The ARDAgent allows the virus to execute code as root when it is run on a machine. The ARDAgent virus has the setuid bit. According to Intego, "Users running such an executable [allows the virus to] gain the privileges of the user who owns that executable." In this case, ARDAgent is owned by root, allowing the virus to run code without first entering a password.
ARDAgent can be invoked to execute shell commands through AppleScript.
The second Trojan Mac users need to be aware of comes in the form of a poker game download. The exploit is masquerading as a poker game application that users can download, according to Intego. Called 'Poker Game,' the Trojan requires users to download the application and then run it before it becomes active.
According to Intego, "The Trojan in question is a shell script encapsulated in an application, and is distributed in a 65 KB Zip archive; unzipped, it is 180 KB."
Once downloaded and run, the virus activates the SSH and sends the user name and password to a server. From there, hackers can access the user's machine, deleting files, modifying the OS or worse.
According to SecureMac, the Trojan horse "affects Mac OS X 10.4 and 10.5. AppleScript.THT Trojan Horse runs hidden on the system and allows a malicious user complete remote access to the system, can transmit system and user passwords, and can avoid detection by opening ports in the firewall and turning off system logging."
As an added nasty benefit, the Trojan is also able to log keystrokes, activate the Apple iSight Camera and turn on file sharing. The virus affects Mac OS x 10.4 and 10.5.
- Juniper Honors 12 Americas Partners
- Facebook And Four More Web Sites We Love To Hate
- Cisco Honors Top Partners During 2010 Partner Summit
- HP Salutes Top Partners At APC 2010 Award Show
- Upclose And Personal With AMD And friends
- Will Oracle's Phillips' Affair Revelation Be A Distraction?
- Apple, Microsoft Unlikely Allies Against Google
- HP-Microsoft Cloud Partnership Needs To Show Us The Goods
- Blog: It's Time For A Cybercrime Public Service Announcement
- Nortel Sell-Off Continues: Ethernet Business To Ciena?
- Want To Deploy Exchange 2007 SP2 In A Server 2008 R2 Domain? Sorry
- Apple Improves iTunes 9 With Syncing, Visual Enhancements
- Oracle Ad Refutes Sun Hardware Fears
- U.S. Copyright Chief Rips Google Book Deal In Testimony
- Apple Slashes iPod Price Tags
- Price Is Right? Asus To Launch Low-Cost E-Reader
- Microsoft Xbox 360 Consoles Fail More Often Than Wii, PS3
- Privacy Group To Congress: Stop Online Advertisers In Their Tracks
- Microsoft, Intel Tout Their Collaboration On Windows 7
- Tech Data Adds Integration Services With New Center
| • |
| • |
| • |
| • |
| • |
| • |
| • |
|
|
