Comments on: Bluetooth worm targets Mac OS X
Pest isn't believed to have attacked users yet, but two examples of malicious software to target Mac OS in two days may signal trend.
Pest isn't believed to have attacked users yet, but two examples of malicious software to target Mac OS in two days may signal trend.
January 4, 2010 8:25 PM PST
January 4, 2010 7:20 PM PST
January 4, 2010 7:10 PM PST
Add headlines from CNET News to your homepage or feedreader.
More feeds available in our RSS feed index.
Related quotes
surfaces to announce a worm (that is not even in the wild) that was
effectively squashed 8 months ago, and then call it a trend.
How convenient.
computers that happen to be within, what, 30ft?
Oooh, I'm shaking in my boots.
Upgrade to Windows and have no more problems with BLuetooth infestations!.
nb - Blootooth works up to 100 Metres away!
Upgrade to Windows and have no more problems with BLuetooth infestations!.
nb - Blootooth works up to 100 Metres away!
security hole they expose(to thos hackers to hackers to exploit)
even if your system crashes every second , do not buy any of their
products. if they don't announce it,most hackers won't know about
nowadays. old school hackers knew a lot now they just wait until
these companies reveal the problems
and if someone with a bluetooth device comes near your precious
powerbook or macbook and infects you ,put down your and tussle,
put him down.
advantage of "flaws" that were patched a year ago?
Seriously, in your article you even say "Inqtana is a "proof-of-
concept" worm".... which means... there is no threat.. it's not even
out in the wild.
This is ridiculous.
has been falling for a decade, we can't keep up with the Windows
virus' and we could really use some money.
Signed,
The Anti-Virus Companies
puh-lease.
nonsense in others? MPD!
Show me.
Your not one of those looney ID proponents, are you?
Mac anti-virus software!!
I know that the Mac stuff brings page views to CNet, but seriously, have some professionalism.
looking for non-Windows market share? Too bad. ClamAV works
great on a Mac - and is free.
But I've seen more Windows mobile phones advertised lately and
they are sure to be the next MS platform to be successfully
attacked. So make sure you have a mobile av product ready.
detect.
Check out the University of Hamburg's (authoritative) AV test
results at http://agn-www.informatik.uni-hamburg.de/vtc/
en0407.htm
If you don't want to read that much, they gave Clam a grade of
"useless."
successful Windows worms have exploited old vulnerabilities.
Most people do not patch their systems religiously. And a lot of
people have been burned by past problems with Apple's Security
Updates -- I have two friends who have sworn off installing any
updates from Apple after one of the earlier Security Updates
killed their Airport access.
Face it, two OS X worms in two days -- after five years of
nothing -- is news. It was enough to get me to reinstall my
copy of Norton.
their products. You fell for it.
index.php
call for all of us to closely examine those things we download prior
to making the double-click decision."
Of course some people here are too busy blaming the AV
companies to hear that wake up call. Sucks to be them.
others now reporting proof of concepts as something to be
alarmed about.
Never, ever buy a product from Symantec, F-Secure etc.
Leap also propogates through Instant Messaging. That makes it
a worm.
The fact that humans are involved in its propogation is
immaterial. The same is true of the vast majority of malware for
the PC.
Look, we're all upset to learn that the malware authors have
discovered our beloved Macs. But to claim that the AV
companies are at fault for categorizing the malware using the
same criteria as they use for Windows malware... well, that's just
whining.
"Just a day after experts warned of what is believed to be the
first Trojan in the wild to target Apple Computer's Mac OS X,
alerts are being published on a new worm that exploits an 8-
month-old vulnerability in the operating system.
The new Inqtana worm spreads through a security flaw in
Apple's Bluetooth software, antivirus vendors Symantec and F-
Secure said on Friday. Apple provided a fix for the flaw last June
with security update 2005-006."
The vulnerability is not 8-months old. The announcement is!
Apple fixed this 8-months ago. A little late to be reporting it.
ONE infected machine? (Outside of M$, er, Symantec)
Apple people, how about this? Since your beloved Operating System is so great and secure, don't install ANY AntiVirus, AntiMalware software, and just run free like a nudist on his birthday. Ignore all the warnings anyone gives, and let nature take its course. You'll be fiiine!
Or, grow up! Respect software companies for what they are and stop slandering them! This applies to Microsoft people too. Zealotry will only lead to a lot more crap.
System is so great and secure, don't install ANY AntiVirus,
AntiMalware software, and just run free like a nudist on his
birthday. Ignore all the warnings anyone gives, and let nature
take its course. You'll be fiiine!"
Um... yes i do - I setup a PC on my network and it has viruses on
it before I can patch to SP2 if I plug it into the network.
My iMac on my desk has no antivirus software and is virus and
malware free, no problem.
Do I take off my clothes now?
angers me and I think most Mac users is that both (this and
Leap-A) of these so called proof of concept trojans are poor
proofs but they've gotten attention that should be reserved for
real threats.
Both require an extraordinary set of circumstances to be in place
in order to work at all. This guarantees that neither can be
spread without direct and constant human intervention, making
them hardly worthy of a mention other than the fact that
somebody is making an attempt at writing Mac malware. We've
known that for a long time though, so where's the news?
Is there going to be a trojan that endangers my bank account if I
log in from my Mac as there are for Windows systems? ( http://
news.com.com/New+Trojans+plunder+bank+accounts/
2100-7349_3-6041173.html?tag=nefd.top )
I seriously doubt it. If these two are any indication of what Mac
users have to look forward to, then the future is looking great.
All I have to do to protect my Mac is not be incredibly unlucky
AND not be incredibly stupid at the same time. I think I can
manage that without any 'help' from Symantec. I think my 75
year old mother can manage that too.
Of course, I'm an old school linux geek, so I know how to administer a *nix system.
That said, these viruses are jokes. They don't even work properly, and if you're dilligent in maintaining your updates (not like Apple makes that difficult, as opposed to MSoft) then you have nothing to worry about.
Hell, even when I was on Windows I didn't run any anti-malware software. Why? Becuase I know how to frikkin' take care of a computer, handle patches, I never EVER used Internet Exploder.
And personally, regardless of what OS I hear about a Proof-Of-Concept for, I point it out to friends, and discuss its severity.
Which brings me to my last point. These two proof-of-concepts gave the virus the capacity to do what? Not much- one tricked a user into thinking it was an image (which should teach people about getting images from .tgz files!) and the other requires user intervention to accept the bluetooth file anyway. At that point, you're tricking the user and can do anything you want. Hell, I could whip up a nice little "virus" that IMs itself to all of your friends and formats your hard drive- unless you've properly secured your computer (Don't run as ADMIN!)
Meanwhile, in the Windows world, the last flaw allowed somebody to execute any program on your computer from a WEB PAGE. That too, was a proof of concept, but which one is more severe?
- BULL CRAP
- by Thomas, David February 19, 2006 8:34 PM PST
- Let me get this straight.
- Like this Reply to this comment
-
(40 Comments)It's supposedly a worm, that is supposed to be able to propagate via bluetooth. But it is a "proof of concept" presented by the Symantec and F-Secure, and it is an 8 month old vulnerability that was fixed last June?!
-- proof of concept. Hmm where is it and is it working (but as you will soon see, not)
-- proof of concept. Did Symantec and F-Secure author this worm to sell their software?
-- 8 month old vulnerability that was fixed last June. By my calculations, (can't stop laughing), then it must have been a vunerablitity for about a day, and therefore does not even exist.
-- 8 month old vulnerability that was fixed last June. How the hell can it be 8 months old when it was fixed last June?! Stranger and stranger.
-- Furthermore, it uses a Bluetooth component that is locked to a specific address, that expires next week. What the hell does that mean?! Did F-Secure create some kind of temporary device to try and infect one of their "test" machines?!
What in the world is really going on? Symantec can't sell software to Mac users, and Mac users are growing in numbers. As a result they result to a campaign of fear, and smear? If they keep this up, they might just find themselves in a whole hell of a lot of legal trouble.
Sick of this.