Showing posts with label Mac OS X. Show all posts
Showing posts with label Mac OS X. Show all posts

Thursday, 12 November 2015

Google Stops Support Chrome On XP And Vista In 2016


A little more than four months and then stop supporting Google Chrome on Windows XP, Vista and Mac OS X 10.6, 10.7 and 10.8, as Google has announced. The browser will still continue to work, but will not receive security updates and other fixes more.


The reason that Google discontinues the support is that the operating systems are no longer supported by Apple and Microsoft. Users of Windows XP, Vista and the older OS X versions get Google advised to upgrade to a newer operating system. According to the Internet giant walk unsupported platforms such as Windows XP, a greater risk of becoming infected by malware.

The Google story is remarkable. Support for Windows XP expired last April, but Vista until April 11, 2017 supported by Microsoft security updates, according to the Windows life cycle.

Friday, 6 November 2015

Extra Secure Tor Browser For Linux Launched



The creators of Tor Browser, the software for browsing through the Tor network, have released a security-enhanced version of Linux. It is the first time that the Tor Project offers a "hardened" version of Tor Browser. This browser includes a customized version of Firefox and Tor software.

The extra secure Tor Browser is based on the Tor Browser Alpha series. These are test versions of the browser that appear in the final versions. In addition, extra protection is added which should offer protection against memory exploits. For this are both the Tor software, and Firefox version Address Sanitizer compiled. This should give users a safer Tor Browser, especially if JavaScript is partially or completely disabled. It also helps to find problems earlier and to remedy them in the alpha and stable versions.

The additional security does have several disadvantages. Thus, this version is slower, consumes more memory and is slightly larger than the normal version. In addition, the added security of Address Sanitizer not perfect. An attacker who successfully back halls which it is practiced can still via JavaScript certain types of attack vulnerabilities. To date, the high-security Tor Browser only for Linux available, but is being given to versions for Mac OS X and Windows.

Tor Browser lets Internet users hide their IP address and visit censored websites. Every day, over two million people from all over the world using the Tor network, such as activists, people in totalitarian regimes and Internet users who value their privacy. The software is also used by criminals. Two years ago, users of legacy Tor Browser still the target of an attack allegedly by the FBI conducted. The attack users of the real IP address could be traced. To avoid Tor Browser Users with outdated versions meanwhile continue surfing is an automatic updater added to the browser.

Researcher Unveils First Ransomware For Mac


A Brazilian researcher is the first ransomware developed for Mac OS X, in his own words to break the myth that there is no malware for the Mac. Rafael Marques calls his creation "Mabouia 'and this is a so-called" proof-of- concept. "

A creation which is intended purely for demonstration purposes and the investigator wrote in two days. He will therefore not publish the source code of the malware. Although there are already 'ransomware' for Mac was released in these cases to Javascript code that the browser unlocked and a warning that supposedly showed the FBI or Europol originated. Files on the computer remained unaffected.

The Marques of ransomware encrypts files and actually uses the eXtended Tiny Encryption Algorithm (XTEA) and then sends the key to a server. The researchers developed a way to decrypt the files. Critics argue that the ransomware is not as complex as the ransomware for Windows. "I never said that [the ransomware] is complex. I made ​​it in two days. But it's still the first Mac OS X ransomware", as the researcher leaves via Twitter know. He also made ​​this demonstration video.

Saturday, 24 October 2015

Tens Of Thousands Of Users MacKeeper Want Money Back



Tens of thousands of people who have bought the MacKeeper program indicated that they want their money back. Following is a "class action" lawsuit filed last year. According to the woman who started the lawsuit MacKeeper would have warned wrongly for security and performance issues in order to get more consumers on purchasing the full version of 40 dollars.

MacKeeper is controversial software. According to some experts, the "scareware" because the user through misleading alerts and pop-ups trying to push you into purchasing the full version. The lawsuit was filed against the Ukrainian software ZeoBIT, the original developer of MacKeeper. In April 2013, the company decided to MacKeeper German Krom Tech Alliance Corp. to sell. ZeoBIT decided the lawsuit for an amount of $ 2 million to settle. A third of that goes to the lawyers, while the remaining $ 1.25 million will be kept in a special fund. The settlement has been tentatively approved, but is still awaiting final approval.

Since August, more than 513 000 people approached who bought MacKeeper in the US and were eligible for refund of the purchase price. Meanwhile, almost 79 000 people have filed a claim. An unprecedented number of in this type of arrangements. It means that there is less money left for the plaintiffs. Instead of $ 40 will be released the fee now at 15 or 16 dollars, reports Macworld. Users of the software have until November 30th time via this website to submit their claim.

Friday, 23 October 2015

Vulnerabilities In Network Time Protocol (NTP) DoS Permit



In the Network Time Protocol (NTP) Multiple vulnerabilities have been identified that could allow attackers to systems that make use of NTP can cause a Denial of Service (DoS). NTP is a protocol that allows systems to synchronize the time for different services and applications.

It is present in network devices and embedded devices', as well as desktop and server operating systems, including Mac OS X, various Linux distributions and BSD-based systems. Decided last year to start the Linux Foundation on the occasion of the Heart Bleed vulnerability Core Infrastructure Initiative (CII) with the aim of securing popular open source projects on the Internet. Cisco is part of the CII and focuses on researching NTP.

Researchers at Cisco have a total of eight vulnerabilities discovered in NTP, which in ntp-4.2.8p4 been resolved. Also five other leaks are history. In addition to a Denial of Service are also bug fixes are causing memory corruption or path traversal were possible. The only vulnerability that is too general, according to the developers of NTP abuse is concerned a bug allowing attackers with NTP servers for DDoS attacks can deploy. In August, warned the FBI for DDoS attacks that uses the Network Time Protocol.

Friday, 16 October 2015

Company Claims Nearly 1,000 New Mac Malware In 2015


An American security company claims it has this year found nearly 1,000 instances of malware for Mac OS X, five times as many as in 2010, 2011, 2012, 2013 and 2014 combined. However, the report from Bit9 and Carbon Black does not know what malware is involved.

Also not reported how it is contracted, how widespread the malware found and whether for instance, there are trails. As a result, it is unclear how large the actual threat is now. The study (pdf) researchers from Bit9 and Carbon Black gathered for a period of 10 weeks in all sorts of places malware specimens, such as blacklists, Cont Agio malware dump, open source and security incidents. In total more than 1400 unique OS X malware specimens were found. 180 examples date from 2010 to 2014. 948 copies were for the first time this year have appeared.

"The number of copies in this analysis is large enough that even the most optimistic Mac OS X user realizes that security is now of paramount importance," said the researchers. They expect the number of Mac malware attacks will increase in the coming months. How that will take place just is not reported. Recently, anti-virus firm BitDefender said that nearly half of all Mac malware is actually adware.

Mac users run mainly via adware bundled software, for example through pop-ups and ads on websites that say that something is wrong may be using the computer or the performance improved. Bitdefender recommends Mac users also to be selective about which programs they download and install. It is also advised to only download apps from the official Mac App Store. Researchers at Carbon Black advised Mac users to install a virus scanner, with free alternatives to Avast, Malwarebytes, and Sophos highlights. Users who wonder if they are infected may be advised the Dynamic Hijack Scanner or Knock Knock use.

Tuesday, 13 October 2015

Anti-Virus Company: Nearly Half Of Mac Threats Consist Of Adware


Almost half of the threats for Mac OS X falls into the category of adware, says the Romanian antivirus company BitDefender on the basis of its own research. The virus fighter analyzed the Mac malware that appeared in the first six months of this year.

Of all Mac malware found in the United States showed 46% can be classified as adware. In Germany, Denmark and Romania was about 45%, 61% and 58% respectively. However, no absolute numbers, so it is unclear how many copies are involved. Once active adware can display unwanted pop-ups and ads and adjust search results.

Mac users run mainly via adware bundled software, for example through pop-ups and ads on websites that say that something is wrong may be using the computer or the performance improved. Bitdefender recommends Mac users also to be selective about which programs they download and install. It is also advised to read the terms and conditions of the software, install a AdBlocker and Mac OS X to keep up-to-date. Earlier it was even called that adware is the main threat for Mac users.

Monday, 17 August 2015

New Zero-Day Vulnerability Revealed In Mac OS X



On the Internet, details of a new vulnerability in Mac OS X appeared which there is no update available from Apple. Through the vulnerability can allow a local attacker who already has access to a system or a malicious app already installed enhance the rights.

It is reported via Hacker News and Reddit . An attacker can not take away or run this code on the system via the zero-day vulnerability. In this case, there is first requires an additional vulnerability. For users of Mac OS X Yosemite, there is no update available. The problem would by now have been addressed in Mac OS X 10:11 El Capitan, but this version is not yet rolled out to the general public.

Recently, a similar vulnerability in Mac OS X was revealed which at that time was still no update available from Apple. This zero-day vulnerability was finally an adware installer to install additional software with root privileges. This week Apple issued an update for Mac OS X that leak 133 fixed it in the operating system, including this vulnerability.

Thursday, 13 August 2015

Karma-Attack Is Still Dangerous For WiFi Users



Consumers who wifi on their laptop, tablet or smart phone use still run the risk of being the target of a Karma attack, allowing an attacker could then intercept the traffic of the user. The Karma attack in early 2005 for the first time demonstrated.

The attack is possible because some computers and mobile devices continues to Wi-Fi networks nearby. It sent the name of the Wi-Fi network. A malicious access point can occur later as the network, allowing the laptop, smartphone or tablet automatically connects. An attacker could then perform a man-in-the-middle attack, as he is between the user and the Internet. Although Karma attack is over 10 years old, he is still usable.

For example, the latest Mac OS X version still appears to look for nearby networks where the network name is sent. Also in the case of Ubuntu 14:04 platform is vulnerable to the Karma attack. Windows 7 does not appear to be vulnerable by default because it is not looking for Wi-Fi networks. Researcher Will Dormann of the Software Engineering Institute at Carnegie Mellon University found that the wifi adapter which he used Windows or made ​​vulnerable. The wifi software made ​​to it that there to Wi-Fi networks was sought.

It also appears that older Android versions as Gingerbread vulnerable. In Ice Cream Sandwich was the problem rectified. Also iOS devices proved to be vulnerable. Consumers who want to protect are advised not to use open Wi-Fi networks and previously used Wi-Fi networks that are saved by the system to remove from attack. Dormann also recommends to disable wifi when not in use and keep an eye on what WiFi network the device connects. He further recommends that to connect to networks that have a hidden network name (SSID).

Friday, 24 July 2015

AV Comparatives Test Lab: Experienced Mac User To A Virus Scanner


Experienced Mac users can watch what they download a virus scanner, according to the Austrian test lab AV-Comparatives . The test lab decided to test ten virus for Mac OS X on the detection of malware. In addition, specimens were taken for both Mac and Windows, because the Mac virus indicate that they can also detect Windows malware.

The reason is that Mac computers can also get in touch with Windows malware, for example in the case of e-mail attachments or USB sticks. What is striking about the test, the amount of malware which has been tested. In the case of Mac malware is about 105 newly discovered specimens, while the most prevalent malware specimens were used for Windows. In other tests of AV-Comparatives for Windows be used thousands of malware examples, but the number for Mac is so low that the counter remains stabbing at 105.

Of the ten scanners able to detect seven parcels 100% of all Mac malware, while a similar number this occurs in the Windows malware. Avast, AVG, ESET, Kaspersky and Sophos are the scanners that detect all malware in both areas. When it comes to Windows malware are the only F-Secure (28%) and Intego (50%) who stabbing drop in the detection of Windows malware.Meanwhile, all the anti-virus companies have their signatures updated to missed malware are detected.

The question remains whether Mac users now need a virus scanner. "Experienced and responsible Mac users to be careful with the programs they install and where they get which can reasonably argue that they do not risk running Mac malware," said AV-Comparatives. The lab says that users who are not experts, children and users with regular software experiment there can take advantage of to use a Mac virus scanner.

Thursday, 9 July 2015

Criminals Hacked Apple And Microsoft Still Active



A group of cyber criminals in 2013 Microsoft , Apple , Facebook and Twitter hacked is still active and has provided the large companies, which both malware for Windows and Mac OS X is used. Before the attack on the US Internet companies at the time the attackers used a zero-day vulnerability in Java. At the time of the attack there was no update available for the leak.

After all the attention to the burglaries, the attackers vanished in 2013 for almost a year, but now they are back and they use a previously unknown vulnerability in Adobe Flash Player and use a certificate from the Taiwanese manufacturer Acer to sign with malware. That report anti-virus firms Symantec and Kaspersky Lab today. Both virus fighters have put a group of the analysis.

This is according to anti-virus companies to a group of cyber criminals who operates on a much higher level than other cyber criminals. So is wanted there for credit card information, but to very valuable information. The attacks were the past few years aimed at law firms, Bitcoin-related companies, investment companies, IT companies, health companies and brokers, as well as individual users. Most victims are located in Canada, Europe and the United States.

Attacks

To infect victims they have used the aforementioned zero-day vulnerability in Java and at least one vulnerability in Internet Explorer 10, says Symantec. Kaspersky Lab reports that the attackers have used an unknown vulnerability in Flash Player.The victims are attacked by the leak is unknown. At the first attacks in 2012 and 2013 were hacked websites which targets already visited by itself. How the attackers in the new series of attacks proceed in 2014 and 2015, however, a mystery. In case the attack is successful, the attackers use various tools, including a backdoor for Mac OS X and Windows.

The attackers have mostly provided on mail servers. Once access to the Microsoft Exchange or Lotus Domino servers obtained the e-mail traffic probably bugged, says Symantec. There may also be "fraudulent e-mails" are injected.Furthermore, Kaspersky Lab discovered the malware that was used this year by the group signed with a legitimate certificate from Acer. The certificate has been obtained is unknown. The certificate authority that issued the certificate has been asked to withdraw the certificate.

"Compared with other intelligence groups, this group is one of the most exciting we have analyzed and monitored," Kaspersky Lab says. The virus fighter warns that the criminals are still active. Symantec also warns companies of the group, which not only has excellent operational security, but also succeeded in expanding the activities and not be noticed. "The group is a threat that companies should take seriously," said the virus fighter. The data that the group steals the possible uses for their own financial gain, or by selling to the highest bidder.

Thursday, 18 June 2015

Researchers Have Malware In Apple App Stores




Researchers at Indiana University have succeeded in malware for Mac OS X and iOS to get into the App Store from Apple that allows access to sensitive data from other apps can be obtained. Examples include passwords to iCloud, your default e-mail program and Internet banking and the secret token for the note program Evernote.

It also showed that the design of the app sandbox on Mac OS X was vulnerable, so the malware could approach the private directory apps. The malware could thus have access to notes, and contacts that were stored in Evernote, as well as photos of WeChat. The researchers published their work in late May in a report ( PDF ) called "Unauthorized Cross-App Resource Access on Mac OS X and iOS." To prevent apps access to each other's information systems get fit "app isolation" to which each app is in its own sandbox.

It appears that in some cases for apps still be possible to access the "resources" of other apps, which the researchers call "unauthorized cross-app resource access" (XARA). It was known that this problem played in Android, but the researchers wanted to know whether Mac OS X and iOS are vulnerable. Two platforms, which are believed to be safer than Android, so the researchers in the report know. They discovered that the problem also affects the Apple operating system. Thus, the mechanism can be hijacked that controls access to the Keychain, so it is then possible to gain access to passwords and other credentials of apps and websites that are stored here.

Impact

"The consequences of these attacks are serious, including the leak of passwords, secret tokens and all kinds of sensitive documents. Our research shows that the problem is caused by a lack of authentication at app-to-app and app-to-system interactions "the researchers said in their conclusion. They developed a scanner to analyze binaries for OS X and iOS apps to determine if the proper protection measure is contained in their code or not.

More than 88.6% of the 1612 popular Mac apps and 200 iOS apps were completely vulnerable to a XARA attack, which could steal a malicious app security information. Apple would be informed by the researchers in October 2014 and then asked to wait with the publication of the report, but the investigators would have since heard nothing more, reports The Register . The problem in Mac OS X 10.10.3 and 10.10.4 still present.

Friday, 29 May 2015

Apple Blocks Unsafe Versions Adobe Flash Player


A little later than usual, Apple released an update to block insecure versions of Adobe Flash Player on Mac OS X, however, are Windows users who certainly have to ensure that they have the latest version.Mac OS X has a "Web Plugin blocking mechanism" that Apple can update to block insecure browser plug-ins and to protect users from potential attacks.

On May 12, Adobe patched 18 vulnerabilities in Adobe Flash Player that could allow an attacker in the worst case, the underlying system could take over completely. Safari users not using the latest version of Flash Player and a site visit to see the plug-in call have since today a notification. The report says that Adobe Flash Player is outdated and there is a newer version can be downloaded from Adobe. The blockade applies to all Flash Player versions prior to 17.0.0.188 and 13.0.0.289.Apple blocks more vulnerable versions of Flash Player, but does so usually a few days after the update in question appeared.

But they are Windows users who must surely check whether they are using the most recent version, as cyber criminals have begun attacking one of the vulnerabilities that Adobe patched two weeks ago. Again, there is a trend whereby the exploit to attack the vulnerability soon after the release of the security appears. In this case it is the Angler Exploit kit which is now able to Flash users with version 17.0.0.169 and earlier attack, warns security firm FireEye . Through this page, users can see whether and which version of Flash Player is installed on their system.

Wednesday, 6 May 2015

Expert: Mac Malware Invisible By Lack Of Anti-Virus


Because Mac users install anti-virus software is difficult for anti-virus companies to estimate how big the problem of Mac malware is actually. That says Bogdan Botezatu, an analyst of the Romanian antivirus company BitDefender. Previously, Apple had yet know that users could install a virus, but now it no longer does so.

"Apple is promoting these products as virus-free. They say you do not need a virus scanner, because they know that people hate anti-virus software. The tools often slow down your computer, so they themselves will not promote," Botezatu said front Digital Trends . Mac OS X, according to the analyst to deal with more serious vulnerabilities than all the different Windows versions added. Because Microsoft has always been attacked over the years would have learned to respond quickly to security threats.

Having vulnerabilities still says nothing about attacks on the platform. However, when it comes to Mac computers is missing important information to say something about this, the analyst noted. "The absence of virus scanners on Mac OS X hides the reality, because the malware is not reported. We know it happens on Windows because it is visible to us here, but with Mac OS X, there is often no anti-virus to give something back report. "

In addition, Mac users would not know that their computer is infected, because most malware these days is hardly noticeable."It's the same as with the PC. Hackers realized how silent they are, the longer they go unnoticed. Modern Mac and Windows malware slows down your computer, unless the bitcoin-miners are," said Botezatu. The large market share of Windows would, according to the analyst still ensure that cyber criminals are targeting this platform.

Tuesday, 28 April 2015

VirusTotal: "Knock Knock Searching With Google For Mac Malware"


A program for Mac OS X that shows what programs and scripts are automatically started is now able to quickly malware via VirusTotal tracks, the online anti-virus service from Google. Knock Knock for OS X is similar to Microsoft's Autoruns for Windows and provides a detailed overview of what all is happening on the operating system.


VirusTotal is a website where users can upload files in order to submit it by 50 different virus scanning. Early this year, Microsoft decided to VirusTotal with Autoruns integrate , allowing Windows users now easily able to detect malware. Patrick Wardle, developer of Knock Knock, has now followed that example and VirusTotal added to his application.

"This tool is very useful for quickly finding malware on Mac OS X systems, and integration with VirusTotal give further momentum to our efforts to protect Mac OS X users," says Emiliano Martinez VirusTotal, which since 2012 part of Google.Last year VirusTotal decided already to the analysis of OS X and iOS malware improve and the corresponding upload tool .

Wednesday, 22 April 2015

Apple Update Shows Root Pipe Leak In OS X Not To Close



Apple released two weeks ago an update for a vulnerability which allows a local attacker root access on Mac OS X could get. Now it appears that the update does not solve the problem, and the latest version of Mac OS X is still vulnerable. The leak did all the necessary controversy.

The vulnerability was namely remedied only by Apple in Mac OS X Yosemite and not in older versions. The Swedish researcher Emil Kvarnhammar also spoke of a backdoor . The problem could certainly since 2011 are present in Apple's operating system. According to researcher Patrick Wardle , it is, however, not yet been resolved.

He discovered his own words a new but simple way in which a local user can use the root pipe leak. Details he shared only with Apple. Through his short message he wants to warn, however, Mac users. He also made demonstration video.

Wednesday, 25 March 2015

Oracle Provides Mac Version Of Java Again With "Adware"


Oracle has started with the delivery of the Java installation for Mac with the infamous Ask Toolbar. Also users get back to whether they have their home in Ask.com want to change. In early March showed that Oracle had the setup of Java for Mac bundled with the Ask Toolbar.

The software does this for some time for the Windows version, but it's the first time it does this for the Mac version. The Ask Toolbar is labeled as adware by different parties. The toolbar uses the Ask search engine, which would be full of bad classified ads. Advertisements that are not of the "organic" results would be distinguished in most cases.

There was considerable controversy because of bundling the Ask Toolbar and after a week seemed Oracle thus stopped to be. Several parties indicated they when installing Java to see the toolbar no longer received. Security firm Intego reports that Oracle now controls the location of users first before it is decided to activate the installation of the Ask Toolbar. Thus, French users will not see the toolbar, while US users will be asked if they want to install.

Regardless of the country of the user is always installed the "Sponsors.framework" when installing Java on the Mac, which again to install the Ask Toolbar is responsible. Intego suspects that the Ask Toolbar can be enabled with future updates , without the need for Java to be installed. The framework would say, if it is already installed, can be updated silently.

Monday, 16 March 2015

Oracle Removes "Adware" From Java Installation On Mac


Recently there was great controversy when it became known that Oracle is the Ask Toolbar was bundled with the installation of Java for Mac OS X, but now the company seems to have stopped here quietly along. The Ask Toolbar is labeled as "adware" by various parties.

The toolbar uses the Ask search engine, which would be full of bad classified ads. Advertisements that are not of the "organic" results would be distinguished in most cases. In addition to installing the toolbar were Mac users with the Java installation also asked whether they wanted to change their home page in Ask.com. Both options were selected by default.

Oracle Java installer now delivers without Ask Toolbar this is now confirmed by both The Safe Mac as security Intego . The virus of the company blocked the toolbar. Report Although various parties that the Ask Toolbar is no longer installed, Oracle late own site know that the toolbar is also installed on Mac OS X. However, it may be that the website has not yet been adjusted.

Friday, 6 March 2015

Oracle Adds "Adware" To Java Installation On Mac


For years, the installer for Java on Windows bundled with additional software, such as the Ask Toolbar, but now Oracle applies this practice also allows for the Java installer on Mac OS X. The Ask Toolbar is labeled by various parties as "adware." Under Windows Follower Ed Bott shows the Ask search engine bad results that are filled with advertisements that do not "organic" results can be distinguished in most cases.

In the case of Mac OS X is about 8 Java Update 40 whereby the Ask Toolbar is installed and the home page is changed. This version came out the week. The option to install the Ask Toolbar and change home is checked by default. Anyone who does not pay attention during installation has also a toolbar at. Bott discovered the new bundle of Oracle policy. He also discovered that the Ask developers in the Chrome Web Store does not use their own name, but "chromewebstore12".

Developers do when two other apps the same, allowing users might think that it is official Chrome apps. Oracle website now also makes mention that cooperation with certain parties that offer different products, but provides no further explanation or lets you know what people can do to remove Ask their system. Oracle's decision to join the toolbar follows the Lenovo Superfish debacle. Lenovo did this knowing that in the future cleaner machines will offer without much preinstalled software.

Monday, 23 February 2015

Shop Sees Increase In Adware Mac Users


A US store warns Mac users to download software only from the official supplier, after it saw an increase in clients who were infected with adware. According to Annie Hayes iCape Solutions is the number of Mac customers that come along because adware increasing.

"Although Macs are resistant to viruses, we have an increase of adware / malware seen as Genio and Install mac," says Hayes. This is because according to its Mac users software such as Adobe Flash Player for free outside the official Adobe website. Once active adware modifies the home page and search engines and injects ads. "In order to avoid this kind of programs you should only download programs from a reliable place. For example if you need the latest version of Flash, make sure that you are on the genuine Adobe website."

Another problem that the Mac store regular customers see return is MacKeeper. This is a program that claims to optimize Mac OS X systems and to protect the privacy of users. "I can give you a million reasons to avoid it, but I refer to this article on iMore , "Hayes says. "Ordinary users do not need anti-virus software or cleaner, and much of what is in circulation resembles MacKeeper, a program designed to let you pay for a service."