Home User CP Donate Chat Register Today!  
  Get New posts Faq / Help?
   


Go Back   Hackint0sh > OSX and Hackint0sh/OSX86 > OSX Security

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-23-2009, 04:38 PM
sam's Avatar
sam
Status: Offline
Chief of Administration
iPhone Dev Team
 
Join Date: Jun 2007
Posts: 1,337
Rep Power: 10
sam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond repute
Default iServices.a Analysis

For everyone who wants to take a look at the trojan and analyse the code himself, here is a copy of a not dangerous x86 disassembly:

RapidShare: Easy Filehosting
__________________
If you just want to support hackint0sh.org with a donation click here.
Follow me on twitter: http://twitter.com/sam_hackint0sh
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 01-23-2009, 10:49 PM
JayBird's Avatar
JayBird
Status: Offline
Senior Member
 
Join Date: Oct 2008
Posts: 369
Rep Power: 23
JayBird will become famous soon enough
Default

was this in a iWork 9 distro???
__________________
I Do Not Condone Piracy, If You Like It BUY IT! - It's Ok To Test But Not Steal - MacBook Pro Owner

iPhone Owner 3G
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 01-24-2009, 04:14 PM
sam's Avatar
sam
Status: Offline
Chief of Administration
iPhone Dev Team
 
Join Date: Jun 2007
Posts: 1,337
Rep Power: 10
sam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond repute
Default

Yes, exactly this one.
__________________
If you just want to support hackint0sh.org with a donation click here.
Follow me on twitter: http://twitter.com/sam_hackint0sh
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #4 (permalink)  
Old 01-24-2009, 11:26 PM
JayBird's Avatar
JayBird
Status: Offline
Senior Member
 
Join Date: Oct 2008
Posts: 369
Rep Power: 23
JayBird will become famous soon enough
Default

sorry Sam, really really really stupid question
__________________
I Do Not Condone Piracy, If You Like It BUY IT! - It's Ok To Test But Not Steal - MacBook Pro Owner

iPhone Owner 3G
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5 (permalink)  
Old 01-27-2009, 05:17 PM
JayBird's Avatar
JayBird
Status: Offline
Senior Member
 
Join Date: Oct 2008
Posts: 369
Rep Power: 23
JayBird will become famous soon enough
Default

Just Wait, before you know it, to keep in pattern with these iSerives Trojans, there will be a iService.C deployed in iLife09
__________________
I Do Not Condone Piracy, If You Like It BUY IT! - It's Ok To Test But Not Steal - MacBook Pro Owner

iPhone Owner 3G
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #6 (permalink)  
Old 01-28-2009, 07:26 PM
haygun
Status: Offline
Trial Member
 
Join Date: Jan 2009
Location: Canada
Posts: 1
Rep Power: 0
haygun is on a distinguished road
Default Little Snitch

So I am assuming if you have Little Snitch installed you can catch this?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Remove advertisements
Advertisement
Advertisement Sponsored links

  #7 (permalink)  
Old 01-28-2009, 09:21 PM
JayBird's Avatar
JayBird
Status: Offline
Senior Member
 
Join Date: Oct 2008
Posts: 369
Rep Power: 23
JayBird will become famous soon enough
Default

i would think so, but if a trojan has root access its hard to think what it cannot do....
__________________
I Do Not Condone Piracy, If You Like It BUY IT! - It's Ok To Test But Not Steal - MacBook Pro Owner

iPhone Owner 3G
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #8 (permalink)  
Old 01-28-2009, 11:38 PM
dtube
Status: Offline
Administrator
 
Join Date: Oct 2007
Posts: 3,622
Rep Power: 10
dtube is a name known to alldtube is a name known to alldtube is a name known to alldtube is a name known to alldtube is a name known to alldtube is a name known to all
Default

Man ... this kind of stuff is getting out of control ....
iLife family pack is $100 ...
Get 4 more friends to join, your cost is $20 to avoid the headache.
The time & money you save can be used for better things ... such as donation to the forum :-))
__________________
** If you just want to support hackint0sh.org with a donation click here **
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #9 (permalink)  
Old 01-29-2009, 02:22 PM
sam's Avatar
sam
Status: Offline
Chief of Administration
iPhone Dev Team
 
Join Date: Jun 2007
Posts: 1,337
Rep Power: 10
sam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond repute
Default

Well LittleSnitch can cacth A and B but they are getting more and more better meade with each generation and they open a backdoor to your system. So if you are infected you are vulernable, even if you catch the trojan's ping to the author.

As I said in my blog post, the troojan seems to have so far unknown embedded p2p capacities. What it exactly does, no idea yet but I assume mashing up to a botnet or similar. Turning you mac in a wide open brain fried zombie with root access.
__________________
If you just want to support hackint0sh.org with a donation click here.
Follow me on twitter: http://twitter.com/sam_hackint0sh
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #10 (permalink)  
Old 02-01-2009, 01:33 AM
JayBird's Avatar
JayBird
Status: Offline
Senior Member
 
Join Date: Oct 2008
Posts: 369
Rep Power: 23
JayBird will become famous soon enough
Default

scary thoughts, i agree with dtube tho, $100 its not that much money, especially if 5 people joined up to pay for it.
__________________
I Do Not Condone Piracy, If You Like It BUY IT! - It's Ok To Test But Not Steal - MacBook Pro Owner

iPhone Owner 3G
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
MacNN: MacVector 10.5 updates DNA, protein analysis tools hackint0sh Latest Headlines 0 01-16-2009 04:40 AM
Apple: iMac delivers MRI analysis in less than 10 minutes hackint0sh Latest Headlines 0 11-17-2008 07:50 PM
MacNN: Statistical analysis tool Aabel 3 adds new tests hackint0sh Latest Headlines 0 11-11-2008 12:10 AM
MacNN: UBS turns to Apple analysis, predicts new hardware hackint0sh Latest Headlines 0 08-05-2008 07:00 PM
Leak analysis js- iPhone Developer Exchange 1 05-03-2008 02:24 PM



All times are GMT +2. The time now is 05:55 AM.



Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.2 Ad Management by RedTyger
follow us on Twitter!

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105