FBI Solves Mystery Surrounding 15-Year-Old Fruitfly Mac Malware Which Was Used By a Man To Watch Victims Via their Webcams, and Listen in On Conversations (zdnet.com)
The FBI has solved the final mystery surrounding a strain of Mac malware that was used by an Ohio man to spy on people for 14 years. From a report: The man, 28-year-old Phillip Durachinsky, was arrested in January 2017, and charged a year later, in January 2018. US authorities say he created the Fruitfly Mac malware (Quimitchin by some AV vendors) back in 2003 and used it until 2017 to infect victims and take control off their Mac computers to steal files, keyboard strokes, watch victims via the webcam, and listen in on conversations via the microphone. Court documents reveal Durachinsky wasn't particularly interested in financial crime but was primarily focused on watching victims, having collected millions of images on his computer, including many of underage children. Durachinsky created the malware when he was only 14, and used it for the next 14 years without Mac antivirus programs ever detecting it on victims' computers. [...]
Describing the Fruitfly/Quimitchin malware, the FBI said the following: "The attack vector included the scanning and identification of externally facing services, to include the Apple Filing Protocol (AFP, port 548), RDP or other VNC, SSH (port 22), and Back to My Mac (BTMM), which would be targeted with weak passwords or passwords derived from third party data breaches." In other words, Durachinsky had used a technique know as port scanning to identify internet or network-connected Macs that were exposing remote access ports with weak or no passwords.
Describing the Fruitfly/Quimitchin malware, the FBI said the following: "The attack vector included the scanning and identification of externally facing services, to include the Apple Filing Protocol (AFP, port 548), RDP or other VNC, SSH (port 22), and Back to My Mac (BTMM), which would be targeted with weak passwords or passwords derived from third party data breaches." In other words, Durachinsky had used a technique know as port scanning to identify internet or network-connected Macs that were exposing remote access ports with weak or no passwords.
... attack.
It little behooves the best of us to comment on the rest of us.
Judging from TFS, he was just the cyber equivalent of a peeping tom. And, if he was only 14 when he started, I don't know if you could really call him a pedofile if the pictures were of girls his own age.
Good, inexpensive web hosting
By others I could imagine some of those three letter federal government agencies use this software or other functionally like it to keep an eye on us in the name of national security. Cover up your camera and computer microphone, folks. I'm not sure your phone would be vary useful without the microphone, though.
In a time of universal deceit, telling the truth is a revolutionary act. George Orwell
Oh shit. No! stop! Oh god wtf is wrong with you!
Well, shit.
I was going to match you IQ for IQ and say that your momma wears combat boots, but these days that's a compliment.
I want to express my "thanks," to all the moms who have served, are serving, and will serve, while wearing combat boots.
It little behooves the best of us to comment on the rest of us.
Do you know where the data you had 14 years ago is? Every single HD you ever owned, every single CD you ever burned? Can the hysteria, please.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Straight up creep, mother focker.
Operating systems should not have any remote services running by default. That's obviously a bad idea. It's clearly done purposely. Securing systems is acutally rather easy...
... who was looking through windows without drapes ....
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
... we would have lost a great science fiction writer John McFly
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
Wow you must be into some really questionable shit for you to ball so hard for this guy. Hint- the majority of the time he has been at this, he has been a legal adult.
The FBI comes in and they image everything you've got that they find.
You might be safe now but in the future legitimate things you have might become crimes. You don't know what that might be; even if you do, like parent said, your old backups get lost or the old computer in the basement you didn't recycle or give away because you've not wiped it clean and put that off...
Think about something innocent not this guy's stuff-- and a decade from now the mere possession or mention of such things is a crime. You are not charged with a crime back in time (not allowed) but instead are charged for currently having such materials.
This could be the Anarchist's Handbook you got online in the 90s because everybody was making a fuss about the silly thing. Then after 9/11 they find that in your stuff and get you as a terrorist!
Think.
Democracy Now! - uncensored, anti-establishment news
Um no its not. My mom is a clinical psychologist. She said going by the posts he/she/it is probably bipolar.
;) J/K (lol)
...and might be creimer
I love how most of the comments are debates on whether the guy is a pedo or not and virtually none so far has addressed the fact that this vulnerability has been in use for fifteen years! I can't believe the Mac haters aren't piling on. Come on guys...don't let me down!
"A person is smart. People are dumb, panicky dangerous animals and you know it." - K
macs sure are insecure.
He was producing cp up until last year when he was arrested.
ged and incorporated by reference as if fully set forth herein. ...
15. From on or about October 25, 2011 through on or about January 14, 2017, in theNorthern District of Ohio, Eastern Division, and elsewhere, Defendant PHILLIP R.DURACHINSKY did use a minor and minors to engage in sexually explicit conduct, as defined in Title 18, United States Code, Section 2256(2), for the purpose of producing a visual depiction of such conduct, knowing and having reason to know that such visual depiction would be transported and transmitted, using any means and facility of interstate and foreign commerce, and in and affecting interstate and foreign commerce; such visual depiction was produced and transmitted using materials that had been mailed, shipped and transported in and affecting interstate and foreign commerce; and such visual depiction was actually transported and transmitted, using any means and facility of interstate and foreign commerce, and
Let's see: steals keyboard strokes, watches victims via the webcam, and listens in on conversations via the microphone.
If he's not the author of Win10 then he must surely be one of the top tech people at Google or Amazon.
When I was 14, hardly any floppy existed. A hard drive costed more than your car and CDs definitely did not even exist as a wet dream of a research lab assistant.
But I get your point ... my stupid parents most surely have a naked pic of me when I was 7 or 8 or 10 playing at a Baggersee. Or god forbid: even younger!!!
Cost free eBook I read (by iBook/Kobo/Amazon/ObookO/Gutenberg etc.): "The Green Odyssey" by Philip Jose Farmer.
I can go back 22 years for hard drives images with data on, before that it is hit and miss but most "data" that was on floppy or zip drives I've also extracted.
Honestly, storage is so cheap these days I just buy two extra drives every couple of years and make a giant copy of all my old crap, + the drive(s) I'm upgrading from to one of the drives, clone it to the other one and stick one of them in an offsite safe and one in a little sealed fireproof safe on the shelf..
What about those that serve without wearing combat boot? And why you "thanks" and not your thanks?
Is this a verdict or accusation?
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
15 year old fruit flies like 14 year olds' bananas
Now excuse me while I get back to my Mac. Oh wait I don't have one. I have this peculiar aversion against proprietary stuff.
It's totally unclear what he actually did. Did he mail these kids porn, or have it pop up on their screens, and then film them whacking off? It's hard to engage in sexplicit conduct with somebody who is not supposed to know you're in their computer.
When I was 14 I hardly ever had a floppy either
3.5" is a standard size, though some have 2.5".
We don't let this limit us though -- despite the physical sizes remaining unchanged for years the capacities have been growing by huge amounts, enough to satisfy even the most voracious users.
Why are YOU trying to accuse others.
It sounds like the FBI's cold case unit filing another 15 year old success.
When reading the article (yes I know) title should be more like:
Criminal successfully evades FBI during a 15 year long crime spree.
See subject: his FAKEname on a post impersonating me https://linux.slashdot.org/com... & altering /.er's words.
c6gunner tried to mock me 1st https://linux.slashdot.org/com...
So I challenge c6gunner to show he did better work than mine & he CAN'T!
YOU DEMAND PROOF of others here? "I've yet to see you provide any evidence of that." by c6gunner on Monday March 15, 2010 @10:02PM (#31490942) ?
So now I DEMAND IT OF YOU & YOU FAIL!
c6gunner = "Run, Forrest: RUN!!!
* c6gunner's LYING saying I did a MacOS X one - I haven't yet & c6gunner's LYING impersonating me hosts work vs. Intel CPU issues (spectre/meltdown).
APK
P.S.=> You say hosts = shit here https://slashdot.org/comments.... ? /.ers & security pros SAY DIFFERENT: /.ers https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments....
SECURITY PROS https://slashdot.org/comments....
REAL RESULTS w/ hosts vs. threats https://slashdot.org/comments....
EAT YOUR WORDS!
See subject: his FAKEname on a post impersonating me https://linux.slashdot.org/com... & altering /.er's words.
c6gunner tried to mock me 1st https://linux.slashdot.org/com...
So I challenge c6gunner to show he did better work than mine & he CAN'T!
YOU DEMAND PROOF of others here? "I've yet to see you provide any evidence of that." by c6gunner on Monday March 15, 2010 @10:02PM (#31490942) ?
So now I DEMAND IT OF YOU & YOU FAIL!
c6gunner = "Run, Forrest: RUN!!!
* c6gunner's LYING saying I did a MacOS X one - I haven't yet & c6gunner's LYING impersonating me hosts work vs. Intel CPU issues (spectre/meltdown).
APK
P.S.=> You say hosts = shit here https://slashdot.org/comments.... ? /.ers & security pros SAY DIFFERENT: /.ers https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments....
SECURITY PROS https://slashdot.org/comments....
REAL RESULTS w/ hosts vs. threats https://slashdot.org/comments....
EAT YOUR WORDS!
See subject: his FAKEname on a post impersonating me https://linux.slashdot.org/com... & altering /.er's words.
c6gunner tried to mock me 1st https://linux.slashdot.org/com...
So I challenge c6gunner to show he did better work than mine & he CAN'T!
YOU DEMAND PROOF of others here? "I've yet to see you provide any evidence of that." by c6gunner on Monday March 15, 2010 @10:02PM (#31490942) ?
So now I DEMAND IT OF YOU & YOU FAIL!
c6gunner = "Run, Forrest: RUN!!!
* c6gunner's LYING saying I did a MacOS X one - I haven't yet & c6gunner's LYING impersonating me hosts work vs. Intel CPU issues (spectre/meltdown).
APK
P.S.=> You say hosts = shit here https://slashdot.org/comments.... ? /.ers & security pros SAY DIFFERENT: /.ers https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments....
SECURITY PROS https://slashdot.org/comments....
REAL RESULTS w/ hosts vs. threats https://slashdot.org/comments....
EAT YOUR WORDS!
Swoosh
It little behooves the best of us to comment on the rest of us.
Weak Passwords make for Weak Security.
" The attack vector included the scanning and identification of externally facing services, to include the Apple Filing Protocol (AFP, port 548), RDP or other VNC, SSH (port 22), and Back to My Mac (BTMM), which would be targeted with weak passwords or passwords derived from third party data breaches." In other words, Durachinsky had used a technique know as port scanning to identify internet or network-connected Macs that were exposing remote access ports with weak or no passwords."
Film at 11.
Nothing to see here, move along...
It's an indictment from the Grand Jury that heard and saw evidence collected by the FBI. Don't be so fucking obtuse.
3.5" is a standard size, though some have 2.5".
I had an 8" Wang.
I don't always use unix-like operating systems; but when I do, I prefer FreeBSD.
The indictment is pretty straightforward in laying out the feds case against him. I
My Wang had dual 8 inchers!
No.
You must not know that North Korea exists today? You must not know that Germany was probably the most educated, most literate DEMOCRACY and known for being practical to the point of being "cold" before they descended quickly into extreme despotism and you think my comment is silly? You must not live in the USA, outside a big liberal city either. You must not live in a big liberal city either or you'd get plenty of ideas from the SJW.
Seriously? an example? ok how about what should be obvious:
Nude photos of yourself. your a teenager. include others too. Hell, even adults exchange such things so this is not insanity.
Later, you are an adult and the mere possession of such photos is a crime. We have teens who have been charged with crimes sending out photos of themselves! registered sex offenders...
Or what I just said, I distinctly remember people being charged with extra crimes and given harsher punishments simply because The Anarchists Cookbook was found on their computer. There are variations out there where it probably wasn't a crime by itself but lumped in... or used to smear somebody (which can do damage in a jury setting or with press coverage etc.) Thought crime BS... materials get your charges raised by implied thoughts in your head..
Democracy Now! - uncensored, anti-establishment news