TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The Mac.BackDoor.iWorm threat in detail

59 pointsby ConceitedCodeover 10 years ago

9 comments

nknighthbover 10 years ago
All of the information I&#x27;ve seen about this &quot;worm&quot; comes from a single anti-virus vendor I&#x27;ve never heard of, and the information is painfully thin -- most critically, there is no information at all on how it&#x27;s spread.<p>This particular headline (which, to be fair, does not come from the linked page) uses the word &quot;exploit&quot;, but there is no evidence of what, if any, flaw is being exploited.<p>&quot;Worm&quot; has a rather specific meaning. It&#x27;s malware that self-propagates through a network. Strictly construed, the only way this can happen is if there is a security flaw being exploited. A looser definition includes things like the infamous &quot;ILOVEYOU&quot; &quot;worm&quot;, that automatically distributes itself, but requires user interaction to infect a target.<p>In this case, neither means of distribution is in evidence.<p>At this point, I&#x27;m skeptical that this &quot;worm&quot; exists at all.
评论 #8407649 未加载
评论 #8408341 未加载
评论 #8407835 未加载
tonypleeover 10 years ago
In Linux, one way I protected my webserver in the past was to just do:<p><pre><code> cd &#x2F;; sudo git init; git add &#x2F;etc &#x2F;{bin,sbin,lib} &#x2F;usr&#x2F;{bin,sbin,lib,local} ... ; sudo git commit git clone &#x2F; into another remote server, and I can git diff from time to time to see if anyone&#x2F;code mod my system. One very nice side effect of this system is that I got to know in details what files were modded and added when ever I did an &quot;apt-get install ...&quot; </code></pre> Questions for mac Guru:<p><pre><code> 1. Have anyone done this in Mac? 2. Any pro&#x2F;con on why, why not do this? 3. Other than, &#x2F;{bin,sbin,lib} &#x2F;etc, &#x2F;usr&#x2F;{bin,sbin,lib}, What other dirs should I add? What&#x27;s best way to handle &#x2F;Applications&#x2F; (25GB ) ? 4. What other dirs can a worm,virus, hide in my Mac? Any good dtrace scripts to help monitor who&#x2F;what is writing to those places?</code></pre>
评论 #8407859 未加载
评论 #8408323 未加载
评论 #8408900 未加载
评论 #8408018 未加载
X-Istenceover 10 years ago
Alright, now how does this spread? How would I get this piece of malware onto my computer? Do I need to browse the web? Do I need to install a piece of software that is vulnerable?<p>That&#x27;s what I care about, how can I protect myself against this, and saying &quot;Buy Anti Virus software&quot; is NOT the right answer.<p>All I see so far from other reports is that you would have had to install software, bypass the signing requirement and that software had to come from a less than legitimate location to carry with it the malware ...
评论 #8408756 未加载
评论 #8408374 未加载
ricardobeatover 10 years ago
The reported signature goes back to a backdoor found in 2009: <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2009-012620-2836-99" rel="nofollow">http:&#x2F;&#x2F;www.symantec.com&#x2F;security_response&#x2F;writeup.jsp?docid=...</a><p>Looks like you have to install an unsigned app plus give it admin permissions, so not a worm.
pebbleducover 10 years ago
<a href="http://appleinsider.com/articles/14/10/03/iworm-malware-controls-macs-via-reddit-more-than-17k-affected" rel="nofollow">http:&#x2F;&#x2F;appleinsider.com&#x2F;articles&#x2F;14&#x2F;10&#x2F;03&#x2F;iworm-malware-cont...</a><p>Because iWorm extracts into a folder on OS X, users can check if their Mac is infected by navigating to &quot;Go &gt; Go to Folder&quot; from the OS X Finder menu and typing in &#x2F;Library&#x2F;Application Support&#x2F;JavaW. If OS X cannot find the folder, the computer is clear. If the folder is found, however, users are urged to employ an anti-virus program to wipe iWorm from their hard drive.
评论 #8409063 未加载
rnovakover 10 years ago
I would really love to submit this encryption method to the PCI auditors.... &quot;uses encryption extensively&quot;.<p>Edit: seriously? The first example is a shift cipher and a one time pad of all &#x27;M&#x27;.
评论 #8408218 未加载
评论 #8409692 未加载
评论 #8408953 未加载
评论 #8408360 未加载
super_marioover 10 years ago
Guys, this is such obvious scare propaganda to sell you their anti-virus software (which I would be more scared about installing).<p>Basically their pitch is: Be afraid, be a afraid, there is this malware we have no idea how it gets to your computer, but we have it and have analyzed what it does. And did you know that if you had our antivirus program you would be completely safe.<p>And as it turns out it&#x27;s just another trojan horse that has to be installed by user to work.<p><a href="http://www.thesafemac.com/iworm-method-of-infection-found/" rel="nofollow">http:&#x2F;&#x2F;www.thesafemac.com&#x2F;iworm-method-of-infection-found&#x2F;</a>
aespinozaover 10 years ago
More information here: <a href="http://www.thesafemac.com/dr-web-announces-new-iworm-malware/" rel="nofollow">http:&#x2F;&#x2F;www.thesafemac.com&#x2F;dr-web-announces-new-iworm-malware...</a>
joshkpetersonover 10 years ago
The reddit thread [1] explains that the worm was posting information on &#x2F;r&#x2F;minecraftserverlists, presumably as a way to easily, anonymously, and publicly store and retrieve information.<p>Just last week in the thread on the twitter image bots [2] someone postulated:<p>&gt;I wonder if you could build some kind of distributed neural net on top of twitter or another social network. Find some way to get nodes with very little computation power hidden within a free app, webpage, screensaver or something[1], and use twitter as a communications channel instead of IRC or whatever.<p>...<p>&gt; Or a botnet, if you&#x27;re feeling evil.<p>[1]<a href="http://www.reddit.com/r/news/comments/2i6rte/hackers_have_found_a_flaw_in_macs_and_are_using/ckzdvf4" rel="nofollow">http:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;news&#x2F;comments&#x2F;2i6rte&#x2F;hackers_have_fo...</a><p>[2]<a href="https://news.ycombinator.com/item?id=8377985" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=8377985</a>
评论 #8409697 未加载