<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in The Silly New Mac OS X Trojan or HoHum.A</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Wed, 07 Nov 2007 20:58:26 -0000</lastBuildDate><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323411</link><description>This story was recently picked up by the Onion.&lt;br&gt;&lt;br&gt;&lt;a href="http://www.theonion.com/content/amvo/new_trojan_horse_strikes_mac" rel="nofollow"&gt;http://www.theonion.com/content/amvo/new_trojan...&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Hal B</dc:creator><pubDate>Wed, 07 Nov 2007 20:58:26 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323399</link><description>It's not free. It takes effort to deploy and maintain it.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Mon, 05 Nov 2007 08:38:24 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323398</link><description>Gadi Evron being a fame whore again? BREAKING NEWS!</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">zazou</dc:creator><pubDate>Mon, 05 Nov 2007 05:30:35 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323410</link><description>well, I dont think the OP was talking AV, but since you asked..&lt;br&gt;&lt;br&gt;why not "invest" in teh free clamXav?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">JP</dc:creator><pubDate>Mon, 05 Nov 2007 04:43:47 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323409</link><description>Security and cost are two sides of the same coin. You have finite resources. There are more countermeasures available to you than you can afford. &lt;br&gt;&lt;br&gt;What should you invest in? OS X antivirus? No? Then what point are you making?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Sun, 04 Nov 2007 20:45:49 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323408</link><description>AV is pretty useless. I would say invest in making your browsers and mail clients secure, invest in hardening your OS, invest in training your end users, invest in blah, blah, yadda, yadda, etc, etc,....&lt;br&gt;&lt;br&gt;Waiting until its "worth it" to invest in security means you have to be compromised many times over before you will get a good ROI. Of course a single compromise can lead to a string of misdeeds that can cost a company hundreds of millions. This was TJX's plan, and look where it got us.&lt;br&gt;&lt;br&gt;-JP</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">JP</dc:creator><pubDate>Sun, 04 Nov 2007 14:27:00 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323397</link><description>By your logic, JP, we should all invest in Linux antivirus.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Sun, 04 Nov 2007 12:13:29 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323396</link><description>You said something unbelievably stupid:&lt;br&gt;&lt;br&gt;"To this day, I am not entirely convinced that it makes sense to invest in security before it costs you."&lt;br&gt;&lt;br&gt;&lt;br&gt;So you are saying you should wait until after blaster hits before investing in security?&lt;br&gt;&lt;br&gt;sheesh</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">JP</dc:creator><pubDate>Sun, 04 Nov 2007 12:03:16 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323407</link><description>"What unpatched vulnerabilities is he referring to?"&lt;br&gt;&lt;br&gt;The users who find it ok to run questionable files on their machines.  We forgot to create a patch for them.  Would this be like a nicotine patch?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lori</dc:creator><pubDate>Fri, 02 Nov 2007 17:52:53 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323406</link><description>Once again, Gadi Evron has shown himself to be quite the "expert" (read: Fat guy with a CISSP cert who gets beer cans thrown at him at DEFCON). While I am by no means a fan of Mac OS X, Gadi's claims are simply insane. While malware that requires user interaction can produce a decent yield (think Storm Worm), I don't see this one getting a +10,000 userbase anytime soon. It really all comes down to what type of people watch pr0n, and what percentage of those will be surfing on a Mac running OS X, as opposed to their parents' Windows XP Home Edition box. Don't quote me on that though, I don't run a pr0n site and can't conduct an analysis of useragents used by visitors, nor do I have the type of statistical data avalible to me that AV vendors and the HoneyNet research alliance do ("Hey, looks like the .br and .ro kiddies are ./sshbrute'ing again...).&lt;br&gt;&lt;br&gt;Perhaps I'm missing something here, but Gadi's comment seems to be the work of a half-brained moron, rather than a BugTraq $uper$tar. Oh well... what can you do...&lt;br&gt;&lt;br&gt;Oh, and for the record, I'm not saying that there will not be a yield for this trojan; I'm just saying we're not talking OpenSSH remote root 0day here. Or xnu remote root 0day. Whatever.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">sigsegv</dc:creator><pubDate>Fri, 02 Nov 2007 16:05:02 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323405</link><description>It's complete nonsense. &lt;br&gt;&lt;br&gt;There is very little about the "Unix architecture" that makes Unix safer than Win32.&lt;br&gt;&lt;br&gt;The distinction people are actually talking about is not "Unix vs. Win32". It's "single user environment" versus "server environment". &lt;br&gt;&lt;br&gt;From a security perspective:&lt;br&gt;&lt;br&gt;OS X has more in common with Windows XP SP 2 than it does with Solaris 10.&lt;br&gt;&lt;br&gt;Windows Server 2007 has more in common with Solaris 10 than it does with Windows XP SP 2.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Fri, 02 Nov 2007 14:07:55 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323404</link><description>Whats your opinion about this ?&lt;br&gt;&lt;br&gt;&lt;a href="http://www.blackfriarsinc.com/blog/2007/11/mac-os-x-malware-myth-continues-and-no" rel="nofollow"&gt;http://www.blackfriarsinc.com/blog/2007/11/mac-...&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Just out of curiosity...</dc:creator><pubDate>Fri, 02 Nov 2007 13:57:03 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323403</link><description>One thing I find interesting is that the blogs are just writing about the behaviour of the preinstall and postinstall scripts.  They don't mention anywhere that I've seen, what the plugin itself actually does put a plugin bundle in /Library/Internet Plugins/.  But no one describes what this plugin does.&lt;br&gt;&lt;br&gt;In general, this thing is the most well-behaved malware installer I've seen - nice clean well-indented perl scripts with explanatory variable names and all.  So I can't imagine they'd have obfuscated the function of their plugin either.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">dragonfrog</dc:creator><pubDate>Fri, 02 Nov 2007 02:19:17 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323402</link><description>Thanks for bringing some sanity to the discussion of this trojan.  From the way this is playing out elsewhere, you'd think we had a full blown self-replicating virus which required no user intervention.  &lt;br&gt;&lt;br&gt;The most secure systems in the world can't defend against user ignorance...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">jjarmoc</dc:creator><pubDate>Thu, 01 Nov 2007 20:58:19 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323401</link><description>Well, he's a little better than SC Magazine's Dan Kaplan who originally wrote the following today:&lt;br&gt;&lt;br&gt;"I just IM’d my buddy Ryan, who has a Mac, to determine whether he runs AV on his machine. His response: “I don’t think so.”  &lt;br&gt;&lt;br&gt;Mac users are so arrogant and clueless about security, they don’t even know if they have AV installed in the first place. I love it.”&lt;br&gt;&lt;br&gt;So I suppose that makes us clueless about security, huh?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alex</dc:creator><pubDate>Thu, 01 Nov 2007 20:26:17 -0000</pubDate></item><item><title>Re: The Silly New Mac OS X Trojan or HoHum.A</title><link>http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/#comment-2323400</link><description>What is it with Windows 98 anyways?  Somebody compared the iPhone to it a few weeks ago.  Why not 2000?  Or Redhat 9?  Two OSs that were more full of holes when released than 98.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">tim</dc:creator><pubDate>Thu, 01 Nov 2007 20:12:36 -0000</pubDate></item></channel></rss>