Kamis, 04 Desember 2008

Trojan and Backdoor 'Ghostly' Apple Mac OS X



Two Trojan was present menginfeksi Apple Mac OS X, with the ability to download and install the code 'evil' from an attacker, and the tool hackers to create a backdoor. Trojan is called OSX.RSPlug.D were found by Intego, a security specialist Mac. Trojan is a variant of the code 'evil' old edition, but with the new installer.

"A OSX.RSPlug.D Trojan Trojan Downloader, and will contact the server to download a file that will be installed. This means, Downloader can install the payload more than ever installed. "Intego said. Trojan is the same as the previous version of Trojan, namely RSPlug, which found in October 2007. Trojan RSPlug will install the code 'evil', which is known by DNSChanger, which will play a user's Internet traffic to the DNS server 'evil', users have to make phishing websites or pages that display the ads.

Trojan OSX.RSPlug.D found on a pornographic website as the code required to play video files, a technique that is used in order to trap attacker users to download and install the code 'evil' is. Intego also find the Trojan OSX.TrojanKit.Malez and other vendors, such as Symantec and Trend Micro Trojan OSX.Lamzev.A found in Mac OS X. Trojan OSX.Lamzev.A a hacker tool designed to facilitate the attacker to install backdoor in the user's system. However, both the tool vendors have not considered such a threat hackers weight, because the hacker must be physical access to the system to install a backdoor.

According to Intego, not as Trojan horse malware and other hacker OSX.TrojanKit.Malez request for access to the first Macs to install the code 'evil'. For that, many security vendors, including Symantec and Trend Micro assess that the Mac platform is not necessarily safe for users. However, Apple is not commenting on this matter.

Tidak ada komentar: