Welcome to our website
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
New Trojan Leverages Unpatched Mac Flaw
Posted by Philipp Esselbach on: 06/26/2008 01:28 PM [ Print | 0 comment(s) ]
OSNews posted a news story on a new trojan that are affecting both Mac OS X Leopard and Tiger
The issue in question is a trojan (affecting both Leopard and Tiger) that can tag along normal Mac OS X applications. Once installed, it sets up a keystroke logger named 'logkext'. It then moves on to set up a VNC server listing the infected computer, giving the hacker remote access to the machine. In addition, it also installs a web-based 'PHP shell' program, giving the hacker control over your machine through a mere web browser. To prevent losing track of the infected machine because of changing IP addresses, the trojan also sets up the machine so that it can be tracked using a dynamic DNS services. The trojan makes use of either last week's unpatched ARDAgent vulnerability, or an old, already patched privilege escalation vulnerability.
New Trojan Leverages Unpatched Mac Flaw
