Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » When is a NAT Router Not Enough? » Now that is
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« About time !!  
AuthorAll Replies


ThunderCorp

join:2002-03-11
Chula Vista, CA

reply to Sandman5
Re: Security through obscurity

McAfee's analysis of this so-called OS X Trojan:
The only mildly non-trivial discovery associated with this malware is that its author managed to combine a valid MP3 file and a PowerPC application in one file without violating any of the two file formats. That means the trojan is playable within iTunes as MP3 sound file and it can also be launched as a program by Finder. This works under MacOS 9 and OS X.
  However, dual personality of a file has little relevance to the malicious function. If a user is convinced to double click on an icon representing a file the program will run regardless of being a simple disguised application or dual-format file. Thus, the discovery of dual-format files does not really introduce any new penetration or propagation vector. It can only obfuscate a little the function of the disguised program, which will appear as a valid sound file and it can be played from iTunes.
  To achieve this dual personality of the file the PowerPC application (Type 'APPL', Creator = 'vMP3') is registered in the resource fork as 'cfrg' (code fragment) within the data fork. At the same time this data fork (with an ID3 record at the beginning of the MP3 file that holds the binary code) is a valid MP3 file image.
That, plus the fact that this "trojan" is easily killed just by sending it over the internet, which strips its executable code fork and renders it useless.
Forums » When is a NAT Router Not Enough?« About time !!  


Tuesday, 24-Nov 14:46:37 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [97] New AT&T Ad Campaign Hits Back At Verizon
· [79] New Bill Takes Aim At Higher Verizon ETFs
· [30] Earthlink Suffers From Major E-mail Outage
· [30] AT&T Offers New Prepaid Wireless plans
· [28] Frontier Increases Modem Rental Fee
· [23] In-Flight Internet Headed For Bumpy Landing?
· [22] Senators Want ACTA Made Public
· [16] Vivendi In Way Of Comcast's NBC Desires
· [15] Charter Still Fighting With Creditors
· [11] Time Warner Dallas Customers Get WiMax December 1
Most people now reading
· Mysterious $800 Cash Deposit? [General Questions]
· NDP - Jack Layton email on broadband [TekSavvy]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· Big Bank Alternative to Bank of America? [General Questions]
· What to use while demonoid is down? [Filesharing Software]
· Is Gear Score now the new requirement to get pug invite? [World of Warcraft]
· Killing the source - Google bans advertisers, not just ads [Security]
· Climate Change Scandal Erupts After Email Hack. [Security]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]