OS X flaw may leave Macs open to virus attacks

By David Becker, Special to ZDNet
12 April 2004 02:03 PM
Tags: apple, os x, security, virus, flaw, mac, david, becker
Apple Computer was investigating a reported security flaw Friday in its OS X operating system that could allow vandals to trick Macs into opening dangerous files, such as Trojan horses and viruses.

The flaw was reported by Intego, a French security firm specialising in Apple systems. The company said in a statement that it had encountered a proof-of-concept Trojan horse for OS X disguised as an MP3 music file.

"Mac OS X displays the icon of the MP3 file, with an .mp3 extension, rather than showing the file as an application, leading users to believe that they can double-click the file to listen to it," according to Intego. "But double-clicking the file launches the hidden code, which can damage or delete files on computers running Mac OS X, then (launches) iTunes to play the music contained in the file, to make users think that it is really an MP3 file."

Proof-of-concept bugs are typically created by security researchers to prove the existence of a software flaw. They exploit the flaw but don't do any damage. The OS X Trojan began circulating last month via a newsgroup posting.

Apple said in a statement that it was looking into the matter. "We are aware of the potential issue identified by Intego and are working proactively to investigate it," the statement said. "While no operating system can be completely secure from all threats, Apple has an excellent track record of identifying and rapidly correcting potential vulnerabilities."

In a bulletin released on Friday, Security software and services company Symantec verified the bug but said it posed no immediate danger. "This Trojan does not contain any malicious code," the bulletin said. "MP3Concept is a proof-of-concept Trojan and is not currently seen 'in the wild'--it is not spreading and infecting Mac users."

An Intego researcher said that exploit works by embedding a file with code written for Carbon, the OS X component that allows older programs to be updated to run natively in the new operating system. OS X's Finder application, which associates file types with appropriate applications, doesn't see the Carbon code and launches the malicious file.

A number of such spoofing exploits have surfaced for Microsoft's Windows operating systems, but Macs have been relatively safe from such exploits and other types of attacks. Apple released a security update for the latest version of OS X earlier in the week.

Christophe Guillemin contributed to this report.

Advertisement

Talkback 1 comments

    Similar exploits are possible ...Anonymous -- 12/04/04

    Similar exploits are possible for years already on Mac OS 9 and earlier. The simpliest variant is an application with a custom icon of a folder, picture or sound file. And appropriate extension since Mac OS 9 ignore them completely.

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured