Download

Fermé
vincenttouchard1@me.com Messages postés 2 Date d'inscription mardi 3 février 2009 Statut Membre Dernière intervention 5 février 2009 - 3 févr. 2009 à 11:11
Chris 94 Messages postés 50978 Date d'inscription mardi 8 janvier 2008 Statut Modérateur Dernière intervention 17 février 2023 - 5 févr. 2009 à 13:48
Bonjour,
INTEGO SECURITY ALERT - January 26, 2009

New Variant of Mac Trojan Horse iServices
Found in Pirated Adobe Photoshop CS4



Exploit: OSX.Trojan.iServices.B Trojan Horse

Discovered: January 25, 2009

Risk: Serious

Description: Intego has discovered a new variant of the iServices Trojan horse that the company discovered on January 22, 2009. This new Trojan horse, OSX.Trojan.iServices.B, like the previous version, is found in pirated software distributed via BitTorrent trackers and other sites containing links to pirated software. OSX.Trojan.iServices.B Trojan horse is found bundled with copies of Adobe Photoshop CS4 for Mac. The actual Photoshop installer is clean, but the Trojan horse is found in a crack application that serializes the program.

OSX.Trojan.iServices.B

After downloading this version of Photoshop, users will run the crack application to be able to use it. The crack application extracts an executable from its data, than installs a backdoor in /var/tmp/, a directory which is not deleted when the computer is restarted. (If the user runs the crack application again, the Trojan horse creates a new executable with a different name; these random names make it harder to ensure safe removal of the malware.)

The crack application then requests an administrator password, launching the backdoor with root privileges. This copies the executable to /usr/bin/DivX, then creates a startup item in /System/Library/StartupItems/DivX. The program checks to see if it has been launched with root privileges, then saves the root hash password in the file /var/root/.DivX. It listens on a random TCP port, and answers requests such as GET / HTTP/1.0 by sending a 209-byte packet, and makes repeated connections to two IP addresses.

Next, the crack application opens a disk image which is hidden in its resource folder, in a folder named .data, and proceeds to crack the Photoshop program, allowing it to be used.

OSX.Trojan.iServices.B


Since the malicious software connects to a remote server over the Internet, the creator of this malware will be alerted that this Trojan horse is installed on different Macs, and will have the ability to connect to them and perform various actions remotely. The Trojan horse may also download additional components to an infected Mac.

Intego is issuing this alert to warn Mac users not to download Photoshop CS4 installers from sites offering pirated software. (As of 6 am EST, nearly 5,000 people have downloaded this installer, according to a major BitTorrent tracker site.) Since the Trojan horse, in this case, is found merely in the crack application that is bundled with Photoshop CS4, users should avoid downloading any cracking software from sites that distribute pirated software. The risk of infection is serious, due to the number of infected users, and these users may face extremely serious consequences if their Macs are accessible to malicious users. The first version of this Trojan horse was seen downloading new code to infected computers, which were then used in a DDoS (distributed denial of service) attack on certain web sites. Since this new variant uses the same technology, and contacts the same remote servers, it is likely that it will attempt to download new code and perform such actions.

Intego VirusBarrier X4 and X5 with virus definitions dated January 25, 2009 or later protect against this Trojan horse. Intego recommends that users never download and install software from untrusted sources or questionable web sites. In spite of Intego’s security alert regarding the first version of this Trojan horse, and in spite of comments on torrent trackers, people continue to download these infected torrents. The iWork 09 torrent that we warned about on January 22 has been downloaded by at least 1,000 more people since our warning. This is why we consider this Trojan horse to be a serious risk.


About Intego
Intego develops and sells desktop Internet security and privacy software for Macintosh.

Intego provides the widest range of software to protect users and their Macs from the dangers of the Internet. Intego's multilingual software and support repeatedly receives awards from Mac magazines, and protects more than one million users in over 60 countries. Intego has headquarters in the USA, France and Japan.

We protect your world.

Voilà, ce que j'ai téléchargé.
A voir également:

4 réponses

Chris 94 Messages postés 50978 Date d'inscription mardi 8 janvier 2008 Statut Modérateur Dernière intervention 17 février 2023 7 335
3 févr. 2009 à 15:12
Bonjour,

Vous allez créer un profil pour chaque discussion ? :-) voir ici

C'est effectivement la mutation d'un troyen signalé peu avant, déjà par Intego je crois, pour accompagner le téléchargement d'un autre logiciel piraté. Comme tous les troyens, il ouvre "la porte de derrière", celle qu'on ne surveille généralement pas bien et, quand la télé a été volée ou la chambre squattée, on se mord les doigts.

@+
0
vincenttouchard1@me.com Messages postés 2 Date d'inscription mardi 3 février 2009 Statut Membre Dernière intervention 5 février 2009
5 févr. 2009 à 10:01
MÊME SI JE N'AI PAS OUVERT LE DOSSIER TÉLÉCHARGÉ ?
0
Chris 94 Messages postés 50978 Date d'inscription mardi 8 janvier 2008 Statut Modérateur Dernière intervention 17 février 2023 7 335
5 févr. 2009 à 12:26
Hum, hum... Evitez les majuscules, SVP, la tradition en fait un signe de mécontentement envers votre interlocuteur, comme si vous criiez.

Si j'ai bien compris ce que j'ai lu, il faut lancer le programme piraté pour que fasse tourner le troyen.

@+
0
vincenttouchard1
5 févr. 2009 à 13:26
Je crois !
0
Chris 94 Messages postés 50978 Date d'inscription mardi 8 janvier 2008 Statut Modérateur Dernière intervention 17 février 2023 7 335
5 févr. 2009 à 13:48
...Donc, à jeter sans lancer. Téléchargez quand même MacScan et vérifiez qu'il ne détecte rien.

@+
0