Since no one else is going to say it... Suddenly it doesn't seem like such a bad idea to remove Java from OS X. I for one can go without any applets and even minecraft on my macbook pro.
New Java trojan attacks Mac OS X via social networking sites
21–27 of 27 posts
Re: New Java trojan attacks Mac OS X via social networking sites
#22FTA: > A new trojan horse has cropped up that affects Mac OS X (and Windows as well) . Perhaps noteworthy in the title.
Re: New Java trojan attacks Mac OS X via social networking sites
#23Since no one else is going to say it... Suddenly it doesn't seem like such a bad idea to remove Java from OS X. I for one can go without any applets and even minecraft on my macbook pro.
Re: New Java trojan attacks Mac OS X via social networking sites
#24Earlier quoted context omitted.
First, Apple isn't removing Java from OS X. They will stop shipping their customized version of Java in several years. Second, every popular piece of software has vulnerabilities. So if this warrants the removal of Java, you should remove Safari and the BSD kernel from OS X as well.
There is no BSD kernel in OS X. The entire OS is Darwin running an XNU kernel that has a BSD layer within it. There is no way to remove the BSD layer without removing the entire OS.
Yup, that's the joke I was making... grandparent comment would have us remove all our software...
Re: New Java trojan attacks Mac OS X via social networking sites
#25Since no one else is going to say it... Suddenly it doesn't seem like such a bad idea to remove Java from OS X. I for one can go without any applets and even minecraft on my macbook pro.
Re: New Java trojan attacks Mac OS X via social networking sites
#26It seems to imply that once the link is clicked it downloads and runs the payload automatically, but this is rather hard to believe (I would guess that there is some user action required). Is the article correct?
Drive by download & execute vulnerabilities exist in Java for many browsers. So yes, it is possible for the "trojan" to work as described.
Re: New Java trojan attacks Mac OS X via social networking sites
#27Earlier quoted context omitted.
Drive by download & execute vulnerabilities exist in Java for many browsers. So yes, it is possible for the "trojan" to work as described.
If "as described" includes running automatically (without user permission), then you'd be incorrect in this case. This particular trojan doesn't include any privilege escalation exploits, so the user must confirm a couple of security dialog boxes (including keying their password) before the trojan can install.
The applet has full access to the local filesystem with the same priviliges the original user has. If needed the hackers can further exploit the machine, by escalating user priviliges with some corrupt scripting..
One click is enough to seriously damage your machine, be careful;) This is what the popup looks like in Firefox http://www.ussu.ca/studentgroups/JavaApplet.jpg