Slashdot Mirror


Apple Developing Tool To Remove Flashback

Trailrunner7 writes, quoting Threatpost: "Apple is planning to release a software fix that will find and remove the Flashback malware that has been haunting Mac users for several months now. ... Apple said on Tuesday that it was in the process of developing a tool that would detect and remove Flashback, but the company did not specify when the fix would be available. Security researchers and customers have been questioning why Apple hasn't yet provided a fix for the malware even though Flashback has been around in one form or another for more than six months now."

40 of 212 comments (clear)

  1. if steve jobs was still here by alen · · Score: 5, Funny

    he would hire elite apple assasins to kill these supposed security researchers to stop the bad news

    1. Re:if steve jobs was still here by Anonymous Coward · · Score: 2, Funny

      If Jobs was still here he would tell you that you are "holding it wrong".

    2. Re:if steve jobs was still here by cant_get_a_good_nick · · Score: 5, Funny

      Begun. the cat and mouse game has.

      Proper grammar, Yoda would speak with.

    3. Re:if steve jobs was still here by CAIMLAS · · Score: 2

      That may be modded funny, but their response has probably closer to that right now than it is any actual sincere security response.

      It's really quite embarrassing (for them). I'd expect this from a small company, not a multibillion (trillion?) dollar international corporation. It does not make me have faith in their ability to effectively and safely maintain their software stack.

      --
      ~/ssh slashdot.org ssh: connect to host slashdot.org port 22: too many beers
  2. Slow is good by Sarten-X · · Score: 4, Informative

    Security researchers and customers have been questioning why Apple hasn't yet provided a fix for the malware even though Flashback has been around in one form or another for more than six months now.

    Because they're doing the same thing Microsoft does with its slow-as-molasses patches: testing for side effects, on every major application, on every piece of hardware they can get their hands on.

    --
    You do not have a moral or legal right to do absolutely anything you want.
    1. Re:Slow is good by FudRucker · · Score: 4, Informative

      if it was Linux based malware a patch would have been out within 24 to 48 hours, six months is enough time to create a new version of the entire operating system,

      --
      Politics is Treachery, Religion is Brainwashing
    2. Re:Slow is good by ledow · · Score: 2

      Meanwhile, all those applications are running in your large corporation while riddled with malware that's difficult to detect, isolate and remove.

      Put out a patch and EVERYONE can test, and those for whom it is critical can TELL you what it did to their machines and/or choose to apply it or not.

      Meanwhile, every home user is typing in their bank details into a computer that's reading their every move because some obscure application on the other side of the planet "might crash".

      And, to be honest, any application that is affected by an external tool that clears a malware infection was either a) infected or b) poorly designed and implemented. That's what an OS is FOR - to isolate programs from each other and the hardware.

    3. Re:Slow is good by Coisiche · · Score: 4, Funny

      ...on every piece of hardware they can get their hands on...

      But it's Apple, isn't there just one bit of hardware to check?

    4. Re:Slow is good by Anonymous Coward · · Score: 5, Informative

      Actually the quote is quite opinionated and wrong. Apple provided java patches that basically close the hole and make the malware issue mute. Flashback HAS existed for months, but its also using a new vulnerability each time it comes up (its used a Flash hole, a PDF hole and a Java hole, three things not even developed BY Apple.) Likewise they have been patching the OS to flag Flashback in previous versions of the trojan.

      The whole quote both shows the writers complete lack of knowledge of whats been done about Flashback that any competent system administrator knows already (hell we even have scripts developed to flag machines that MAY be infected and have had them for months this is ON TOP OF the info Apple has been providing us) as well as his bias in trying to spin this as if this thing is a huge issue (honestly is not, its not even the first real vulnerability on the Mac OS, there were numerous worms for Quicktime back in the 90's that abused Quicktimes autoplay feature, AND THOSE didnt require you to authenticate as admin since pre-osX you ran as root.)

    5. Re:Slow is good by Sarten-X · · Score: 4, Funny

      If you're running Linux, you're probably competent to fix things if a patch breaks them.

      If you're running OS X, you're probably confused enough by the patch in the first place.

      If you're running Windows, you're probably just going to complain to some IT guy when the report looks slightly different.

      Disclaimer: I triple-boot, with more VMs. I can make fun of everybody.

      --
      You do not have a moral or legal right to do absolutely anything you want.
    6. Re:Slow is good by Theophany · · Score: 4, Interesting

      Whilst I'd like to believe you, I fear that it is more to do with Apple spending so long in flat out denial that an issue ever existed.

      Don't get me wrong, I'm no hater and I'm no shill. I used to exclusively use Macs, now I don't use them at all (although I do use an iPhone/iPad) purely because their support practices in terms of viruses or serious issues are disgraceful. Whilst they do have an excellent support system whilst you're covered by AppleCare, they also have a culture of denying widespread hardware and software failures that most other companies would acknowledge quickly and get fixed quickly too.

      Case in point, I bought a batch of Macbook Airs a few years back for the company I was then working for. After two years, every_single_one_ died within a few days of each other from the same catastrophic hardware failure. Apple refused to acknowledge that there was any link, no matter how tenuous, of a manufacturer failure. They said it was pure coincidence.

      Like I said, I'm no hater. I know that corporations have to be ruthless to make money, but once I realised just how often they bury their heads in the sand (and how infuriating it can be) that was the day I ceased to buy big ticket items from them.

    7. Re:Slow is good by JohnBailey · · Score: 5, Funny

      Apple is still in disbelief that that Flasback is real.

      No.. Apple is still trying to figure out if this is from Adobe or not.

      --
      It is difficult to get a man to understand something when his job depends on not understanding it.
    8. Re:Slow is good by Anonymous Coward · · Score: 2, Informative

      they also have a culture of denying widespread hardware and software failures that most other companies would acknowledge quickly and get fixed quickly too.

      Really? Because I have never in 15 years of being a tech or system administrator who worked exclusively with Macs EVER had a issue with Apple admitting a hardware issue. Maybe a tech once in a while who didnt want to go through paperwork, but not my executive contacts who have replaced systems even when it WAS our fault, and we didnt have AppleCare on it.

    9. Re:Slow is good by Anonymous Coward · · Score: 2, Informative

      Yes, because Apple will have to test on such a VAST range of hardware...

      Actually yes, they do. They currently offer support on 3 different OSs (10.5-10.7) and close to a hundred different platforms with different configurations going back 4 years.

      You can even rent their test lab as a developer if you wanted to as well.

    10. Re:Slow is good by schnikies79 · · Score: 2

      And they have no idea they are using it and have no direct interaction with the OS or it's file system. We are talking about actively used computers, mainly desktops/laptops.

      Don't be douche.

      --
      Gone!
    11. Re:Slow is good by Idbar · · Score: 3, Funny

      Did you just compared Apple to... Microsoft!!??

      Run for your lives!

    12. Re:Slow is good by Anonymous Coward · · Score: 2, Insightful

      From what I understand is that Apple up keeps it's own version of Java that runs on the Mac. So in fact they own the problems that come with allowing it on their systems. Here is a link about that pretty much says that http://www.nl-tech.com/apple-users-download-malware.html

      "Oracle, which develops Java, issued a critical patch update in February 2012 to correct the problem, but because Apple controls Java updates in its computers, it did Apple users no good."

      and here http://whatculture.com/technology/mac-flashback-virus-what-it-is-and-how-to-remove-it.php

      "The reason Apple computers were still at risk was Apple develops its own version of Java, and does so at a slower pace."

      I expect to see more of this. Apple wants to keep a tight grip on everything so anything that slips thorough their fingers are fair game to allow blame on them. Look at Microsoft I don't remember Microsoft ever writing a virus/mal-ware to attack their own system but they get blamed for everything. Now that Apple is at the top of the game people will target it more so. So your opinionated comment that they are opinionated is just wrong when you look at the facts.

    13. Re:Slow is good by Anonymous Coward · · Score: 2, Informative

      And it would have required editing a text configuration file and then running the patch from the command line,.

      Bit of a pathetic troll given there's been gui package managers where you click on 'apply' or similar to bring your entire system up to date for more than 10 years.

    14. Re:Slow is good by Theophany · · Score: 3, Informative

      Logic board went kaput on each on of them. IIRC there were 8 machines in total. Despite my many attempts to reason with them, they wouldn't even give us a discount on the repair costs as a show of goodwill.

    15. Re:Slow is good by olau · · Score: 4, Funny

      So, I'd much rather have a slow patch from a company that cared enough to actually test it, vs a hobbyist who doesn't care enough to produce quality robust code.

      True. That's why I run a mix of Windows ME and Apple MacOS 9 on all my servers. I'm not letting that Linux distro run entirely by volunteers, what's it called, Debbi's Ian? near any of my good stuff. When was the last time Microsoft or Apple released a security fix for those two systems? See. Flawless software.

    16. Re:Slow is good by CharlyFoxtrot · · Score: 4, Insightful

      if it was Linux based malware a patch would have been out within 24 to 48 hours, six months is enough time to create a new version of the entire operating system,

      The vulnerability has been patched. This is about removing the malware from infected systems.

      --
      If all else fails, immortality can always be assured by spectacular error.
    17. Re:Slow is good by oh_my_080980980 · · Score: 4, Informative

      Actually no that's not correct. Apple and Oracle are working together on it:

      "In November, Apple and Oracle announced that they would collaborate on a Mac-based incarnation of OpenJDK, an open source version of Java."

      http://www.theregister.co.uk/2011/02/27/no_java_in_mac_os_x_lion/

    18. Re:Slow is good by oh_my_080980980 · · Score: 3, Informative

      And this

      Oracle Previews Java SE 7 for Mac OS X, Unveils Java SE Roadmap
      Oracle is releasing a technology preview of Java SE 7 on Mac OS X and said it plans to release Java SE 7 on Mac OS X for developers in the second quarter of 2012 and a consumer version later that year.

      http://thejournal.com/articles/2011/10/06/oracle-previews-java-se-7-for-mac-os-x-unveils-java-se-roadmap.aspx

    19. Re:Slow is good by CharlyFoxtrot · · Score: 5, Informative

      A) Vulnerability has been patched.
      B) It's not that difficult to detect and remove.

      This is strictly about helping non technical users that might be infected in an easy way. It's these users that were specifically targetted by the way since the malware targets old versions of Java and even checks for the existence of "power user" tools installed and doesn't install if they are :

      "4. You do not have certain security tools installed on your Mac that Flashback checks for, including Little Snitch, Xcode, and a few anti-malware tools.'

      --
      If all else fails, immortality can always be assured by spectacular error.
    20. Re:Slow is good by hairyfeet · · Score: 5, Funny

      Bah Ur doin it wrong, let the old Hairyfeet show you how to REALLY insult all three OSes!

      1.-if the patch comes out on linux it will be 14 pages of CLI and a tarball that will need a specific version of GCC, if they put it in the repo upon application it will throw you into single user mode on first boot. you DO know how to edit your config files, right?

      2.-If the patch comes out on Windows it will take 2 hours to install, followed by an hour on the "waiting to shutdown' screen and ANOTHER hour on the "Please wait, configuring Windows" boot up and may God have mercy upon your tortured soul if the power goes out while that is happening!

      3.-If the patch comes out on Apple it will be a year behind, but it will come in a cool silver look and everyone will talk about how truly wonderful it is. it doesn't actually patch anything "bad" it just brings sprinkles of Steve's magic to your poor pathetic life because "hey Apple never gets viruses' so everything you've read here? Total lie spread by those Windoze and Lunix luzers because they can't afford magic sprinkles, poor bastards.

      Now THAT is how you insult all three boy! I'd insult the BSD guys while I was at it but they'd be so damned grateful that anybody even mentioned them at all they'd probably thank me for doing it which just takes all the fun out, its like kicking a really stupid puppy that just smiles and wags its tail at you.

      --
      ACs don't waste your time replying, your posts are never seen by me.
    21. Re:Slow is good by Theophany · · Score: 2

      Reality would tend to differ with your example.

      As I said, I used to use Macs exclusively and had never had an issue with their tech support. My first Mac was a TiBook back in 2001 (which I still have and is still working perfectly). I'm not saying that their service sucks on the individual level (which, I hasten to add is not what I was talking about in my example), but the level of service I received in the example given was appalling.

      Am I trying to boycott them? No. Am I saying their service sucks universally? No. In my experience with them as a big customer (15x expensive laptops) was I pleased with the service I received? Hell no.

      So when you tell me about your ONE laptop with a graphics card issue and make it out to be directly comparable to a situation totally different, I have to think that you're missing the point somewhat.

    22. Re:Slow is good by tqk · · Score: 2

      if it was Linux based malware a patch would have been out within 24 to 48 hours ...

      The vulnerability has been patched. This is about removing the malware from infected systems.

      Yeah, and how hard is that? Is this about malware that magically attaches itself to existing executables, or does it just drop itself into a system directory and run itself?

      Both are pretty bloody old problems and easily mitigated. How is it that OSX can be owned by a driveby exploit trojan that adds it to a botnet? I thought its underlying guts were Unix. How is it that Windows can't notice that something new has been installed and executed without the user's instigation?

      What have Apple and Microsoft OS developers been spending their time on for the last decade? Surfing pr0n? Posting "you guys suck" on web forums? Making Clicky spin more gracefully?

      Meanwhile, their users are unwittingly added to botnets and their machines run keyloggers that phone home to crackers. And they get to pay for these "privileges"?!? Gee, what a great deal.

      $DEITY help them if their shareholders ever wise up.

      --
      "Tongue tied and twisted, just an Earth bound misfit ..." -- Pink Floyd.
    23. Re:Slow is good by Guy+Harris · · Score: 2

      Actually yes, they do. They currently offer support on 3 different OSs (10.5-10.7)

      Actually, they're not offering security updates for 10.5 any more. They're offering security updates for 10.6 and bug-fix and security updates for 10.7; "bug-fix and security updates for the current major release, security updates for the previous major release" has been the policy for many years.

    24. Re:Slow is good by toadlife · · Score: 5, Funny

      If it came out for BSD, the dependency check would trigger a complete recompile of KDE 4.x, bogging down your desktop for 34 hours. After it was done, everything would work fine, but in all practicality, you wouldn't be any safer because face it, you're running BSD; no one gives shit about you.

      --
      I don't always use unix-like operating systems; but when I do, I prefer FreeBSD.
    25. Re:Slow is good by mcgrew · · Score: 2

      They aren't facts, troll. I've been using Linux for ten years. Never compiled a program for it, never needed to edit one of its text files (although the fact that I can is a nice feature, another reason Linux is superior to Windows), and only use the command line if I forget the root password and need to reset it. A software patch has nothing to do with the hardware it runs on. Linux does sometimes have issues with drivers for new hardware, but that's a separate issue, and Windows has issues with drivers for older hardware.

      As to "RTFM n00b" I never encountered that, either. Every Linux question I ever asked on the internet garnered me at least an attempt to help, including which FM to R and where to find it. But I can see why you and the GP get treated harshly by Linux people, if someone with an attitude like yours asked a question in that tone I wouldn't say "RTFM n00b" I'd say "go fuck yourslef, asshole". Nice begets nice, hostility begets hostility. Only an idiot treats someone he needs help from badly.

  3. Flashback? by Vinegar+Joe · · Score: 2, Funny

    It's not a bug.....it's a feature.

    --
    "The average reporter we talk to is 27 years old......They literally know nothing." - Ben Rhodes
  4. I know why by BlastfireRS · · Score: 2

    Unfortunately, security isn't that big of a deal to Apple...yet. With the increase in market penetration the bulls-eye on Macs is getting larger and a lot more tempting; hopefully they realize this before something very serious happens and take steps to bolster their in-house security research (or hell, outsource it).

  5. Re:How good is it? by SJHillman · · Score: 5, Funny

    Would probably help if you didn't make it your desktop wallpaper.

  6. Manually Detect & Remove by guttentag · · Score: 5, Informative
    Running Software Update today to update Java will prevent you from getting flashback going forward, but that's not going to do anything if you already have it.

    Here's how to figure out if you have it (from Gizmodo):

    1.Run the following command in Terminal:
    defaults read /Applications/Safari.app/Contents/Info LSEnvironment
    2. Take note of the value, DYLD_INSERT_LIBRARIES
    3. Proceed to step 8 if you got the following error message:
    "The domain/default pair of (/Applications/Safari.app/Contents/Info, LSEnvironment) does not exist"

    If you don't get that error message, well, time to head to F-Secure for your fix. If you're clean so far, you can move on to step eight:

    8. Run the following command in Terminal:
    defaults read ~/.MacOSX/environment DYLD_INSERT_LIBRARIES
    9. Take note of the result. Your system is already clean of this variant if you got an error message similar to the following:
    "The domain/default pair of (/Users/joe/.MacOSX/environment, DYLD_INSERT_LIBRARIES) does not exist"

    In other words: "does not exist" means you've got a healthy rig. Anything else, just keep following F-Secure's instructions to vanquish the intruder.

  7. Re:How good is it? by Canazza · · Score: 2

    It's a tired Koala!

    --
    It pays to be obvious, especially if you have a reputation for being subtle.
  8. Steve Jobs: Ninja Assasin by Guppy · · Score: 5, Funny

    he would hire elite apple assasins to kill these supposed security researchers to stop the bad news

    You fools, don't you realize Steve Jobs himself was the elite apple assassin?

    Concealed under his black shinobi-shzoku-turtleneck was a lethal array of ninja weapons; many an unlucky Samsung executive or uncooperative tech-journalist has met their end at his hands, dispatched by a Firewire-cable garrot or iShuriken (they're like regular Shuriken, but with patented rounded corners). Gates himself has only survived thanks to the vigilant guard of his hulking 'roid-enhanced genetically engineered gorilla henchman.

    He was a shinobi of un-matched caliber, until his fateful battle against Google-fu masters Page and Brin, when he was felled by the Pancreas Death-Strike technique.

    1. Re:Steve Jobs: Ninja Assasin by mybecq · · Score: 2

      Gates himself has only survived thanks to the vigilant guard of his hulking 'roid-enhanced genetically engineered gorilla henchman.

      And here I was thinking it was because he was some kind of Borg creature. My mistake.

  9. Why apple waited so long... by wjcofkc · · Score: 2

    Because they are working on the next version of OS X: Honey badger. It don't give a shit.

    http://www.youtube.com/watch?v=4r7wHMg5Yjg&feature=player_detailpage

    --
    Brought to you by Carl's Junior.
  10. Has Flashback done any damage? by alispguru · · Score: 2

    Casual web searches don't turn up anything other than exploiting a vulnerability to get onto your machine (bad enough!).

    Did anyone successfully command it to do anything?

    --

    To a Lisp hacker, XML is S-expressions in drag.
  11. Re:The Joke you are not getting by Eponymous+Hero · · Score: 2

    i got the joke, idiot. the joke YOU'RE not getting is that i'm attacking his grammar nazi attack with one of my own. also, he didn't need to use the word "with" at all. "Proper grammar, Yoda would speak," makes just as much sense and has better grammar. adding the word "with" in his case really does make it sound awkward. if you don't like crow, you can always eat a shit taco and die. everyone knows how Yoda speak works, like everyone knows pig latin. we don't need a primer on that either. douchebag.

    --
    insensitive clod overlords obligatory xkcd car analogy russian reversals whoosh pedant fanbois ftfy in 3...2...1..PROFIT