This Weeks Topics
This week I discuss Mavricks and iOS 7, the rumor mill of badBIOS, hoax, bad day or something else.
Finally, you can expect to hear more regular podcast in the future. A project that was a game changer for Magmatic has now been completed. We expect 2014 to be a real game changer for us. We have lots of tools and ideas we are really excited about.
iTunes Preview
This Weeks Topics
This week I discuss Oracle's Java 1.7.0_09 for Mac OSX. While the System Preference Pane is a welcome addition it would be nice if it actually worked.
After several months of using Gatekeeper it is official, I love it and you should too. Gatekeeper provides a host of protection against rouge developers. Best of all it stops rouge Java APPS in their tracks.
Sandy reminds us all of what is important, that includes having a backup of critical data and the capability to keep your customer facing resources up and running.
iTunes Preview
This Weeks Topics
Adobe Flash, Reader, Acrobat and Shockwave Updates
iOS SMS Spoofing and Phishing
This week we discuss the recent Adobe updates. While no specific threat in the wild currently targets Mac OSX there are zero days targeting unpatched versions on the Windows platform. Criminals have regularly used the Adobe update cycle as cover to fool Mac users into installing malicious software, usually in the form as a Flash Player.
SMS protocol is vulnerable to spoofing, this includes all version of iOS. A recent release of a tool to make this process easier can allow a criminal to create SMS Phishing messages, what is called SMiShing. The pattern is similar to email phishing as are the defenses, do not visit links sent via unsecure comminication. There are a host of tools that this proof of concept was built off of. Some that requirer your iPhone to be Jail Broken, something you should never do. (See Reference Links) I consider this really low risk. Using iMessage prevents this form of attack, so for clients or users that are Mac/iOS based use iMessage.
Lastly I have some thoughts on Cloud based services. It is important that businesses and users realize that while the data is in the cloud, the responsibility for compliance and security is completely their responsibility.
iTunes Preview
This Weeks Topics
Social Engineering iCloud, The Curious Case of Mat Honan.
Gatekeeper Code Signing.
Summary
This week I give my take on the Apple ID account compromise of Former Journalist for Gizmodo, Mat Honan. I address some of the issues companies have to consider when working with Free-lancers who bring their own devices or their own eco-systems into your security umbrella. There are various Risk that need to be considered from a host of perspectives. I explain why it is important to have control over your backups.
Next I touch on the issue of code signing in Mountain Lion. User can override and set exceptions but the only way to manage these exceptions from the administrator perspective is via a command line tool called spctl. I argue that for most users and organizations, code signing make security sense and eliminates RISK, especially if code review is outside the scope of your business.
Finally, my commentary on why now is the day to turn off Java on your Mac, eliminate the RISK of crime ware using Java.
iTunes Preview
This Weeks Topics
Drop Box Spam
Icon Decoys
Java RISK and Updates
Summary
This week I address something old and something new. What do we need to consider after the recent revolation by Dropbox that an employee was compromised resulting in malicious actors gaining access to the email addresses of account holders.
I then discuss the social engineering method of Icon Decoying. A method that has been used over the last several months by criminals with mixed success.
Last we discuss Java and touch on how to manage RISK using the Java Preferences.app.
iTunes Preview
Imuler.c, reported by Intego, is a low risk icon decoy social engineering attack. In MacOSX the user you can simply copy an icon to another file by using "File>Get Info (Comand-I)" in the Finder.
Summary Within a zip file the criminals hide an Application with an icon that looks like an image along with other image files. The decoy is an attempt to get the user to click on the Application and run the malicious file.
FACTS * This is a social engineering attack based on an attack method dating back to Mac OS 7 (Pre-OSX). * The stratergy of the attacker is Icon Decoying. * Users can turn on view extensions or use detail list to see the file type. (This is not really needed.) * MacOSX will prompt the user if they try to open a file for the first time downloaded from the internet. * You need to be the administrator to install or run the malicious application. Enterprise managers should manage these options in Mac OSX.
Figure 1: Warning Dialog for downloaded Application from Internet
RISK Imuler.C as all of it's previous versions are VERY LOW RISK. The attack method is similar to the PDF decoy in September 2011. The Application with the Icon Decoy is an attempt to use tactics decades old.
MITIGATION * Do all your computing as a general user, not the administrator. This stops most malicious installers in there tracks. * Do not open files from un-trusted sources. * Make sure that if you open an Application that you downloaded that you confirm the (HASH). * When you first open a file downloaded from the internet you will recieve the dialog in Figure 1, make sure that you trust that application. * Optional : Turn on "Show all applications extensions" in Finder>Preferences>Advance. * Enterprise administrator can manage what applications user can and cannot run. * Enterprise adminstrators should rely on the priciple of least privileged for application exectuion for users.
Apple has announced today a new System Preference Pane and Core Service called Gatekeeper along with other features of OX Mountain Lion. Gatekeeper will allow the user or Mac Systems Administrator to control the installation of software allowing them to ensure that only software signed by an Apple developer from the Mac APP store can be installed.
The iPhone ecosystem has been making it's way on to the desktop of Mac OSX users and developers for sometime. Mobile operating systems are influencing what we can expect in the coming years on our laptops, desk tops, servers, PaaS and computing devices. (For my PC friends, wait until you see Metro.) Gatekeeper will be a game changer because Apple has the capability to implement it effectively. It is my thinking that this adds a layer of protection and control that is long over due. Basically, this control will, at the user's/admin's discretion, result in the Mac OSX platform to truely mimic the iOS application code signing ecosystem. (Only code signed by a Mac developer can be installed with additional options.) Clearly as has been demonstrated by iOS sand-boxing approach, what once was thought of as restrictions now are considered an excellent balance of protection verse features. But why stop there?
I have long been an avocate for administrators creating their own seat-belt profile files(.sb) to enhance the settings already used in MacOSX. I expect additional controls including seat-belt in a very user friendly control pane as well in the not to distant future. Many applications and users do not need access to the file system, particular frameworks or networking. (Yes, there are other way to control this and Apple has added these controls to XCode for developers to implement. Figure 1) Allowing users and administrators a simple manner in which to manage these very complicated controls over applications and their privileges seems a logical next step in porting some of the security features from iOS to the desktop.
Currently XCode 4.2.1 build 4D502 allows developers various sandboxing controls as of Lion.
Of course, Gatekeeper is not a perfect solution, nothing is, once you create a system there are flaws. Gatekeeper provides the user/administrator with an additional technical tool to enhance Mac OSX's security robustness. The technology is not new and various technical aspects have been discussed for some time by many researchers. Apple's controls at various levels including development, distribution, installation and administrator has lots of potential. However as with any security schema the devil is in the implementation. What makes this a game changer is that Apple, largely due to the success of the iOS ecosystem, is extremely capable of implementing Gatekeeper along with these other security controls in a way that will matter.
Ade Barkah has posted on his site Peekay.com details about his discovery of a bug in iOS which allows access to the camera roll when the device is locked. Rolling back theDate & Timewill allow unauthorized access to any photos that were already taken on any future Date & Time.
Summary If the Date & Time IS ROLLED BACK on an iOS device running 5.x a malicious actor will have unauthorized access to the photos with future dates and times in the camera roll.
FACTS * Rolling back the Date & Time on a device running iOS 5.x will allow access to the camera roll on a locked device to images with only with future dates and times.
RISK There is a RISK that if you travel across time zones and your Date & Time is rolled back a malicious actor with physical access to your device can access your camera roll without the need for a Passcode and access photos taken between the two times.
Overall RISK: LOW RISK
Mitigation General Users
Make sure that Set Automatically is enabled in General>Date&Time to ensure that your device has the current Date & Time for your current Time Zone.
Set Automatically Date & Time
This will ensure correction by your location's temporal condition until Apple's update.
Result-ResidualRISK: Extremely Low RISK (Pending Update.)
High Value Users
Restricting the Camera ensures that this bug will not be triggered. High value users should considered this option when traveling. This can further be managed by using Configuration and Provisioning Profiles which includes the capability to configure Restrictions on iOS devices. Enterprise managers can manage restrictions using the iPhone Configuration Utility.
The site blog.chpwn.com has reported that there is a version of Carrier IQ within Apple's iOS 5.x.x. I am sure that by now you have read the reports about Carrier IQ being discovered on mobile devices by Trevor Eckhart. The analysis on blog.chpwn.com is missing some key details as it relates to iOS 5.x.x that are useful in managing any RISK. To help users make informed decisions and understand the risk involved we will provide full details related to Apple's "Diagnostic & Usage Data."
Summary In iOS 5.x.x you do not need to Jail Break the Phone and finding the information collected does not require technical expertise. (Just have to know where to look.) What is most important to note is that the data is anonymous and users have complete control. Turning off "Diagnostics and Usage" along with System Services Location will prevent any reporting. Users can view and disable the sharing of data on their iOS device running 5.x.x at anytime. What is collected, transmitted and how a user manages the collection of data is clearly stated in Apple's "About Diagnostics and Privacy" statement.
The improvements in the management of the data can be traced back to April 2011, when it was discovered that Apple was in fact tracking users location data. The result of that discovery has resulted in Apple providing a clear and concise way in which users can manage "Diagnostic & Usage Data." So after all there is something to be said for a company being scared straight.
Checking Your Diagnostic & Usage Files and Settings Apple iOS 5.x.x during the inital setup phase will ask the user if they would like to share "Diagnostic & Usage Data." (This is disabled by default.) If a user enables this option data about the phone including location data related to cell service will be anonymously collected and sent to Apple. It is really easy to turn this option on and off and to review the data that has been collected and transmitted if the option is enabled.
If you go into Setting>General>About>Diagnostic & Usage you are presented with the following screen. On this device below automatically send diagnostic and usage data is turned on.
Diagnostics & UsageIf you select "Diagnostic & Usage Data" you will see a list of files the collected data if the phone had "Automatically Send" enabled at some point. The file format is awdd_
aawd File ListIn addition to crash logs and calibration information the files contain information about the iOS 5.x.x device but all device information remains anonymous. Apple clearly explains what data is collected and how a user can manage it, more on that in a moment.
awdd Example one
Notice that the isAnonymous key <value is set to TRUE. You can also view all of the other key
awdd Example Two
This awdd data files also contain diagnostic information related to applications and hardware, the example below is specific to the camera.
com.apple.camera Example
Turning Off Reporting of Diagnostic & Usage
Turning off the collection of "Diagnostic and Usage Files" is very easy to do, you simply select "Don't Send" in Settings>General>About>Diagnostic and Usage.
Turning Off Diagnostic and Usage DataNo data or crash logs will be shared or sent but the files created will remain on the device for a undetermined period of time (Update Pending). They also remain in any backups of any iOS device backup. If you want to achieve a zero impact foresic foot print as it relates to these files you must setup the device initially with "Don't Send" selected.
Turning Off Location Services As stated above a major issue back in April 2011 was the discovery that Apple was collecting location data of users. Location data is a double edge sword no matter the device in question. (When it comes to mobile devices device=user.) The profile of the user predetermines all specific location settings for Applications and System Services. (For example a high value user would have a different location settings profile as compared to a low value.) At the enterprise level these can be managed with iPhone Configuration Utility.app.
If you have "Diagnostics & Usage" set to "Automatically Send" and enabled the location based services for the system service "Diagnostics & Usage" in the Settings>Location>Services>System Services window, cellular data related to your location is shared anonymously. You can turn this off in Settings>Location>Services>System Services and toggle "Diagnostocs & Usage" to off.
Location Services System Services
Apple's Diagnostics and Privacy Apple has a plain language privacy policy when it comes to diagnostic data collection along with clear instructions on how to turn it off. That infomation can be found on every iOS device running 5.x.x at Settings>General>About>Diagnostics & Usage. If you click the "About Diagnostics and Privacy" on the bottom of the view the following will appear.
Apple Diagnostics and Privacy
Facts
* iOS 5.x.x Diagnostics & Usage data is anonymous.
* iOS 5.x.x Diagnostics & Usage data reporting can be turned off.
* iOS 5.x.x is Diagnostics & Usage data uses SysInfoCrashReporterKey as a key
RISK Poor management, limited knowledge and misleading information represent the Highest Degree of RISK related to iOS 5.x.x "Diagnostic & Usage" reporting.
iOS 5.x.x "Diagnostic & Usage" RISK can be mitigated with management of your iOS settings.
The RISK to user privacy is LOW in iOS 5.x.x as it relates to "Diagnostic & Usage" reporting.
Mitigation Individual user or system profile must determine all Applications and System Services specific location and "Diagnostic & Usage" reporting settings.
It is not recommended to provide any "Diagnostic & Usage" data or location data for any high value system or user.
General users should consider disabling "Diagnostic & Usage" reporting and turn off location services for this system service. Residual risk remains such as interception and physical access compromise thus consider additional mitigation.
Addition Mitigation
Additional Notes
Test done on iPad 2 and iPhone 4s running iOS 5.0 and 5.0.1. Due to our specific privacy policiy some information has been removed. To contact us please use the following form here.
Apple has released iOS 5.0.1 to address an array of concerns including the battery life issue reported by some users.
This update also fixes the unsigned code access to Standard Data Management and Frameworks demonstrated by @0xCharlie (Charlie Miller). His discovery exposed a weakness in Apple's code approval process. There is NO THREAT to the general user population.
The logic error discovered by @0xCharlie took advantage of failures in mmap system calls checking of flags. This allowed any application to execute code at a level similar to Mobile Safari. Malicious Applications could use objects/classes such as NSURL, NSURLRequest, NSURLConnection and NSXMLParser to fetch additional code to execute in memory from a remote source.
This opened a possible pathway in which a malicious actor can execute unsigned code or possibly launch a more complex exploit. Charlie Miller's application represents no threat to any user. However malicious actors have the capability and technical knowledge to duplicate his findings very easily.
Users should update their version of iOS immediately on compatible devices.
Apple will be rolling out iCloud over the next couple of days. Apple has released iTunes 10.5 as a first step today.
What's new in iTunes 10.5 (From Software Update.)
iTunes in the Cloud. iTunes now stores your music and TV purchases in iCloud and makes them available on your devices anywhere, any time, at no additional cost.
Reuse of code in crimeware kits and tools targeting Windows infrastructure via Java has been building momentum. Java is a cross platform environment which can allow criminals to take advantage of systems regardless of operating system. For example, much of the crime ware kit call BlackHole RAT is still written in Java and Real Basic. We still consider this kit Low Risk.
It is our thinking that in the case of JAVA, due to the cross OS nature and Apple's custom update cycle, it continues to be the attack vector platform of choice.
Ways to Eliminate any Threat from malicious JAVA Applets If you do not need or use Java than disable it in Safari.
Suggested Setting in the Java Preferences.app to Protect Your Mac * In /Applications/Utilities/Java Preferences.app disable "Allow User to grant permissions to content from an untrusted authority." * In /Applications/Utilities/Java Preferences.app disable "Use certificates and keys in browser keystore" * In /Applications/Utilities/Java Preferences.app disable "Use personal certificate automatically if only one matches server request." * In /Applications/Utilities/Java Preferences.app enable "Enable blacklist revocation check." * In /Applications/Utilities/Java Preferences.app enable "Check certificates for revocation using CRL" * In /Applications/Utilities/Java Preferences.app enable "Enable online certificate validation" * In /Applications/Utilities/Java Preferences.app enable Verify mix security code. "Enable-don't run untrusted code, no warning." **This should be reviewed based on business needs. * Review Trusted Publishers in Security pane.
Java Preferences.app also allows the user control over the cache and storage space used.
Consider each option based on your specific business needs. For example, if you are developing jar/applets internally consider reviewing of the signing process to insure that all internal app/jar used for production systems and properly signed by your organization. You may also want to disable Java or create a custom seat-belt file.
Recently F-Secure has reported they may have come across a Mac Trojan. The operative word being "may" from their original post which was not picked up by additional press accounts. (F-Secure is a five start organization, not that they cannot make errors but they are a gold standard when it comes to accurate disclosure.)
This PDF Decoy Malicious Installer is actually an attempt to use tactics found on the Windows platform by sending rouge documents that an unsuspecting user will open up. The taxidermy of the Windows attack attempts to execute a malicious application, open a malicious site or exploit a vulnerability in the Adobe Product line or Microsoft's Product line. In this particular case targeting Mac OSX there are very important key differences.
This is not a TROJAN running from a PDF taking advantage of an exploit or vulnerability. It is NOT EXPLOITING ANY KNOW FLAW at all, it is however using a host of deceptive tactics. It is a rouge Package Installer that installs and opens a PDF DECOY to cover up the installation of an additional services (Apache) without getting the user suspicious. In it's current form it is the technical equivalent of putting a square peg into a round hole.
How it Works The PDF Decoy Rouge Installer PACKAGE runs additional scripts after the decoy is installed and opened up on screen. Using combinations of Preinstall scripts, Post Install scripts and/or Actions within the Package the scripts will attempt to install and/or download additional services. (We have encountered a version which installs apache.) The developer of this malicious package has attempted to use an application which cleans itself up, similar to the one used in latter version of MacDefender, AVRunner. (Class Diagram) The good news is that a properly configured Mac will mitigate this PDF Decoy Installer. This represent a LOW RISK threat in its current form.
Reports of Changing Extensions to Execute PKG Files are WRONG! If you change the extension of a file in Mac OSX to one that it is not compatible with it will not execute or open. For example, a DMG, MPKG or PKG file that has had its extension changed to .PDF it WILL NOT open or execute. What will happen is that an error will be generated.
Fig. 1.1 Firefox DMG file extension changed to .PDF
Primary Mitigation Currently XProtect has been updated and will recognize this installer. In Apple Menu>System Preferences>Security & Privacy Make sure to have "Automatically update safe downloads list" Enabled for automatic updates of XProtect. (If you toggle this option it will update but make sure to do a "Show All" to save your settings. Advanced users can update XProtect manually** by doing the following:
It is important to realize that a developer can bypass the need for the user to enter the Administrator Password when creating an installer Package. The best defense is not to perform general computing as an administrator. This will limit what and where files can be installed. The administrator account type in Mac OSX is the equivalent of root and has full rights to install and write to a host of directories. You must use a standard user account for all your computing.
Fig. 2.1 Installer Failing Standard User Account
In larger deployments of Mac OSX systems protect the administrator account as you would root using layered administrative permissions and sudo to execute system altering commands. (Administrator's should never have full access to root privileges and all activities should be audited.)
Mac OSX System
Safari
For Chrome
Secondary Mitigation * We also recommend that you only install Applications that come from trusted sources or from the Mac App Store. These are digitally signed so their is trace back to the developer. * Consider installing an Anti-Virus product. We love F-Secure and Intego.
RISK The RISK related to this PDF Decoy Malicious Installer is LOW.
We continue to monitor how this evolves since the tactics are similar to larger scale Phishing attacks designed to create a beach front into an sensitive internal systems of high profile organizations. Due to recent system updgrades at previously targeted companies of users in certain departments and groups to Mac OSX systems, these actors are attempting to discover how to use their old tactics to create new jump off points to internal compromises.
**Apple does not recommend doing this from the command line and users should consider the risk. For the general user setting the system preferences should suffice. This solution is ideal in larger managed environments.
Directory Services Command Line (dscl) allows authenticated users to change various settings including their password. We wanted to provide some clarity to the RISK and avoid headlines, little detail or poor analysis. Below we provide all the facts along with mitigation technics to limit the effectiveness of a this type of physical access attack. It is our desire to clear up misconceptions so that users and administrators have a clear understanding of the Risk and mitigation methods to take.
Background
This issue reported by the blog Defence in Depth and than picked up by various news outlets states exactly what dscl does. (See man dscl) We think that this issue was reported without proper quantification of risk. dscl allows users to alter their setting in directory nodes they are authenticated to. (See man dscl) If you are a root user or administrator you can alter every user.
Facts -A user authenticated in Mac OSX Lion can from the terminal use the Directory Service Command Line Utility to set various options to the directory node the user is authenticated to.
-Using the dsl command with the -passwd option a user that is already authenticated can change their password without having to provide the old password.
Last login: Tue Sep 20 07:18:30 on console
Box23Lion:~ joeuser$ dscl localhost -passwd /Search/Users/joeuser
New Password:
-This is clearly stated in the man page for dscl -passwd option:
passwd
Usage: passwd user_path [new_pasword | old_password new_pasword]
Changes a password for a user. The user must be specified by full path, not just a username. If you are authenticated to the node (either by specifying the -u and -P flags or by using the auth command when in interactive node) then you can simply specify a new password. If you are not authenticated then the user's old password must be specified. If passwords are not specified while in interactive mode, you will be prompted for them. Passing these passwords on the command line is inher-ently insecure and can cause password exposure. For better security do not provide the password as part of the command and you will be securely prompted.
-As an account with Mac OSX Administrator or as root privileges you will be able to change any user's password. This is why you should never do general computing as the root user.
-The original Key Chain cannot be accessed without the old password, thus your saved passwords are protected.
-The File Vault Recovery Key and Password will continue to work.
Myths Myth-You can change any users password and lock them out of the system.
If the malicious actor has physical access to a logged in account with Administrative privileges they can make it difficult for a user to gain access. Any password change will not affect the users keychain which stores saved passwords and developer certificates, the old password is required to access that key chain. They will not have access to chainging FileVault Settings.
Using an Administrator account for computing is extremely bad idea, MacOSX is Unix thus privileges come with responsibilities. Create a general account that for doing your daily computing task. If the Administrator password is changed resetting it is an easy task.
Myth-A general user can change any password they want.
One hundred percent false, as a non-administrative user cannot change the password of any user other than themselves. Read the man page above.
Box23Lion:~ joeuser$ dscl localhost -passwd /Search/Users/aliceuser
New Password:
Permission denied. Please enter user's old password:
passwd: DS error: eDSAuthFailed
Myth-I can be locked out of my system.
If a malicious actor gains physical access to a command prompt with root or Administrative privileges and changes the user or root account all is not lost. You can use your Lion Emergency Disk or Lion Recovery Disk Assistant.
Primary Mitigation Never do computing as the Administrator, set up an Administrator account and a user account. Do all your computing as the user. Mac OSX has various layers of protection, use them. Shame on any organization or user who continues to operate in this manner or falsely confuse users instead of educate.
Secondary Mitigation In System Prefences>Security & Privacy ensure that "Require Password immediately after sleep.." is selected.
In System Prefences>Security & Privacy ensure that "Log out after 2 minutes of inactivity" is selected.
For organizations with multiple administrators, never give your administrators the keys to the castle. Have specific administrative accounts that are logged and audited.
Make sure to setup File Vault and to store your recovery key in a safe place.
RISK The risk of this type of attack is LOW due to the need for the attacker to have physical access and administrative privileges.
We believe that already poorly configure MacOSX machines will be vulnerable to this and a host of physical attacks.
Disappointment We are disappointed that there continues to be an issue with dscl, which has been reported to Apple in the past. The user should be prompted again to enter their password even if they are already authenticate to the node. At that same time there is no weakness or true flaw, just bad implementation. We also think that the combined layers of protections in Mac OSX mitigate this risk, similar to all physical threats. So the real Risk we rate as LOW.
There is nothing to discover or new here except that someone read the man page for dscl who may have not done before. Due to the limited understanding about how best to secure MacOSX a LOW RISK flaw has become poorly reported on and explained.
We expect better and have done so here.
There have been inaccurate reports that the MacGuard installer bypasses the administrator account. This is false, what it does is take advantage of users who are doing general computing task such as Web Surfing, Email and Word Processing as the Administrator account. On MacOSX, this account has access to write to the application folder. MacGuard is taking advantage of poor deployment, not a complex circumvention of the Administrator Privileges.
The Facts
Fact- YOU MUST BE THE ADMINISTRATOR ACCOUNT ON THE MAC TO INSTALL MACGUARD.
Fact- If you are not the administrator account or an account that is in the administrative group the installer WILL NOT INSTALL MacGUARD.
Trying to install MacGuard not as the Administrator
Fact-When you visit a page hosting MacGuard, the new variant of MacDefender, after the common fake scan in the browser window the user is promoted to download MacProtector.mpkg.zip
Fact-The Zip file contains avSetup.pkg which installs /Applications/avRunner.app.
Fact- avSetup.pkg has two postinstall scripts called postinstall and avSetup.post_install which run /Applications/avRunner.app
Fact-acRunner.app connects to a nginx server as the User Agent: avRunner/1 CFNetwork/454.11.12 Darwin/10.7.0 (0000) DDDDDDDDDDDDDD
Fact-acRunner.app downloads MacGuard.app.zip
Fact-acRunner.app unzips the file, removes the zip and places MacGuard.app into Applications.
Fact-This can only happen if you are the Administrator or an account with Administrative Privileges.
Fact-MacGuard can be removed using the manual method and our script.
We have created a script to help you remove MacProtector and MacDefender which you can download below. Please note that this is not Anti-Virus product, this is only a script which removes these particular malware applications. Users should backup their computer and confirm the hash below the file download. We have used it successfully and will have an improved on by Sunday.
The instructions are as follows after unzipping and mounting the Disk Image File.
Close MacProtector's or MacDefender's annoying window and stop any scans it is performing, THEY ARE FAKE!.
Double click on RemoveMacDefenderProtector.
You will be in the Applications folder, scroll down and find either MacDefender or MacProtector, MacSecurity.
Choose the one you wish to remove and eventually the MacProtector/defender indicator will close.
If you have any questions please use the contact form on our site. For more information about our investigation please see our draft report page. Please note, our site has no ads and we do not wish to track your. This script we have used with our clients and have determined that we can release it publicly.
System requirements- MacOSX 10.6
MagmaticMalwareRemove5_02v.dmg.zip
SHA(MagmaticMalwareRemove5_02v.dmg.zip)= dc795ac2fcc92a284802090048a20e38e147918e
http://magmatic.com/storage/publicscript/MagmaticMalwareRemove5_02v.dmg.zip
That recent malware that targeted Mac OSX systems, MacDefender and MacProtector, are fake anti-virus products designed to steal users personal information including credit card accounts. We think version OSX/MAcDefender.F tries to steal two credit card numbers by bouncing one and directing the user to another site. Below is our pending draft analysis for OSX/MacDefender.A , OSX/MacDefender.D and OSX/MacDefender.F.
Our analysis includes takeaway’s of the evolution of key inherited traits within each rouge application followed by an detailed technical breakdown or the woking three variants we have. Our format is broken into stakeholder sections for executives, users, researchers and experienced MacOSX administrators. This report is a draft and may change without notification.
Excerpts From Our Analysis
Files
/Contents/MacOS/MacDefender (OSX/MacDefender.A)
MD5(MacDefender)= 2f357b6037a957be9fbd35a49fb3ab72
SHA(MacDefender)= 470e1c99d7b5ec6d00b26715f4fa37bc70984fb4
/Contents/MacOS/MacProtector (OSX/MacDefender.D)
MD5(MacProtector)= 1f8e9cd3f0717a85b96f350e4f4a539a
SHA(MacProtector)= 361ba7b420e1a9ec0af5f7811e84dc95d04624a9
Added 05_21_2011
/Contents/MacOS/MacProtector (OSX/MacDefender.F)
SHA(MacProtector)= a94bd6a52bcb275a8ff1cd15977167f709b7ab04
UPADTE PENDING
MacProtector (OSX/MacDefender.F)
It is our theory that this version of MacProtector will trick the user into to providing two credit card numbers by directing them to two separate sites. It also can ensure that if one site is down the other will continue to steal credit cards.
//
@interface URLMaster : NSObject
{
}
+ (id)getBuyPageIP; // IMP=0x000000010000f1f7
+ (id)getBackupBuyPageIP; // IMP=0x000000010000f1e8
+ (id)getSoftInstallLink; // IMP=0x000000010000f391
+ (id)getBuyPagLink; // IMP=0x000000010000f30d
+ (id)getBackupBuyPageLink; // IMP=0x000000010000f289
+ (id)getSendTicketLink; // IMP=0x000000010000f0a8
@end
@interface URLMaster : NSObject{}
+ (id)getBuyPageIP; // IMP=0x000000010000f1f7+ (id)getBackupBuyPageIP; // IMP=0x000000010000f1e8+ (id)getSoftInstallLink; // IMP=0x000000010000f391+ (id)getBuyPagLink; // IMP=0x000000010000f30d+ (id)getBackupBuyPageLink; // IMP=0x000000010000f289+ (id)getSendTicketLink; // IMP=0x000000010000f0a8
@end
Downloads-DRAFT Update-Draft report v2.
Magmatic_Analysis_MacDefender_MacProtectorv2Draft.pdf (MAJOR UPDATE PENDING)
SHA(Magmatic_Analysis_MacDefender_MacProtectorv2Draft.pdf)= 72b17c4250da23ae3c744fb26508d2b1889ae49e
Draft report v1
Magmatic_Analysis_MacDefender_MacProtector(DRAFT)
sha=5a708a3751c3ddd7bf38fcf240d8abc676514452
Magmatic_Analysis_MacDefender_MacProtector(DRAFT)
sha=c20f74b6eef02667033ddf50ff8a4ef1a10c7f13
Class Diagrams MacProtector (OSX/MacDefender.A)
OSX_MacDefender.A_ClassDiagramDraft2.pdf
SHA(OSX_MacDefender.A_ClassDiagramDraft2.pdf)=d4b9902967f842773a563b215cae49ac5d3bde40
MacProtector (OSX/MacDefender.D)
OSX_MacDefender.D_ClassDiagramDraft2.pdf
SHA(OSX_MacDefender.D_ClassDiagramDraft2.pdf)= 2a92c951b9378d2370d559cbcbce873660fcc12d
MacProtector (OSX/MacDefender.F)
OSX_MacDefender.F_ClassDiagramDraft2.pdf
SHA(OSX_MacDefender.F_ClassDiagramDraft2.pdf)= 2b80717c46157cd2606dcbe6a7817e5993fb7ace
Class Dumps MacDefenderOSX_MacDefender_A_ClasssDump (OSX/MacDefender.A)
SHA(MacDefenderOSX_MacDefender_A_ClasssDump.txt)= 5087f008da46bdd3cfacaf1be9d3729f19916f65
MacDefenderOSX_MacDefender_D_ClasssDump (OSX/macDefender.D)
SHA(MacProtector_OSX_MacDefender_D_ClassDump.txt)= a53cc5a8c9cd2f19726e56beed8b07a097d7b8e2
MacDefenderOSX_MacDefender_F_ClasssDump (OSX/MacDefender.F)
SHA(MacProtector_OSX_MacDefender_F_ClassDump.txt)= f26c0091ab26b1ca998d8f58e9ee133d967c5bd8
**Note-This is draft data and contains raw information, final release of the document and addition updates will be located at here. All information is provided as is and falls under the copyright located on this site and within the draft report. Any questions use the Contact Us Link and put "MacDefenderProtector Report" in subject line.
Background * MacDefender, MacProtector, MacSecurity and MacGuard are all rouge mac Anti Virus products. * They are crime-ware designed to steal your Credit Card information. * Created by Criminals out of Russia.
What if I purchased it? Call your Credit Card company and report the card compromised. Review all charges on all your accounts. Remember they also have you address and phone number so exercise caution to phone solicitations.
How to remove MacDefender, MacProtector and MacSecurity if I installed it? 1. Open the Activity Monitor in the Applications/Utilities/ directory.
When the Activity Monitor opens up find the rouge application based on its name from the process list. Once you find either MacDefender, MacProtector or MacSecurity select it in the list.
Quit the Process.
Trash MacDefender, MacProtector or MacSecurity
Move the application to the
thrash and then select
Finder>Secure Empty Trash.
Go into your Apple Menu>System Preferences and open accounts. Select you account and tab to the Login Items Pane.
Make sure that once you are done to change your password and all other passwords on the Mac. Close System Preferences and then restart your Mac to ensure removal.
Check Safari and Chrome consider the following settings.
Do not install any program that installer open directly from the Web.
If you still are having problems removing MacDefender, MacSecurity and MacProtector and your computer is within the United States we can help. Go to the Contact Page and put Remove into the Subject and we will contact you to see if we can help. We are only asking for suggested payment of $19.99 + NYS Sales Tax for remote repair service which covers our cost. We only expect you to pay if we remove it and your happy with the results. This about the cost in lost time and transportation of going to the Genius Bar.
Adobe has added a new Preference Pane for Flash for Mac OSX, which allows you to control Flash Privacy and Update Notification via a standard MacOSX Preference Pane. While this is a good step, the problems which existed with the Setting Manager still exist in the Preference Pane when it comes to the handling of Local Shared Objects (LSO) otherwise know as Flash Cookies. Below we expose the various issues with the Preference Pane, mainly when you select Storage>Delete All and Advance>Delete All site data remains.
The Flash Player Preference Pane
The Flash Player Preference Pane replaces the clumsy Setting Manager for Flash which ran directly from the Browser. One great feature of the pane is the management of Flash updates which was horrible in the Setting Manager. The Advanced tab enables you to determine the version installed and provides a direct link to the About Flash Player page. You also have the capability to set storage and privacy controls for the camera and microphone. "Private Browsing" is supported in Safari 5.0.5, thus private browser session information including Flash content is not stored in the usual directories ~/Library/Preferences/Macromedia/Flash Player/macromedia.com or ~/Library/Preferences/Macromedia/Flash Player/#SharedObjects.
Sounds Good, So What is the Problem
We have discovered that if you visit a site with "Allow sites to save information on this computer" enabled in the Preference Pane or had previous sites that stored information the "Delete All" button does not provide the protection describe here on Adobe's site and below.
After reading this you would expect buttons labeled "Delete All" to perform as advertised and remove all content saved from sites. This is not always the case, and some data remains, similar to the failures in the Setting Manager, thus the "Delete All" does not perform as expected. In our demo we will clearly show that the Flash Player Preference Pane does not work properly resulting in Flash Cookie (LSO) data remaining on the system.
Note : (For our demo we will be using Philipp Kostin Flash Site Demo titled "Flash Cookies: Local Shared Objects" to create the data and Flash Cookie (LSO).)
Follow these steps to duplicate our results in the video that follows:
Wasn't This Always a Problem?
In previous versions of Flash Player for Mac OSXdeleting site storage did not remove all the Flash Cookies (LSO) including the .sol file and a folder with the site name. This was one of the many issues which made using the Setting Manager very frustrating. Flash Cookies (LSO) have raised all kinds of privacy issues since they were first used, and that continues to be the case even if Adobe has introduced a Preference Pane.
In the Flash Player Preference Pane the language is clear so we expect that "Delete All" would do exactly as expected. In our demo this was not the case. The only solution that worked one hundred percent of the time was to manually remove Flash Cookies (LSO) and then enable "Block all sites from storing information on this computer."
Conclusion
In the current state the Flash Player Preference Pane for Mac OSX does not work as advertised, thus it continues to be a work in progress. The Flash Player Preference Pane clearly does not improve the management of Flash content privacy. In fact, the Flash Player Preference Pane will result in users having a false sense of privacy. It is our hope that Adobe was making an attempt at making Flash privacy easy to manage and not trying to layer the issue of privacy in a veil of confused user interaction. Take a chance Adobe, your business goals can be met while providing users and developers with clear dependable controls over Flash Cookies (LSO) and their privacy. The other option is to agree with Steve Jobs and move away from the Flash Platform.
Intego has reported a new rouge Anti-Malware program targeting Mac OSX and Mac products. There are several things that can be done to mitigate the risk of this rouge product. Do not attempt to purchase this application via PayPal or Credit Card. If you have purchased it then report your credit card or PayPal account compromised immediately.
Currently the risk from this product is low but users in various discussion forums are reporting that they already have downloaded and installed it.
To remove the rouge Anti-Malware software if you downloaded it:
Select the "+" button and scroll down to Other and add "System files."
Select "System Files are Included"
Delete the Application by moving to the trash along with items in the Startup folder or files associated with MACDefender. This includes web pages in the cache /Library/StartupItems or ~/Library/StartupItems.
How to Protect yourself:
We continue to evaluate the risk created by rouge installers and malware related to Apple products. The "Human Interface Guidelines" which are key for any successful Apple developer to follow also creates risk skewed by users expectations of the Apple experience. We expect this to only increase in the future.
In our independent testing, using XCode and very little effort, we created various rouge installers which successfully convinced many Mac OSX users and Administrators they were safe to install. Far more Mac users were convinced by the Malware's ability to conform with the Apple operating system experience and never considered the source.
In our view the most threatening form of malware for Apple Productions is one that focuses on the MacOSX or iOS experience for the user. (This is very true for all GUI based computing devices, just more so on a platform that is experience driven.) Windows administrators and users have had to deal with this threat for sometime, whose experiences can beneficial as this threat continues to grow.
If you have not done so already we recommend installation of a complete Anti-Virus and Internet security package. Our favorite in Intego's Internet Barrier and we are very excited about F-Secure's beta offering. (Beta is not recommended for production critical systems.)
Google has released Chrome update 11.0.696.57 to the stable channel. The update address various security fixes. This is directly taken from the reference link attached.
Apple has released iTunes 10.2.2 for Windows and Mac OSX. The Mac OSX update includes the following fixes.
Google has released Chrome 10.0.648.205 to the stable channel which fixes the Flash Zero day along with the listing below. (Mac Only)
Apple has released Safari version 5.0.5. to address two issues within WebKit. Users should apply this update promptly.
Apple has released Apple-SA-2011-04-14-4 Security Update 2011-002 for Mac OSX and Mac OSX Server to address the Certificate of Trust Policy issue related to the Comodo CA compromise. This update is critical, a reboot is required after the update.