How I love the hunt!
Today's prey is an Internet rat known as species 'Scamware stupidicus'.
The rats who brought you the scamware (rogueware) "MAC Defender" (see my previous blog post) have now tweaked their code slightly and renamed the thing "Mac Security" with an installer entitled "BestMacAntivirus2011.mpkg.zip" which expands to the installer file "MacSecurity.mpkg". Expect there to be other name variations.
Good old Intego discovered this new variation, posting an article and a "How It Works" video here:
Intego Discovers New Variants of Mac Defender Fake Antivirus
You can directly watch the video on YouTube HERE.
Intego have updated their Virus Barrier malware signatures to detect this new rodent excrement.
What is hilarious about this scamware is the LAZINESS of the hacker rats who wrote it. The interface for the scamware is that of Microsoft WINDOWS!!! Hardy har. If you've used Windows in the last decade, you'll spot it immediately as BOGUS.
At this time the dangers are:
A) You fork out $money$ to buy useless garbage.
B) You give away your CREDIT CARD to criminals. It's a good as posting your card publicly on the Internet.
C) You give away your computer's PASSWORD. (This is now clearly evident from Intego's provided video). Consider yourself as good as PWNed (i.e. botted, i.e. zombied, i.e. no longer in control of your computer). So far the Trojan horse software is 'empty', containing nothing dangerous. But it could! Most likely, future variations will.
As with all current Mac malware, this POS relies upon social engineering, aka LUSER behavior, to entice the user to install it. Don't do that!
To keep ourselves safe, let's chant the mantra of...
The Top Two Rules Of Computing:
I) Make A Backup.
II) Verify All Software Before Installing It Or Running It.
(I'm considering using the following as Rule III:
III) Verify all links before clicking them).
Happy shooting!
--
Friends the content is bit messed up! Search from the searchbox and you will get what you want.
Showing posts with label PWNed. Show all posts
Showing posts with label PWNed. Show all posts
Thursday, 5 May 2011
Thursday, 17 March 2011
BBC: "US cyber war defences 'very thin', Pentagon Warns"
--
A quick post to note an article that finally points out the big DUH: That the US government has terrible cyber-security. It is well known, certainly if you've been following my posts, that the US government has been repeatedly PWNed by Red China since 1998. The US feds only admit, however, to being PWNed since 2007 when they discovered all their computers attached to the Internet had been infected with bots that were feeding every piece of their data over to Red China. It was also uncovered around that time that Red China had been circulating an internal memo declaring 'cyber war' on the USA. This is our #1 trading partner benefiting from 'Most Favored Nation' status. The mind boggles.
It's a good and short read, important if only because the Pentagon has finally come clean about their incredible LACK of readiness in the ongoing cyber-security warz.
US cyber war defences 'very thin', Pentagon Warns
And yes, despite FUD to the contrary, the US feds would be remarkably better off if only they would dump Windows and, chant along with me:
GET A MAC
Red China says: "Thank you USA for using Windows!" (0_o)
Mac OS X is far from perfect. But Windows is far from adequate. Mac OS X remains the single safest GUI operating system on the planet. Only OpenBSD and FreeBSD have better security reputations. Sorry Linux.
--
A quick post to note an article that finally points out the big DUH: That the US government has terrible cyber-security. It is well known, certainly if you've been following my posts, that the US government has been repeatedly PWNed by Red China since 1998. The US feds only admit, however, to being PWNed since 2007 when they discovered all their computers attached to the Internet had been infected with bots that were feeding every piece of their data over to Red China. It was also uncovered around that time that Red China had been circulating an internal memo declaring 'cyber war' on the USA. This is our #1 trading partner benefiting from 'Most Favored Nation' status. The mind boggles.
It's a good and short read, important if only because the Pentagon has finally come clean about their incredible LACK of readiness in the ongoing cyber-security warz.
US cyber war defences 'very thin', Pentagon Warns
And yes, despite FUD to the contrary, the US feds would be remarkably better off if only they would dump Windows and, chant along with me:
GET A MAC
Red China says: "Thank you USA for using Windows!" (0_o)Mac OS X is far from perfect. But Windows is far from adequate. Mac OS X remains the single safest GUI operating system on the planet. Only OpenBSD and FreeBSD have better security reputations. Sorry Linux.
--
Friday, 20 November 2009
The SANS Institute sez: NSA Helping to Harden Operating Systems
--
I'm kind of surprised to read this blurb from the latest edition of the SANS NewsBites newsletter (Vol. 11 Num 92):
My concern about this news:
If the NSA is so good at hardening operating system security, and good at protecting their systems from 80% of known cyber attacks, how come the US federal government computer system has been PWNed by China and other countries every year since 1998, including 2009?
Read THIS list from the Center for Strategic & International Studies and have a heart attack. Included on the list are:
February 2009 - US Federal Aviation Administration hacked.
March 2009 - US federal computer containing plans for the new presidential helicopter hacked.
April 2009 - The revelation that the US power grid had been hacked.
May 2009 - US Homeland Security Information Network hacked.
So where was the NSA during all this? And the NSA has what skills to offer Microsoft, Apple, Sun and Red Hat? Just asking.
More likely the NSA is supplying their experiences in security FAILure, such as sharing what hacking methods were successful against federal computers during their watch. Just saying.
You know I'm itching to point out that switching to a proven secure operating system is always helpful. For example, why are the feds still using Windows?! It boggles my mind. Windows is dead last on the list of secure operating systems. The top 3 are still:
- OpenBSD
- FreeBSD
- Mac OS X (which incorporates BSD Unix)
But I'm just some laymen guy with a few science degrees and some decades of computer experience who rants about the ridiculous state of computer security in my country.
(o_0)
--
I'm kind of surprised to read this blurb from the latest edition of the SANS NewsBites newsletter (Vol. 11 Num 92):
--NSA Helping to Harden Operating SystemsYou can subscribe to the SANS newsletters HERE.
(November 7, 18 & 19, 2009)
In testimony before the Senate Subcommittee on Terrorism and Homeland Security, National Security Agency (NSA) information assurance director Richard Schaeffer said that his agency helped Microsoft harden Windows 7 and that it is also helping Apple, Sun Microsystems, and Red Hat with similar endeavors. The NSA's involvement in the development process has led to speculation that backdoors will be built into the software to allow communications monitoring and interception. The NSA refutes those claims and says it is helping develop security guidelines and checklists. Schaeffer also said that agencies can protect their systems against 80 percent of known cyber attacks by following three steps: implementing best security practices, configuring networks properly, and monitoring networks effectively.
http://www.theregister.co.uk/2009/11/19/nsa_enhanced_windows7_security/
http://www.computerworld.com/s/article/9141105/NSA_helped_with_Windows_7_development
http://www.h-online.com/security/news/item/NSA-helps-Apple-Sun-and-Red-Hat-harden-their-systems-863889.html
http://fcw.com/Articles/2009/11/17/NSA-3-steps--better-cybersecurity.aspx
[Editor's Note (Pescatore): Ah, conspiracy theories. NSA and other government agencies have been involved in developing "gold" configuration definitions for standard software and network hardware products for a long time, along with the IT industry. Hardening in this case means better configuration and minimization of unneeded services.]
My concern about this news:
If the NSA is so good at hardening operating system security, and good at protecting their systems from 80% of known cyber attacks, how come the US federal government computer system has been PWNed by China and other countries every year since 1998, including 2009?
Read THIS list from the Center for Strategic & International Studies and have a heart attack. Included on the list are:
February 2009 - US Federal Aviation Administration hacked.
March 2009 - US federal computer containing plans for the new presidential helicopter hacked.
April 2009 - The revelation that the US power grid had been hacked.
May 2009 - US Homeland Security Information Network hacked.
So where was the NSA during all this? And the NSA has what skills to offer Microsoft, Apple, Sun and Red Hat? Just asking.
More likely the NSA is supplying their experiences in security FAILure, such as sharing what hacking methods were successful against federal computers during their watch. Just saying.
You know I'm itching to point out that switching to a proven secure operating system is always helpful. For example, why are the feds still using Windows?! It boggles my mind. Windows is dead last on the list of secure operating systems. The top 3 are still:
- OpenBSD
- FreeBSD
- Mac OS X (which incorporates BSD Unix)
But I'm just some laymen guy with a few science degrees and some decades of computer experience who rants about the ridiculous state of computer security in my country.
(o_0)
--
Subscribe to:
Posts (Atom)



