March 29, 2009 7:00 PM PDT

'60 Minutes': What's next for the Conficker worm?

by CBS Interactive staff
  • Font size
  • Print
  • 78 comments

Correction, April 1, 9:19 a.m. PDT: "60 Minutes" made a mistake in using a photograph in its story called "The Internet is Infected." The picture was described in the story as a group of young Russian computer hackers, which was inaccurate. The picture, provided to the CBS television news magazine by an Internet security company, had appeared on a Russian hacker magazine Web site.

The following is the updated, corrected transcript and video of the "60 Minutes" report on Internet viruses that aired Sunday.

The Internet is infected. Malicious computer hackers have been creating more and more weapons that they plant on the Internet. They call their weapons viruses and worms--they're creepy, crawly toxic software that contaminate our computers without our ever knowing it. You can be infected by simply visiting your favorite Web site, or just by leaving your computer on, overnight while you're asleep.


And the problem is growing, exponentially. Last year the number of infections tripled. And an entire industry of computer security professionals is in a race to keep the hackers from their goal, which is usually to steal your money.

One of the most dangerous threats ever, a computer worm known as "Conficker," is spreading through the Internet right now. By some estimates, 10 million computers have been infected worldwide.

At Symantec, the company that makes Norton antivirus software, engineers have been tracking Conficker since last November as it worms its way across the globe.

"This map is showing a visual representation of where all of the known infections of Conficker are across the world," explained Steve Trilling, a Symantec vice president who says the worm is now living on millions of computers, mainly in corporations.

So far, the bad guys who created it haven't triggered Conficker. It's just sitting out there like a sleeper cell.

"Imagine a network of spies that has infiltrated a country. And every day, all of the spies are calling in for their instructions on what to do next," Trilling explained.

Asked what the worm is being asked to do, Trilling told Stahl, "That's the interesting thing. The only thing the worm is being asked to do is to ask for further instructions."

For several months, Trilling says the worm has just been sitting there, awaiting instructions.

It's that ominous, because once the hackers issue instructions, Conficker could turn menacing in an instant.

With one click, the worm's creator can instruct it to suck sensitive data, like bank passwords and account numbers, out of millions of computers, or launch a massive spam attack to clog up the works.

The newest targets of worms are social networking sites. Trilling demonstrated to Stahl how it might work.

Looking at a real Facebook page, Trilling explained, "We added your friend and colleague Morley Safer, you can see down there on the left."

He says a worm can crack into a Facebook account, like Morley's, and send a message to anyone on his friends list.

It's a message a friend or colleague, like Stahl, would be sure to open since it comes from a trusted friend. Stahl took the bait and clicked on what looked like Morley's video link.

"Something looks a little off," Trilling remarked. "You're already infected."

As Trilling demonstrated on a second screen, the hacker "owned" Stahl's online movements. "From here on out, everything you do, gonna show up on the hacker's machine," he explained.

So when Stahl typed her username and password into a bank Web site, it appeared instantaneously on the hacker's screen, along with her bank account details.

"Every single keystroke you hit, in fact, if you make a mistake and hit a backspace, that shows up in the window," Trilling explained.

The hacker then followed her around, as she browsed the Internet from CBS News to Amazon.com.

"So, if I buy something, they're gonna have my credit card," Stahl remarked.

"Everything you type in, your address, your credit card, it's all gonna show up in that window," Trilling warned.

A minefield on the Internet
The Internet has become a minefield. Hackers have hidden their malicious software known as "malware" on some of the most trusted Web sites, like eBay, the Miami Dolphins football team, even my.barackobama.com.

Trilling says too few people have top-notch, up-to-date security software.

"There is something that would have prevented me from answering Morley's message. Or I would never have gotten Morley's message?" Stahl asked.

"As soon as you clicked on that link and you had security software, you would immediately get an alert. 'This is a bad Web site.' And it would have blocked the attack. You would have never been hit. Putting on that software, you're preventing yourself from becoming a victim," Trilling advised.

But according to Symantec's own figures, the hackers are inventing up to 15,000 new infections every day, designed specifically to get around the latest anti-virus protections. Symantec has to send out updates every five minutes.

"You sell the antivirus, anti-worm stuff. I mean, how do I know you're not just saying, 'Go out and get this,' 'cause you sell it? I mean, you know... there's a sort of conflict of interest here," Stahl pointed out.

"Well look, Lesley, in 60 minutes we are blocking nearly 400,000 threats around the world. If you're goin' out on the Internet and you're not protected, it's like walkin' outta your house and leavin' the door open," Trilling argued.

But Mary Rappaport says all the doors on her home computer were locked tight. She had antivirus software and a firewall, and so she thought she was safe to do her banking online. But then she noticed something odd going on and called the bank.

"They told me that three charges in the last three days had been made to my account. One for $3,000, one for $4,000, and one for $1,200," she recalled.

Rappaport knew she had to act quickly.

The bank replaced the stolen money and suggested that she merely change her password. That was to be the end of it. But the next day, she was checking her balance. "And I saw $1,000 being moved from my son's savings account into my checking account," she recalled. "Right before my eyes. I saw my money being moved."

A hacker was trying to move all her money into one account, her checking account, to make it easier to transfer overseas. Luckily, the bank was able to freeze her accounts before she lost any more money.

"I had what I thought were adequate protections. You know, I had anti-spyware software," she said. "And antivirus."

"And I thought I had a good enough firewall. Wrong!" Rappaport told Stahl. "My understanding anyway is that they were able to get some sort of bug onto my system that disabled the ability to update these software programs."

Mary suspects her teenage sons picked up the bug while downloading from music or game Web sites. But it could have come from any number of Web sites.

Going to Google
Stahl asked Google what they're doing to deal with these big problems, because their search engine is what most people use to surf the net.

Stahl went to talk to Vint Cerf, one of the founding fathers of the Internet, and now a vice president at Google. The company itself says that one in every 100 Google searches brings up an infected site.

"People are blaming Google 'cause if you do the search, they say, you--Google--should be responsible if we get infected," Stahl remarked. "Now you've heard that."

"I have heard that, and I think that's a very bizarre way of looking at things," Cerf replied.

Google's position is that it's not the policeman of the Internet, but its engineers do scour the Web and issue warnings about malicious infections, or malware.

"If we happen to see what we believe is malware on that Web site, then when you go there we will pop up a Web page and it says, 'We think we found malware on this site. Maybe you don't want to go there,'" Cerf explained.

"Now I understand that if you go there anyway, Google sends you a second warning, saying: 'Are you kidding? Are you serious? We told you not to go there.' Something like that," Stahl said.

"Of course people still go," Cerf acknowledged. "And at that point it's their problem."

"The more you hear about this, the more you feel that if you bank online, shop online, open an e-mail, I mean, that almost anything you do puts you in jeopardy," Stahl remarked.

"That's a true statement. There are things. Bad things can happen. On the other hand, I've been on the Net ever since the Net started, and I haven't had any of the bad problems that you've described," Cerf replied.

But tens of millions of people have--one if four Americans, according to recent reports, as the hackers get more and more sophisticated.

Hunting hackers
Don Jackson is a hacker hunter. He is director of threat intelligence at SecureWorks in Atlanta, which protects corporations against cyber-attacks and tracks the hackers who launch them.

"Part of my job is to know the enemy, to know our adversaries," he explained.

To Jackson, the enemy is a hacker. "An enemy is somebody who wants to use computers to hurt somebody else or to make money for themselves."

Using an assumed name, "Gozi," Jackson infiltrates chat rooms where hackers sell their worms and viruses to their clients: other hackers. He asks for a demo so his company can create software to disable the malware. The hackers, he says, are typically young, male and often from Russia.

Asked how he tracks them down, Jackson said, "Well, they're like any other business. They have to advertise to get clients."

As Jackson explains, these brazen hackers do this openly on the Internet. "Unfortunately they're all too easy to find," he said.

He says many Russian hackers are in cyber-gangs that display fascist symbols, like a Swastika and anti-American artwork. They boast about all the dollars they've stolen from the rich Americans. A single hacker can make $30,000 a month and be championed in local newspapers.

"There's an example recently where two boys were arrested actually and then let go the next day, but the article in the newspaper wasn't that they were arrested and that they committed a crime, but saying: 'Look at our two local boys made good. They've cheated some greedy Westerners out of so much money,'" Jackson explained.

"They're heroes," Stahl remarked.

"They are," he agreed. "And it's bringing money into the local economy."

It's not known who's behind the computer worm Conficker, whether it's a gang of Russian hackers or some solitary evil genius. This worm is wily--it keeps mutating. Security software companies have been kept very busy.

But Conficker can jump over protections. While Stahl was reporting this story in early March, she was stunned to learn that the wily worm had struck CBS News.

"People were havin' problems with their BlackBerries, their logons," explained Louie Pelaez, a network engineer.

He says Conficker is so aggressive, it took CBS technicians 24/7 over 10 days to hunt down and quarantine the affected computers.

"Do you actually know where it started? Can you pinpoint it?" Stahl asked.

"We really will probably never know exactly how it infected the network," Pelaez said. "We just know that, you know, once it hit, it began to propagate."

CBS News has now contained the infection, but Pelaez says Conficker could still be hiding undetected somewhere within the network.

Asked if he thinks CBS is safe, or if this could happen again, Pelaez told Stahl, "No, I pretty much thought that we were pretty solid. You try to secure a network. But there's no guarantee that somebody can't come up with something that will, you know, wreak havoc."

Conficker investigators have been talking about an April Fool's attack, because in dissecting the worm, they can see it's been programmed to receive new instructions on April 1. But nobody knows if the instructions will be benign, or something that could disrupt the entire Internet.

Recent posts from Security
So, is it safe to tweet now?
Twitter hijacked by 'Iranian Cyber Army'
Firefox, Adobe top buggiest-software list
Predator drones hacked in Iraq operations
Adobe to patch zero-day Reader, Acrobat hole
Firefox 3.5.6 patches critical security holes
Facebook sues men for allegedly phishing, spamming
Scammers exploit Google Doodle to spread malware
Add a Comment (Log in or register) Showing 1 of 2 pages (78 Comments)
by ballmerisanape March 29, 2009 7:20 PM PDT
This will be the best "get a Mac" commercial ever conceived.

Conficker, brought to you by your friends at Microsoft. We realized that you all missed 90's style computing... so we decided to leave a few back doors open for a while.

Macintosh unaffected.. unless you have an unpatched version of Windows installed.. ;)
Reply to this comment
by aj37viggen March 29, 2009 7:29 PM PDT
Yeah, but the main reason we Mac users haven't been affected much is that we're still not numerous enough to be worth the bother. Sooner or later, somebody will decide to bother. Maybe sooner, if we keep on acting too cocky!
by ewelch March 29, 2009 7:39 PM PDT
@aj36viggen -

You are only partly right. One reason Macs are not vulnerable is because they are more obscure. But they are fundamentally more secure by design. And they will continue to be more secure than Windows computers. Also more secure than Linux. Solaris and BSD UNIX are as secure or more secure. But I can't run Photoshop on them. ;-D
by BOTNET March 29, 2009 9:01 PM PDT
ewelch, did you hear about Windows VISTA and how it's kernel work? I guess you should read a bit more before you say that MAC is more secure than Windows.

btw read a bit about last week browsers hacking competition.... SAFARI was cracked first
by Mac OS XP March 29, 2009 11:32 PM PDT
@BOTNET -
Did you notice the OS that the woman's computer who had internet security software? It was Vista.
Safari was cracked first, big whoop. The thing is this: Windows computers are the ONLY ones getting Conficker. The ONLY way to protect yourself is to stop using Windows. End of story.
by santuccie March 30, 2009 1:25 AM PDT
To ewelch:

Actually, aj37viggen is entirely right. Do a search for "OS X more secure than Vista," and the only thing you'll get is the opposite. The Mac has been taken at the Hack a Mac contest by Dino Dai Zovi, hacked in under two minutes at CanSecWest last year by Charlie Miller last year, and again this year in under 30 seconds. They're saying the Mac is nowhere near as secure as Vista, as is everyone else:

"I have found the code quality, at least in terms of security, to be much better overall in Vista than Mac OS X 10.4. It is obvious from observing affected components in security patches that Microsoft's Security Development Lifecycle (SDL) has resulted in fewer vulnerabilities in newly written code. I hope that more software vendors follow their lead in developing proactive software security development methodologies." - Dino Dai Zovi

'"Mac OS X is easy pickings for bug finders. That said, it doesn't have the market share to really interest most serious bug finders," added Gwerdna.'

'"The only thing which has kept Mac OS X relatively safe up until now is the fact that the market share is significantly lower than that of Microsoft Windows or the more common UNIX platforms.... If this situation was to change, in my opinion, things could be a lot worse on Mac OS X than they currently are on other operating systems," said Archibald at the time.'

"It was the easiest one of the three," said Charlie Miller, an analyst at Independent Security Evaluators (ISE), a Baltimore-based security consultancy. "We wanted to spend as little time as possible coming up with an exploit, so we picked Mac OS X."

"Safari on the Mac is easier to exploit. The things that Windows do to make it harder (for an exploit to work), Macs don't do. Hacking into Macs is so much easier. You don't have to jump through hoops and deal with all the anti-exploit mitigations you'd find in Windows.

"It's more about the operating system than the (target) program. Firefox on Mac is pretty easy too. The underlying OS doesn't have anti-exploit stuff built into it."

"For all the browsers on operating systems, the hardest target is Firefox on Windows. With Firefox on Mac OS X, you can do whatever you want. There's nothing in the Mac operating system that will stop you."

http://i.gizmodo.com/256768/mac-os-x-less-secure-than-vista
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9072959
http://www.zdnet.com.au/news/security/soa/Mac-OS-X-hacked-under-30-minutes/0,130061744,139241748,00.htm
http://blogs.zdnet.com/security/?p=2941

OS X is no more secure than XP with a limited user account, and worms can still get around that. But people who leave UAC enabled in Vista have been blocking Conficker, as well as the MBR super-Trojan Mebroot a few months ago. Personally, I secure XP by simply locking down system32 and its drivers subfolder; no need for antivirus.

The bottom line is that it is being demonstrated again and again that remote code execution is easily doable on the Mac. And where did you get this information that Mac OS is more secure than Linux? Actually, no one has hacked Linux at CanSecWest to my knowledge. The only operating system I would put money on for being more secure than the average Linux distro is OpenBSD, without a single vulnerability for 4 years running.

Like it or not, the most vulnerable operating system currently on the market is OS X. As long as professional crackers see no profit in going after your platform, you're pretty well safe. The only ItW exploits I know of have been written by small-timers, and distributed via traditional social networking. But as it were, you're actually depending on the choices of the hackers themselves to keep you safe. I could never sleep with that knowledge. I'll stick with battle-hardened Windows, which I know how to keep clean, and have been doing for the last 2-1/2 years straight.
by aMUSICsite March 30, 2009 1:47 AM PDT
"For all the browsers on operating systems, the hardest target is Firefox on Windows...."

And i thought is was Chrome!
"Firefox, Safari, and Internet Explorer were all exploited during the Pwn2Own competition that took place at the conference. Google's Chrome browser, however, was the only one left standing".

OS X is better defended against self replicating threat, but any system can be hacked. If OS X is less targeted because it has a smaller install base, don't that still make it safer?
by santuccie March 30, 2009 7:28 AM PDT
You're right, Google Chrome is the safest of all browsers because it uses a sandbox. But Chrome is presently available only for Windows, and doesn't even come stock with Windows. It could not be used in this context. Miller was talking about the underlying operating system, first and foremost. Chrome was still game in the contests, but only after the standard apps competitions.

I would like to see your sources which state that Mac OS X is better defended against self-replicating threats than Windows Vista. Both of my sisters use Macs, and the only security feature I can see is non-root restriction. Evidently it's no more secure than a limited user account in XP, because it is the first one to get hacked in each competition. And make no mistake; these people aren't looking for the notoriety of hacking a Mac, they're trying to be the first to hack SOMETHING. And for that reason, Charlie Miller chose OS X, the "easiest one of the three."

Whether obscurity amounts to safety is subjective to opinion. Like I said, my opinion is that you're relying on the choices of the criminals themselves. The very first ItW malware to come out for OS X was a self-replicating worm. It didn't carry a payload, but it could have. If hiding in the bushes is the way you stay secure, then more power to you. Personally, I take matters into my own hands, and put on my own armor (and I'm not talking about antivirus).
by CrashPad63 March 30, 2009 7:35 AM PDT
Have anyone of you naysayers really thought about what youre saying? My God people. Matters not what OS what browser, even the sites are being infected. Wakeup, stop pointing fingers and work toward what is really important tracking down and putting an end to these hackers.
by santuccie March 30, 2009 7:44 AM PDT
I agree, although it's kind of difficult with the the P2P networks criminals are using nowadays, as well as sheer size. In my opinion, the way everyone (everyone with at least rudimentary PC savvy) can contribute is by cleaning up their systems if they are infected, and then locking them down. Here's my contribution: http://invincible-windows.blogspot.com/
by Lerianis3 March 30, 2009 12:17 PM PDT
ewelch is living in a dreamland, as BOTNET pointed out. The fact is that Windows Vista and the upcoming Windows 7 are pretty much bulletproof against ConFicker type infections. Why? Nothing is allowed to be installed WITHOUT A WARNING. Nothing in the slightest.
That's the problem today: people are STILL on Windows XP computers that do not have the security protections that Vista and Windows 7 have in them, and that needs to change. Even with security software, Windows XP is too insecure in today's environment, unless you are NEVER going to hook it up to the internet, even with Security software installed.
See more comment replies
by vmlenigma March 29, 2009 7:30 PM PDT
You guys failed to address that this only affects Windblows Machines, NOT MAC NOT SOLARIS NOT LINUX
only Windblows

ah Ill pay my Mac Tax any day to avoid this crap
Reply to this comment
by RammerRW March 29, 2009 10:06 PM PDT
LOL! Windblows! That's clever! Did you come up with that all by yourself? How cute! :3
by 1363nd0f1337 March 29, 2009 11:14 PM PDT
No, this affects UNPATCHED Windows machines. There's a difference. Unpatched Windows machines have users that can't seem to navigate their way to a website once a month (XP) and go through the process of downloading and installing updates and opening another window and continuing their work, or turn on automatic updates with a notification and have a little tray icon let you know when updates are available and downloading and installing these in the background. Or if you use Vista, you could've just let it run int he background. No need for a website or any of that. Seriously, this fix has been out since February. No excuses for not getting it installed.
by bgnm March 30, 2009 7:17 AM PDT
Safari was hacked by someone in physical possession of the computer. That's a far cry from being susceptible to thousands of worms, trojans, and viruses just by surfing the net.
by CrashPad63 March 30, 2009 7:44 AM PDT
I was wondering when this would come up. Patched in Octoberr of 2008. Will not affect anyone with a patched system. Now note most of the est 10 million computers affected come from Asia, Russia. This coincides with the largest saturation of Pirated Windows on the planet. Go figure. People, think for yourselves and stop this blind condemnation of a very hardened OS that in its position holds up remarkebly well.
by Seaspray0 March 30, 2009 9:28 AM PDT
@bgnm. The mac was hacked by opening safari to a malicious website. It was the website itself that broke into the mac. That is the exactly the same as being suscetible just by surfing the net.
by GTFMco March 30, 2009 1:23 PM PDT
And all these years I have been calling it Windoze
by unkn0wn_f0rces April 1, 2009 7:10 AM PDT
LOL apparently you don't read vmlenigma....santuccie clearly addressed that with almost a whole other web article about this....really there is no difference what operating system you are on...what web browser you are on....they are trying to infect everyone...the worm isnt just gonna say "Oh you are using Safari on OSx, I dont think I'll attack you!" Come on man, get with the program....

lolololshift+1
by DKrudop March 29, 2009 7:33 PM PDT
Where's the part of the headline that indicates this worm ONLY affects Windows computer? Those of us in the Mac community remain unaffected.
Reply to this comment
by 1363nd0f1337 March 29, 2009 8:33 PM PDT
Notice how they say "mainly corporations" are affected by this. Corporations are notorious for not keeping up with Windows updates as they have to be incrementally tested with any proprietary software. Many corporations haven't even updated to SP3 for XP. When I worked at a naval facility over last summer as part of a program to give full-time students jobs, I got tasked with applying updates to many of the computers and they were so behind it wasn't even funny.
by truthortroll March 29, 2009 8:17 PM PDT
where's the part of the headline that indicates this worm only affects UNPATCHED windows computers? way to go with the doomsday story instead of stating the facts. CNET your journalism is slipping ever since CBS took over...
Reply to this comment
by Lerianis3 March 30, 2009 12:20 PM PDT
Correction: only affect unpatched WINDOWS XP computers. Windows Vista's UAC protections would stop this infection in it's tracks before it could do any damage in the slightest.
by Dalkorian March 30, 2009 5:02 PM PDT
That's just unadulterated bull Lerianis and you know it. Otherwise there wouldn't be fista patches against this, now would there. Oh yeah, your beloved fista is also susceptible against this.

The key is patching the system. If you're patched, then (supposedly) you're OK. If you're not, then don't get all comfortable because you got suckered into paying for fista.
by santuccie April 3, 2009 1:06 PM PDT
To Dalkorian:

I wouldn't venture to say that. It's true there are security patches for Vista, and that the patches address veritable vulnerabilities. However, this doesn't mean UAC won't stop malware that attempt to exploit these vulnerabilities.

While UAC is not the same thing as HIPS, and does not impose the confusion a novice user would be confronted with using a firewall like ZoneAlarm or Comodo, it does still place responsibility on the user. It is Microsoft's intention that the user miss as seldom as possible, so they work to reduce attack vectors before exploits ever make it to the UAC checkpoint.

In addition, UAC can be deactivated if desired. Of course this is not recommended. It's because of UAC that even unpatched machines have been safe from Mebroot and the headlining Conficker worm. And UAC is just the same as the root authentication mechanisms in Mac OS and most Linux distros. I'm an outspoken opponent of HIPS, yet I have no problem with UAC.

Finally, Vista has additional security that often goes unmentioned. It has self-healing technology to insure system file integrity, as well as strict, preemptive stipulation of service and driver associations. Vista x64 also adds ASLR and hardware-based DEP.

I won't chance making a fool of myself by making a claim I can't back up, but it is my understanding that Vista compromises at CanSecWest were demonstrated on machines with both IE protected mode and UAC turned off. Is there anyone who can verify this (links, please)? Thanks.
by CBSTV March 29, 2009 8:50 PM PDT
Another reason to be a Macintosh user.
Reply to this comment
by 1363nd0f1337 March 29, 2009 9:09 PM PDT
Well, if more people become Mac users then coders of malicious programs will begin to turn their attention to them.
by vmlenigma March 29, 2009 9:11 PM PDT
and another Reason why I would Gladly pay that Mac Tax Ballmer keeps on yapping about
by Seaspray0 March 30, 2009 6:55 AM PDT
I never got a virus on my Atari ST either, but that doesn't mean that it's more secure. It takes two things to get hacked. A vulnerability and code that exploits it. So far, the mac has been lucky nobody is writing that code, because it does have more vulnerabilities.

http://news.cnet.com/8301-1009_3-10154662-83.html
The Macintosh and base Linux kernel operating systems have dominated the top spots for vulnerabilities by operating system over the past three years
by Dalkorian March 30, 2009 5:10 PM PDT
Sigh - OS 9 had viruses in the wild, so by Seaspray0's logic OS 9 was infinitely more popular than OS X.

I'll wait until everyone stops laughing ...

(pause)

Hint: "vulnerability" and "security" are not necessarily the same thing. Example, say I have an OS that has a dozen vulnerabilities, but they require certain conditions to be met (like I'm at the keyboard, or certain outdated software has to be running, or certain mistakes have to be made in configuration). Say you have an OS that only has one vulnerability, but that vulnerability allows anyone to gain admin access remotely by simply overflowing an input buffer. I have more "vulnerabilities", but a far more secure system.
by santuccie April 2, 2009 6:07 PM PDT
Actually, OS X has malware in the wild as well. And not just malware that you have to install, but actual drive-by downloads as well:

(2006) Leap-A, the first ever virus for Mac OS X was discovered. Leap-A can spread via iChat. The Inqtana worm and proof-of-concept virus soon followed.

(2007) Sophos discovered an OpenOffice multi-platform macro worm capable of running on Windows, Linux and Mac computers. The BadBunny worm dropped Ruby script viruses on Mac OS X systems, and displayed an indecent JPEG image of a man wearing a rabbit costume.

Sophos reported the first financial malware for Mac. The gang developed both Windows and Mac versions of their malware.

(2008) Cybercriminals targeted Mac and PC users in equal measure, by planting poisoned adverts on TV-related websites. If accessed via an Apple Mac, surfers would be attacked by a piece of Macintosh scareware called MacSweeper.

In June, the OSX/Hovdy-A Trojan horse was discovered that could steal passwords from Mac OS X users, open the firewall to give access to hackers, and disable security settings.

Troj/RKOSX-A was discovered - a Mac OS X tool to assist hackers create backdoor Trojans, which can give them access and control over your Apple Mac computer.

In November, Sophos warned of the Jahlav Trojan, and Apple issued a support advisory urging customers to run anti-virus software.
-------------------------------------------------
Did Seaspray0 say anything about a popularity contest? Apple has a lot more market share than Linux; but unless I'm mistaken, the annals of Linux malware over the years outnumber Mac malware by several hundred samples. One enormous advantage OS 9 has over OS X Tiger and Leopard is the additional obscurity of the PowerPC processor, while everything else runs on Intel. Very few criminal hackers know the PPC shell. But Apple stepped out of the protection of the thicket and into the wide open meadow in 2006.

You still have relative obscurity compared to Windows, but apparently not enough, because some hackers have already noticed you. And now that Vista stocks the shelves for MS, hopefully to be replaced quite soon by Windows 7 which is faster than XP (don't ask me how, because I don't know), the most vulnerable of all platforms is now Mac OS. And finally, if Apple's market share starts rising again after this recession is over, you'll start getting the hackers' attention. Before long, it will be the Windows and Linux users yukking it up about Mac viruses, while Mac users curl themselves up into balls and suck their thumbs dumbfoundedly.

Depending on criminals to pass you over is poor preparation. You can't hide in the bushes forever; someone will see you, and the bush doesn't protect very well. There are security tools already available for the Mac, and for valid reason. Those who warm up to security software now (or find a way to lock the kernel) will be in much better shape when trouble arrives than those who scoff at the enemy, saying they'll never be attacked because it's too much work (which it isn't, as demonstrated by Dino Dai Zovi and twice by Charlie Miller, both of whom are saying OS X has taken Windows' place as least secure). Hope this helps!
by gerrrg March 29, 2009 8:54 PM PDT
So where are the good Western hackers that are creating their own worms to spread, and counter the infected computers by disinfecting them???
Reply to this comment
by Mr. Dee March 29, 2009 9:53 PM PDT
I am broke, so they can break into my computer all they want. The only thing of value is a Word doc to my lady love, some porn and a few songs I downloaded reminiscing over the year '99.
Reply to this comment
by The_happy_switcher March 30, 2009 8:12 AM PDT
This confirms my earlier suspicions that you are probably living in a van down by the river.
by Dalkorian March 30, 2009 5:11 PM PDT
(*grabs some popcorn to watch the troll fight*)
;-)
by jacksoncapper March 29, 2009 10:30 PM PDT
I better go check my bank account...
Reply to this comment
by azeerover March 30, 2009 12:42 AM PDT
As a Vista user, I've never been able to find my files. It's reassuring to know that it's at least theoretically possible, since the virus apparently succeeds in finding them. With all the popups in Windows, it reminds me of my infant son's peg-pounding workbench. If the hackers could do something about that, I'd prefer the virus to a fresh install of vista.
Reply to this comment
by boxter March 30, 2009 3:57 AM PDT
This is just another ad for symantec security products.
Reply to this comment
by Perry_Clease March 30, 2009 4:45 AM PDT
Putting the Windows v Mac thing aside, this Conficker is going to affect us all regardless of the OS we personally use. It is going to affect people who do not use a PC, it will affect our daily life. Part of the blame goes to the people responsible for securing their systems, part of the blame goes to our governments who are supposed to protect us, but the biggest part of the blame goes to the slime balls who write this stuff.
Reply to this comment
by davidwb March 30, 2009 5:07 AM PDT
Let's not forget that another part of the Windows problem is due to the fact that updating a Windows system can be problematic. Over the years I don't know how many times I've added a service pack and had the system go down. That's why I began scheduling updates for Saturdays - assuming the system was going to be mostly down Saturday...not always a safe bet in a company that runs 24/7 or is in the midst of the home stretch of a project. So updates can be delayed - this is Microsoft's fault. And we are just as leery of updating workstations. This nonsense of giving Microsoft some kind of a pass because infection is inevitable or because it is the mainstream OS has to stop and Microsoft has to be held accountable.

As for me: I won't use it for mission critical work because I cannot afford the downtime. The great irony is as an IT guy I use a Mac and did so even when my supervisors made me enforce rules keeping the workplace a Windows only shop.
Reply to this comment
by santuccie April 4, 2009 12:16 AM PDT
What would you do if your supervisors required you to set an example as well? In case you haven't worked that one out yet, I'd like you to know that it's possible to secure Windows XP or 2K with indiscriminate blocking that doesn't depend on updates: http://invincible-windows.blogspot.com/ Hope this helps!
by linuxkg100 March 30, 2009 7:23 AM PDT
I just feel like, once the news hit TV media, it then becomes some scare tactic and if you not aware of or havin't been in the knowing of these things you go out of your way to spend more money to get symantec security software, when there are other security company that have even better software to help fight off the crimeware that's out to get us. Remember folks awareness is the best defense, first, then understanding how to use the firewall and security software helps... Knowledge is the key.
Reply to this comment
by Seaspray0 March 30, 2009 7:34 AM PDT
@davidwb. What BS! Cnet, who wrote several articles on such things like the several hour blackberry outage would have a field day if millions of computers running windows went down due to an update... and yet nothing. Over the many years I've had to deal with hundreds of windows computers, not one of them has ever gone down due to an update.
Reply to this comment
by Dalkorian March 30, 2009 5:16 PM PDT
Updates do have a nasty habit of breaking existing software. This happens to all OS's, but appears to happen to M$ more often than the others (not saying why, just pointing out the appearance is there).

Why do you think M$ regularly releases their patches on the second Tuesday of the month, coincidentally named "Patch Tuesday"? Because it sounds cool?
by santuccie April 12, 2009 9:24 PM PDT
To Dalkorian:

No, they release updates on a monthly schedule to give them some time to debug the patches on multiple versions of the operating system with multiple applications, and to give administrators a predictable cycle, around which they can schedule deployment. I apologize if I just made you snort Coke and spew it out your nose, laughing hysterically at a seemingly preposterous "debug" explanation, but the fact goes something like this...

There are more applications for Windows than any other platform. Yes, Linux has Wine and Win4Lin, but these still don't give full compatibility, especially when there are so many different makes one can find in a Google search, with different features that appeal to different people with different needs. I will add to this another problem for which Microsoft itself is at fault, and that's the fact that they make multiple versions of every new operating system.

That said, the most secure computer is one that is backed up. If more people knew how to image a hard drive, or at least made good friends with someone who does, then they'd have a safety net to fall back on if an update hoses their system. This, and fear of an application/driver conflict waiting to happen, are two of the three fears for which I keep two backups on each machine, and one for each machine on DVD media. The third is HDD failure. Do you backup your Mac? You should.
by linuxkg100 March 30, 2009 7:36 AM PDT
also.. If you that paranoid... turn your computer off, and unplug it from outlet, and make sure it's not connected to any networks. I feel like this, when you're doing important stuff like checking bank accounts and such, never use the same computer for download music or games like that lady in the video said. I also notice she said she had a firewall and AVP, but was the firewall configure properly? apparently not since she said her kids download games and such , but did she ever mention a router??? come on folks who fooling who here. Why you thihk enterprises uses routers, and switches, and thinks like... what you don't know can hurt you... learn how to configure your firewall, and also update your security software. Common sense things can help us in our defense against attackers.
Reply to this comment
by Dalkorian March 30, 2009 5:19 PM PDT
Home users rarely have a reason to skip security updates and Conficker is exploiting a vulnerability that was patched last October. Business users have to be more careful (what if your ERP system went down because a patch broke it?), but there are few excuses for home users.

Of course, they could have installed Linux too and used that regularly - it's not affected by this by any stretch of the imagination.
by The_happy_switcher March 30, 2009 8:07 AM PDT
I kept waiting for someone to bring the point that this only affects Windows machines during that 60 Minutes story. Maybe Microsoft is a sponsor or something and CBS was afraid.
Reply to this comment
by 1363nd0f1337 March 30, 2009 10:07 AM PDT
Again, only people who haven't run Windows update in over a month have anything to worry about. The patch was released in late February and fixed the security issue. Any idiot can keep a computer virus free, it takes a truly special breed of moron to let their computer get infected.
by darfjono March 30, 2009 10:12 AM PDT
ANYONE ELSE WANT TO SAY WHAT HAS ALREADY BEEN SAID MULTIPLE TIMES?
by The_happy_switcher March 30, 2009 11:18 AM PDT
Somebody already said Microsoft is to blame?
by 1363nd0f1337 March 30, 2009 11:35 AM PDT
No, that Microsoft already fixed the issue and that only idiots who don't keep up with updates, especially ones labeled "Critical", will be affected. You seem to forget that Macs can be affected by things like trojans a lot easier than Windows computers can because of the user. A lot of Mac users don't have AV software and when they download things, especially like pirating songs over LimeWire, they open themselves up to having malicious software installed on their computer. While malicious programs for Mac are rarer, much rarer, they do exist.

http://www.macfixit.com/article.php?story=20090326104010541
by real_bgiel March 30, 2009 10:17 AM PDT
Surprising that security pro's quoted in the article don't know what a "hacker" is. The term is almost always misused.
Reply to this comment
by Dezeit March 30, 2009 11:14 AM PDT
LOL to all those people posting my mac is safe.

Quick question to you - are you running malware protection on your machine?

Now just think about this, majority of malware today has no visible sign it is there, it just sits and watches what you do and sends back login information. How do you know you are not infected?

Could it be you have not suffered loss of personal information because the malware writers have so much user data they have not got round to your data yet?
Reply to this comment
by The_happy_switcher March 30, 2009 11:19 AM PDT
"How do you know you are not infected? " For the same reason that I know the tooth fairy doesn't exist.
by 1363nd0f1337 March 30, 2009 11:31 AM PDT
There actually have been several trojans over the last few years aimed at Macs. I think the DNSChanger trojan was one. There was another that was attached to a keygen that was packaged with a pirated version of iLife '09.
by GTFMco March 30, 2009 11:58 AM PDT
Looks like More should have taken the paper on Curious Yellow a little more serious, this has been out for quite some time now, I recall reading this a couple of years ago http://blanu.net/curious_yellow.html and wondered when this day would come. as this paper shows the concept has been around for awhile read and enjoy and if your a hacker or just plain savvy you might even understand it.
tnx
jody - GTFM
Reply to this comment
by lihis1 March 30, 2009 2:37 PM PDT
I'd like question the reliability of this show. The "hackers" which were show in the picture were from Finland, not from Russia. You can clearly see the Finnish coat of arms next to the "hacker".
Reply to this comment
by AppleRules March 31, 2009 2:49 PM PDT
Yes, because it sure wouldn't be possible to put any coat of arms you want in the picture.
Showing 1 of 2 pages (78 Comments)
advertisement

Behind the scenes: NORAD's Santa tracker

For decades, the defense group has let you follow the Christmas Eve travels of the jolly old elf. These days, technology is playing a bigger role than ever.

Intel redesigns Atom chip for Netbooks

The chipmaker officially announces the next generation of its popular Atom CPUs for Netbooks, the N450, weeks before the CES trade show.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right