IMPORTANT NOTIFICATION

This site is an archive of Simon's first blog.
Current writing and commentary is now published at
simonedwards.com.
Showing posts with label linux. Show all posts
Showing posts with label linux. Show all posts

Friday, 30 March 2012

Malware attacks both PC and Mac

This month security companies discovered a threat that attacks both Windows PCs and Macs running OS X.

The threat, called JAVA_RHINO.AE by Trend Micro, arrives via infected websites, which means that potential victims won't notice anything amiss unless their security software detects it. It exploits a vulnerability in Java*.

Java is commonly found on both types of computer, which is interesting in itself. Its presence reduces the difference between a PC and a Mac by some way. There are, of course, other very significant similarities that I've mentioned before.

Here is the really interesting part, though. When it runs the threat determines whether it is running on a Mac or a PC and behaves differently depending on what it finds.

In the words of Trend Micro:

"Once it successfully exploits the said vulnerability, it drops and executes the following file:
  • On Windows: %User Temp%\file.tmp - detected as TROJ_RHINO.AE
  • On Mac OS X: /tmp/file.tmp - detected as OSX_RHINO.AE"
-----
Related news: Security company AlienVault, which is investigating Mac malware at the moment, has found a new Trojan containing a relatively ancient Linux backdoor from 1999.
-----

* UPDATE: I have just noticed that this vulnerability has been included in the Metasploit Framework since November 2011.

Ranked as 'Excellent' (which means that it works very reliably), the exploit is described thus:
"This module exploits a vulnerability in the Rhino Script Engine that can be used by a Java Applet to run arbitrary Java code outside of the sandbox. The vulnerability affects version 7 and version 6 update 27 and earlier, and should work on any browser that supports Java (for example: IE, Firefox, Google Chrome, etc)"

Thursday, 10 November 2011

First malware was for the Mac

Elk Cloner was the first virus
to affect desktop computers
Apple Mac personal computers are often said to be invulnerable to viruses.

I've heard this claim from many Mac users as well as from the company itself. However, it just so happens that the very first known piece of malware was written for the Mac*.

The Elk Cloner program was written by Rich Skrenta in 1982 (a year before Fred Cohen demonstrated a virus proof of concept on Linux UNIX**. The Brain virus, which appeared in 1986, is generally considered to be the first so-called 'in-the-wild' PC virus, but Skrenta was infecting his friends' Mac II computers four years previously.

Skrenta has a website with a page dedicated to Elk Cloner. If you want to know what it looked like, see the image above.

Apple plays down the malware threat to Macs and makes interesting claims such as, "A Mac isn’t susceptible to the thousands of viruses plaguing Windows." This is, perhaps, rather obvious. In the same way, a Windows PC isn't susceptible to malware that affects Macs.

The same can't be said for Macs versus Linux computers, though. There is some compatibility, which means that Linux malware can sometimes run on Macs (perhaps with a little tweaking).

Mikko Hypponen from F-Secure has presented a short documentary about the Brain virus and even interviewed the original authors, who are legitimate businessmen working from the same address as they were in 1986. You can watch this below:


* It really depends on how you define virus, malware and so on but arguably the first virus was a worm called Pervade, which was unleashed onto UNIVAC systems in 1975 by John Walker. It wasn't an internet worm, though, because 'the internet' did not exist in the way that it does today.

** Thanks to Anonymous (below) for noting my stupid mistake :)

Thursday, 27 October 2011

Anti-virus myths busted

Last week I gave the début presentation of my anti-virus myths talk at the London International Technology Show.

A few people have asked for access to the basic information that I used, so here it is. The talk lasted for around 40 minutes so this really is a bare-bones summary.

Myth #1: Anti-virus protects 100%
Real-world protection tests by Dennis Technology Labs (DTL) and other testers show that even well-known brands of security software can be compromised by malware.

Myth #2: Anti-virus slows PCs
In performance tests conducted by DTL, most popular anti-virus software makes virtually no impact on general system performance.
However, system startup (boot) times can be affected, as can shutdown times. These are important because they are very noticeable by users.
Myth #3: I don’t need it (I’ve never been infected)
Current threats tend not to make themselves known to the casual observer. Rootkits make it hard, even for experts. 
Myth #4: Viruses stay in the bad bits of the internet
While some areas of the internet are riskier than others, legitimate sites can be infected. We demonstrated a real, legitimate site infecting our test PC.
Myth #5: Protection costs a lot
Free products are OK, while commercial products often come with multiple licenses.
Myth #6: Avoid Internet Explorer
All popular browsers have security holes. Internet Explorer has fewer known issues than Opera and Firefox. Chrome and Safari are not immune*.
Myth #7: My ISP will save me
There is no business reason why it would, without raising subscription costs. We covered various options to reduce exposure to threats, including ISP-like techniques such as using special DNS services.
Myth #8: Salvation is a Mac, Linux or Android
Attackers go for popular systems. As Mac and Android users become more prevalent so will the threats to those systems. There are more known sets of vulnerabilities for OS X and Linux than there are for Windows*.

The following video clip was taken by one of the audience. Special thanks to PDTalkinTech for providing the photos and this video footage from part of the presentation:



* Data on software vulnerabilities was provided by Secunia.

Wednesday, 5 October 2011

Kaspersky rescue CD

If your system becomes badly compromised by malware then one approach to fixing it is to boot from a read-only disk (such as a CD disc) and run a scanner from a safe, uninfected environment.

Kaspersky provides a free bootable rescue CD that includes an anti-virus scanner. Other vendors do the same, but I mention Kaspersky here because a previous article, about an older version, is one of the most popular posts on this blog and still attracts large numbers of visitors. Hence the belated update.

The disc contains a live Gentoo Linux operating system that can run in text or graphical mode. It is compatible with 32- and 64-bit x86 systems (i.e. normal PCs). As you might hope, you can download updates before running a scan.

Interestingly, if you are scanning a system that already has a Kaspersky anti-virus program installed the updater will check the update files already available and only download those that are not available locally.

A utility called Kaspersky USB Rescue Disk Maker is also available from the site. It takes the contents of the Rescue Disk and copies it to a USB device, which you can then use to boot an infected PC.


More documentation is available from Kaspersky's Technical Support site.

Tuesday, 4 October 2011

Linux may be rooted

Linux developers have been asked to check their systems for signs of rootkits. The warning comes after Linux leaders discovered that important servers had been compromised.

The advice given to developers is to re-install their operating systems. Alternatively the alerting email lists three Linux anti-rootkit tools. Then it's a matter of double-checking the package signatures and other onerous tasks.

The rootkit tools mentioned are:

The email thread includes some useful and interesting tips for securing Linux systems, and handling those that one suspects as being compromised.

Wednesday, 27 May 2009

Kaspersky Anti-Virus 2009 (Live CD)

Russian security firm Kaspersky has produced a bootable Linux CD capable of mounting and disinfecting hard disks used by Windows PCs.

The ISO file seems to be freely available, although is tucked away on a part of the company's website that is pretty well hidden. This makes me suspect that it is not intended for general use.

Amed Kamal wrote about it a week ago, providing a direct link.

Using a rescue disc could improve the detection of threats that are usually hard to find and remove, such as rootkits. This is because the Windows operating system is not running - and rootkits hide by tricking the operating system.

UPDATE: There is a newer version available.