根據華爾街日報報導,新型電腦病毒可能會感染蘋果作業系統(Mac OS X). 然而,病毒威力並不強,蘋果使用者不必過於擔心,病毒會透過iChat詢問使用者是否同意接收latestpics.tgz的圖片檔案,如果同意接收的話,則會透過iChat的Buddy list將病毒檔案傳給名單上的每個人.
根據蘋果電腦指出,感染新型電腦病毒的主機可能會運作不正常.另外,根據早期的蘋果使用者指出,十五年前蘋果電腦的病毒比現在更多,所以並不驚訝蘋果電腦也會感染病毒.
大型防毒軟體公司如McAfee Inc.和Symantec都將此病毒列為低度危險.
---
Virus for Mac OS X System Found
By ANDREW SIMONS
February 16, 2006 7:51 p.m.
LOS ANGELES -- Users of Apple Computer Inc.'s Macintosh computers like to think their machines are better protected than their counterparts running Microsoft Corp.'s Windows operating system.
Not so fast, says Sophos PLC, a U.K. computer-security firm.
A new virus could begin making the rounds on Macintosh computers around the world. Called Leap-A, the virus spreads through the iChat software inside the Mac OS X operating system, Sophos researchers said.
The virus masks itself as a picture file called "latestpics.tgz" -- purportedly screenshot pictures of Apple's new operating system. Once opened, it's forwarded to the people on the user's iChat buddy list.
Applications in infected machines might not run correctly.
"This is the first real virus to infect the Mac OS X," said Graham Cluley, a Sophos researcher, in an interview. "It's always been presented and marketed as a much safer operating system."
Apple played down the threat.
"Leap-A is not a virus, it is malicious software that requires a user to download the application and execute the resulting file," said an Apple spokesperson.
"Apple always advises Macintosh users to only accept files from vendors and Web sites that they know and trust," said the spokesperson. "We have a guide to safely handling files received from the Internet."
McAfee Inc. rated the virus at "low-profiled" on its security Web site, citing media attention to the threat.
Symantec Corp. also issued a notice about the worm, saying it is a low-level threat.
"This first Macintosh OS X threat is an example of the continuing spread of malicious code onto other platforms," Vincent Weafer, senior director at Symantec Security Response, said in a statement.
"However, this worm will not automatically infect, but will ask users to accept the file, giving potential victims a heads-up and the opportunity to avoid infection."
Still, the virus is rare for Macintosh users, which don't see nearly as many viruses as Windows users.
"They haven't always been immune," said Mr. Cluley, who said there used to be more Macintosh viruses 15 years ago.
But these days, viruses are designed with financial motivations -- as opposed to sheer mischief. For example, viruses can be used to steal personal information, such as credit card and bank account numbers, and send them back to the virus writers.
And there are many times more unprotected Windows users than Macintosh users.
"They don't need to go to all that extra effort to write a virus for Macs," said Mr. Cluley. "There are plenty of unprotected Windows computers out there."
Two weeks ago, a new virus threat attacked Windows users.
Discovered in the middle of January, the virus was designed to delete files created with Microsoft's Word, Excel and PowerPoint software programs that are stored on a user's local hard drive.
The virus is transferred through e-mail systems and Web browsers. Once inside an office computer network, the virus can easily transfer itself through office intranets.
The virus was set to harm files on the third day of every month. Despite high anticipation of that threat, not much happened.
czh wrote:
是覺得老是有人自誇mac不會中毒
老是自認為mac沒有病毒
卻不自覺自己用的是讓人連想下毒都提不起興趣的系統
事實上這系統病毒與漏洞也不少
就像車的零件常被偷,也都是暢銷車種也會有賊有興趣去偷
否則冷門車系,偷了也轉手不掉,那不是偷心酸的
阿.....
就是看他不會中毒才用阿 我不喜歡常常重灌
您的譬喻也滿妙的~
不過感覺....恩....二字就不用多說了
相信您發文時按下確定之前就知道接下來會有什麼樣的回文囉!
appleseed wrote:
要是主人笨笨的放行讓小偷偷那就~Orz
不過說真的,撇除駭客寫病毒是為了大範圍癱瘓電腦的原因外,有沒有人寫出一種病毒是會惡意破壞MAC系統的呀?例如說在某些網站上植入給MAC的病毒,利用MAC用戶瀏覽網站時偷渡進電腦,然後再利用通訊錄.app還是ichat名單將病毒散播出去這一類的,不然病毒要執行都還要獲得使用者密碼~那還有什麼搞頭嗎?
其實也不是完全這樣的啦。
因為 Windows 的病毒,也多是因為使用者疏忽,以及微軟貪圖讓使用者覺得方便使用才會引起的。
我覺得很多觀念上還是必須釐清的。如什麼是 Virus?什麼是 Melware?什麼是 Backdoor?什麼是 Trojen 等等?
現在理論上來講,只要妳的 Mac OS X 有開啟一些服務如 SSL、Apache、FTP 等等,要進去實在不是 Rocket Science。進去以後植入後門,也不是做不到。In fact 就有一位安全專家再某次網路安全會議中突然 PowerBook 被控制... 這算是 Security Exploit,Unix/Linux/OS X 絕對不輸給 Windows。
現在主要幾點難題就是,要是沒有開服務,要寫出一個程式繞過 root password 去搞,實在不容易。即使是 Unix/Linux,是有一些小程式做的到繞過 root pwd 去做事(無非是遠端攻擊比較可能),但是並無法傳播,但是可以植入後門開啟服務,也是類似 rootkit 的想法下去跑,這樣絕對無法傳播的快。即使使用類似 kernal rootkit 下去,也只是讓整台電腦被破壞,但是還是無法傳播的快。這就是為什麼現在 Unix/Linux/OS X 還沒有出現大型傳播性快速而且破壞性猛烈的 "軟體"。
不過,由於 OS X 上的軟體方便性承襲 Windows,當 Mac OS X 類似的 kernal rootkit 一出,絕對有辦法造成大型嚴重損毀。只是當時有一些設計者來不及去完全寫出 kernal rootkit 去搭 Safari Widget 便車。現在 iChat 使用者也不多,倒是到最後經由 MSN Messanger 或 E-mail 傳輸,才是最大的可怕性所在。而且 OS X 的 Mail 對這方面比較沒有防備心。

內文搜尋
X



























































































