tech industry

03/24/2006, 5:20pm, EST

Friday, March 24th

Briefly: AAPL history; Macs in botnets

In brief: To celebrate the thirty-year history of Apple Computer, Nicholas Pyers will be giving a presentation remembering the history using Apple's own print and video advertisements.... A recent article about "botnets," or networks of compromised computers, notes that in recent times numerous Macs have been used as zombie systems.... Scosche Industries today announced its new FreestyleT line of RF remotes ($70) specifically designed for fifth-generation iPods and iPod nano.... Wait times for both the 1.83GHz and 2.0GHz MacBook Pro notebooks have decreased from 3-5 days on Wednesday to 1-3 days.... Audioengine is shipping its Audioengine 5 speakers ($350, shown at right) designed for portable media players such as Apple's iPod.


Filed under: industry

, , 7comments, del.icio.us, slashdot, digg, buzz


7 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
Whaaaa?
0
03/24, 7:27pm, EST
This is the first I've ever heard of any OS X systems hacked with malware. If this is true (that they were used as bots, then why haven't we heard of this before? Methinks something is bogus.
Mac Elite
Joined Jan 2000
User is offline
re: whaaaa?
0
03/24, 7:45pm, EST
Unfortunately, it's not at all bogus. Some of the vulnerabilities common to all Unix-based systems are also present in the Mac. The attacks are mostly done by script kiddies though. A number of them rely on trivial passwords, some rely on existing security holes (haven't seen many of these, though) and others rely on holes in 3rd party software (i.e. phpBB). One of my friends with an iMac had his machine botnetted because a friend of his with an account on it was an idiot and used a trivial password. It's definitely not bogus.
Senior User
Joined Dec 2002
User is offline
Botted?
0
03/24, 7:59pm, EST
In what way was your friend's imac turned into a member of a botnet? Just curious.
Fresh-Faced Recruit
Joined Aug 2001
User is offline
BULL!!!
0
03/24, 9:58pm, EST
Here is a claim that Mac can be owned in 30 mins http://www.zdnet.com.au/news/security/soa/Mac_OS_X_hacked_in_less_than_30_minutes/0,2000061744,39241748,00.htm

but what it doesn't tell you is this link

http://macdailynews.com/index.php/weblog/comments/bona_fide_mac_os_x_security_challenge/

and this is what finally happened http://www.informationweek.com/security/showArticle.jhtml?articleID=181502434

So get the fact straight.. Mac is still one of the most secure OS in the WORLD!!!

:)
Joined
User is
yes, good security, but..
0
03/26, 2:07pm, EST
Mac OS is one of the most secure OSs available, but nothing will protect you from stupid passwords.

It took me about 8 hours to clean up after one of my clients got a server hit by a paypal phisher. They came in through an account with a VERY weak password (account "pc" password "pc") that was used for a windows machine to connect. I had been saying to them for months that they had inadequate passwords, they didn't want to hassle with good ones.

The hacker came in through ssh - which actually needed to be on, since it's a server that has to be remotely managed. And ssh login attempts are CONSTANT these days.

And of course the client's passwords are better now, and ssh is significantly more locked down. So, while the Mac is better than most, you shouldn't take that as an excuse to get careless.

Oh, and after an incident, you REALLY need to back up all your data, reformat & reinstall, and restore ONLY the data, NOT the apps. Unless you're 100% certain that an attacker didn't get root, anything less is asking for trouble.
Fresh-Faced Recruit
Joined Sep 2001
User is offline
Password
0
03/26, 2:53pm, EST
I agree..

If they get your password then it's over..

I think that goes for every single OS out there.. Until we have some kind of widely used biometric identity for a password, we'll have this problem..
Joined
User is
Mac Botnets
0
03/26, 4:00pm, EST
Here are the straight facts. The follow-up article (http://blog.washingtonpost.com/securityfix/) explains the exploit used. The botnet was created using a known security hole in something that runs on top of the operating system. This is PHP, a development programming language built specifically for Web sites. By leveraging this PHP flaw, the attackers were able to seed the Mac systems with several tools designed to turn them into drones for distributed denial of service attacks.

So, despite the fact that the Mac OS is relatively secure, a false sense of invulerability is dangerous. As is a false sense of smugness.
Fresh-Faced Recruit
Joined Feb 2005
User is offline
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News
Want To Sell Your Laptop? Any Condition - receive Top Cash. Get an instant quote. Free shipping www.CashForLaptops.com
Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.