Low End Mac Reader Specials
TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
Don't install Parallels to play poker online! Poker Mac will show you how
to download and install a native Mac poker application such as Full
Tilt Poker Mac.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.
Compare products like desktop computers, apple laptops, apple macs, and LCD Monitors side by side! All the information and reviews to make the best purchasing decision for new mobile phones, sat nav systems, or MP3 players. The Ciao online shopping community makes searching products easy for you.
Stop the Noiz
Mac Trojans Exploit User Vulnerabilities, Not Security Holes
Frank Fox - 2009.02.03 - Tip Jar
Popularity: ![]()
![]()
![]()
With the news that Trojans have been found in pirated software, is it time to start worrying that Macs are not secure?
Something has changed, right?
Well, the news is important, but don't sell your Mac just yet. There is a big difference between a Trojan and a virus.
Both a virus and a Trojan can do the same things to your computer, but how they get installed is very different. A virus uses a weakness in the operating system to sneak in, while a Trojan uses deception to fool the user into installing it. These differences are important and worth looking at in more detail.
We all need applications to be installed on our computers to get anything done. Most applications run in their own little environment, and if anything goes wrong, the app crashes but the rest of the computer continues to run fine. This wasn't always true, but modern operating systems, like Windows XP and Mac OS X, do a better job of keeping each piece of software running safe away from others.
Some applications, like drivers, can't work alone. They need to work with many other applications. A printer driver has deeper access to your computer than other software. These applications/drivers can be written to avoid the protection of the operating system, because in order to function they has to do more than normally allowed.
Where do these applications get the permission to operate with so much access? From you, the user. That's why you get those alerts when you install or run a new program. The operating system is checking with the user before allowing anything new to run.
Once you run something for the first time, any malicious software code has a chance to run and take over your computer and mess things up. This is okay in the security sense, because you, the user, allowed it to happen. This is why you need to know what you are doing before installing software. (This is why I don't like it when my kids install software from the Internet.)
Trojans
Here is where Trojans come in. They are bad code hidden with good code. This is why the two Trojans were found with pirated software, the legitimate version of this software wouldn't have the Trojans attached. The user who downloads the pirated software unknowingly accepts the bad code when they installed the pirated software. Sure, a "virus checking" program can test for this situation once they learn about the problem, but it may be too late for you if you are one of the first who were downloading the pirated software.
The worst kind of Trojan is a rootkit exploit. This kind of malware is designed to hide itself in the operating system so that even the operating system doesn't know that it is there. This is the hardest to remove. Sony was accused of doing this with the copy protection software on its music CDs. This is not a good practice for legitimate program developers, and Sony had to settle the lawsuit against it.
We know that a Trojan is software you installed yourself - you personally gave permission for it to be on your computer. You were tricked into accepting it, but the computer did nothing wrong in following your request.
An application may be free of Trojans, but there will still be errors in the code (bugs) that usually don't hurt anything. Sure, errors may make the application crash, but the operating system should keep it isolated. The good news is that everyone is constantly trying to find and fix these errors to improve performance and keep things running smoothly.
Viruses
Among the people looking for these bugs are security experts and virus writers. If the security experts find it first, they are supposed to notify the programmers to fix their code. Once the bug is known to virus writers, they start figuring out a way to use the bug to insert bad code (a virus) into a document, picture, webpage, etc. This will trick the application into running the bad code (virus) and allow it to mess with your computer.
The virus writers wait until the day that a patch is announced to write a virus to exploit the flaw. This works, because not every computer is patched that same day - or even that month. They have time to circulate their virus to the unpatched computers and wreak their havoc. The sooner they release their virus, the more time it will have before systems are patched.
The shortest time is the zero day exploit, meaning a virus is written the same day the patch is released. Obviously these flaws are similar to older ones, for a virus to be written so quickly. This shows that the same sorts of mistakes are being made again and again. Constant work is going on to continually exploit computers. This, in turn, means that there is probably a big financial incentive to find and exploit these flaws.
Worms
A special type of virus is called a worm. This type has a way to replicate itself and move onto other computers, often through email or other network connection. The problem with worms is that they spread themselves and can quickly infect millions of computers, as the Conficker worm has been doing for months on Windows PCs.
A virus is worse than a Trojan because it works through applications that you installed in good faith. You have to trust something, and applications from good vendors should be safe. Virus writer are exploiting the flaws for their gain, but some of the problem does fall on the shoulders of the original software vendor for letting easy mistakes through.
Why the Mac has been better at security is whole other story. Finding two Trojans on pirated software doesn't change things much.
Remember that a Trojan is installed by a person who has been
tricked, while a virus fools an application to allow it to run. To be
safe don't run any software you are not sure of, especially pirated
software. Also watch out for strange attachments in emails that come
from people you don't know or who aren't in a habit of sending
attachments.
Recent Stop the Noiz Columns
- Apple's Tablet an End Run Beyond Netbooks, 11.20. Whatever Apple has planned will leverage existing technologies while going beyond what its competitors can offer.
- Psystar Joins Ranks of Dumb Criminals, 11.16. The judge has ruled, and Psystar has been found guilty of illegally using Mac OS X on its computers.
- My Windows 7 Launch Party, 10.23. "The final surprise was that things started to slow down during my demo. I had XP Mode running, several open windows, and a half dozen other apps running."
- Windows 7: Bait for Windows XP and Vista Users, 10.19. While Win 7 is competing with OS X in features, it's target audience is Windows users, not Mac users.
- More in the Stop the Noiz index.
Links for the Day
- Mac of the Day: 17" MacBook Pro Core Duo, Apr. 2006 - The top-end MacBook Pro includes a 1680 x 1050, 2.16 GHz Core Duo CPU, and supports Apple 30" Cinema Display.
- Group of the Day: G4 List is for those using Power Mac G4s or G4 upgrades.
- Support Low End Mac
Recent Content on Low End Mac
- Pismo WiFi Networking Issue Finally Solved?, Charles W. Moore, Miscellaneous Ramblings, 11.24. It turns out the problems wasn't the Pismo, the Buffalo WiFi card, or Mac OS X 10.4. It was the Wireless G router - Linksys to the rescue!
- Mini VGA to S-video Adapter a No Go for eMacs, Dan Bashur, Apple, Tech, and Gaming, 11.24. You might think that Apple's Mini VGA S-video adapter is a cheap way to connect your eMac or G4 iMac to your TV. You would be wrong.
- Google Calendar with iPhone or iTouch Is Great for Scheduling, John Hatchett, Recycled Computing, 11.24. Web-based Google Calendar allows access and updates from any computing platform, including Mac, Windows, Linux, and iPhone OS.
- Why Spaces is My Favorite Leopard (and Snow Leopard) Feature, Charles W. Moore, Miscellaneous Ramblings, 11.23. Spaces, a feature introduced with OS X 10.5, is like having several monitors on your Mac without the cost and space of using multiple displays.
- i5 iMac Benchmarked, Mac mini 'Shouldn't Be Overlooked', Twitter Client for Classic Mac OS, and More, Mac News Review, 11.20. Also why Apple leaves the low end to others, 10.6.2 fixes video playback problem in 27" iMac, 3D Leopard and Snow Leopard performance, and more.
- Apple #4 in Reliability, Apple Tablet a Gadget for All?, HP's i7 Notebook Outdoes Mac Rivals, and More, The 'Book Review, 11.20. Also Flash 10.1 improves video on Hackintosh netbooks, thin-and-light notebooks impress, Windows XP finally on the way out, and more.
- NASA Chemical Sensor for iPhone, Smartphone Death Match, iPhone Earrings, and More, Ian R Campbell, 11.20. Also mobile phone dangers, new apps, GPS solution for iPod touch, new iPod and iPhone cases, and more.
- More links in our archive.
Recent Deals
- Best iPod nano Deals, 11.25. Refurb 8 GB 4G nano, $99; new, $126; refurb 16 GB, $129; new, $150; new 5G/8 GB, $134.60; 16 GB, $161.12. Shipping included.
- Best Classic Mac OS Deals, 11.25. System 6.0.8 floppies, $10; 7.1, $12; 7.5, $20; 7.6 $13; 8.1, $11; 8.5, $20; 8.6, $90; 9.0, $20; 9.2.2, $30.
- Best 15" PowerBook G4 Deals, 11.25. Used 1 GHz Combo, $400; 1.5 GHz SuperDrive, $449; 1.67 GHz hi-res, $600.
- Best G4 iMac Deals, 11.24. Used 15" 700 MHz CD-RW, $150; 800 MHz Combo, $229; 1 GHz, $289; 17" 1.25 GHz, $200; 20" 1.25 GHz, $509.
- Best MacBook Air Deals, 11.24. Used from $899; refurb from $1,099; new 1.6 GHz/120 HD, $1,150 after rebate; 1.8/64 SSD, $1,150 a/r; 1.86/128 SSD, $1,350 a/r; 2.13/128 SSD, $1,694 a/r.
- Best PowerBook G3 Deals, 11.24. Used 233 MHz WallStreet, $75; 266 MHz, $160; 400 MHz Lombard, $199; 400 MHz Pismo, $289; 500 MHz, $350.
- Best 12" PowerBook G4 Deals, 11.23. Used 867 MHz SuperDrive, $348; 1 GHz Combo, $379; SD, $519; 1.33 GHz, $529; 1.5 GHz Combo, $549; SuperDrive, $609.
- Best Mac Pro Deals, 11.23. Used 2.66 GHz 4-core, $1,300; 3.0 4-core. $1,919; refurb 2.66 4-core Nehalem, $2,149; 2.93, $2,549; 2.93 8-core, $4,999; new 2.26 8-core, $2,290.
- Best Time Capsule and AirPort Deals, 11.23. Used 802.11g AirPort Extreme, $49; 500 GB Time Capsule, $150; new, $190; 1 TB dual-band, $280; 2 TB, $469; 802.11n AirPort Extreme, $170.
- More deals in our archive.
About LEM | Support | Usage | Privacy | Contacts
Navigation
Used Mac Dealers
Apple History
Video Cards
Email Lists
Favorite Sites
MacSurfer
MacMinute
MacInTouch
MyAppleMenu
InfoMac
Macs Only!
The Mac Observer
Accelerate Your Mac
RetroMacCast
PB Central
MacWindows
The Vintage Mac
Museum
DealMac
DealsOnTheWeb
Mac2Sell
ramseeker
Mac Driver Museum
JAG's House
System
6 Heaven
System 7 Today
the pickle's Low-End
Mac FAQ
Abandonware
Petition
Mac vs. PC Info
Affiliates
The Apple
Store
Mac
Connection
B&H
MacMall
TechRestore
ExperCom
Crucial
Memory
batteries.com
Advertise
MacMinute
MacInTouch
MyAppleMenu
InfoMac
Macs Only!
The Mac Observer
Accelerate Your Mac
RetroMacCast
PB Central
MacWindows
The Vintage Mac
Museum
DealMac
DealsOnTheWeb
Mac2Sell
ramseeker
Mac Driver Museum
JAG's House
System 6 Heaven
System 7 Today
the pickle's Low-End
Mac FAQ
Abandonware
Petition
Mac vs. PC Info
Mac Connection
B&H
MacMall
TechRestore
ExperCom
Crucial Memory
batteries.com
