Showing posts with label mac. Show all posts
Showing posts with label mac. Show all posts

Thursday, 16 July 2015

Malwarebytes Launches Free Anti-Malware Tool For Mac



Anti-virus firm Malwarebytes has launched a free tool for Mac users to malware, adware and potentially unwanted programs (PUPs) to remove it. In addition, the company also take Adware Medic of The Safe on Mac, as the virus fighter let know .

From examination of OPSWAT showed that 50% of Mac users have not installed virus scanner. According Malwarebytes this is because malware is not seen as a problem for Mac. Compared to Windows, there is much less Mac malware in circulation. These are often malware via pirated software and downloading software from untrusted sources is distributed. It is also adware and toolbars by some parties as the biggest threat are labeled for Mac users.

Something that is also reflected in the number of downloads of Adware Medic, a program to remove adware along. The software is in the first half of this year already downloaded 2.8 million times. Also from research from Google shows that adware on Windows and Mac is a problem. Nevertheless, users can also protect against here. So anti-virus company Avast suggested recently that a lot of adware and toolbars can be prevented if consumers better read and pay attention when installing software.

Thomas Reed Adware Medic, who is now at Malwarebytes will focus on the development of Mac products, says that Mac users need protection against adware, which assumes more and more the form of an epidemic. Malwarebytes Anti-Malware for Mac is available for free download and use. Later this year there are versions for SMEs and large enterprises.

Friday, 3 April 2015

Tool Protects WiFi Networks Against Malicious Access Points


To prevent employees and other Wi-Fi users with hostile access points to connect to a programmer has developed a tool that offers protection against this. Through EvilAP_Defender like tool called Mohamed Idris, network administrators can discover so-called evil or rogue access points and prevent them from WiFi users attacks. A rogue access point is a Wi-Fi network as another Wi-Fi network to make do with the ultimate goal that employees through this network connection. Then the attacker could intercept and perform other attacks.

Once active EvilAP_Defender can send an e-mail to the administrator when a rogue access point detected. Soon there will also appear for SMS support. The tool can also be set to perform a Denial of Service attack on the rogue access point, so that the network administrator has time to take action.

The tool will only perform against rogue access points with the same network name the DoS attack, but a different BSSID (the MAC address of an access point), or if they are running on a different channel. This should prevent a DoS attack is performed on the legitimate network. On Reddit , where Idris tool announced yesterday, let him know that there is also a control signal. He also has plans to later develop a client-server version in which there are arranged at various places sensors that look for rogue access points.

Saturday, 14 March 2015

Forensic Tool Can Extract All Data From iCloud Drive


A forensic tool of Russian Elcomsoft in the last year news came because that would be used to steal nude photos of celebrities, is now able to extract all kinds of data from both Apple iCloud as iCloud Drive.It involves all the Apple data and data from third party applications.

In addition, the new version of Elcomsoft Phone Breaker can now also the keychain in iCloud backups decrypt. For this, it is required that the "securityd-key" of the device is physically removed. Russian software company would have spent almost half a year to write the new communication protocols iCloud Drive to reverse engineer and software to communicate with the iCloud Drive servers.

ICloud Drive

ICloud Drive is an upgrade from Apple iCloud and allows users to store all sorts of data in the cloud. Data are accessed via a Windows or Mac computer. Some data such as iOS backups and stored iOS appdata however stored separately. These data are only accessible by a backup on a new iOS device to replace. Elcomsoft's software is now able to access application data from user accounts that have been upgraded to iCloud Drive. In addition, the software also offers access to iOS backups.

Keychain

Another major adjustment is the ability to decrypt the keychain from iCloudback-ups. The keychain contains all kinds of sensitive information such as account passwords and certificates. On the device itself, the keychain is encrypted by a combination of hardware and software. As soon as the keychain is stored in a back-up change the security level depending on the type of backup. If the user makes a local password-protected backup through iTunes, the keychain is encrypted with a key that is dependent on the backup password.

Through the backup password most things in the keychain can be decrypted. If the local backup is created without a password, the keychain will be encrypted with a hardware-dependent key, which is unique for each device. This device will probably not change over the lifetime of the device. Once the key is superseded that can be used for future backups.

These keychains however, can only be put back on the same physical device, and to decrypt with the same hardware-dependent decryption key. If this key is retrieved from the physical device, it is then possible to decrypt all of the data from the outside of the keychain device. Finally there is the possibility to have a iCloudback up where the keychain is secured with the device password. This is similar to the iTunes backups without a password. All three kinds of keychains are according to decrypt Elcomsoft now, provided that the hardware-dependent key is present.

Wednesday, 11 March 2015

Apple Fixes FREAK Vulnerability In Mac OS X And iOS


Apple has released updates for Mac OS X, Apple TV and iOS that it " FREAK leak fixes "in SSL / TLS.Through the vulnerability, an attacker who is between a target and the Internet is in some cases the encryption of the encrypted connection to downgrade to a weak encryption to crack then that and to see the encrypted traffic.

Further resolves Security Update 2015-002 for Mac OS X four other vulnerabilities. It involves leakage and malicious app could execute arbitrary code with system privileges, memory addresses in the kernel were determined and could allow an attacker on the network arbitrary code via iCloud Keychain. iOS 8.2 fixes beside FREAK leak five other vulnerabilities.

Through these vulnerabilities, an attacker could iPods and iPads remote reboots and an attacker with physical access could see the home screen, even though the device was not activated. Furthermore, the same vulnerabilities resolved in Mac OS X, allowing attackers to execute arbitrary code. The same applies to AppleTV 7.1 , where a total of three leaks were patched.Finally, there is also an update for Xcode appeared, the development software from Apple for OS X and iOS. This five leaks were patched.

Friday, 6 March 2015

Oracle Adds "Adware" To Java Installation On Mac


For years, the installer for Java on Windows bundled with additional software, such as the Ask Toolbar, but now Oracle applies this practice also allows for the Java installer on Mac OS X. The Ask Toolbar is labeled by various parties as "adware." Under Windows Follower Ed Bott shows the Ask search engine bad results that are filled with advertisements that do not "organic" results can be distinguished in most cases.

In the case of Mac OS X is about 8 Java Update 40 whereby the Ask Toolbar is installed and the home page is changed. This version came out the week. The option to install the Ask Toolbar and change home is checked by default. Anyone who does not pay attention during installation has also a toolbar at. Bott discovered the new bundle of Oracle policy. He also discovered that the Ask developers in the Chrome Web Store does not use their own name, but "chromewebstore12".

Developers do when two other apps the same, allowing users might think that it is official Chrome apps. Oracle website now also makes mention that cooperation with certain parties that offer different products, but provides no further explanation or lets you know what people can do to remove Ask their system. Oracle's decision to join the toolbar follows the Lenovo Superfish debacle. Lenovo did this knowing that in the future cleaner machines will offer without much preinstalled software.

Monday, 23 February 2015

Shop Sees Increase In Adware Mac Users


A US store warns Mac users to download software only from the official supplier, after it saw an increase in clients who were infected with adware. According to Annie Hayes iCape Solutions is the number of Mac customers that come along because adware increasing.

"Although Macs are resistant to viruses, we have an increase of adware / malware seen as Genio and Install mac," says Hayes. This is because according to its Mac users software such as Adobe Flash Player for free outside the official Adobe website. Once active adware modifies the home page and search engines and injects ads. "In order to avoid this kind of programs you should only download programs from a reliable place. For example if you need the latest version of Flash, make sure that you are on the genuine Adobe website."

Another problem that the Mac store regular customers see return is MacKeeper. This is a program that claims to optimize Mac OS X systems and to protect the privacy of users. "I can give you a million reasons to avoid it, but I refer to this article on iMore , "Hayes says. "Ordinary users do not need anti-virus software or cleaner, and much of what is in circulation resembles MacKeeper, a program designed to let you pay for a service."

Monday, 1 December 2014

Virustotal - Added New Tool For iOS & Mac Malware Analysis




VirusTotal.com, the online virus scanner from Google, two weeks ago quietly added a new tool to improve the analysis of suspicious files Mac and iOS apps. Via VirusTotal users can upload files and then to scan dozens of virus scanners.

In addition, the binary contents of each file is scanned, regardless of file type, then to check whether anti-virus companies recognize the scanned code. The new tool launched recently trying executable files Mac OS X and iOS apps to further characterize by finding out interesting features. Thus collected header information of the file, as well as file segments, shared libraries that the file uses, load commands and signature information if the code is digitally signed.

In the case of Mac OS X that contains executable mach-o-files for different systems, each embedded file of the properties will be displayed. When it comes to iOS apps will generate VirusTotal also metadata about the package itself and iTunes detail. Emiliano Martinez VirusTotal hopes that the new tool will help you find and study threats for Mac OS X and iOS.

Recently, Virustotal has expanded the size limit from 64MB to 128MB.

Monday, 24 March 2014

White Hat Security company launches "secure browser" on Internet


An American security company claims to have the "most secure browser" launched on the Internet that users must protect. Against both malware and parties who want to violate the privacy Aviator, such as the browser is called, was published last year, the Mac version and now there is also a Windows version.

Aviator has been developed by white hat security and based on Chromium, the open-source browser that is used. Google Chrome The reason it was chosen Chromium is that it has several unique security features, such as a sandbox. White Hat found that Chromium is not safe enough and made ​​an adapted version with more security and privacy settings.

"Google and Microsoft make a lot of money on online ads. Unfortunately, very intrusive online advertising, because you basically follow anywhere on the Internet. Even Mozilla receives most of the revenue through advertisements. Implementing truly effective security and privacy could adversely for their business operations, " said the security company

For example, the default search engine DuckDuckGo instead of Google and integrates the browser Disconnect. An extension that ads and tracking on the Internet blocking. In addition, the browsing history, cache, cookies, auto-complete, and local storage after restarting the browser removed. Standard third party cookies are blocked, plug-ins require an additional mouse to work state Do-Not-Track is enabled by default and minimum data is sent to Google.

Earnings
Although there is little advertising for the Mac version was made, was downloaded thousands of times in recent months. The browser is free to download, but still is underway on a revenue model, allows product management director Robert Hansen know . He gives the guarantee that no money will be earned on the information provided by users, as do many other browsers.
Current users of the browser, however, would be no need to worry, because the browser can always use for free. "Once we have determined how we can make money on new users will only have to pay for a license." In the future, other operating systems are supported. Alongside Mac and Windows