Earlier quoted context omitted.
What does that do?
From the article: For home users, unfortunately there isn't a simple solution for preventing this type of attack, until or unless Apple releases a macOS security update to mitigate the vulnerability. Cavallarin describes a possible temporary mitigation (opening /etc/auto_master in a text editor and adding # to the beginning of the line that starts with /net).
OS X/Linker: New Mac malware attempts zero-day Gatekeeper bypass
11–19 of 19 posts
Re: OS X/Linker: New Mac malware attempts zero-day Gatekeeper bypass
#12Earlier quoted context omitted.
From the article: For home users, unfortunately there isn't a simple solution for preventing this type of attack, until or unless Apple releases a macOS security update to mitigate the vulnerability. Cavallarin describes a possible temporary mitigation (opening /etc/auto_master in a text editor and adding # to the beginning of the line that starts with /net).
what are the implications of making this change to auto_master, beyond risk mitigation (i.e. to everyday use)?
Re: OS X/Linker: New Mac malware attempts zero-day Gatekeeper bypass
#13Most Mac users know that Flash is a piece of malware itself and would never be fooled into installing it.
Re: OS X/Linker: New Mac malware attempts zero-day Gatekeeper bypass
#14> The disk images are disguised as Adobe Flash Player installers, which is one of the most common ways malware creators trick Mac users into installing malware. Most Mac users know that Flash is a piece of malware itself and would never be fooled into installing it.
Re: OS X/Linker: New Mac malware attempts zero-day Gatekeeper bypass
#15Earlier quoted context omitted.
From the article: For home users, unfortunately there isn't a simple solution for preventing this type of attack, until or unless Apple releases a macOS security update to mitigate the vulnerability. Cavallarin describes a possible temporary mitigation (opening /etc/auto_master in a text editor and adding # to the beginning of the line that starts with /net).
what are the implications of making this change to auto_master, beyond risk mitigation (i.e. to everyday use)?
The first legit feature is automount (aka autofs) that allows a user to automatically mount a network share just by accessing a "special" path, in this case, any path beginning with "/net/". [..]
[1] https://www.fcvl.net/vulnerabilities/macosx-gatekeeper-bypas...
Assumably commenting out the line quoted by gp disables automount for network shares which start with "/net" in their path.
Re: OS X/Linker: New Mac malware attempts zero-day Gatekeeper bypass
#16> The disk images are disguised as Adobe Flash Player installers, which is one of the most common ways malware creators trick Mac users into installing malware. Most Mac users know that Flash is a piece of malware itself and would never be fooled into installing it.
What was the purpose of this statement?
Re: OS X/Linker: New Mac malware attempts zero-day Gatekeeper bypass
#17> The disk images are disguised as Adobe Flash Player installers, which is one of the most common ways malware creators trick Mac users into installing malware. Most Mac users know that Flash is a piece of malware itself and would never be fooled into installing it.
What was the purpose of this statement?
Re: OS X/Linker: New Mac malware attempts zero-day Gatekeeper bypass
#18> The disk images are disguised as Adobe Flash Player installers, which is one of the most common ways malware creators trick Mac users into installing malware. Most Mac users know that Flash is a piece of malware itself and would never be fooled into installing it.