MacDailyNews - Where Mac news comes first

MacDailyNews Poll

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

Macworld UK

TUAW

MacRumors

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Sun, Oct 12, 2008 - 01:48 AM EDT  —  AAPL: 96.80 (+8.06, +9.08%)  |  NASDAQ: 1649.51 (+4.39, +0.27%)

New Mac OS X Trojan horse identified
Monday, June 23, 2008 - 04:30 PM EDT

The OSX/Hovdy-A Trojan horse, which relies on the user giving it permission to install itself, is an attempt to steal passwords, open firewall to give access to hackers, and disable security settings.

The Hovdy-A Trojan horse takes advantage of a vulnerability in Apple's Mac OS X operating system, affecting the Apple Remote Desktop Agent (ARDAgent), to gain root access. Once the user has given permission and installed the OSX/Hovdy-A Trojan horse, the hacker can gain complete control of the compromised Macintosh - covering its tracks by disabling system logging.

This Trojan horse relies on the user giving it permission to install. Using social engineering techniques, the Trojan horse could be disguised as a game, a video codec, etc.

When run the Trojan will attempt to install itself to the /Library/Caches folder and perform the following tasks:

- disable system logging and delete system log files
- start PHPShell and web server
- start ARD, VNC and SSH services
- disable system updates
- open ports in the firewall
- disable third party security software
- steal various password hashes and keys which may be used to compromise other systems

OSX/Hovdy-A will also attempt to use the ARDAgent vulnerability to obtain root access.

More info via Spohos here.

MacDailyNews Note: As always, do not download, authorize, and install software from unknown, untrusted Websites or any other sources.

  • Social Web
  • E-mail






Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: ( = registered)

Jun 23, 08 - 04:33 pm Comment from: AP

Let FUD begin!

Jun 23, 08 - 04:35 pm Comment from: wow

When some calls me on the phone and asks for SS# should I do that?

mine 555-55-FIN dorks!!!!

virus free and still no firewall know anti virus...... I guess I am just lucky

Jun 23, 08 - 04:37 pm Comment from: Jay-Z

Unfortunately, no anti-malware software can protect against ID-10T errors.

Jun 23, 08 - 04:42 pm Comment from: Bandit Bill

Did you read the article? I'm sure most of us have installed an application at some point. I'll typically source apps through versiontracker, I'll read the comments and note the number of people who have downloaded the application etc. This isn't fool proof, but it's the best that I know of.

Any suggestions?

Jun 23, 08 - 04:43 pm Comment from: Wandering joe

nice 1 Jay-z grin

Jun 23, 08 - 04:45 pm Comment from: ron

But, but, but, MAC's never get viruses, I thought!

Ah hahahahahahahaha!

You man-pudding swallowing homo MAC fags get what you deserve.

All high and mighty and now you've got viruses, too!

Told you, you baby batter eating homo MAC fags.

You get what you deserve. Your MAC is the same as my Windows PC now, you gay fags.

I've been waiting for this day for so long!

Ah hahahahahahahaha! Stupid MAC fags overpaying for nothing. Enjoy your viruses, you H-mo sausage smugglers!

Jun 23, 08 - 04:47 pm Comment from: Think

I believe RON was molested as a child.

Jun 23, 08 - 04:48 pm Comment from: @ron

Oh my. Little angry are we? Do you kiss your mother with that filthy mouth?

This isn't a virus, btw...

Are all Windows users that angry? I find it amusing.

Jun 23, 08 - 04:51 pm Comment from: pr

Dear Ron:
You are a dipshit. Crawl back in your 8th grade locker and stop commenting on things you know nothing about.
This is NOT a virus you moron. Even if it WERE...it would still be 144,000 (yes that's the real number) to ONE in seven years since the introduction of OS X...But again..this is NOT a virus.
You are only proving what we all know. The vast majority of PC users are simply not very smart.

Jun 23, 08 - 04:51 pm Comment from: Viktor

@ron
Yes, let's celebrate that finally we can get to know a computer virus and experiment what windoes users fell every day...... oh crap, I forgot that they also suffer from bad crappy bad copy windows bugs, malware, adware and that all stuff... forget, let keep boring with our Macs that JUST WORKS!

Jun 23, 08 - 04:53 pm Comment from: @ron

A trojan is not a virus.

Jun 23, 08 - 04:53 pm Comment from: @Ron

We see asswipes like you all the time. Makes us sleepy. Ha!

Jun 23, 08 - 04:55 pm Comment from: MacLovin

@ RON: ok, ron, you fsking dumbass... We don't over pay for one thing. Our computers are usable... Our computers are good looking... Our computers are fast, your computers slow down over time, have 9.000,000,000,000,000,000,000 viruses made for it, and just plain suck, IE is a joke, windows firewall is a joke, the windows GUI is a joke gone bad. There is one freakin virus for mac? verses the 9 trillion+ for PC? I like my odds on a mac...

PS, have fun using windows mobile on your motorolla...

Jun 23, 08 - 04:57 pm Comment from: Macs King

The trojan can act like a porn video, that's how you download it. The next button you press will activate it. You have been warned.

Jun 23, 08 - 04:57 pm Comment from: Dirty Pierre le Punk

Ron,
you need to get over being touched by your uncle and calm down enough to realise that a trojan is totally different to a virus.

Jun 23, 08 - 04:57 pm Comment from: Mac-nugget

@ron
A virus self replicates and self installs. This is a Trojan, fool.

You are right, we get what we deserve, that is a superior safer more intuitive elegant snappier computing environment.

Believe me, we all get what we deserve.

Jun 23, 08 - 04:57 pm Comment from: HotinPlaya

Get a life Ron

Jun 23, 08 - 04:59 pm Comment from: JAYGEE

The more popular the Mac gets, the more Trojans will appear. Lets just hope a fully working virus isn't released for the Mac ohh

Jun 23, 08 - 04:59 pm Comment from: HMCIV

OMG!!!! THE TROJANS ARE COMING. ABANDON YOUR MACS IN THE STREET!! UNPLUG YOUR INTERNETS!! BUY SECURITY SOFTWARE FROM SECUNIA!! EJECT ALL YOUR FLOPPIES AND FOR FRAK'S SAKE, SWITH TO VISTA!!

S-W-I-T-C-H TO V-I-S-T-A-A-A-A!!!!

Jun 23, 08 - 05:00 pm Comment from: BSOD

I thought Ron was funny, whether he meant it or not.

Jun 23, 08 - 05:04 pm Comment from: HMCIV

BTW, does anyone know roughly how many Mac have actually been laid to waste by this Trojan? I'm sure Ron would like to know.

And while I'm at it, what's an HMO sausage smuggler? I didn't realize medical care included sneaking bratwurst out of the grocery store. I may have to give Blue Cross/Blue Shield a call!

Jun 23, 08 - 05:05 pm Comment from: MacLovin

@HMCIV: NO SHIT!!! WINBLOWS VISTA IS SOOO MUCH BETTER THAN OS X!!!! AS WE SPEAK, I'M PUTTING MY MAC ON EBAY AND BUYING A DELL!!! AND PS, FLOPPIES ARE THE SCHIZZ MAN!!! haha

Jun 23, 08 - 05:06 pm Comment from: Kit-N

Hey MacLovin,

We're farther ahead than you give us credit for. As the above posts indicate, a trojan isn't a virus.

That takes us back to:

Windblows PC - 144,000+
Mac OSX - 0

Jun 23, 08 - 05:06 pm Comment from: BSOD

You know what the irony of all this is? I have been manually removing viruses, Trojans, and spyware from Windows systems for so long that it is almost second nature. But I have no clue where to start on a Mac, and I have been using them since 1984.

Jun 23, 08 - 05:10 pm Comment from: mdabrosca

Okay, we've had enough fun of sad, sick Ron.

Now, on to the big question:
What should I be looking for to discern if I've been infected or not?

Jun 23, 08 - 05:11 pm Comment from: MidWest Mac

@ Ron

Lighten up, Francis.

Jun 23, 08 - 05:17 pm Comment from: Mac Monkey

*yawn*

Nothing to see here folks. Move along.

Jun 23, 08 - 05:17 pm Comment from: tz

Gee MDN I have been reading about this for two or three days now, where have you been?
OOOooo a trojan horse! I am soo scared. That does it. I'm going to get some Vista tomorrow.

Jun 23, 08 - 05:19 pm Comment from: MacLovin

@ Kit-N, my bad, just started ranting and couldn't stop... lol

Jun 23, 08 - 05:19 pm Comment from: smackman

I don't know...I think Ron is a bit more entertaining than Zune Tang....

smile

Jun 23, 08 - 05:20 pm Comment from: neomonkey

"When run the Trojan will attempt to install itself to the /Library/Caches..."

And what would its name be? Seems like it would be simple enough to delete it if there were only some way to identify it.

Jun 23, 08 - 05:22 pm Comment from: MacLovin

@Smackman: naw... he uses the word "fag" too much... and he doesn't have a slogan either... lol But does it really matter? they're both idiots... at least ZuneTang doesn't really mean it.

Jun 23, 08 - 05:24 pm Comment from: G4Dualie

Another example of the millions of ways in which the Mac is exploited each day.

I am truly grateful for this process; culling the tards from the herd is natural process and should be embraced, as it only makes us stronger.

Jun 23, 08 - 05:24 pm Comment from: MacLovin

oh, and ron reminds me of a 13 year old nerdy boy who cant stand in the sun for more than 5 minutes because his skin is so pale from playing Halo 3 all day...

Jun 23, 08 - 05:25 pm Comment from: Bandit Bill

@mdabrosca

Good luck getting an answer on this forum. I asked for suggestions to avoid Trojans and now you are asking how to discern if you have a Trojan.

I'll don't think this forum is the place to discuss things in a mature manor. It's more about cracking jokes and getting attention. It is what it is. Lots of people enjoy MDN.

Jun 23, 08 - 05:32 pm Comment from: Jesus

At least it's not a Spartan... then we would really be screwed.

http://dubiousacademia.com/blog/wp-content/uploads/2007/04/spartan40.bmp

btw... anyone computer nerd worth their salt can write an applescript that is more dangerous than this little nasty.. Until there is an actual virus.. I will continue to be a smug apple fanboy.

Jun 23, 08 - 05:36 pm Comment from: Merv

I'm not really interested in this latest FUD.

I'm interested in knowing why 'Ron' thinks semen tastes like pudding. I need to tell my girlfriend something.

Jun 23, 08 - 05:40 pm Comment from: Merv

Bandit,

MacUpdate and VT are your best choices. Also HyperJeff.

Stay the course, buddy.

Jun 23, 08 - 05:44 pm Comment from: Me In LA

ron = Ballmer.
Dork.

Jun 23, 08 - 05:44 pm Comment from: Macaday

I look forward to hearing if anyone AT ALL falls foul of this Trojan which is almost certainly created by the security companies reporting it...

Jun 23, 08 - 05:57 pm Comment from: me

@ RON

MAC stands for Media Access Control. This is a Macintosh site, not a Media Access Control discussion group.

Jun 23, 08 - 06:05 pm Comment from: Thorin

Ron just played many of you like a $10 guitar with his thinly veiled sarcasm.

Jun 23, 08 - 06:16 pm Comment from: ron

That ron perv is an impostor. Get yer own monicker, wrong ron.

Jun 23, 08 - 06:22 pm Comment from: t

everyone - just ignore ron - obviously he's a troll.

Jun 23, 08 - 06:24 pm Comment from: t

to the real ron..i meant the fake ron...

Jun 23, 08 - 06:25 pm Comment from: CYxodus

It seems that ron suffers from a low self-esteem from using Windows and all the viruses, trojans and errors it has. As a result, he's desperate to prove that the Mac OS is just as inferior as Windows. I just amazes me how emotional invested Windows users are in such a flawed OS.

Hey ron...dump Windows and go with something that isn't a hacker's paradise.

Jun 23, 08 - 06:38 pm Comment from: MattyG

the hotfix for this is ridiculously easy

http://www.macosxhints.com/article.php?story=20080620052233168

again, mountains out of mole hills thank you mass media

Jun 23, 08 - 06:51 pm Comment from: Stiffy

Blaaah Mac OS is just another lame Windowz flavor now...this sukz:(

Jun 23, 08 - 07:05 pm Comment from: Bartsimpsonhead

Hey, I kinda liked Ron's comments (however stupid), and would like to read mor in future.

Come join me in chanting for him to add mor: Mor-Ron, Mor-Ron, Mor-Ron...

Jun 23, 08 - 07:06 pm Comment from: d'nomder

The OSX/Hovdy-A Trojan horse ... relies on the user giving it permission to install itself

</i>Let FUD begin!</i>

I gave a stranger the keys to my car, and he gained both access and complete control.

In another era I'd be an naive idiot. Today I'd blog (and possibly sue) how I was victimized by the automaker's poor design... raspberry

Reader feedback page 1 of 2 pages:  1 2 >

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my personal information   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below: