A tool for exploiting an unpatched security hole in Mac OS X systems has been developed and until earlier today was being distributed through an online forum that caters to Mac hackers, Security Fix has learned. The exploit tool, labeled “Applescript Trojan horse template” by hackers at Macshadows.com, appears to be a collective and ongoing effort to create a package of malicious software that capitalizes on the ARDagent security hole first publicized last week. The vulnerability essentially allows any program to run on a Mac user’s machine without first prompting the user to enter his or her user name and password. The first Macshadows.com post on developing this Trojan, dated May 18. Currently, the Macshadows user forum appears to have been wiped clean, both from the Macshadows.com Web site and from Google’s cache. However, Security Fix obtained screen shots of forum postings from the code’s authors, which are sprinkled [...]
Search
Recent Posts
- Peculiar Patch Pits iPhone Security vs. Safari
- Web Fraud 2.0: Faking Your Internet Address
- US Army bans USB devices to contain worm
- Computer virus quarantines London Hospital for second day
- Lame Mac Trojan limps into view
- ‘Network Identity Theft’ Politely Avenged
- PC virus forces three London hospitals into computer shutdown
Categories
Monthly Archives
- November 2008 (44)
- October 2008 (54)
- September 2008 (40)
- August 2008 (66)
- July 2008 (60)
- June 2008 (51)
- May 2008 (57)
- April 2008 (82)
- March 2008 (60)
- February 2008 (46)
- January 2008 (41)
- December 2007 (20)
- November 2007 (37)
- October 2007 (36)
- September 2007 (27)
- August 2007 (39)
- July 2007 (34)
- June 2007 (77)
- May 2007 (142)
- April 2007 (722)
- March 2007 (2124)
- February 2007 (612)