Apple, Mac, iOS4, iPad, iPhone and (in)security...
88
Everything related to the (in)security of Apple products
Curated by Gust MEES
Follow
Scooped by Gust MEES onto Apple, Mac, iOS4, iPad, iPhone and (in)security...
Scoop.it!

Apple patches the Java hole its own developers fell into - eventually

Apple patches the Java hole its own developers fell into - eventually | Apple, Mac, iOS4, iPad, iPhone and (in)security... | Scoop.it
Shortly after admitting that its own techies got infected thanks to a Java hole, Apple has pushed out a Java update for the rest of us.

Apple, with this most recent update, seems to have washed ...

 

Both Facebook and Apple have now admitted to being owned due to malicious Java code hosted inadvertently by a website popular with mobile developers.



Gust MEES's insight:

Nobody is PERFECT!!!

 

No comment yet.
Your new post is loading...
Scooped by Gust MEES
Scoop.it!

OSX.Macontrol Back at It Again

OSX.Macontrol Back at It Again | Apple, Mac, iOS4, iPad, iPhone and (in)security... | Scoop.it

Most recently, we have come across a new variant of OSX.Macontrol (first seen in March 2012). This current sample appears to be spread through targeted email and has a very low distribution rate. The binary [md5 - e88027e4bfc69b9d29caef6bae0238e8] is small in size (75kB) and provides little functionality other than a backdoor to a remote host (61.178.77.16x).

 

The web server appears to be a custom HTTP command and control server that can collect and modify system settings. HTTP command and control allows the attacker to evade detection by sending commands that appear to be clean, normal web traffic.

 

OSX.Macontrol has the ability to:

 

- Close the connection to the remote location and end the threat
- Collect information regarding the compromised computer and send it back to the remote server
- Send the process list of the compromised computer to the remote server
- End processes
- Fork running processes
- Retrieve the install path of the Trojan
- Delete files
- Run files
- Send files to the remote server
- Send user status and information to the remote server
- Log out the current user
- Put the compromised computer to sleep
- Restart the compromised computer
- Shut down the compromised computer

 

===> To ensure that you are protected, please make sure your AV definitions are always up to date. Also, please do not download or open attachments from senders that you do not recognize. <===

 

Symantec Note: We were able to connect with Apple and they stated they updated their OS X malware definitions recently to address this version of Macontrol.

 

Read more:

http://www.symantec.com/connect/blogs/osxmacontrol-back-it-again

 

No comment yet.