Everything iPhone iPhone Accessory Store iPhone news iPhone accessory reviews iPhone forums iPhone Social


Go Back   iPhone 3G | iPod touch Forums > Apple iPhone Software > iPhone Software

Notices

iPhone versions available: Enhanced | Light



Reply
 
Thread Tools Display Modes
Old 11-01-2007, 05:52 PM   #1 (permalink)
 
Hawk's Avatar
 
Join Date: Aug 2007
Location: Atlanta, Georgia, USA
Posts: 1,946
Thanks: 29
Thanked 43 Times in 33 Posts
Send a message via AIM to Hawk
Default DNS malware roots Macs

Chris, sorry if I posted in the wrong place, But I figured this could possibly affect iPhone users too through sites like seeqpod and other quicktime sites.
http://www.techworld.com/security/ne...gtype=samechan
Quote:
A new Trojan horse malware called OSX.RSPlug.A specifically targets Mac users, according to security firm Intego.
The Trojan is a form of DNSChanger that changes the Mac's Domain Name Server (DNS) address. According to Intego, the Trojan has been found on several pornographic websites. When trying to view a movie, the user is told that "Quicktime Player is unable to play movie file. Please click here to download new version of codec."
When the user clicks the link a disk image (.dmg) is downloaded to the desktop. When the user installs the software, they are actually installing the Trojan, not a free video codec. The Trojan is installed with full root privileges, which means it has access to all files and commands on the system.
When the malicious DNS server is active, it hijacks some web requests, leading users to phishing sites (for sites such as eBay, PayPal and some banks) or to pages displaying ads for other pornographic sites, according to Intego.
The Trojan also installs a root crontab which checks every minute to ensure that its DNS server is still active, the company said. Since changing a network location could change the DNS server, this cron job ensures that, in such a case, the malicious DNS server remains the active server.
Intego said that using Mac OS X 10.4, there is no way to see the changed DNS server in the operating system's interface. Under Mac OS X 10.5, this can be seen in the Advanced Network preferences; the added DNS servers are dimmed, and cannot be removed manually.
Hawk is online now   Reply With Quote
Old 11-01-2007, 06:04 PM   #2 (permalink)
 
x999x's Avatar
 
Join Date: Aug 2007
Posts: 1,785
Thanks: 0
Thanked 20 Times in 7 Posts
Default

Ouch, that's really an annoyance if you happen to catch this bug. Good thing its delivery method is limited, and so obvious.
__________________
The First Rule of Fight Club...
x999x is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT. The time now is 09:36 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
Integrated by BBpixel ©2004-2008, jvbPlugin
Android forums

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53