Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


October 25, 2004

Malware for Macs

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

Some of you use Macinstosh systems on your Windows networks, so be aware that a group of people have been developing a "rootkit" for Mac OS X.  A recent post on the Macintouch.com Web site offers insight into what the kit does after it becomes installed on a user's computer.

According to
the article the kit, dubbed "Opener," takes the form of a bash shell script (originally discovered at Freak's Macinstosh Archive) that will perform the following actions, as outlined below by a contributor to the article, Chris Waldrip: 

  • Opener tries to install ohphoneX, a teleconferencing program - for spying on you through your webcam I'm sure.
  • It kills LittleSnitch before every Internet connection it makes
  • It installs a keystroke recorder
  • Allows backdoor access in case someone deletes the hidden account
  • Grabs the open-firmware password
  • Installs OSXvnc
  • Grabs your office 2004 PID (serial number), as well as serial numbers for Mac OS XServer, adobe registrations, VirtualPC 6, Final Cut Pro, LittleSnitch, Apple Pro Apps, your DynDNS account, Timbuk2, and webserver users to name a few.
  • It tries to decrypts all the MD5 encrypted user passwords
  • Decrypts all users keychains.
  • Grabs your AIM logs, and tons of other settings and preferences with info you probably don't want folks to have... even your bash (terminal) history
  • Grabs stuff from your Classic preferences
  • Changes your Limewire settings to max out your upload and files.
  • The hidden user account is called LDAP-daemon instead of the name hacker used in earlier versions. Looks more innocent than hacker.
  • Even has your daily cron task try to get your password from the virtual memory swapfile
  • It installs an app called John The Ripper - a password cracker that uses a dictionary method to crack passwords
  • installs dsniff to sniff for passwords...

Another contributor to the article, Dave Taylor, points out a command (below) that can help determine if the kit has become installed on a given computer: 

$ sudo ls -l /Users/*/Public/.info

Typical command output should be:

ls: /Users/*/Public/.info: No such file or directory

Taylor said that "if you get anything else, it's time to pop into /Library/StartupItems and see what's in there. "

If you use Macintosh systems then you should consider reading then entire article regarding "Opener."

End of Article



Reader Comments
Wow you guys are clueless. You post a link to the script which looks like it was written by a 1st year compsci student and then you go on to post misinformation that anyone who looked at the script first would know to be FALSE.

There is *nothing* in that script that installs a keystroke logger - looks like they wanted too but couldn't figure out how.

Nothing in the script creates, installs or opens a backdoor - it turns on the normal sharing services that are part of OS X.

Nothing in the script installs VNC.

It does not decrypt (nor even try to) the keychain files (and if they can figure that one out I'd be impressed.)

And why on Earth are you calling it malware when they tell you exactly what it does???? If you download LimeWire and then use it to share your personal information KNOWING FULL WELL THAT YOU ARE DOING IT does that make LimeWire malware?????

Please, find another line of work. Have you ever considered selling shoes? There's much less studying, learning and thinking involved.

Anonymous User October 25, 2004 (Article Rating: )


If you bother reading the latest script then you'd see that it does what is described above...

http://freaky.staticusers.net/ugboard/viewtopic.php?t=10712&postdays=0&postorder=asc&start=120&sid=a47c4000155a6ef234d862bc89044ec0

Anonymous User October 27, 2004


"Limewire", Anonymous poster number one.

Are you a tard?

They clearly stated that Limewire settings were affected, NOT that Limewire was the malware.

It doesn't take a shoe salesman to read properly so perhaps you should work in a Taco Truck eh?

Anonymous User October 27, 2004


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now





Search Security Matters
 
Security Matters
JULY 2009
    1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  
or

 Recently in Security Matters
Will ICANN Ban Top Level DNS Wildcarding?
Make a Comment
SecureBrowsing Extension for IE and Firefox
Make a Comment
Wireshark 1.2.0 Sports Lots of New Features
Make a Comment
Gmail to go with HTTPS by default

Last Comment
Why was this never an issue with Hotmail...? It's been around a lot longer than Gmail, yet no one s...
(2 Comments)
iPhone Recovery over USB
Make a Comment

More blogs about technology,
software, and Windows.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home asp.netPRO Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement | Reprints and Licensing