The Rolex Forums   The Rolex Watch

ROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEX


Go Back   Rolex Forums - Rolex Forum > General Topics > Open Discussion Forum

Reply
 
Thread Tools Display Modes
Old 5 April 2012, 01:24 PM   #1
johnbeth
"TRF" Member
 
johnbeth's Avatar
 
Join Date: Jul 2010
Real Name: John
Location: Australia
Watch: Depends on mood.
Posts: 9,536
Icon20 Serious Mac flaw needs urgent fix.Macs infected with the Flashback Trojan.

Apple releases patch as 500,000 Macs infected with the Flashback Trojan.
Apple has released an urgent patch that will fix a security hole in its Mac operating system that has allowed some 30,000 Mac computers in Australia and more than 500,000 worldwide to be infected with malicious software (malware).

The critical update to Apple's version of Java for Mac OS X plugs at least a dozen security holes in the program and mends a flaw that attackers have recently pounced on to broadly deploy a malicious software program, known as Flashback Trojan, both on Microsoft's Windows and Apple's Mac operating systems.

Flashback Trojan's most recent variant (it has been around since 2011) self installs after users visit legitimate websites that have been infected to distribute the program - a process known as drive-by download. Once installed, the malware sniffs data traffic from the computer in search for user names and passwords.

The update, Java for OS X Lion 2012-001 and Java for Mac OS X 10.6 Update 7, sews up an extremely serious security vulnerability (CVE-2012-0507) that miscreants recently rolled into automated exploit kits designed to deploy malware to Windows users. But in the past few days, information has surfaced to suggest that the same flaw has been used with great success by the Flashback Trojan to infect large numbers of Mac computers with malware.

The revelations come from Russian security firm Dr.Web, which reports that the Flashback Trojan has successfully infected more than 550,000 Macs (hat tip to Adrian Sanabria who wrote on his blog "(...) many Mac users have been lured into a false sense of security, and will be, or may already be, in for a rude awakening. Apple's marketing efforts are at least partially responsible for this."). Dr.Web's post is available in its Google translated version here.

Flashback is an increasingly sophisticated malware strain that sniffs network traffic in search of user names and passwords. Early versions of it prompted Mac users to enter their password before it would run, but the most recent strains will happily infect vulnerable Mac systems without requiring a password, writes Ars Technica, among others. F-Secure has additional useful information on this Trojan attack here.
As Ars notes, although Apple stopped bundling Java by default in OS X 10.7 (Lion), it offers instructions for downloading and installing the Oracle-developed software framework when users access webpages that use it. If you need Java on your Mac only for a specific application (such as OpenOffice), you can unplug it from the browser by disabling its plugin. In Safari, this can be done by clicking Preferences, and then the Security tab (uncheck "Enable Java"). In Google Chrome, open Preferences, and then type "Java" in the search box. Scroll down to the Plug-ins section, and click the link that says "Disable individual plug-ins." If you have Java installed, you should see a "disable" link underneath its listing. In Mozilla Firefox for Mac, click Tools, Add-ons, and disable the Java plugin(s).

Delete Java
I can't stress this point strongly enough: If you don't need Java, remove it from your system, whether you are a Mac or Windows user. If you need further convincing of my reasons for this recommendation, I'd encourage you to browse through some of my past Java-related posts.
Apple maintains its own version of Java, and as with this release, it has typically fallen unacceptably far behind Oracle in patching critical flaws in this heavily-targeted and cross-platform application. In 2009, I examined Apple's patch delays on Java and found that the company patched Java flaws on average about six months after official releases were made available by then-Java maintainer Sun. The current custodian of Java – Oracle Corp. – first issued an update to plug this flaw and others back on February 17. I suppose Apple's performance on this front has improved, but its lackadaisical (and often plain puzzling) response to patching dangerous security holes perpetuates the harmful myth that Mac users don't need to be concerned about malware attacks

johnbeth is offline   Reply With Quote
Old 5 April 2012, 02:17 PM   #2
77T
2024 SubLV41 Pledge Member
 
77T's Avatar
 
Join Date: Dec 2010
Real Name: PaulG
Location: Georgia
Posts: 42,024
Thanks installing patch - Java for OS X 2012-001

Too many Java enabled web Apps to drop it entirely.

See http://support.apple.com/kb/HT5055 for more details about this update.

See http://support.apple.com/kb/HT1222 for information about the security content of this update.
__________________


Does anyone really know what time it is?
77T is offline   Reply With Quote
Old 5 April 2012, 04:11 PM   #3
InTime
Banned
 
Join Date: Nov 2011
Location: BermudaAntarctica
Posts: 892
doesnt yahoo mail need java
InTime is offline   Reply With Quote
Old 5 April 2012, 05:10 PM   #4
bayerische
"TRF" Member
 
bayerische's Avatar
 
Join Date: Nov 2009
Real Name: Andreas
Location: Margaritaville
Watch: Smurf
Posts: 19,879
Running software updater now.
__________________
Yeah, well, you know, that's just, like, your opinion, man.
bayerische is offline   Reply With Quote
Old 5 April 2012, 06:12 PM   #5
Bobble
Member
 
Join Date: Jun 2011
Real Name: Paul
Location: Midlands UK
Watch: GMT IIc, Daytona
Posts: 423
Thanks for that, I just ran software update and it just downloaded a Jave update
Bobble is offline   Reply With Quote
Old 5 April 2012, 08:40 PM   #6
HL65
TRF Moderator & 2024 SubLV41 Patron
 
HL65's Avatar
 
Join Date: Dec 2007
Real Name: Ken
Location: SW Florida
Watch: One on my wrist.
Posts: 64,009
Just ran it John--thanks!!
__________________

SPEM SUCCESSUS ALIT
HL65 is offline   Reply With Quote
Old 5 April 2012, 10:42 PM   #7
KKB
"TRF" Member
 
Join Date: Apr 2009
Real Name: Eric
Location: San Diego, CA
Watch: GMTIIC
Posts: 605
Thanks for the heads-up. I don't do software updates very often. Will update my Macs today.
__________________
116234 | 116710 | OMEGA 2551.80 | Reverso GMT
KKB is offline   Reply With Quote
Old 5 April 2012, 10:48 PM   #8
1675-David
"TRF" Member
 
1675-David's Avatar
 
Join Date: Jan 2011
Location: Stockholm
Posts: 6,061
uppdated, thanks for the heads up
1675-David is offline   Reply With Quote
Old 5 April 2012, 11:07 PM   #9
joleel7
"TRF" Member
 
joleel7's Avatar
 
Join Date: Jul 2009
Real Name: Joey
Location: Canada
Watch: DSSD, PAM, BALL
Posts: 869
Thanks for the information
joleel7 is offline   Reply With Quote
Old 6 April 2012, 12:52 AM   #10
robertneville
"TRF" Member
 
robertneville's Avatar
 
Join Date: Jan 2010
Real Name: Greg
Location: PA
Watch: me burn
Posts: 1,435
you might want to make sure you don't have it.

http://www.f-secure.com/v-descs/troj...shback_i.shtml
__________________

Motocross is life!
robertneville is offline   Reply With Quote
Old 6 April 2012, 07:34 AM   #11
johnbeth
"TRF" Member
 
johnbeth's Avatar
 
Join Date: Jul 2010
Real Name: John
Location: Australia
Watch: Depends on mood.
Posts: 9,536
Excellent everyone for updating their macs.. Patches are important especially if you are a pc user like myself.


johnbeth is offline   Reply With Quote
Old 6 April 2012, 08:12 AM   #12
FNFZ4
2024 Pledge Member
 
FNFZ4's Avatar
 
Join Date: Jan 2012
Real Name: Alfred
Location: DC Metro
Watch: None
Posts: 29,368
Great news!!!
__________________
NEED PC HELP? ASK HERE!

Watches:
Patek 5205G | Patek 5167A | 16613 Serti | 116718 Green | 216570 Black | 16700 Pepsi

Wish list:
Patek 5726/1 | AP RG Ceramic | Patek 5712 | Patek 5130
FNFZ4 is offline   Reply With Quote
Old 6 April 2012, 06:30 PM   #13
tattooedfagin
"TRF" Member
 
tattooedfagin's Avatar
 
Join Date: Jan 2010
Real Name: Chad
Location: the neighbourhood
Watch: 1680 Red
Posts: 2,262
had no update here in the UK, just searched my Mac for Java & only had VM or Preferences but both when selected said to open i needed 'runtime' installed so i'm guessing i'm ok ?
__________________
SS Sub Date (F)
DSSD (V)
Red Sub (Mk4)

TRF Hall of Fame
tattooedfagin is offline   Reply With Quote
Old 8 April 2012, 01:31 AM   #14
daveathall
"TRF" Member
 
daveathall's Avatar
 
Join Date: Dec 2007
Real Name: Dave
Location: England.
Watch: Various
Posts: 7,305
Apple have released a further java update.

http://www.macrumors.com/2012/04/06/...a-in-two-days/

Just installed using "software update"
__________________
KINDEST REGARDS

DAVE


daveathall is offline   Reply With Quote
Old 8 April 2012, 11:47 AM   #15
Lol-x
Facilitator
 
Lol-x's Avatar
 
Join Date: Nov 2005
Real Name: Steve
Location: Omnipresent
Posts: 33,593
Just download and install the update (for free) and you will be fine.
__________________

Most folks are about as happy as they make up their minds to be. ~Abraham Lincoln
Nothing compares to the simple pleasure of a bike ride. ~John F. Kennedy

ROLEXploitation - yeah I'm a victim
Lol-x is offline   Reply With Quote
Old 8 April 2012, 12:11 PM   #16
tranny
Banned
 
Join Date: Feb 2012
Real Name: Steve
Location: Boston, MA
Watch: 116509,A21330,MVQV
Posts: 773
Hellboy re: Macs: "industrable my ass"
tranny is offline   Reply With Quote
Old 8 April 2012, 03:08 PM   #17
johnbeth
"TRF" Member
 
johnbeth's Avatar
 
Join Date: Jul 2010
Real Name: John
Location: Australia
Watch: Depends on mood.
Posts: 9,536
Quote:
Originally Posted by transio View Post
Hellboy re: Macs: "industrable my ass"
johnbeth is offline   Reply With Quote
Old 8 April 2012, 03:11 PM   #18
ReMember
"TRF" Member
 
Join Date: Mar 2012
Location: Sin City
Posts: 391
Quote:
Originally Posted by transio View Post
Hellboy re: Macs: "industrable my ass"
What is industrable??
ReMember is offline   Reply With Quote
Old 8 April 2012, 08:48 PM   #19
MoBe
"TRF" Member
 
Join Date: Sep 2011
Location: Canada
Posts: 6,773
Quote:
Originally Posted by ReMember View Post
What is industrable??
It`s a Mac with a speach impediment. (caused by a virus)
MoBe is offline   Reply With Quote
Old 10 April 2012, 10:59 AM   #20
tranny
Banned
 
Join Date: Feb 2012
Real Name: Steve
Location: Boston, MA
Watch: 116509,A21330,MVQV
Posts: 773
Quote:
Originally Posted by ReMember View Post
What is industrable??
In-des-truct-i-ble. It means it cannot be destroyed.

http://lmgtfy.com/?q=%22industrable+my+ass%22
tranny is offline   Reply With Quote
Old 11 April 2012, 10:15 PM   #21
Bangel
"TRF" Member
 
Bangel's Avatar
 
Join Date: Oct 2011
Location: Australia
Watch: 116610LN
Posts: 15,802
Thanks for the heads up. I'm new on the Mac bandwagon, still learning the ropes and found this very helpful.
Bangel is offline   Reply With Quote
Old 12 April 2012, 02:00 PM   #22
HYDROMAROC
"TRF" Member
 
HYDROMAROC's Avatar
 
Join Date: Aug 2007
Location: SAN DIEGO, CA USA
Watch: me pass...
Posts: 1,111
Ha Ha... Welcome to the crap that PC have had to deal with for years....
HYDROMAROC is offline   Reply With Quote
Old 13 April 2012, 06:42 AM   #23
daveathall
"TRF" Member
 
daveathall's Avatar
 
Join Date: Dec 2007
Real Name: Dave
Location: England.
Watch: Various
Posts: 7,305
New software update.

Quote:
Apple just released Java for OS X 2012-003, an update to the Java implementation in OS X. The update removes "the most common variants of the Flashback malware." Interestingly the update disables Java for users who haven't used it recently and disables the automatic execution of Java applets.
__________________
KINDEST REGARDS

DAVE


daveathall is offline   Reply With Quote
Old 13 April 2012, 06:56 AM   #24
subtona
"TRF" Member
 
subtona's Avatar
 
Join Date: Jan 2011
Real Name: gus
Location: East Coast
Watch: APK & sometimes Y
Posts: 26,601
Quote:
Originally Posted by HYDROMAROC View Post
Ha Ha... Welcome to the crap that PC have had to deal with for years....
been a mac user since day one, the little gray box... also fully aware of the shortcomings of pc since day 1.

it would be nice if pc didn't suffer as bad as they did, but at least there was a better choice ... you could have joined anytime, you chose not to?.
__________________
subtona is offline   Reply With Quote
Old 13 April 2012, 10:02 AM   #25
Kevin B
"TRF" Member
 
Join Date: Apr 2010
Location: San Diego
Posts: 324
Am I the only one that thinks this thread is in regards to a problem with a McDonalds menue item every time I glance at it?
Kevin B is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

OCWatches

Wrist Aficionado

My Watch LLC

WatchesOff5th

DavidSW Watches

Takuya Watches


*Banners Of The Month*
This space is provided to horological resources.





Copyright ©2004-2024, The Rolex Forums. All Rights Reserved.

ROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEX

Rolex is a registered trademark of ROLEX USA. The Rolex Forums is not affiliated with ROLEX USA in any way.