Security experts: 600,000-plus estimate of Mac botnet likely on target
#1
Posted 06 April 2012 - 03:01 PM
#2
Posted 06 April 2012 - 04:33 PM
It's a JAVA exploit, the same JAVA that runs on every supported platform.
#3
Posted 06 April 2012 - 05:25 PM
#4
Posted 06 April 2012 - 06:11 PM
#5
Posted 06 April 2012 - 06:11 PM
#6
Posted 06 April 2012 - 08:21 PM
Security "expert": 600,000 estimate of Mac botnet disputed
There is not agreement that the 600,000 reported by 1 source are all Macs and not another OS.
In a con game, an expert is a stranger that someone we trust has told us is knowledgeable on a subject.
#7
Posted 07 April 2012 - 04:34 AM
#8
Posted 07 April 2012 - 07:02 AM
lkrupp, on 06 April 2012 - 05:25 PM, said:
do you think ClamX is up to this particular job?
#9
Posted 07 April 2012 - 07:09 AM
LelandHendrix, on 06 April 2012 - 04:33 PM, said:
It's a JAVA exploit, the same JAVA that runs on every supported platform.
It's a Java exploit that targets folders and files that are only present on a Mac. Thus it's Mac specific.
But glittering prizes and endless compromises
Shatter the illusion of integrity."
-Rush
#10
Posted 07 April 2012 - 08:02 AM
#11
Posted 07 April 2012 - 08:42 AM
klahanas, on 07 April 2012 - 07:09 AM, said:
LelandHendrix, on 06 April 2012 - 04:33 PM, said:
It's a JAVA exploit, the same JAVA that runs on every supported platform.
It's a Java exploit that targets folders and files that are only present on a Mac. Thus it's Mac specific.
In all fairness, there are multiple versions of Flashback. It is not clear that the 600K number is referring only to the latest Mac flavor.
#12
Posted 07 April 2012 - 09:06 AM
k88dad, on 07 April 2012 - 08:42 AM, said:
klahanas, on 07 April 2012 - 07:09 AM, said:
LelandHendrix, on 06 April 2012 - 04:33 PM, said:
It's a JAVA exploit, the same JAVA that runs on every supported platform.
It's a Java exploit that targets folders and files that are only present on a Mac. Thus it's Mac specific.
In all fairness, there are multiple versions of Flashback. It is not clear that the 600K number is referring only to the latest Mac flavor.
The 600K number is the latest Mac flavor, and was measured as such. Older variants of this malware are obsolete. To your point, which I will take as a "best case" scenario, see the link below.
http://www.securelis...otnet_confirmed
Exerpted from above link:
"We have used passive OS fingerprinting techniques to get a rough estimation. More than 98% of incoming network packets were most likely sent from Mac OS X hosts. Although this technique is based on heuristics and can’t be completely trusted, it can be used for making order-of-magnitude estimates. So, it is very likely that most of the machines running the Flashfake bot are Macs."
But glittering prizes and endless compromises
Shatter the illusion of integrity."
-Rush
#13
Posted 07 April 2012 - 09:20 AM
klahanas, on 07 April 2012 - 09:06 AM, said:
http://www.securelis...otnet_confirmed
Exerpted from above link:
"We have used passive OS fingerprinting techniques to get a rough estimation. More than 98% of incoming network packets were most likely sent from Mac OS X hosts. Although this technique is based on heuristics and can’t be completely trusted, it can be used for making order-of-magnitude estimates. So, it is very likely that most of the machines running the Flashfake bot are Macs."
Thanks for the research. My main point is that Macworld is not including enough info in these articles. Let me rephrase my previous statement to: It is not clear from this article... Most of my knowledge on this is coming from a large number of websites that are not necessarily Mac-oriented.
#14
Posted 07 April 2012 - 09:35 AM
lkrupp, on 06 April 2012 - 05:25 PM, said:
Same here. Apparently the Flashback malware doesn't install itself if ClamXav or other anti-virus apps are already installed. To "avoid detection."
We use ClamXav, and we've donated to the developer.
Help













