Slashdot Mirror


Mac Trojan Horse Disguised as Word 2004

Espectr0 writes "Macworld is alerting of a malware program for the Mac. A Macworld reader alerted the magazine to the malware after he downloaded the file from Limewire. The reader told Macworld: 'I downloaded the file in the hope that perhaps Microsoft had released some sort of public beta. The file unzipped, and to my delight the Microsoft icon looked genuine and trustworthy.' However, he added: 'I clicked on the installer file, and to my horror in 10 seconds the attachment had wiped my entire Home folder!'" This sounds similar to the recent trojan horse proof-of-concept. There are many ways to make one file look like another, on any platform. This is 2004, you should know by now not to open a file from an untrusted source.

170 of 785 comments (clear)

  1. "Darwin" - style award winner by ericspinder · · Score: 5, Funny
    I downloaded the file [off Limewire] in the hope that perhaps Microsoft had released some sort of public beta...and to my delight the Microsoft icon looked genuine and trustworthy"
    We have got to come up with a name for "someone who makes a good effort at removing themselves from the Internet".
    --
    The grass is only greener, if you don't take care of your own lawn.
    1. Re:"Darwin" - style award winner by Ieshan · · Score: 5, Funny

      Already got one. Notice how "microsoft" came up, even in the story about the Trojan on a Mac?

    2. Re:"Darwin" - style award winner by LookSharp · · Score: 2, Funny

      Congrats, you've just invented the Spinder Awards!

      How do I nominate someone? And when are the awards given? :)

    3. Re:"Darwin" - style award winner by Short+Circuit · · Score: 3, Funny

      Ouch.

      I was about to type a search for "spinder" in the google search in Firefox when I noticed the original poster's username.

    4. Re:"Darwin" - style award winner by rjamestaylor · · Score: 5, Funny

      Why do you think they call it Apple Darwin, anyway?

      --
      -- @rjamestaylor on Ello
    5. Re:"Darwin" - style award winner by pegr · · Score: 2, Funny

      There's a big difference between being mean-spirited because it's funny, and being mean-spirited because you're an ASS.

      /Obvious
      So which one are you? ;)

    6. Re:"Darwin" - style award winner by hazem · · Score: 2, Funny

      I'll bet he never does that again!

      One user educated... several millions to go!

    7. Re:"Darwin" - style award winner by Anonymous Coward · · Score: 2, Funny

      and so this joke dies...

    8. Re:"Darwin" - style award winner by Anonymous Coward · · Score: 5, Funny
      Trojan Horses do not wipe out Home folders... they only sit dormant and collect information. I think it was a virus that this guy downloaded, not a Trojan.

      Maybe if you look on Limewire you can find a "dictionary"

    9. Re:"Darwin" - style award winner by bamf · · Score: 5, Informative

      Actually I think you'll find that it fits the defintion of Trojan Horse perfectly.

    10. Re:"Darwin" - style award winner by SquadBoy · · Score: 5, Insightful

      This was a person who based a choice on whether or not to run an app based on how the ICON looked. They will repeat over and over and over again and wonder why the hell their shit keeps breaking.

      --

      Cypherpunks: Civil Liberty Through Complex Mathematics. Those who live by the sword die by the arrow.
    11. Re:"Darwin" - style award winner by anonymous+loser · · Score: 5, Funny

      This man is luckier than he realizes. He might have actually installed a Microsoft product instead of a mere trojan horse!

    12. Re:"Darwin" - style award winner by Paradise+Pete · · Score: 2, Informative
      Who dubbed this thing a Trojan Horse? Trojan Horses do not wipe out Home folders... they only sit dormant and collect information. I think it was a virus

      Two things there, chief: You don't know what a trojan horse is and you don't know what a virus is. Lemme enlighten youse:

      A Trojan Horse is something that appears benign, but has evil lurking inside. Ya see, there supposedly was this war, and Greece was having a tough time of it, so after a long siege they rolled up to the gates of Troy a huge wooden horse - a "gift" to their worthy adversary. After having put up this tremendous defense, the Trojans see this horse outside and say to themselves "Hey, we ARE great! And now even the great Greece is acknowledging it with this beautiful gift!" After some debate about what to do, they said "Let's being it inside! Yeah!" And so they did. That night the Greeks hiding inside the horse slipped out and opened the gates. It was curtains for the Trojans, and a metaphor was born.

      So you can see that a Trojan Horse does not "sit there and collect information." It does whatever bad things the creator wants it to, and the disguise is what gets it inside your gates..er, firewall.

      A virus is a piece of code that attaches itself to other programs, replicates, and may or may not do other bad things. It does not masquerade as something good, it tries to go unnoticed, at least at first.

    13. Re:"Darwin" - style award winner by Paradise+Pete · · Score: 2, Funny
      So basically, Microsoft Windows is a trojan horse?

      I guess so. I think they're starting to slip a bit on the benign appearance part, though.

    14. Re:"Darwin" - style award winner by 0x0d0a · · Score: 3, Interesting

      This was a person who based a choice on whether or not to run an app based on how the ICON looked. They will repeat over and over and over again and wonder why the hell their shit keeps breaking.

      And what methodology do you use to ensure that your software is safe, I have to ask? Really, there are no good generally-available methods of avoiding such trojans.

      I think I'm reasonably competent at determining whether something's a trojan, compared to most folks. I've been known to strings binaries, to disassemble and do raw code analysis, to use various debugging tools, and to run things chrooted. I generally stick with free open source software only. However, in all honesty, there are no real strong protection mechanisms available. It's not very difficult to produce a trojan that will get past these barriers.

      The problem is that people look at the statement "the icon looked legitimate" and think "hey, that isn't a good method to use to check the legitimacy of something" and immediately (and illogically) jump to "and I could do better".

      There's no real reason to ridicule the guy.

    15. Re:"Darwin" - style award winner by tuber · · Score: 2, Informative

      To be totally accurate, it wasn't a gift to the Trojans, that would make no sense. The Greeks pretended to have gone back to their respective kingdoms (Ithaca, Mycenae, etc.) and to have left the horse as an offering to the gods as atonement for Odysseus' theft of the Palladium from the temple of Athena in Troy.

    16. Re:"Darwin" - style award winner by cyril3 · · Score: 3, Interesting
      there are no good generally-available methods of avoiding such trojans.

      But even the bad ones are better than 'Gee, the Icon looks pretty. Virus writers are nortoriously bad artists so this program I downloaded from some unknown person that claims to be a secret beta of a Microsoft product should be fine to run'

      Hows this for a logical jump.

      Hey, that isn't a good method to use to check the legitimacy of something

      so

      I'll ring my aged grandmother and ask her should I run it and she'll say "Don't be stupid, running software like that you could catch one of those virus thingys that are running around these days" (She has a 50% chance of being right)

      and that would be better than looking at the freaking ICON.

    17. Re:"Darwin" - style award winner by FLEB · · Score: 2, Insightful

      And what methodology do you use to ensure that your software is safe, I have to ask?
      ---

      Download it from a trusted source (or check it against a hash from a trusted source). It might not be totally secure, but there's a lot less of a chance of it being malicious.

      --
      Information wants to be free.
      Entertainment wants to be paid.
      You just want to be cheap.
    18. Re:"Darwin" - style award winner by hesiod · · Score: 2, Funny

      > This was a person who based a choice on whether or not to run an app based on how the ICON looked

      That seems to be the status quo for a Mac user... If it looks cool, it must be really good!

    19. Re:"Darwin" - style award winner by geoffspear · · Score: 2, Insightful
      Macs ship with the ability of the root user to login turned off, but the "first user" and "root" have the same password by default - again it's worth changing that too (just change either password) so if you're asked by a program for your password, you can't inadvertently give that application root privilege.

      Thank you for that completely inaccurate explanation of administrator priviledges, which demonstrates you don't have any clue whatsoever what you're talking about.

      By default, root does not have a password at all. You don't need to enable the ability for the root user to login; setting an actual password for the root account (whether it's the same as that of any admin user or not) will allow root to login with that password. This is how the "Enable root access" option in NetInfo Manager enables root login. You can accomplish the same thing with "sudo passwd root" in your shell.

      As for making the root password different from the password of the first user's admin account, that has no effect whatsoever. An admin user can run sudo from the command line or give root access to the Install application (or any other application that knows how to get root access) with his or her own password no matter what you change any other account's password to.

      --
      Don't blame me; I'm never given mod points.
    20. Re:"Darwin" - style award winner by SmittyTheBold · · Score: 2

      And what methodology do you use to ensure that your software is safe, I have to ask? Really, there are no good generally-available methods of avoiding such trojans.

      Well, don't download warez from LimeWaire, for one. That guy was lying through his teeth; he tried tt get Word for free and got bitten. LimeWire has never been the fastest method for downloading anything, and you can bet if MS were offering Word for free you'd find out about it through other channels.

      --
      ± 29 dB
  2. New paradigm? by Suffering+Bastard · · Score: 5, Funny

    I downloaded the file in the hope that perhaps Microsoft had released some sort of public beta...I clicked on the installer file, and to my horror in 10 seconds the attachment had wiped my entire Home folder!

    Maybe this is Microsoft's new security paradigm. No one can steal your data, not even you!

    --
    "Molest me not with this pocket calculator stuff."
    - Deep Thought
    1. Re:New paradigm? by Bonker · · Score: 5, Insightful

      Surrrrreeee they thought it was a beta. Uh huh. That's why they went to Limewire rather than the MS website. Sure. Yeah.

      Open Office porters take note. At my last check, Mac users are still stuck with a sucky x11 version of OOO1.1 rather than the spiffy version available for Windows users.

      --
      The next Slashdot story will be ready soon, but subscribers can beat the rush and slashdot the links early!
    2. Re:New paradigm? by donnyspi · · Score: 2, Funny

      (Score:-1, Used the word Paradigm)

    3. Re:New paradigm? by Suffering+Bastard · · Score: 2, Funny
      (Score:-1, Used the word Paradigm)

      Dude...that was part of the joke. Is subtle sarcasm worth docking a point?

      Sheesh. Well, at least you're honest about your moderation.

      --
      "Molest me not with this pocket calculator stuff."
      - Deep Thought
    4. Re:New paradigm? by Applepuppy · · Score: 2, Funny

      I was wondering how long it would take for someone to blame this on Microsoft...

    5. Re:New paradigm? by AKAImBatman · · Score: 2, Informative

      I've been using NeoOffice/J for a little while, and it's far better than the "Official" X11 version. The only down side is that it's an older version that lacks PDF export support. :-( (Of course, the X11 version doesn't have that either.)

    6. Re:New paradigm? by JVert · · Score: 2, Insightful

      No one said he belived he was doing anything legal. He could have assumed it was from a closed beta test that would not be mentioned on the website or freely avalable.

    7. Re:New paradigm? by nomadic · · Score: 2, Insightful

      The guy was a moron.

      Well the fact that he expected us to believe that "public beta" line does call his intelligence into question.

    8. Re:New paradigm? by spiritraveller · · Score: 2, Insightful

      Another downslide is that it's very slow due to its reliance on java.

    9. Re:New paradigm? by jonom · · Score: 2, Funny
      No one said he belived he was doing anything legal. He could have assumed it was from a closed beta test that would not be mentioned on the website or freely avalable.

      In which case it would be, ummm...pirated?

    10. Re:New paradigm? by Anonymous Coward · · Score: 2, Funny

      >Open Office porters take note. At my last check, Mac users are still stuck with a sucky x11 version of OOO1.1 rather than the spiffy version available for Windows users.

      They're not stuck, the new version is on Limewire. Make sure that you check the icon to verify it's the real thing.

    11. Re:New paradigm? by SirTalon42 · · Score: 2, Informative

      Still stupid because he could of downloaded it from OpenOffice's website, or any of the mirrors. Most everything in p2p networks are slower than any of the mirrors would be.

    12. Re:New paradigm? by dave1212 · · Score: 2, Informative

      Heh. it's called 'Print-to-PDF' and it's for Classic mode or OS 9 only. Under OS X just choose File->Print and then choose 'Save as PDF..' instead of printing.

      That's for any app in OS X. Instant multipage PDFs from any program that can print.

  3. Think first by BWJones · · Score: 5, Insightful

    The reader told Macworld: 'I downloaded the file in the hope that perhaps Microsoft had released some sort of public beta.

    Using Limewire? A likely story.

    The file unzipped, and to my delight the Microsoft icon looked genuine and trustworthy.' However, he added: 'I clicked on the installer file, and to my horror in 10 seconds the attachment had wiped my entire Home folder!'"

    This is the risk you take when downloading stuff that you don't pay for. If you purchased Office 2004 from Microsoft (thus supporting the promotion and development of software for OS X), then you would have something to gripe about. As it stands, one might suggest you got what you paid for.....

    This is 2004, you should know by now not to open a file from an untrusted source.

    Well said. However, this does raise the possibility of other code that could be made to look like just about anything. So, once again, think about what you install on your computer just like you would think about what you eat or who you have sex with. If you don't know, trust or suspect that software/food/person, then either screen them or think twice.

    --
    Visit Jonesblog and say hello.
    1. Re:Think first by lukewarmfusion · · Score: 5, Funny

      "So, once again, think about what you install on your computer just like you would think about what you eat or who you have sex with. If you don't know, trust or suspect that software/food/person, then either screen them or think twice."

      The Slashdot folks obviously think alot about what kinds of food they eat (everything) and who they have sex with (nobody).

    2. Re:Think first by John_Sauter · · Score: 4, Funny
      So, once again, think about what you install on your computer just like you would think about what you eat or who you have sex with. If you don't know, trust or suspect that software/food/person, then either screen them or think twice.
      Hmmm. I detect a market for a software condom. That's a much better term than "sandbox" in some markets.
      John Sauter (J_Sauter@Empire.Net)
    3. Re:Think first by somethinghollow · · Score: 5, Funny

      just like you would think about what you eat or who you have sex with

      Or who you eat and what you have sex with.

    4. Re:Think first by bazmonkey · · Score: 2, Funny

      So, once again, think about what you install on your computer just like you would think about what you eat or who you have sex with.

      And make sure you have backups of anything worth keeping.

      Too bad you can't back up the other two... instruments. I must admit to seeing obviously-vile food items and wondering "What if...?"

      ...Then again, that doesn't hold true for the third example. Times like that I'm happy to have no reason.

    5. Re:Think first by nomadic · · Score: 5, Funny

      Using Limewire? A likely story.

      Yes, that's probably the least credible statement I've ever seen on slashdot. Just so you understand the impact of this statement, I'll highlight the important words: that's probably the least credible thing I've ever seen on SLASHDOT.

    6. Re:Think first by Anonymous Coward · · Score: 2, Funny

      It's not funny if your user ID is greater than his by 500,000.

    7. Re:Think first by eatmadust · · Score: 3, Funny
      So, once again, think about what you install on your computer just like you would think about what you eat or who you have sex with

      I doubt many /.ers need to worry about that ...

    8. Re:Think first by valkraider · · Score: 2, Funny

      I worry about it every night. I worry it will be no one... Again...

    9. Re:Think first by Trejkaz · · Score: 2, Funny

      That's a bit harsh. I mean, you do need a hole, and that considerably cuts down the candidate list.

      --
      Karma: It's all a bunch of tree-huggin' hippy crap!
  4. Windows by dicepackage · · Score: 4, Funny

    This would never of happened if they were using a secure operating system like Windows.

    1. Re:Windows by javatips · · Score: 2, Funny

      You're right... On Windows, the trojan would have been much more efficient... It would have wiped the entire hard drive!

    2. Re:Windows by johkir · · Score: 2, Funny
      From the article:

      A Microsoft spokesperson said: "Security is a top priority for Microsoft, and we are committed to ensuring a safe and reliable computing experience for all of our customers. Which means there will never be a trojan like that for windows.

      Ouch! Now my nose hurts.

      --
      These are some of the things molecules do...... given 4 billion years -Carl Sagan
    3. Re:Windows by aristotle-dude · · Score: 4, Informative

      I know this is meant to be a joke but this would happen on any platform with a stupid user at the helm. This is nothing like the proof of concept Trojan. It is a classic trojan (malware program claiming to be some useful program). Fortunately, the OSX security model prevented the damage from spreading outside of the home folder. An admin account (default on Home and Pro XP) would have the ability to totally destroy a system whereas Admin accounts on OS X are not root accounts.

      --
      Jesus was a compassionate social conservative who called individuals to sin no more.
    4. Re:Windows by BlackHawk-666 · · Score: 3, Funny

      All except for the IE cookies file which appears to be indestructable.

      --
      All those moments will be lost in time, like tears in rain.
    5. Re:Windows by b1t+r0t · · Score: 2, Informative
      If you doubt this, just try this from a terminal launched from any admin account:

      I did, but instead of deleting the file, it asked me for my password! :-)

      Seriously, with sudo, you still have to enter your password. You might as well call the standard admin security authorization dialog at that point. But "rm -rf ~/" on your home directory is still fair game to a cheap trojan.

      --

      --
      "Open source is good." - Steve Jobs
      "Open source is evil." - Microsoft
  5. beta by pizza_milkshake · · Score: 5, Funny
    in the hope that perhaps Microsoft had released some sort of public beta...

    yeah.

    1. Re:beta by sql*kitten · · Score: 2, Funny

      Microsoft releases betas. You can download the 64bit version of Windows XP, and it's good for a year.

      On Limewire?

  6. Let the Liar Beware by American+AC+in+Paris · · Score: 5, Funny
    A Macworld reader alerted the magazine to the malware after he downloaded the file from Limewire. The reader told Macworld: 'I downloaded the file in the hope that perhaps Microsoft had released some sort of public beta.

    Uh-huh.

    Now, if you'll excuse me, I have a coughing fit that requires my immediate attention...

    --

    Obliteracy: Words with explosions

    1. Re:Let the Liar Beware by Forgotten · · Score: 3, Insightful
      My guess is that the person doesn't exist at all, and instead was created by someone from Intego. The correspondence Macworld received is fictional. This would be in keeping with Intego's manner of operation in the past. They didn't necessarily create the Trojan and inject it into Limewire, but they'd certainly want to make it known as quickly as possible.

      Like most companies selling security software for personal computers, they're basically in the business of marketing snake oil, and that means the creation of FUD. It's a new concept in the Mac world, but age-old for Windows.

      From the Intego site:

      Intego VirusBarrier X eradicates this Trojan horse, using its virus definitions dated May 11, 2004, and Intego remains diligent to ensure that VirusBarrier X will also eradicate any future viruses that may try to exploit this same technique.


      WTF is that supposed to mean? And what is "infection" in the context of a Trojan horse?
  7. don't be dumb billy. by SuperguyA1 · · Score: 5, Funny

    Let's see... You downloaded a microsoft public beta from a p2p net without checking ms's website for any existance of the beta. Then just because the icon looked like a m$ icon you figured it was safe with no virus scan? If you purchase this BEAUTIFUL florida swampland I have I bet your files will be restored and word 2004 will work fine

    call me

    --
    "as plurdled gabbleblotchits on a lurgid bee" - Prostetnic Vogon Jeltz. (One man's humorous is another mans flamebait)
    1. Re:don't be dumb billy. by Trigun · · Score: 2, Interesting

      anyone know if a Mac comes with strings or a similar program?

      Always helpful when downloading off the net.

    2. Re:don't be dumb billy. by Daniel_Staal · · Score: 2, Informative

      Yep. It's there. (Though it may be part of the developer bundle, which I have installed also. Of course, the developer bundle comes standard, it just isn't installed standard.)

      --
      'Sensible' is a curse word.
  8. The Icon Looked Trustworthy! by Eagle5596 · · Score: 4, Funny

    Because everyone knows the icon is the best way to ascertain the security and authenticity of any piece of software. It's very secure and hard to change, uh huh.

    1. Re:The Icon Looked Trustworthy! by urmensch · · Score: 3, Interesting

      To be fair, a lot of windows users don't understand the difference either.

      A client I worked for couldn't deal with two mdb files on her desktop. It confused her that she could work with two databases independently, because to her, they were both just "Access".

      Cheers to the lusers!

  9. Not really similar to the other article by sith · · Score: 2, Informative

    The earlier article dealt with a document file showing the wrong file type because of extension VS resource fork issues.

    This is just a case of assigning a different icon to an application. Could be as simple as an rm -rf / shell script with a word icon.

    1. Re:Not really similar to the other article by Rick+Zeman · · Score: 2, Interesting

      This is just a case of assigning a different icon to an application. Could be as simple as an rm -rf / shell script with a word icon.

      That's exactly what it is. An Applescript calling rm -rf in a shell script with an MS icon on the Applescript applet. But, since it's UNIX, not windows, the only damage is self-inflicted by default.
      Now if the writer was mo' clever, he could have added authentication ("with administrator privileges") so the stupid person could have totally eradicated himself after supplying the administrator password.

  10. Why Not? by tarballedtux · · Score: 3, Insightful

    Every OS is vulernable to the ultimate virus: Stupidity.Virus.a Only one release was needed.

  11. This has nothing to do with Apple? by davidu · · Score: 4, Insightful


    This should be filed under the "Humans" topic as this has nothing to do with apple or even computers.

    Trojan Horses are social problems -- there isn't much apple or microsoft or anyone can do other than try to keep people on their toes.

    I mean come on, limewire?

    davidu

    --

    # Hack the planet, it's important.
    1. Re:This has nothing to do with Apple? by stratjakt · · Score: 3, Insightful

      No, I don't own a Mac, but I've worked with OSX a little, and more apps than should pop up that little sudo-dialog thing.

      So if the trojan popped up the "you must enter your administrator password to continue" box, how many would without asking questions?

      I mean the guy thought he was getting a beta release of word2k4 off of limewire?

      How big was the package he downloaded? Hundred megs or so, like word would be, or some 50k zip?

      UNIX doesnt magically protect you from stupidity, or from making mistakes.

      --
      I don't need no instructions to know how to rock!!!!
    2. Re:This has nothing to do with Apple? by austad · · Score: 2, Funny

      WTF don't some idiots realize that the valuable stuff on a computer is IN THE USERS HOME DIRECTORY.

      This is why I keep all of my valuable stuff in /tmp. No trojan would bother to look there. I think when I get home though, I'll move it all to /dev/null.

      --
      Need Free Juniper/NetScreen Support? JuniperForum
  12. Limewire Legal! by MacWannabe · · Score: 5, Funny

    Seriously, what a tard. The only things you can trust off Limewire is the quality porn!

    1. Re:Limewire Legal! by beatleadam · · Score: 3, Funny

      Here is how the article should have read.

      I downloaded this Phat slice of porn in the hope that perhaps Microsoft had released some sort of public beta porn. Well dude, I unzipped, and to my delight the Microsoft icon looked genuine and trustworthy...I clicked on the installer file, and to my horror 10 seconds later the attachment had wiped my entire Porn folder...now I need to figure out how to clean off this friggin' keyboard...

      --
      I have a theory that the truth is never told during the nine-to-five hours. -- Hunter S. Thompson
  13. Stupid user in, virus sob tale out... by LostCluster · · Score: 3, Informative

    'I downloaded the file in the hope that perhaps Microsoft had released some sort of public beta'

    That's a likely story...

    Come on people. The only trustworthy source of any public beta software from Microsoft would be a website in the form of "http://*.microsoft.com/*" and there'd likely still be pretenders claiming to be that package floating on Limewire. Don't trust that it's Microsoft software unless you've seen Microsoft make an say that the distributor is legit.

  14. Dear trojan writers. by juuri · · Score: 5, Funny

    Instead of deleting a person's files (I know you 0wn3r3d th3m!@#!) how about you do the rest of us a favour.

    From this point on all trojans, such as this one, who invite idiots to test the lows of their computer skills should, instead of removing random files, disable a person's net connection. Think about the good you would suddenly be doing for the online world! You can make a positive difference! Your life isn't lost yet! Go you!

    --
    --- I do not moderate.
    1. Re:Dear trojan writers. by DarkHelmet · · Score: 2, Funny
      disable a person's net connection

      Didn't blaster do something like this? It was an attempt at making the Windows morons not be able to go online...

      Now all we need are the mac morons offline and, the net is ours again!

      Yippie.

      --
      /^[A-Z0-9._%+-]+@[A-Z0-9.-]+\.[A-Z]{2,4}$/i
  15. Who would have thought ? by Jesrad · · Score: 5, Funny

    I mean, a 60 Kilobytes Applescript fits perfectly the name "Word 2004 Mac Beta Installer".

    D'uh.

    --
    Maybe we deserve this world ?
    1. Re:Who would have thought ? by Chanc_Gorkon · · Score: 2, Funny

      DOUBT that dude. No no, this is Microsoft. Their bloated installer would be around 2-5 MB at least! :D

      --

      Gorkman

  16. Fast User Switching Rules... by rthille · · Score: 4, Interesting


    This is a perfect use for Fast User Switching. Create an account with no perms and no data you care about losing. Test downloads in that account. You can do it without even logging out.

    Be careful though of the fact that there's no restriction on network access for a 'no perms' account. (This is a failing of UNIX in general, not MacOS in particular.) This would allow Microsoft/anyone to put out a trojan like this, and send back a 'this IP fell for it' packet, or even run a server on a 'high' port (depending on your firewall configuration).

    --
    Awesome furniture, accessories and cabinetry in Santa Rosa, CA: http://humanity-home.com/
    1. Re:Fast User Switching Rules... by Bullet-Dodger · · Score: 5, Informative

      Little Snitch is good for preventing anything from phoning home. Does have slightly annoying behavior unless it's registered, however. Anyone know of an OSS program to do this?

    2. Re:Fast User Switching Rules... by ducomputergeek · · Score: 4, Insightful
      Here is a better idea: don't try beating the system. 90%+ of all computer problems are really not lack of secure code, its the idiot sitting in front of the screen. While getting Office and other programs from p2p may be trendy and even "cool" to some, you run the risk that it might not be as advertised.

      Out in the professional world we do pay for everything. Why? In the last 6 months, two graphics designers in this town were busted for using warezed versions of Photoshop and black listed by other companies in the area including long time clients. And advertising/marketing being cut-throat as it is, there were glaring stories about it in the local business journal. Wow, probably $100k+ income lost to save $5k on software. Smart move there!

      If there was such a thing, then download from a MS website or trusted mirror (like download.com) or else roll the dice and take your chances.

      Personally I am waiting for the $10 for shipping beta from MS as I am classified as an "IT manager/decision maker" for our company (and several others as I also do consulting).

      --
      "The problem with socialism is eventually you run out of other people's money" - Thatcher.
    3. Re:Fast User Switching Rules... by scaryfish · · Score: 2, Informative
      Well, it's not OSS but it's free.. DenyIP

      Basically you hit command-option-k in any app and it brings up a window showing all the current connections to or from your computer. And you can kill any of them (by adding a rule to IPFW) right then and there.

  17. I'm lost by oneishy · · Score: 2, Insightful

    Is it just me, or did I miss all the Trojan like aspects of that program?

    Yes, it had undesirable consequences of running an un-trusted application, but Trojan?

    1. Re:I'm lost by justMichael · · Score: 3, Informative

      I think you are thinking of a worm.

      This is exactly what a trojan is.

      Just one of the many definitoins:
      A destructive program that masquerades as a benign application. Unlike a virus, Trojan horses do not replicate themselves but they can be just as destructive.

  18. Hmm by Bullet-Dodger · · Score: 3, Insightful
    This sounds similar to the recent trojan horse proof-of-concept.

    Not really, no. The point of that was that it was a application that looked like an mp3. This is just a application with a misleading name/icon. Anyone write code that erases a users home folder and call it Microsoft Word.

    1. Re:Hmm by CrowScape · · Score: 2, Funny

      But what's really impressive here is that they were able to spell Microsoft without the "$". No wonder he was fooled!

      --
      common sense: noun
      What those who are ignorant of the subject matter think; usually wrong.
  19. One question I'd like answered by Alcimedes · · Score: 2, Insightful

    He doesn't mention this in the article, but I was wondering if this asked him for a password before it executed.

    I would assume it would have to before it runs an rf command on his home directory.

    If it didn't ask for one, that's not good. If it did and he entered it in, he's a complete moron. Although the reality is, any OS will always be vunerable to user stupidity. It's the worms etc., that are a serious problem.

    1. Re:One question I'd like answered by MKalus · · Score: 2, Informative

      No it doesn't only if the program would want to do something that requires root privliges.

      ANY user can execute an rm -rf / it would just fail on all the files the Unix user does not have permissions on.

      M.

      --
      If you want to e-mail me, use my PGP Key.
  20. Untrusted source, maybe... by Conesus · · Score: 3, Insightful

    Sure, that file came from an untrusted source. In fact, doesn't it serve them right to get bitten by illegally downloading software? Software that should cost money, and in fact does (quite a bit).

    But forget that fact that this happened on an unethical download. The fact that this is malware, not a virus or a worm, not something that is exploiting the operating system by opening known bugs or attempting to hack into key parts of the system which normally would require keychain access, but that this is merely software that the user chose to install, and chose to authenticate (maybe? did it require keychain access to be able to delete files from the home directory? I think Apple probably allowed that to happen since programs *do* need to be able to write files to the Home directory, just not anywhere else, save for a temporary folder like /tmp).

    Just keep in mind that while the program itself was not ethical, nor were the actions of the user by downloading non-free software, this should come as no surprise to the user or to Apple, since this is not a compromise of the system nor something Apple can prevent, except through education (Don't open untrusted files and programs).

    Do you think this would have happened if the user was downloading legit sourceforge or another self-produced program that claimed to do something else and just became malware or a random pop-up creator? Would we cry foul if the program was *not* downloaded illegally?

    --

    Don't eat your soul to fill your belly.
    conesus.com
  21. Actually... by rtilghman · · Score: 5, Insightful


    If it was a windows installed you could check to make sure that various files were signed and authenticated by MS, information which I don't believe can actually be faked (dlls, exe, cab files, etc.).

    I don't know if Mac has a similar feature, and I don't know if some random moron like this guy would even have bothered to check. However, it would seem that MS' own security would indeed have offered a better chance of preventing such a Trojan. :)

    -rt

    1. Re:Actually... by aristotle-dude · · Score: 2
      Sorry but no, there is no such mechanism in windows that would prevent this type of trojan. This signature mechanism will only protect you from someone altering the executable and trying to spoof with a valid MS signature. Nothing prevents windows from running unsigned executables.

      I'm a developer on Win32 btw and use Visual Studio tools. All that signing does is prevent someone from altering an executable that has been signed.

      --
      Jesus was a compassionate social conservative who called individuals to sin no more.
    2. Re:Actually... by m_pll · · Score: 2, Informative
      Sorry but no, there is no such mechanism in windows that would prevent this type of trojan. This signature mechanism will only protect you from someone altering the executable and trying to spoof with a valid MS signature. Nothing prevents windows from running unsigned executables.

      Starting with XP you can use Software Restriction Plocy (SRP) which can do exactly this kind of things. Open up Local Security Settings under Administrative Tools and you'll find it.

      With SRP you can allow or disallow execution based on certificates, hashes, paths, or internet URLs.

      SRPs are probably not something that end users can be expected to configure but in a managed environment all these settings can be pushed to clients using group policy, and this is actually a very effective way to prevent trojans.

  22. Only home folder was hosed by trojan.... by Homology · · Score: 4, Insightful
    'I clicked on the installer file, and to my horror in 10 seconds the attachment had wiped my entire Home folder!'"

    A similar program om Windows could do far more than just hose someones Home folder, because most Windows users runs with high privileges.

    1. Re:Only home folder was hosed by trojan.... by HeghmoH · · Score: 4, Informative

      Yes, but the home folder is all that matters. The way UNIX protects system files is very nice, but the reality is that for most users, the stuff in /home or /Users or /users or whatever your flavor of UNIX uses is what counts. If you trashed my entire computer but left /Users alone, I'd be annoyed and reinstall. If you trashed /Users, I'd be annoyed and restore from backup... but most people don't keep anything resembling decent backups. Especially on a Mac, where it takes twenty minutes to reinstall the OS, the difference between trashing /Users or trashing the entire system is miniscule. Of course, if it's a multi-user Mac, a trojan can only trash the current user's files.

      --
      Mod down posts with a "Free Mac Mini/iPod" sig, they're spam!
    2. Re:Only home folder was hosed by trojan.... by nomadic · · Score: 2, Funny

      A similar program om Windows could do far more than just hose someones Home folder, because most Windows users runs with high privileges.


      Tell me about it, when I installed Windows it forced me to give it power of attorney...

    3. Re:Only home folder was hosed by trojan.... by RedBear · · Score: 2, Insightful

      We should always remember that UNIX-like permission systems do exactly what they were designed to do. UNIX was designed to run on mainframes and serve dozens, hundreds or even thousands of users. Normally this would be in a corporate environment or some other situation where the users would have limited space and limited reason to put a bunch of junk in their home folders. Also, the whole system including the dozens or hundreds or thousands of home folders would all be backed up by the organization. In this situation when one user does something stupid like this and hoses their home folder, they get a good scolding and their home folder is restored from backup (whenever the admin feels like being gracious). But that one user isn't allowed to destroy the entire system and bring the organization to a halt and destroy the home folders of every other user.

      There really is no way to protect the user from himself. If you allow that user to change or delete their own files, there is nothing short of a good backup system that will protect those files from a bad application that is allowed to run as that user. It's as simple as that.

      Or of course you could block all users from actually running any executable application outside the system "Applications" folder. I think Linux and BSD can both do this with the nodev/noexec mount options. But you'd also have to block access to things like the shell, so they couldn't run "sh rm -rf ~" and manually execute shell scripts. And you'd have to disallow any dangerous commands in AppleScript if we're still talking about Macs. In short you'd have to lock down the system so tight that it really becomes useless for most users, just to protect people like this from his inability to have a good backup and use common sense.

      But, I think if the home data is so important to everyone then personal computers should come with several FireWire backup drives the same size as the internal hard drive, and an ultra-simple backup/restore system, so they can plug one drive in every day/week and have incremental backups without thinking about it too much. It really wouldn't be too difficult, just expensive for all the extra disk space. Using external FireWire drives that get disconnected would mean that the backups can't get destroyed by a simple 'sudo rm -rf /' command. With tools like CarbonCopyCloner this scenario could be quite simple and workable.

  23. Not like the recent warning by Anixamander · · Score: 5, Informative

    This sounds similar to the recent trojan horse proof-of-concept

    This is nothing of the sort. The recent warning was for mp3 or other non-executable looking files carrying a trojan horse payload...that is far sneakier than this. This is simply a program that doesn't do what it claims to do. He expected an executable, he got an executable. An if he really thought that Microsoft would relase a public beta through limewire...well, caveat emptor and all.

    Since it only deleted his home directory, it probably wasn't that sophisticated. I'm surprised it didn't attempt to escalate privilieges under the guise of an installer and do even more damage.

    I suppose I should make a clippy joke here (I'm really tempted), but I actually like office X and am looking forward to the next version.

    --
    Do not taunt Happy Fun Ball(TM)
  24. Standard Anti-Microsoft Humor... by SuperChuck69 · · Score: 2, Funny

    How does this differ in functionality from Word 2003?

    --
    :wq
  25. Mac as prophylactic? by 7hrs4sec · · Score: 2, Insightful

    I wish I could say I'm surprised at the gullibility of this particular user, but I'm surrounded by an office full of similarly-minded folks. They're of the click-before-you-consider mindset simply because "we're on macs... all that bad stuff is for Windows users." I'm in hopes they're not all anxious to try out Word 2004.

  26. Macosxhints take on it by Isbiten · · Score: 3, Interesting

    Evily stolen from robg Link

    After reading the article and the press release, I think it's pretty obvious what the program is doing -- I suspect it's nothing more than a one-line AppleScript. Although some (perhaps many) will disagree with me, I'm going to publish what I think the exploit to be, because it's not a huge secret. Basically, my guess is that the trojan horse is a one-line AppleScript that contains the following UNIX command (in the script, the command will be accessed via the AppleScript method for calling a shell command, but I'm not going to bother including that part here):

    rm -rf ~

    WARNING!! DO NOT USE THIS COMMAND! YOU WILL ERASE YOUR USER'S DIRECTORY!

    I feel it's important that everyone understand the above command, and know what it looks like -- the more people who know what this line does and how it works, hopefully the fewer who will be fooled by it. And to claim that this is some "deep dark secret" that needs to be hidden is, in my opinion, trying to hide from the truth -- more "security by obscurity," which we all know doesn't work well at all. rm -rf is a very standard, very useful Unix command. In fact, if you search macosxhints (using the advanced search page) for the 'exact phrase' rm -rf, you'll get fully three pages of matches.

    What makes it troublesome in this case is simply that it's called from a program where the typical user will not know what's happening, and will be shocked at the outcome. But listing the command is not like explaining how to write a self-replicating virus that spreads from machine to machine -- this is common knowledge to probably at least a couple of million OS X users who have some knowledge of Unix.

    For those that don't know Unix, rm is "move to and empty trash," -r is "do this for all items and folders within this folder," the f means "force removal without confirmation," and the ~ means "the user's directory." Spelled out, this means that the script will, without warning or user intervention, delete everything in the user's folder. Permanently.

    The Intego press release explains one way to test a program if you suspect it might be a trojan horse -- select it, do a Get Info, and try to delete the icon. Here's another safety check that I often use myself: drag and drop the program onto Script Editor (or control-click on a package and select Show Package Contents to explore the package contents if it's a package installer). If you're lucky, and the script writer was somewhat lazy (by not making the script uneditable), the script itself will open for editing.

    So now that you know about this trojan horse, the question is, what should be done about them on OS X? My first thought on reading the article was "Cool, Darwin at work on the peer to peer networks!" But then, I considered some additional scenarios which may have more applicability in the real world. The current example is likely to remain on Gnutella, given that it's a program that purports to install the currently 'hot' application, the new Office suite. However, think about this version: A useful AppleScript that does something cool (change type/creator codes, backs up your directory, etc.). However, buried in the code is a timer that counts the number of times you've used the program. On the 50th run, it deletes your entire user's folder. Or worse, it pops up a dialog that says "In order to backup the Foo_bar file, we need your admin password." It may then be possible (I'm not quite sure how) for the app to delete the entire hard drive, instead of just your user's folder. If the script were useful enough, it could be very widely distributed, and then go blam! at some non-specified time in the future.

    What, if anything, should Apple do about this? Note that this is not specific to OS X; it's really a 'social engineering' exploit. I think it would be just as easy to write a similar 'exploit' for Linux or even Windows, given that it's a simple script that relies

    --
    I fought the corporate America, and the corporate America bought the law.
    1. Re:Macosxhints take on it by SuiteSisterMary · · Score: 2, Funny
      rm is "move to and empty trash,"

      So..the average mac user wouldn't understand 'rm is 'remove' or 'delete'?

      --
      Vintage computer games and RPG books available. Email me if you're interested.
    2. Re:Macosxhints take on it by Anonymous Coward · · Score: 3, Insightful

      There's nothing Apple can or should do. Aliasing 'rm' to 'rm -i' in your shell will only work if the person who writes the virus is kind enough to run your shell and let it load your aliases. They could write the commands in Applescript rather than using rm. They could write a C program to do it. This is all moot.

      If you have the power to delete all of your own files, then any program you run has that power too. Nothing can change that. Trojan horses are nothing new, and nothing surprising. They are a problem on every platform, even Linux, and have nothing to do with the operating system or the computer.

      There are companies that call people on the telephone and convince them to send them a check for $300 in return for a big-screen TV they'll never receive. This is made possible because (a) people can receive phone calls, and (b) people can give money to other people. No one suggests we remove telephones or checks from our lives to prevent such fraud.

      Trojan horses are just the computer equivalent of fraud. They have been around for a very, very, very long time, and will be around until the end of time. Nothing can be done by Apple to prevent them, just as nothing can be done by Microsoft or any of the Linux distribution maintainers. It's just how life works: if you have a gun, and someone tricks you into shooting yourself in the foot, you've just shot yourself in the foot. It's not a flaw in the gun.

      So how do you combat Trojan horses? Well, Trojan horses are not new. They date back to... yep! Troy!

      Beware of Greeks bearing gifts.

      The ancient adage still holds true today. Welcome a wooden horse full of soldiers into your city, and you're going to have a tough time blaming the manufacturer of the city wall for your city's subsequent downfall.

    3. Re:Macosxhints take on it by Isbiten · · Score: 2, Informative

      I don't think your average Windows user would either. Not all Mac users want to "get dirty" with the terminal.

      --
      I fought the corporate America, and the corporate America bought the law.
    4. Re:Macosxhints take on it by archen · · Score: 3, Insightful

      Holy crap, that has to be the most long drawn out boring explanation of rm -rf ~ I've ever read. I think this guy might have been one of my college professors. I imagine his explanation of DELTREE /Y C:\WINDOWS would put people into a coma.

    5. Re:Macosxhints take on it by Kiryat+Malachi · · Score: 2, Informative

      The standard meaning of "delete" on a Mac would be "move to trash". This is because, by default, selecting a file and "apple-delete"ing it moves it to the trash, it doesn't permanently remove it.

      However, rm doesn't have the intermediate trash step, which might confuse Mac users who rm something expecting it to land in the trash.

      --

      ---
      Mod me down, you fucking twits. Go ahead. I dare you.
      (I read with sigs off.)
  27. Third Mac OS X "Trojan" available by daveschroeder · · Score: 2, Interesting

    From the read me:

    Trojan Example Read Me

    This is an EXAMPLE of an AppleScript with a custom icon. It does nothing malicious. It does not spread. It does not delete files. It speaks and displays some dialog boxes. It's merely poking fun at Intego's sensationalist handling of these issues on Mac OS X, and their claims that these represent serious flaws in Mac OS X.

    I wonder if Intego will protect against, and describe, this trojan...?

    Perhaps they can make another press release hawking VirusBarrier.

    For more information:

    das@doit.wisc.edu


    Available at:

    http://mirror.services.wisc.edu/mirrors/tmp/

    The "trojan" is an AppleScript that speaks the text: "Muhahahaha. You have been owned by this elite trojan. Just kidding." It then displays a series of dialog boxes:

    1. "OMG! it's another trojan for Mac OS X! Will Intego have to protect against this one too?"

    2. "Intego's irresponsible sensationalism about non-issues is quite astounding."

    3. "They make wild claims about 'serious weaknesses' in Mac OS X that simply aren't true, for the sake of hawking their product."

    4. "AppleScripts and fake MP3s do not, nor will they ever, rise to the level of the mind-boggling number of completely remote exploits for Windows, requiring absolutely no user interaction, that plague millions of computers and cost billions of dollars of lost productivity."

    5. "Mac OS X is intrinsically and fundamentally more secure, and more open to peer and community review."

    6. "Social engineering problems, such as tricking a user into launching a fake Word installer that's really an AppleScript downloaded from a P2P network, don't reveal 'serious weaknesses' in Mac OS X."

    7. "Intego would be well suited to selling snake oil at a two-bit carnival."

    It then quits.

    It has Intego's VirusBarrier X installer icon, and is named "VirusBarrier X Install.app".

    (Note: this package is CLEARLY labeled as an example, and comes with a read me.)

  28. Re:Sort of... by Daniel+Dvorkin · · Score: 2, Insightful

    I've been a Mac user for a looong time now, and although the (relative) safety from malware is one of many things I like about using a Mac, I still think that in this situation, the user is at least as much to blame as the person who created the malicious file. There is no excuse for anyone who uses a computer, of any kind, in this day and age, not being aware of the danger of double-clicking on files from an untrusted source. (Cue snarky remarks about how even if it came from microsoft.com, the source would still be untrustworthy ...) Blame is not a fixed quantity -- in any crime, we blame the perpetrator, but sometimes there's some extra blame for the victim as well.

    --
    The correlation between ignorance of statistics and using "correlation is not causation" as an argument is close to 1.
  29. How to write a OS X Trojan by heyitsme · · Score: 5, Insightful

    1) Create shell script with "rm -rf $home/*"
    2) Package script with Microsoft Icon
    3) Upload to P2P network
    4) ???
    5) Laugh as retarded Slashdot editors call it valid malware

    Come on guys... lets get serious.

  30. "This being 2004..." by ChiralSoftware · · Score: 4, Interesting
    "This being 2004, you should know not to open a file from an untrusted source." WRONG! This is exactly the mindset that has resulted in the security problems that plague computers today. Operating environments should have the ability to fully contain and isolate any process. Operating environments should have the ability to run hostile code with complete safety. The smart thing to do is to start regarding ALL code as hostile. One side effect of that is that failures of non-hostile code will be contained, too, making for a more reliable system.

    How can such a goal be attained? There are many ways available now. The most obvious one is a VM system with security policies, such as the JVM. That's not the only one, though. Another method is a capabilities-based system, so when a process starts, it has only a defined set of capabilities to work with. OpenBSD has a similar, but more limited system called systrace. The TrustedBSD project and SELinux have similar aims, and SELinux is being integrated into mainstream Linux distros. Another way to run untrusted things is with user-mode Linux, which I believe is integrated with Linux 2.6

    The editor is right, though, that on currently-used systems like OSX and MS Windows, you have to be careful what you click on. But the problem is that we have come to accept that as "the way things are", when there is no reason for that to be the case. You should be able to run hostile code, see what it does, laugh at it, and delete it without any harm. The technology to do that exists, and has existed for years, but we have come to accept broken products and systems that don't allow that.

    ---------
    WAP news

    1. Re:"This being 2004..." by tc · · Score: 2, Insightful

      So how does the OS know the application is an "installer"?

      Suppose I wanted my installer to offer an option to convert my existing document files to a new format? Could I do that? Would the OS let me? How would I ask the user permission? Wouldn't the average user just say 'yes' if they were asked?

      Even supposing the installer is prevented from doing anything bad, how do you prevent the application once installed from doing bad things? If it has permission to read and write .doc files, say, then there are still plenty of malicious things it can do (like nuking all my documents when it's run).

      Fundamentally, my point still stands. In order to be useful, applications need sufficient permissions to do bad things, because it's not really possible to technologically tell the difference between good and bad in every case. A word processer has to be able to edit documents, so something posing as a word processor will have permissions to trash documents, and so forth.

      Again, the root cause is that the system and the user have no way of knowing that an application is trustworthy. This is a distinct problem from that of fine grained permissions.

  31. How big was the file? by foidulus · · Score: 4, Insightful

    You have to wonder, word is a pretty hefty piece of software, did the attackers even bother padding the program? A really quick download time would be one of a multitude of clues that what you are downloading probably isn't legit.

  32. Trojan was reverse-engineered ! by Jesrad · · Score: 5, Funny

    Newsflash, the source code of the trojan has been obtained. It's thought to be something like this:
    ----------
    tell application "Finder"
    move home to trash
    empy trash
    end tell
    ----------

    --
    Maybe we deserve this world ?
    1. Re:Trojan was reverse-engineered ! by SandSpider · · Score: 2, Funny
      I've found a variant!
      do shell script 'rm -r *'
      =Brian
      --
      There is nothing so good that someone, somewhere, will not hate it.
  33. The 404 Award by Gudlyf · · Score: 4, Funny
    In case it's not obvious, from here:

    "404: Someone who's clueless. From the World Wide Web message> "404, URL Not Found," meaning that the document you've tried to access can't be located. "Don't bother asking him...he's 404, man.""

    --
    Trolls lurk everywhere. Mod them down.
    1. Re:The 404 Award by Anonymous Coward · · Score: 4, Funny

      Going OT here, but here's the whole list of HTTPanties:

      100 Continue (she's accepting you)
      200 OK (go for it!)
      202 Accepted (see 200)
      300 Multiple Choices (pick a hole, any hole)
      400 Bad Request (explain what you mean)
      401 Unauthorized (she doesn't know you yet, but if she does, she'll let you)
      402 Payment Required (self-explanatory)
      403 Forbidden (I guess she's just not in that kind of mood)
      404 Not Found (she may be back)
      405 Method Not Allowed (guess the any hole part of 300 was wrong)
      406 Not Acceptable (she doesn't like you)
      408 Request Timeout (you were too slow - try again)
      409 Conflict (got some 3-way there?)
      410 Gone (damn, you got dumped)
      411 Length Required (she wants to know that first)
      413 Request Entity Too Large (stop buying penis pills)
      414 Request-URI Too Long (see 413)
      415 Unsupported Media Type (wait, this is a LESBIAN HTTP/1.1 error code thing?)
      416 Requested Range Not Satisfiable (she knows she's not good enough for you)
      417 Expectation Failed (self-explanatory)
      500 Internal Server Error (she should be checked out)
      501 Not Implemented (well, teach her!)
      503 Service Unavailable (wait a while, and watch)

  34. This is 2004... by Vrallis · · Score: 4, Funny

    This is 2004, you should know by now not to open a file from an untrusted source.

    This is 2004, you should know by now that Microsoft can't possibly have released Office 2004 this year.

  35. Shell script? by imidazole2 · · Score: 2, Interesting

    Thats just as lame as me writing a shell script to run a command to delete tons of stuff, and making it larger to look like its a real program! Why does crap like this get put on Slashdot?

    --

    -Imidazole2
  36. Word 2004 by Pac · · Score: 3, Funny

    Had Microsoft released it, wouldn't it be a trojan horse anyway? It will slow down your computer, transmit personal data to Microsoft and, if past versions history serves as comparison, open your computer wide to all sorts of attacks. Thinking of it, perhaps the version he downloaded is an alpha including only the "slow down, transmit and open" subsystems.

  37. I CALL BULLSHIT by falcon5768 · · Score: 2, Insightful

    its not a trojan, its a fucking applescript with a Microsoft icon on it. The dumbass deserved to get hit when they saw it was only 104 megs when every install of office had been 300 or more.

    --

    "Slashdot, where telling the truth is overrated but lying is insightful."

  38. There is no secure system by Anonymous Coward · · Score: 2, Insightful

    There is no secure system, and never will, as long as there are mentally-challenged users who blindly trust software from not-100%-legit origins.

    And bragging that such and such OS is more-secure-than-thou does not help either. The least-gifted users of this OSs will believe this and will feel a false sense of security and run whatever application falls on their hand. Most of these will be honest appl, but it takes only one to wreak havoc.

    As Albert Einstein said,

    Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.

  39. Clippy by WushuJim · · Score: 2, Funny

    It's not a virus, it's just Clippy!

  40. It *IS* a public beta from Microsoft by Mustang+Matt · · Score: 2, Insightful

    What better way to get the "security problem" media focus off yourself than by exploiting a competitor.

    --
    The man who trades freedom for security does not deserve nor will he ever receive either. - Benjamin Franklin
  41. You're exactly right by kuwan · · Score: 2, Insightful

    This has nothing to do with the Mac platform or the security of that platform. If I can convince you to run a malicious program, on any platform, then I can do pretty much whatever I want to your system.

    This exact same problem exists for Linux, Windows, Solaris, and *BSD. Unfortunately people will probably take this example to mean that the Mac OS X platform is somehow insecure because of it. I could do the exact same thing for Windows and if you would download it from LimeWire (or any other untrusted source) and run it then it could do just as much damage.

  42. Is there any reason to believe this at all? by bw5353 · · Score: 3, Insightful
    There seems to have been one really silly user who fell for about the oldest trick in the book - calling a bad executable something nice. Why do Macworld even bother reporting it?

    It is a non story even if it happened, and it is unlikely to have happened. Unless the guy is a 10-year old who fell for a trap his 11-year old sister set up for him.

  43. I think of the old yarn by UrgleHoth · · Score: 2, Informative

    If it sounds too good to be true, it probably is.

    --

    Dogma - "let's just say we'd like to avoid any empirical entanglements."
    1. Re:I think of the old yarn by 3dr · · Score: 4, Insightful
      This guy deserved it. "I downloaded it thinking Microsoft may have released a public beta." Oh come on, the attempt at piracy is entirely clear.

      Everyone else knows that they never release applications for public beta testing. They only release operating systems as public betas.

    2. Re:I think of the old yarn by BlackHawk-666 · · Score: 4, Funny

      Heh, Limewire is a well known app for getting warez^H^H^H^H^Hbetas from. He was probably also getting a beta of some albums he liked too.

      --
      All those moments will be lost in time, like tears in rain.
    3. Re:I think of the old yarn by one4nine4two · · Score: 2, Insightful
      do you really believe that the fundamental idea of open source software is too good to be true?
      He said the opposite, that he could not say that open source software was too good to be true.
    4. Re:I think of the old yarn by beerits · · Score: 2, Informative

      Microsoft Office 2004 does exist.

    5. Re:I think of the old yarn by dustmite · · Score: 2, Informative

      Not sure if you're being sarcastic here (don't know the Outlook side), but Office 2003 was mostly just a facelist for Office XP. Do you know how many people really think that the new version is very different just because they made it look different? It's idiotic. Conversely, they could have added tonnes of new features, and if they had left the look and feel the same, same idiots would then think that nothing had changed. Software developers virtually have to change the look and feel of new versions of their software, just to fool users into thinking they're getting some "major" new thing. Just plain psychology.

  44. Mac trojan/viruses: the next big thing? by jridley · · Score: 3, Insightful

    Now that at least some Windows users are starting to become aware of this sort of thing, are Mac users next?
    Most Mac users I talk to do nothing but go on about how they never have to worry about this sort of thing. Seems like a group of users that's that overconfident in their systems are ripe for infection.

  45. A mac virus! That's impossible! by Molonel · · Score: 2, Funny

    Mac's don't get viruses! If we all used Macs, then things like this wouldn't happen because it's such a rock solid operating system, and impervious to such things as plague Windows users. ... right?

    1. Re:A mac virus! That's impossible! by Molonel · · Score: 2, Informative

      Oh. Macs don't get viruses. I didn't know that. Thanks. http://www.faqs.org/faqs/computer-virus/macintosh- faq/ http://antivirus.about.com/cs/allabout/tp/aamacvir .htm http://www.icsalabs.com/html/communities/antivirus /macintosh/archives/macvirus/reference/viruses.htm l

  46. Social engineering by amichalo · · Score: 2, Interesting

    So this trojan was from 'Word 2004'..a decent one to pick because it recently started shipping.

    What other apps are good targets for trojan horses? I have always been afraid of downloading a 'virus scanner' because it just screams 'I have no virus scanner on my computer!'

    Others you have noticed? Perhaps a 'digital wallet' application to keep credit cards, passwords, etc. in :)

    --
    I only came here to do two things; kick some ass, and drink some beer...looks like we're almost out of beer.
  47. Nice handling of it... by CODiNE · · Score: 4, Insightful

    I just made a new user to run an rm -rf ~ on to see how it looks.

    I have to say I'm impressed with how Apple handles this situation. You actually have to do rm -rf ~/* but anyways, once your home directory is emptying there is no error message. No flood of missing files or application crashes. You just log out and log back in and hey you have the default's loaded again like a fresh user. Being a Windows/Linux switcher I have to say this is handled quite differently than I expected. At least in windows losing all your windows files is gonna cause some serious problems, may not be able to log back in again.

    Maybe I'm odd but eh. :)

    -Don.

    --
    Cwm, fjord-bank glyphs vext quiz
  48. Us Slashdot-geeks have created a monster! by WebCowboy · · Score: 4, Insightful

    Remember, a good deal of the Mac users out there are clueless ex-Windows user friends that we instructed to purchase Macs after scrubbing their old PCs of viruses, adware, spyware and other such crap one too many times.

    No matter how often we tell them otherwise, it is ingrained in them to use the icon as an indictor of a file's content. If it wasn't then a great deal fewer email viruses would make it into the wild.

  49. Steps to remove virus by platypibri · · Score: 2, Funny

    1.Box up Macintosh
    2. Return To Vendor
    3. Apologise profusely and tell them what you wanted was a eMachine!
    4. Do not complain when you are handed a box that says Atari 2600. This is more than enough computing for you.
    5. Enjoy Pitfall!!!!

    --
    Yeah, I guess I'm funny like that.
  50. News Flash: Macs can get viruses and trojans by tbase · · Score: 2, Insightful

    I worked on Macs as an certified tech back when the IIfx was the machine. I used to run Disinfectant on every machine I worked on, and there were tons of them that were infected, and this was on machines that didn't even have modems and weren't on networks. The only reason I bring this up is that this is probably a /. story soley because it involves a trojan or virus on a Mac. The fact that some poor schmuck actually downloaded what he thought was a commercial app from p2p network and tried to install it... this is "Stuff that matters"?

    --

    666-607: 6th floor apartment of the beast
  51. that's what I like about OSX by Arslan+ibn+Da'ud · · Score: 2, Funny

    Even the trojans 'just work'!

    --

    Practice Kind Randomness and Beautiful Acts of Nonsense.

  52. Slight mis-reporting of facts by LionMage · · Score: 3, Insightful

    I took the MacCentral website (which is now run by Macworld) to task for this, and I'll take Slashdot to task for the same thing. In some of the more reputable Mac-related news sites, this story was more accurately covered; the Trojan in question was downloaded from the Gnutella network. Limewire is not a network, it's a Gnutella client -- yet sites like MacCentral reported that the file was downloaded from the LimeWire network. Now on Slashdot, we're seeing much the same thing -- as if to imply that this Trojan is somehow only available with Limewire.

    Since there are at least 3 other Gnutella clients available for Mac OS X (Phex, Acquisition, and XFactor are the ones I know of), there are many more potential vectors for this Trojan to find its way onto a Mac user's computer.

    Yeah, I know, it's asinine to trade warez on any P2P network...

    There's nothing to stop this Trojan from making it to other file sharing networks, except perhaps a dose of common sense, so this isn't even a Gnutella-specific problem. I'm just a little peeved with sloppy news reporting.

    1. Re:Slight mis-reporting of facts by LionMage · · Score: 3, Informative
      I see no misreporting of the facts. The fact is that the person in question downloaded it via limewire. I see no statement that excludes other gnutella clients.

      It's nice to see that reading comprehension has dwindled to nothing these days. The article does not say that the file was downloaded "via" Limewire. And I never said that there was a statement excluding other Gnutella clients, but as you know, sometimes what goes unsaid is just as important as what is actually said. It might not occur to less technically inclined people that there is a distinction between Limewire (the client) and Gnutella (the P2P network).

      To prove my point, here's a quote from the Slashdot article.
      A Macworld reader alerted the magazine to the malware after he downloaded the file from Limewire.
      (Emphasis mine.)
      You don't download things from Limewire. You download software from the Gnutella network with (or using) Limewire. The distinction is subtle but important.

      For comparison, here's how the MacCentral article read:
      The latest advisory, posted to the company's Web site on Wednesday, warns of a Trojan Horse downloaded from the LimeWire peer-to-peer network[...]


      By contrast, here's how the incident was reported on Macintouch:
      The reader in question downloaded the file from the Gnutella peer-to-peer network, thinking that it was a public beta of Microsoft Word 2004.
      This is taken almost verbatim from Intego's own web page detailing the Trojan. Interestingly enough, "Limewire" isn't mentioned once on that page.
  53. The real questions... by inkswamp · · Score: 4, Insightful
    Intego is really starting to get on my nerves with this, and their previous, alerts. You could do this little stunt way back in OS 9. Cutting and pasting icons is easy.

    Strange that Microsoft has popped up in this one, huh? Hmm... if I were a conspiracy theorist....

    The real issues is whether it can it replicate itself and whether it can use security holes in OS X to distribute itself to others. I've been round and round with people on this topic and the conclusion is that, at every point, OS X presents too great a hurdle to allow it to occur. You either have to rely on lots of Apple programs working together to do it (which is too unwieldy and too visible to the user) or you have to rely on the more stealthy Unix stuff, much of which is turned off by default (i.e., no using mail quietly in the background to distribute the trojan/virus because sendmail is off by default.)

    It seems to me that Intego is looking to scare people into buying their products and in doing so, they have blown any credibility they have.

    --
    --Rick "If it isn't broken, take it apart and find out why."
  54. The files are not gone by Nom+du+Keyboard · · Score: 4, Funny

    The files are not gone. MSWord 2004 is just converting them all to its native format. Even on a G5 however this will take another 6 days, so simply remain calm and trust to Microsoft.

    --
    "It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
  55. What this makes me think of... by Anonymous Coward · · Score: 2, Interesting

    ...is the old verity about how difficult it is to scam an honest man. The ones who are looking for something more than they deserve are easy pickings.

  56. Like in biology, viruses have hosts by Theatetus · · Score: 5, Informative

    Just to clear things up for you:

    • A virus is a program that runs in the memory space of another executable and replicates itself to other instances of that executable; essentially, it's an unwanted plug-in.
    • A worm is a program that replicates itself against the user's wishes without requiring another executable as a host.
    • A Trojan horse is a program that masquerades as a desired program in order to gain access to the user's system. Trojan horses may or may not replicate themselves.

    This is pretty clearly a Trojan horse: it advertised itself to the lUser as a copy of Microsoft Word in order to gain access to his system. The payload of the unwanted software (be it virus, worm, Trojan, or something else) is irrelevant to its classification.

    --
    All's true that is mistrusted
    1. Re:Like in biology, viruses have hosts by darco · · Score: 4, Informative

      You are pretty close about the trojan, but your virus/worm definition is a bit off.

      The ONLY difference between a worm and a virus is that a worm actively spreads over a network. A virus needs a human to spread it, either by downloading infected files or swapping disks containing infected files. A worm can spread automaticly, requiring zero (or very little, in the case of viewing your mail) human contact. This is why they are so much more dangerous.

      --
      — darco
    2. Re:Like in biology, viruses have hosts by AbRASiON · · Score: 4, Funny

      Only on slashdot could the primary discussion on a topic end up discussing the terminology itself rather than the issue at hand :)

  57. Are they Serious!! by IAmAMacOSXAddict · · Score: 2, Insightful
    You gotta give me a break, this company is a bunch of idiots, or that is at least what they take us for...

    They claim there is a file out there that when you download it it deletes your home directory. I will say YES, there is...

    ONLY IF YOU ARE A FRICKIN IDIOT!!!!

    The "File" is nothing but a script that executes an "rm -rf ~" command. I can write a "Trojan Horse" with the same command in shell script, MS .bat, and numerous other scripting languages and in some cases compile it into an application as to remain unseen till it's too late. Please people stop making this shit up. If anyone seriously thinks the pirated application they are trying to get only takes 1-2 hundred K then THEY DESERVE TO GET THEIR INFO WIPED OUT!!!!

    --
    MacOSX, because making *NIX better is a lot better than waiting for Micro$loth to fix Windows
  58. Props to the adult movie studios for public betas by sjf · · Score: 5, Funny

    If all those adult video companies seed betas of their movies on LimeWire, why is it unreasonable to believe that Microsoft wouldn't do the same with software ?

    Just make sure you help them out by providing feedback...

  59. trojans by tgibbs · · Score: 3, Informative

    This sounds similar to the recent trojan horse proof-of-concept.

    No, that involved an application pretending to be a document. This is a case of an application pretending to be a different application. There is no security regarding the identity of applications, and an application can have any icon it chooses--the burden is on users to obtain their applications from trusted sources, not Limewire. Of course, if he really thought it was a "public beta," as he claims, he probably would have gone looking for it at the Microsoft web site.

  60. Sandbox needed even on Unix-style systems... by Spoing · · Score: 2, Informative
    Having your home directory wiped out can be devistating. (This is a bigger problem for some journaled file systems since it can be much more difficult to recover files that have been deleted.)

    Since the permissions on a Unix-stle system are to allow the user to control over what they 'own ' (mainly the home directory) there's little to prevent a program run by the user from doing whatever it wants with user data. This applies to Linux, *BSD, and the commercial *nixes as well, not just OSX.

    1. Here's the kicker: selinux and other ACL enforcement mechanisms won't protect protect the user from these trojan programs.

    In the short term there are technical 'fixes' that can help but they are not perfect. Libtrash under Linux or using a backup tool that does *not* have the same rights as the user are good CYA in the short run, though an isolated sandbox or similar tools should really be available. How to pull this off, I don't know...if you've heard of end-user tools that can pass the pointy-haired-boss test, let me know!

    1. Note on fast user switching: This is a crude sandbox and doesn't prevent
    2. that user account from being messed with in ways you may not be aware of. It also requires the user to set up this special account...something an automatic sandbox would not require.
    --
    A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.
  61. Aha! by karnifex · · Score: 5, Funny
    to my delight the Microsoft icon looked genuine and trustworthy

    This is where everything started to go wrong.

  62. Actually, it was not a Trojan. by rspress · · Score: 2, Funny

    It sounds like the real office to me.

  63. What good is a glass dagger? by argent · · Score: 2, Interesting

    The Mac doesn't (yet) have the plethora of mechanisms that viruses on Microsoft platforms use to automatically launch themselves, but the good old human engineering attack will work on anything. Back in 1980 at Berkeley people would stick prank files in their home directory with names like "advent450" to make people think they were enhanced versions of the old "Colossal Cave" adventure (which was undergoing frantic expansion at Berkeley at the time) and run them...

    It's like the Warlock in Niven's "The Magic Goes Away": the thing about being a magician is everyone expects you to use magic, but a dagger always works. No operating system can keep someone from explicitly unpacking and executing a file.

    So, no, the Mac is definitely not immune, but the rate of virus propogation on the Mac should be limited by the need for people to deliberately unpack and run the infected file. What makes virus propogation on Windows so rapid is the way they've integrated the browser and the desktop, which means that they have to block potential exploits one by one. Apple's web integration is not nearly so complete, though they're beginning to do things that I find dubious as they start getting feature-crazy with Safari...

    Of course when I tell people they probably want to turn off "automatically open safe attachments" in their browser, just in case, they come back with this argument that the Mac is immune to viruses. Well, yes, it's at least resistant... but that's only because there aren't many things like "automatically open safe attachments" for viruses to take advantage of.

    Yet.

  64. Idiot by dvNull · · Score: 2, Informative

    The reader told Macworld: 'I downloaded the file in the hope that perhaps Microsoft had released some sort of public beta.

    Lies .. The idiot tried to get warez. If you try and download warez off a p2p network and get screwed in the process, you deserve it.

    C'mon .. if it was a public beta, wouldnt it be on the MICROSOFT site?

  65. Well, you're close... by Theatetus · · Score: 4, Informative

    I'll quote wikipedia...

    A computer worm is a self-replicating computer program, similar to a computer virus. A virus attaches itself to, and becomes part of, another executable program; a worm is self-contained and does not need to be part of another program to propagate itself.

    So, to reiterate: a virus requires another executable as a host, a worm does not. That is the difference between the two.

    The concept of a "trojan horse" is somewhat orthogonal to that of "virus" or "worm", though I think it is a distinct enough phenomenon to warrant its own designation.

    --
    All's true that is mistrusted
    1. Re:Well, you're close... by Drooling+Iguana · · Score: 3, Funny

      Windows 95?

      --
      ... I'm addicted to placebos
  66. I think... by Cyno01 · · Score: 4, Funny

    That if i refered to someone as being "404", even my geekier friends would slap me. Almost as bad as the time i heard someone using the future slang from tom clancy's net force books...

    --
    "Sic Semper Tyrannosaurus Rex."
  67. Feature Suggestion - launch as untrusted by soft_guy · · Score: 4, Insightful

    I think it would be a good idea to have a feature in OS X that could launch a program as "untrusted". It should be able to restrict the programs access to the file system, the network stack, etc. Kind of like what .Net does, except not as extreme.

    --
    Avoid Missing Ball for High Score
  68. Re:The actual command by IceAgeComing · · Score: 2, Insightful

    I'd advise protecting yourself and alias rm to 'rm -i'.

    An alias is easy to defeat, so it shouldn't be seen as a good defense. An alias will not prevent the following commands from deleting files automatically: /bin/rm -rf ~
    \rm -rf ~

    Try running on a junk file after you've created the alias if you want to see for yourself.

  69. But... by Cyno01 · · Score: 2, Funny

    As we've seen in recent weeks, quality porn is hardly virus free.

    --
    "Sic Semper Tyrannosaurus Rex."
  70. 7 levels of conspiracy theories by Warlock48 · · Score: 5, Funny
    1- Some guy made a bad joke
    2- A Mac zealot did it coz' he doesn't like Microsoft stuff running on Macs
    3- Microsoft did it to teach pirates a lesson
    4- A Linux zealot did it to discredit Microsoft
    5- A BSD zealot did it to discredit Linux
    6- SCO did it because they own the IP of all Unix-based systems, so there
    7- Kevin Bacon did it

    ... Obviously, any of the above was controlled by NSA's orbital mind-controlling ''lasers''.

  71. Free Software by krmt · · Score: 2, Interesting

    When people ask me why I use Linux, one of the things I always say is "I never have to pirate software anymore." Everyone ignores it, but this story demonstrates why I always mention it. When you don't have to pirate software, you don't have to worry that some program that you need but can't afford or don't want to pay for is going to destroy your system. All my stuff comes from a much more trusted source than Limewire.

    Everyone I know who uses Windows and pirates software like this has to put up with this shit. It's just not worth it, especially when you just want to get your work done. Of course, in these days where you plug your machine in and you get a host of infections automatically within a 24 hour timespan perhaps no one really worries as much about these things anymore.

    --

    "I may not have morals, but I have standards."

  72. Old news? 10 years ago we had this problem by Foo2rama · · Score: 3, Informative

    Isn't this old news?? Back in the BBS days alot of files floated around that purported to be installers. But when run they would trash your system folder, drop alot of viruses, and then install joke extensions. I know many of the So Cal mac BBS's had to clean out alot of files due to installers like these. So 10-11 years ago we had the same problem.

    --


    ---In a time of Chimpanzees I was a Monkey.
  73. pirate who found something odd by Agile+Monkey · · Score: 5, Funny
    Ok, let's see here. He's poking around on limeware looking to get some free software. I'll call it piracy, you can call it "unauthorized downloading of a copyrighted work".

    So anyway, this guy downloaded something, and *GASP* his ignorance of what software is out there made him get something he didn't want.

    This might be kind of funny if its a friend of yours, but seriously folks, is this really front page material for slashdot? I love this site, I truly do, but please editors at least have some standards for what gets on the front page.

    --
    It puts the lotion on its skin or else it gets the hose again.
  74. the best part by SQLz · · Score: 4, Funny
    The file unzipped, and to my delight the Microsoft icon looked genuine and trustworthy.

    Its all about the icon baby, all about the icon. As long as that *looks* legit, you know the warez are genuine. bahahaha.

  75. A note from Intego by theolein · · Score: 5, Funny

    Q&A from Intego regarding Trojan Horse

    Where did Intego first find out about this Trojan horse?
    Intego, after writing and releasing the first mp3 trojan for the Mac OSX platform in order to improve our business, decided to write a dangerous Applescript, give it an installer icon and release it in order to further generate sales for our otherwise uselss AV products that no one wants. Even though this is not a real trojan and this approach involves social engineering that has been known about for years (We initially considered simply writing a readme file that instructed the user to type "rm -rf ~/" in the terminal, but thought that that would be too complex) we know thta our approach, known as the SCO school of IT business, is guaranteed to raise revenue.

    Have you informed Apple, Microsoft and the CERT about this Trojan horse?
    Yes, we informed Apple, Microsoft and the CERT as soon as had done our first working Applescript. They were very proud of us. Especially the people at Microsoft.

    Has Microsoft made any comments about this Trojan horse?
    Microsoft made the following comments: "Microsoft has verified that it does not write or encourage others to write trojans for the Macintosh platform. Microsoft, however, certainly is not above offering the occasional tip when it comes to torpedoing other company's platforms"

  76. TEN Seconds? by bfg9000 · · Score: 4, Funny

    'I clicked on the installer file, and to my horror in 10 seconds the attachment had wiped my entire Home folder!'

    Whaaaat? TEN FRICKIN' SECONDS!!! Dude, you need to upgrade. My G5 smoked my home directory in TWO.

    --

    I'm not normally an irrational zealous dickhead, but I figure "When in Rome..."

  77. Newsflash! by mabu · · Score: 3, Insightful

    Mac user pirates a 10kB OSX version of Word and gets all his stuff deleted.

    Don't you think Slashdot is the last place where people need to be made aware of something like this?

    Turning your boneheaded mistake into a security advisory isn't going to win you much respect here.

  78. /. dichotomy by YrWrstNtmr · · Score: 2, Insightful

    A Mac user opens an unknown file from an untrusted source, it turns out to be destructive, and it blows away his data.
    Conclusion - said Mac user is at fault.

    Windows user open an unknown file from an untrusted source, it turns out to be destructive, and it blows away his data.
    Conclusion - Microsoft is at fault.

    Of course! How could I not see the difference?

  79. Why is this news? by Cruciform · · Score: 2, Insightful

    Honestly, why did this even get a link?

    User downloads executable from peer to peer network, runs said executable, and loses data.

    If it wasn't labeled MS-Word would we have even seen this? I find it highly doubtful.

    You would think by now, with all the scumware out there, people would realize that software should be downloaded at the source, or from a reputable middleman, not from anonymous sources who may have altered the payload in some way.

    It doesn't matter if it's on a Mac, Windows, or Linux machine. Running "mystery code" is just plain stupid.

  80. Re:This looks more like a flaw in the OS. by phillymjs · · Score: 2, Insightful

    However, why are OS's designed to let such a small mistake have such a dire consequence?

    If you want an OS that won't give you complete control over your own data, I think Microsoft will oblige you in a few years, and I'm sure hard drive manufacturers would also welcome an operating system that never let a user delete anything. :-)

    Mac OS X, Linux, and Windows are all designed to let the user have control of their own files, up to and including the ability to delete them without confirmation. There are no dire consequences in this particular case with Mac OS X, the system is fine: it remains bootable, the other user accounts present on the system are untouched, and the affected user account is still perfectly usable, reverting to default settings for everything. Yeah, the victim's data is gone, but if you don't make backups you're just asking for trouble anyway.

    This is nothing at all like a car having a self destruct button-- we're not talking about a special command that does nothing but trash the system here, we're talking about a perfectly valid command with perfectly valid uses. To adjust your analogy, this is like a car having an accelerator that you could push to the floor, and a steering wheel that you could use to guide it into the path of an 18-wheeler heading in the opposite direction.

    Maybe it's time that OS makers realize that computers aren't just used by sys admins, but real people, which includes kids, morons, and the gulliable.

    Microsoft did. This realization begat "Bob." 'Nuff said.

    ~Philly

  81. Easy Pie... by firew0lfz · · Score: 3, Interesting

    On the note about the whole making the Icon look like the real thing... uhm guys, can't you do this just as easy as in Windows?

    Here is a link to get you guys started on tricking your friends into formatting their hard drives:
    http://lockdowncorp.com/hackertricks.html

    From that page:
    "Dangerous Commands That Can Be Embedded

    PIF Shortcut Extensions

    Some hidden file extensions can easily be programmed with hidden commands that could do damage to your system. Following is a simple test:

    1.

    Right click your mouse on your desktop and select New
    and then ShortCut
    2.

    In the command line type: format a: /autotest
    3.

    Click Next
    4.

    In the "Select a name for the shortcut" area type: readme.txt
    5.

    Click Next
    6.

    Select a notepad icon and click Finish

    You now have a file on your desktop called readme.txt with a notepad icon. Make sure there is a disk in your drive that you do not mind being wiped and click on the icon. The file that you click on will do a format on the disk in the A: drive. Of course, the hacker's icon would target another drive, or maybe have a name such as 'game.exe' and with a command to delete your Windows directory or (deltree /y c:\*.*) your entire C drive!

    If the PIF extension were not hidden, this would not be able to fool you."

    Or, you could also do the following:

    "SHS Extensions

    Scrap files can also hide embedded commands. Following is a simple test:

    1.

    Make a copy of notepad.exe and put it on your desktop.
    2.

    Open Wordpad
    3.

    Click and drag notepad.exe into the open wordpad document.
    4.

    Click on Edit and select Package Object, then select Edit Package
    5.

    Click on Edit and then Command Line
    6.

    Type a command in the box such as format a: /autotest and click on Ok
    7.

    The Icon can also be changed from this edit window
    8.

    Exit from the edit window and it will update the document
    9.

    Click and drag notepad back to the desktop
    10.

    Rename the file that it created (Scrap) to Readme.txt

    You now have what will look like a text file. If it is run it will format the disk in the A: drive. As seen in the example above for PIF Shortcut Extensions, the hacker could use more dangerous commands."

    Various other types of info available there. Enjoy.

    --
    Try not to let life get in the way of living.
  82. Smack..... by vwjeff · · Score: 2, Insightful

    I downloaded the file in the hope that perhaps Microsoft had released some sort of public beta. The file unzipped, and to my delight the Microsoft icon looked genuine and trustworthy.

    When was the last time Microsoft released ANY program on a P2P network?

    I guess I should say official release.

  83. Re:Props to the adult movie studios for public bet by Alien+Being · · Score: 2, Funny

    "why..."

    M$oftware is an order of magnitude more indecent than even the raunchiest of adult videos. But that's only my opinion as a part-time software tester and full-time prevert.

  84. No by Dr.+q00p · · Score: 2, Interesting

    "UNIX was designed to run on mainframes and serve dozens, hundreds or even thousands of users."

    Actually, UNIX was designed to run as a game platform on a PDP-7 minicomputer. :)

    From Origins and History of Unix
    "Unix began its life on a scavenged PDP-7 minicomputer[14] like the one shown in Figure 2.1, as a platform for the Space Travel game and a testbed for Thompson's ideas about operating system design."