Tampilkan postingan dengan label security. Tampilkan semua postingan
Tampilkan postingan dengan label security. Tampilkan semua postingan

Apple Update Removes Flashback Trojan

Diposting oleh fawaid on Kamis, 12 April 2012

Today, Apple released another update to Java. This is the big one, it adds further protection against Flashback (and other trojans like it), and it also completely removes the trojan if your Mac was infected. The update will stop Java applets in your browser from automatically running, which will help prevent issues like this in the future. Also, the security hole that the trojan originally used has been closed.

So, fire up Software Update (in the Apple menu) and rest easy. Flashback has been, once again, defeated. As of yesterday, a study done by Symantec showed that the number of infected Macs was down from 600,000 to under 270,000. That was before Apple released this update. With Apple's latest update, that number will be reduced closer to zero (it would be zero if everyone fully updated their Macs). Time to forget all about this Flashback thing, right?

via 9to5Mac and MacObserver

 

Read More

Flashback Removal Tool Released

Diposting oleh fawaid on Rabu, 11 April 2012

Today, F-Secure finally released a removal tool for the Flashback Mac trojan. Its a good step to take if you don't feel like downloading antivirus software. Also, you'll be happy to know that Apple will be releasing an update to Mac OS to remove the trojan. Apple also recommends that users of Mac OS 10.5 (Leopard) or below, disable Java in their browser. In most browsers, this can be done through Preferences > Security. I should note for the non technical readers, that JavaScript is completely different from Java. They have 4 letters in common, and that's it. JavaScript is used by nearly every website, while Java is rarely used online. In fact, I've had it disabled for some time now, and haven't noticed a difference.

Read the rest of this post »
Read More

Even Easier way to Check for Mac Trojan

Diposting oleh fawaid on Selasa, 10 April 2012

I listed a few ways to check and remove the Flashback trojan from your Mac before. But, if you're looking for an even easier way to check to see if your Mac is infected, use this handy app. Essentially, like the scripts from before, it runs the terminal commands that were previously posted, and makes the result easy to read for the 'computer illiterate'. Juan Leon made the Flashback checker, which you can download here. If your infected, it won't remove the trojan, but it will give you instructions on how to remove it.

via MacWorld

 

Read More

Check to see if you're Infected with the Flashback Trojan

Diposting oleh fawaid on Jumat, 06 April 2012

There's a single Mac trojan out in the wild, and it's got everyone going crazy. There are thousands of trojans, viruses, worms, and other malware out for Windows, but just one Mac trojan is enough to cause the Internet to explode. Are you worried about it? Well, if so, here's how you can find out if you're infected, and how you can remove it or prevent being infected by it.

Read the rest of this post »
Read More

Apple Updates Java

Diposting oleh fawaid on Selasa, 03 April 2012

Just yesterday, a Trojan was released for the Mac that could install itself. It exploited a Java security hole that would allow it to be installed on your Mac without installation or the user's password. However, that Trojan has already been squashed by Apple. Today, they release an update to Java that would improve Java security on Macs. While Apple could have released this earlier, something has to be said about how quickly they fixed the issue after it was released.

Fire up Software Update (in the Apple menu) to download the update.

 

Read More

iOS and Android Apps can Access Your Photos

Diposting oleh fawaid on Kamis, 01 Maret 2012

Smartphones are paving the way for privacy issues. The latest can be troubling for anyone who has ever sent or stored naughty photos on their phone. As it turns out, app developers can take your photos off your phone and upload them to their servers. The problem comes up in both iOS and Android.

Read the rest of this post »
Read More

Windows Phone 7 Still Suffers from Messaging Bug

Diposting oleh fawaid on Kamis, 05 Januari 2012


I first reported on a massive security hole in Microsoft's Windows Phone 7 back on December 12th. The bug would cause a phone to crash, and lock the user out of the messaging hub if the user received a message with a specific string of characters. The message could be through nearly any messaging service, including text messages and Facebook messages. The only way to fix the problem was to wipe the device of all data, and reset it to factory settings.

On December 28th, a full 14 days after the bug was discovered, Microsoft claimed they were working on a fix for the problem. It's now January 5th, and 24 days have passed since the bug was revealed to the public (no one knows if Microsoft knew about it sooner). Yet, there is still no public fix from Microsoft. Yet, according to the developer who first found the bug, Microsoft is currently testing a possible fix.
It seems like a serious problem, but apparently it's just not serious enough for Microsoft.
via BGR
Read More

Some Android Phones Don't Enforce Permissions

Diposting oleh fawaid on Senin, 05 Desember 2011

"I've got your permissions right here!"
One of the security features Android uses to allow users to protect themselves is to create permissions for apps. When an app is downloaded, you can look at what permissions it has, and allow or disallow the app to use them, much like you can do with location settings in iOS. 

Unlike iOS, however, it seems as though these permissions can be bypassed on some Android phones. In doing so, a malicious Android app could gain access to the internet, record phone calls, or send SMS messages, even if the user has specifically blocked it from doing so. 
Read the rest of this post »
Read More

Android Malware up 472% Since July

Diposting oleh fawaid on Kamis, 17 November 2011

Android Malware has increase by nearly 5 times in the past 4 months. It's incredibly easy to create an anonymous developer account, and upload malicious apps on the Android Marketplace. The platform is unprotected, as there is no review process for apps, and apps aren't code signed. If you're an Android user, your best bet is to check the permissions of every app you download, and only download apps that have a large user base and plenty of good reviews. Looking for new or indie apps might be a bad idea. Your other option is to choose a different phone when it's time to upgrade...


Read the rest of this post »
Read More

iOS 5.0.1 Patches Security Hole

Diposting oleh fawaid on Jumat, 11 November 2011

Remember that security hole found by security expert Charlie Miller just last week? As it turns out, among the iOS 5 improvements made by the update, the security hole he found has also been closed.

Apple fixed that so quickly, I didn't even have time to worry about it. You can download the iOS 5.0.1 update through iTunes, or by using the over the air update in Settings > General > Software Update on your iOS device.
via BGR
Read More

Hacker Finds Security Flaw in iOS

Diposting oleh fawaid on Senin, 07 November 2011


Charlie Miller is a talented hacker. Fortunately, he publishes his hacks so the companies can patch security holes before anyone takes advantage of them.

It's still unsettling to watch the above video, where Miller shows off an app he created that passes inspection to get in the App Store, but still can execute malicious code.

How does it work? When it's run, it will contact his computer, and get new commands. He can then do a number of things with the phone under attack, including execute commands, search the file system, or even make it ring or vibrate.

Fortunately, this isn't exactly an easy attack. It's not as simple as uploading a malicious app, as you can do on the Android Marketplace. Still, it could be used by hackers in the future. Apple will have plenty of time to patch it before the details of this flaw are publicized though, so don't expect your iOS device to become vulnerable to attack anytime soon.
via CultOfMac
Read More

Is the Kindle Fire Browser Secure?

Diposting oleh fawaid on Selasa, 25 Oktober 2011

The Kindle Fire has a special type of browser they call the Silk browser. Basically, what it does is handle most of the processing for a website on the server-side, leaving the Kindle Fire with little processing work. It also stores a cache of pages you've visited. The result is a fast browser, even though the hardware itself isn't too extraordinary. Other browsers have done this in the past, namely the Opera Mini browser. There's always been one huge caveat to browsers like this, they have a gaping security hole.

ZDNet addressed this concern soon after the reveal of the Kindle Fire, saying "Silk looks to be very fast and about as private as a bathroom stall without a door". Personally, I'd never use a public bathroom without a stall door, so this should set off a few alarms for people. But is it as bad as they say?

Amazon recently addressed these security concerns, saying they don't use the server to process or store secure requests. That means websites using SSL (https) will be handled by the Kindle exclusively. Common websites that use secure protocols include banking, payment, and even Facebook, Twitter, and Google. Amazon also told the Electronic Frontier Foundation (EEF) that the acceleration features could be turned off, sacrificing the Silk browser's killer feature, speed, for security. But, is that enough?

Read the rest of this post »
Read More

Flash Trojan for Mac OS

Diposting oleh fawaid on Rabu, 19 Oktober 2011

For some odd reason, this malware was updated. They just won't let it lie down and die. The latest version of the malware can actually disable automatic updating of the built in Mac OS anti-malware software. You could make sure it updates manually though.

Fortunately, it's incredibly easy to avoid this trojan. If your flash installer looks like the photo above, and you downloaded it directly from Adobe, then install it. If it looks like the screenshot below, you've got a trojan on your hands, and you should delete it immediately. You're safe, it still requires you to download, install it, and give it your password, so you're still relatively safe.

Read More

HTC Admits Huge Security Flaw

Diposting oleh fawaid on Rabu, 05 Oktober 2011

HTC has come clean about a massive security flaw in their Android powered phones. The security hole allows an attacker to access all the data on the phone very easily. A malicious app could easily come in, take all your data, and send it elsewhere. HTC is working on a solution.

The flaw is in HTC's Sense UI, not the Android OS, so if you don't have an HTC Android phone, you're safer. Of course, Android has it's own security flaws, but you're at least safe from this issue. Of course, issues like this don't happen when the same company controls every aspect of the OS, like Apple does with iOS.
via Gizmodo
Read More

Apple Updates Malware Definitions

Diposting oleh fawaid on Senin, 26 September 2011

Remember that PDF based trojan I reported on just 3 days ago? If not, there's a link, I recommend reading that story first, getting mildly frightened, and then coming back here for comfort.

Okay, don't be frightened, Apple has already issued an update to the built in malware definitions in Mac OS. That means, without knowing it, your Mac has already updated and protected itself against this trojan. Of course, this is only available to users of Mac OS Snow Leopard or Lion. But that's just another reason to upgrade. Lion has far better security than it's predecessors, even Snow Leopard. So, if you're really worried about security, upgrading to Lion would be your best bet.
via tuaw
Read More

New Mac Trojan on the Loose

Diposting oleh fawaid on Jumat, 23 September 2011

Another annoyance to worry about for a few days: there's a new trojan out for Macs. Of course, issues like these are patched by Apple relatively quickly, and they don't infect many people. Still, be careful until Apple releases an update to fix it.

The trojan gets in through a special PDF, so only open PDF files if you're certain of their origin.  If you're sent a random pdf file, and you don't know what it is, or who it's from, don't open it. 
More malware delivered through an Adobe product, what a shocker. Just be safe over the next few days, and don't open any files you're suspicious of. Also, if you're using antivirus, make sure it's updated, and get ready for an update from Apple.
Read More

Vulnerability Found in Skype for iOS

Diposting oleh fawaid on Selasa, 20 September 2011

If you're using Skype for iOS, you might want to use it less frequently until the next update. News of a vulnerability has been released to the public. Using the technique detailed by the security researcher who discovered the exploit, an attacker could execute Javascript code simply by sending a user a message. With the exploit, any file on the iOS device is up for grabs.

Don't even look at messages from strangers, because the simple act of loading the message will allow your iOS device to be attacked. Remember, Microsoft bought Skype some time ago, and it seems they've continued with their philosophy: if the public doesn't know about a vulnerability, don't fix it.

The exploit was reported to Skype some time ago, but the researcher only came forward to the public about the exploit now. The idea was to give Skype some time to fix it. From the details he posted on the exploit, it doesn't sound like it would be very difficult to fix. In fact, if they dedicate some time to patching the exploit, they could have an update out very shortly. With any luck, now that the attack has gotten public attention a fix for it will be released shortly. Skype doesn't want to make their reputation for poor security any worse.
via CultOfMac

Read More

McAfee: Android Malware Up 76% From Last Quarter

Diposting oleh fawaid on Rabu, 24 Agustus 2011

Yet another security firm has come out stating the obvious: Android is not a secure platform. McAfee reports that Android malware has grown by 76% in the last quarter alone. iOS, however, remains as secure as ever. A lot of this has to do with Apple's "closed" ecosystem, meaning there's a review process for iOS apps, but there is not one for Android. This means attackers can easily load malware onto the Android Marketplace.

Android hasn't been having a lot of luck recently. It's getting harder and harder to report all the malware that's discovered on the platform, and much of it goes undiscovered for quite some time. If you plan on continuing using Android, make sure you're careful about what apps you're downloading.
via CultOfMac
Read More

Apple Patches Fake Flash Malware

Diposting oleh fawaid on Selasa, 16 Agustus 2011

It doesn't take Apple long to patch a security hole. If you'll remember, a new trojan was released for Mac OS on the 6th, which disguised itself as the Adobe Flash installer to trick users into installing the malware. Apple was quick to stomp this one out, because as of last Friday, Macs with the auto-updating save downloads list are immune, as long as you haven't disabled the feature. It's enabled by default in the general security preferences.

If you manage to download this malware, your Mac will warn you that you've downloaded known malware before you have a chance to install it.
via MacRumors
Read More

Trojan Pretends to be Flash

Diposting oleh fawaid on Sabtu, 06 Agustus 2011

Right on the heels of the news of MacDefender company has been taken down by the authorities, a new piece of Mac Malware has been revealed. The malware pretends to be Adobe Flash, and, once installed, will replace google.com with the attacker's own website. The malware is apparently set up to deliver pop-up ads, but it appears as though this functionality is not operational yet.
Fake Google page

Expect Apple to block this quickly, as it did with the multiple versions of the MacDefender malware. Still, until the malware has been blocked, you can prevent it from infecting you by only installing Adobe Flash from Adobe's website. Why would you trust Adobe software downloaded from anywhere else anyway? Like MacDefender, this requires the user to not only download it, but also install it. As long as you only install Flash from Adobe, you'll be fine. 
Read More