User Name
Password
AppleNova Forums » Genius Bar »

I think I got hacked! Weird behavior with Safari


Register Members List Calendar Search FAQ Posting Guidelines
I think I got hacked! Weird behavior with Safari
Thread Tools
porter
Member
 
Join Date: Jul 2004
 
2004-08-21, 22:44

I have a G5 running OSX 10.2.8 with the latest security release.

So my dad tries to log into his banking account using IE and a weird message pops up saying that the certificate expired or that the webpage may be posing as fidelity. OK, so I'm thinking that they're doing some maintenance work over the weekend.

Later on Safari, I try to log into .Mac with Safari and I get the message that the certificate is not valid or expired. Which is a first for me, I've never seen this before.

So I try the same thing on Netscape and I get the same message, only this time it says the certificate won't be valid until 10/11/03 or something like that and it says to check my date and time- the time is correct, so just for shits and giggles I check the date and it's Jan. 1 1970. So I change it and now I don't get the weird messages. I don't think anybody in my family changed it, what could have caused it?
  quote
Ryan
Veteran Member
 
Join Date: May 2004
Location: Promise Land of Trustafarians
 
2004-08-21, 22:49

Did you zap the PRAM recently? That would reset the clock to that date.

Just connect to a network time server(there should be one in System Preferences) and all will be well with the world.
  quote
porter
Member
 
Join Date: Jul 2004
 
2004-08-21, 22:53

No nothing like that, I did unplug the computer last night because of thunderstorms, but this has never happened before.

But yeah, I did change the date and everything works, but I'm trying to figure out why the computer did what it did.
  quote
AirSluf
Member
 
Join Date: May 2004
Location:
 
2004-08-21, 22:59

XXXXX

Last edited by AirSluf : 2004-11-15 at 23:02.
  quote
usurp
High Monarch of MacDebate
 
Join Date: Jul 2004
Location: Kuwait
 
2004-08-22, 02:44

sorry this might be out of topic but how come your G5 is running 10.2.8? dont all G5s come with 10.3? or were the first G5s out before 10.3?

portable: MacBook 2.4Ghz, 2GB RAM, 250GB HD | personal: PowerMac G5 dual 2.3ghz, 6GB RAM, 6TB HD | work: MacBook Pro 2.5ghz, 2GB RAM, 160GB HD | car: Alpine iDA-W407 with black iPod 80GB | pocket: iPhone 3GS with Ultimate Ears Super.fi 5 Pro's
  quote
DMBand0026
Veteran Member
 
Join Date: May 2004
Location: Chicago
 
2004-08-22, 04:00

First G5s that came out ran a special build of Jaguar, 10.2.7 if I recall correctly. That build was only available for the G5s.
  quote
Brad
Selfish Heathen
 
Join Date: May 2004
Location: Zone of Pain
 
2004-08-22, 14:45

Quote:
Originally Posted by AirSluf
Simple, it checked the date on the computer and the date of the certificate and the check failed as the certificate was showing a date newer than what the computer had.
Bingo.

In further details, if the computer loses power or nukes the PRAM or NV-RAM, the internal clock is reset to the UNIX Epoch Time of 00:00 1970 January 1, GMT. This time is noteworthy because the clock on your computer is actually a simple counter that increments every second from that time. At least, that's how it works in UNIX and Mac OS X.

The quality of this board depends on the quality of the posts. The only way to guarantee thoughtful, informative discussion is to write thoughtful, informative posts. AppleNova is not a real-time chat forum. You have time to compose messages and edit them before and after posting.
  quote
FFL
Fishhead Family Reunited
 
Join Date: May 2004
Location: Slightly Off Center
 
2004-08-22, 17:38

Quote:
Originally Posted by DMBand0026
First G5s that came out ran a special build of Jaguar, 10.2.7 if I recall correctly. That build was only available for the G5s.
You Recall Correctly.
  quote
thuh Freak
Finally broke the seal
 
Join Date: May 2004
 
2004-08-22, 23:12

Quote:
Originally Posted by Brad
Bingo.

In further details, if the computer loses power or nukes the PRAM or NV-RAM, the internal clock is reset to the UNIX Epoch Time of 00:00 1970 January 1, GMT. This time is noteworthy because the clock on your computer is actually a simple counter that increments every second from that time. At least, that's how it works in UNIX and Mac OS X.
uninteresting side note: classic mac epoch was 00:00:00 1904 Jan 1, local time. from the jargon file
  quote
porter
Member
 
Join Date: Jul 2004
 
2004-08-23, 23:49

Well after I reset the date, I downloaded Virex from .Mac and ran it- I had 5 infected files all infected with the Exploit-ByteVerify Trojan!
  quote
Brad
Selfish Heathen
 
Join Date: May 2004
Location: Zone of Pain
 
2004-08-23, 23:56

Quote:
Originally Posted by porter
Well after I reset the date, I downloaded Virex from .Mac and ran it- I had 5 infected files all infected with the Exploit-ByteVerify Trojan!
Keep in mind, of course, that this is a Windows trojan. Like all Windows viruses, trojans, etc. it was completely inert on your Mac and could have caused you no harm.

This is a mere coincidence that you found it after your power was zapped and clock reset. It's very likely that it's been sitting on your computer for a very long time in an e-mail or something and since it can do you no harm you never noticed it.

That previous paragraph is so important that is bears repeating. This is a mere coincidence that you found it after your power was zapped and clock reset. It's very likely that it's been sitting on your computer for a very long time in an e-mail or something and since it can do you no harm you never noticed it.

The quality of this board depends on the quality of the posts. The only way to guarantee thoughtful, informative discussion is to write thoughtful, informative posts. AppleNova is not a real-time chat forum. You have time to compose messages and edit them before and after posting.
  quote
alcimedes
I shot the sherrif.
 
Join Date: May 2004
Send a message via ICQ to alcimedes  
2004-08-24, 01:01

Quote:
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

Systems Not Affected: Linux, Macintosh, OS/2, UNIX
as per symantec's page.
  quote
_Ω_
Veteran Member
 
Join Date: May 2004
Send a message via AIM to _Ω_  
2004-08-24, 01:18

Do you think they get tired of cutting and pasting that information for every virus/trojan out there?

  quote
porter
Member
 
Join Date: Jul 2004
 
2004-08-24, 08:29

Hmm... I didn't see that systems not affected section, but I wasn't too worried- not too many viruses out there for OSX.

If I had 5 infected files on a Mac, I wonder how many I had on my old PC!
  quote
Posting Rules Navigation
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Post Reply

Forum Jump
Thread Tools
Similar Threads
Thread Thread Starter Forum Replies Last Post
Safari window zooming thequicksilver Genius Bar 2 2004-07-08 17:39
Screen Shot of Cursor in Safari Stroszek Genius Bar 14 2004-05-21 15:09


« Previous Thread | Next Thread »

All times are GMT -5. The time now is 18:48.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004 - 2024, AppleNova