Daca ai de gand sa iti downloadezi ultima versiune de iWork ’09 … mai gandeste-te … au facut un troian baietii rai (hackeri) care abia au asteptat ca sa poata profita de naivitatea si de zgarcenia unor utilizatori de Mac OS X.
Iata si detaliile:
Exploit: OSX.Trojan.iServices.A Trojan Horse
Discovered: January 21, 2009
Risk: Serious
Description: Intego has discovered a new Trojan horse, OSX.Trojan.iServices.A, which is currently circulating in copies of Apple’s iWork 09 found on BitTorrent trackers and other sites containing links to pirated software. The version of iWork 09, Apple’s productivity suite, are complete and functional, but the installer contains an additional package called iWorkServices.pkg.

When installing iWork 09, the iWorkServices package is installed. The installer for the Trojan horse is launched as soon as a user begins the installation of iWork, following the installer’s request of an administrator password (in older versions of Mac OS X, 10.5.1 or earlier, there will be no password request). This software is installed as a startup item (in /System/Library/StartupItems/iWorkServices, a location reserved normally for Apple startup items), where it has read-write-execute permissions for root.
The malicious software connects to a remote server over the Internet; this means that a malicious user will be alerted that this Trojan horse is installed on different Macs, and will have the ability to connect to them and perform various actions remotely. The Trojan horse may also download additional components to an infected Mac.
Si pe scurt in Romana: in varianta virusata este un fisier: iWorkServices, care se instaleaza impreuna cu restul pachetelor in locatia: /System/Library/StartupItems/iWorkServices. Acesta solicita introducerea parolei de administrator, acest lucru nu este necesar decat la versiuni mai noi decat 10.5.1. Obtinand astfel dreptul de a se rula la pornirea Mac OS X, cu drepturi de read-write-execute (adica sa faca orice). Ulterior se conecteaza la un server via Internet. Hackeri au astfel puterea de a instala si alte componente ale sale si sa infecteze complet Mac-ul tau.
Asadar … nu fi zgarcit daca vrei sa ai sistemul tau Mac sigur si fara virusi/troieni.
Update: Iata si o serie de comenzi care pot indeparta in mare parte troianul … da’ ii indicat sa iti pui si un antivirus daca tot l-ai prins.
Comenzile:
1) (open Terminal.app)
2) sudo su (enter password)
3) rm -r /System/Library/StartupItems/iWorkServices
4) rm /private/tmp/.iWorkServices
5) rm /usr/bin/iWorkServices
6) rm -r /Library/Receipts/iWorkServices.pkg
7) killall -9 iWorkServices
Recent Comments