User Name
Password
AppleNova Forums » General Discussion »

First Mac OS X Worm Discovered


Register Members List Calendar Search FAQ Posting Guidelines
First Mac OS X Worm Discovered
Thread Tools
xeex
Member
 
Join Date: Jun 2005
 
2006-02-17, 09:16

Im sure everyone have read it today, but for those who didnt, here we go:

Experts at SophosLabs, Sophos's global network of virus, spyware and spam analysis centers, have announced the discovery of the first virus for the Apple Mac OS X platform. The virus, named OSX/Leap-A (also known as OSX/Oompa-A) spreads via instant messaging systems.

The OSX/Leap-A worm spreads via the iChat instant messaging system, forwarding itself as a file called latestpics.tgz to contacts on the infected users' buddy list. When the latestpics.tgz archive file is opened on a computer, it disguises its contents with a JPEG graphic icon in an attempt to fool people into thinking it is harmless.

The worm uses the text "oompa" as an infection marker in the resource forks of infected programs to prevent itself from reinfecting the same files.

Graham Cluley, senior technology consultant, Sophos, said, "Some owners of Mac computers have held the belief that Mac OS X is incapable of harboring computer viruses, but Leap-A will leave them shellshocked, as it shows that the malware threat on Mac OS X is real. Mac users shouldn't think it is okay to lie back and not worry about viruses."

"This is the first real virus for the Mac OS X platform. Apple Mac users need to be just as careful running unknown or unsolicited code on their computers as their friends and colleagues running Windows," Cluley said.

Sophos advises all computer users, whether running PCs or Macs, to practise safe computing and keep their anti-virus software updated.

Some members of the Apple Macintosh community have claimed that OSX/Leap-A is a Trojan horse, and not a virus or worm, because it requires user interaction (the user has to receive a file via iChat, and manually choose to open and run the file contained inside).

A Trojan horse is a seemingly legitimate computer program that has been intentionally designed to disrupt and damage computer activity. Importantly, Trojan horses do not replicate or have any mechanism of spreading themselves. They have to be deliberately planted on a website, or accidentally shared with another user, or spammed out to email addresses. There is nothing inside a Trojan's code to distribute themselves further to other victims.

Finally, Trojan horses do not contain any code to distribute or spread themselves, viruses and worms do.

OSX/Leap-A is programmed to use the iChat instant messaging system to spread itself to other users. As such, it is comparable to an email or instant messaging worm on the Windows platform. Worms are a sub-category of the group of malware known as viruses.
 
chucker
 
Join Date: May 2004
Location: near Bremen, Germany
Send a message via ICQ to chucker Send a message via AIM to chucker Send a message via MSN to chucker Send a message via Yahoo to chucker Send a message via Skype™ to chucker 
2006-02-17, 09:18

Dupe.
 
Brad
Selfish Heathen
 
Join Date: May 2004
Location: Zone of Pain
 
2006-02-17, 09:50

Yeah, be sure to check for existing discussions before starting new ones. This is actually the third thread to be started on this subject.

Also, from the posting guidelines:
Quote:
Do not post a link or quote an article while contributing little to nothing of your own.
 
Posting Rules Navigation
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Closed

Forum Jump
Thread Tools

« Previous Thread | Next Thread »

All times are GMT -5. The time now is 17:34.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004 - 2024, AppleNova