of ZDNet France contributed to this report.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 76 Talkback(s)
Exploitation is bad, supporter grief against
other platforms intolerable, and casting stones instead of viable solutions . . . common on Zdnet. Other arguments just seem to pale, or impale. Work for a better tomorrow or just enjoy your Big Mac today.... (Read the rest)
Posted by: FilledOut Posted on: 04/15/04 You are currently: a Guest | | Terms of Use
So long as  MkIIISupra | 04/09/04
you assume  JoeMama_z | 04/09/04
No I read the story...  MkIIISupra | 04/09/04
Recent April 5th security update fixed this.  paul351 | 04/09/04
I disagree  richhayes | 04/10/04
unless ..  g_ludlow | 04/10/04
Yes and no.  Immanuel Tranz-Mischen | 04/10/04
Yes and no  richhayes | 04/10/04
But they have to know the password.  Immanuel Tranz-Mischen | 04/10/04
you must have misunderstood me....  JoeMama_z | 04/10/04
Just goes to show you why...  voska | 04/12/04
True, but...  Immanuel Tranz-Mischen | 04/09/04
But..  d_jedi | 04/09/04
Re: But..  Franklin_z | 04/09/04
OK, then..  d_jedi | 04/09/04
You're missing the whole point.  Immanuel Tranz-Mischen | 04/10/04
More importantly....  JoeMama_z | 04/10/04
User are what they are.  Immanuel Tranz-Mischen | 04/10/04
Easy to avoid  jjenkins | 04/09/04
...or better yet  David Wandelt | 04/09/04
I download legal mp3's all the time  tic swayback | 04/09/04
FUD!  d_jedi | 04/09/04
It is illegal if...  voska | 04/12/04
Are you sure?  Immanuel Tranz-Mischen | 04/09/04
you're kidding, right?  gudin | 04/12/04
Everybody's such a genius...  Christopher McLendon | 04/09/04
That's easy!  MkIIISupra | 04/09/04
Administrator vs. root  Immanuel Tranz-Mischen | 04/10/04
Is that even possible?  Immanuel Tranz-Mischen | 04/10/04
Sales attempt by anti-virus company  tic swayback | 04/09/04
Re: Sales attempt by anti-virus company  Immanuel Tranz-Mischen | 04/09/04
Best extra info I've found on the trojan  Squawkbox | 04/09/04
Wrong Info  ITGuy04 | 04/12/04
Shame on "shame on you"  escoles@... | 04/10/04
You're not being very discerning.  Immanuel Tranz-Mischen | 04/10/04
Unix  richhayes | 04/10/04
really missing the point  TWRX | 04/10/04
Missing the point.  richhayes | 04/12/04
The Point is:  TWRX | 04/12/04
Please notice  richhayes | 04/12/04
richhayes  mabricen | 04/12/04
Do Know  richhayes | 04/13/04
Unix is no less user friendly than DOS.  Immanuel Tranz-Mischen | 04/10/04
Make up your mind  richhayes | 04/12/04
Please make up your mind  NemesisNL | 04/12/04
I agree, to a point  richhayes | 04/12/04
Right on !!!  mabricen | 04/12/04
You succeeded in precisely missing my point.  escoles@... | 04/10/04
How does one miss something precisely?  Immanuel Tranz-Mischen | 04/10/04
You seem to do a pretty good job  escoles@... | 04/12/04
"unable to tell..."  tooner440 | 04/12/04
No security solution, and education is insufficient  escoles@... | 04/12/04
good point  tooner440 | 04/12/04
It's clear that you know nothing of OSX  j.m.galvin | 04/12/04
Not bad.. 60,000 to 1 ratio  Xunil_Sierutuf | 04/10/04
I'm reserving judgement...  tooner440 | 04/12/04
It's the software design  Rick_K | 04/12/04
New Story Title  TWRX | 04/10/04
Zzzzzzzzzzzzz...next  jimk_z | 04/10/04
The Operant Word Here is "May"  Yen_z | 04/11/04
Ouchhh, so right  mabricen | 04/12/04
It's not a virus  Romanval | 04/11/04
Too smart for your own good  jmquinn72 | 04/12/04
Get over yourself  MarcB_z | 04/12/04
Reality Distortion Fields  escoles@... | 04/12/04
jmquinn72  mabricen | 04/12/04
For the record,  mlindl | 04/12/04
mlindl  mabricen | 04/12/04
I buy Macs because they ar superior to Windows PCs  MacGeek2121 | 04/13/04
Intego & Probability  joemckernan | 04/12/04
If OS X is vulnerable with it's BSD OS then......  jfalknor | 04/12/04
Not entirely correct reasoning  dscherf | 04/12/04
Not even close  j.m.galvin | 04/12/04
Too many Windows = glass houses  fuchikoma | 04/12/04
This is not news!  MacGeek2121 | 04/13/04
Exploitation is bad, supporter grief against  FilledOut | 04/15/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here