« VB 2009 Banking Trojans
VB 2009 Gala Dinner Pics »

Mac OS X threats at VB 2009

September 24th, 2009

Methusela CEBRIAN FERRER did a great job presenting at VB2009 on the Mac OS X topic.

meths

Methusela Cebrian Ferrer.

The presentation was solid, underlying the motives and methods of infections for the different Mac Malware threats. The only glitch happened when the Mac she was using to present froze and then the keynotes program crashed. The audience was a little shocked for a minute until somebody made a joke about getting a PC instead.

mac

There have actually been rumors about somebody in the conference trying to hack into Macs. Is that possible? Well, certainly with some many security professionals carrying their laptops, there is a lot of information worth stealing. After all we are all on the same Wireless network and intercepting communications is definitely possible.

Anyway, the conversation went on after for a little while. I chatted with Meths, as Graham Cluley had just finished congratulating her. Some folks (Philippe and Jack) from Intego (a French company who makes a really good Mac security product called VirusBarrier) were there as well. Those guys actually were the first to name what we now know as Jahlav, RSPlug. Very soon after a big AV company (which will remain nameless) sort of took their finding as if they were the one discovering it.

It is quite unfortunate that Intego is not listed on Virus Total as they have probably one of the best security product for the Mac. According to Philippe, they have more than a thousand RSPlug (Jahlav) samples (that includes variants). Anyway, I have been promised a command line version for Linux so that I can do some testing before blogging and saying that no one detects this or that threat ;-)

That concludes a well packed second day at VB 2009.

Jerome Segura

    This entry was posted on Thursday, September 24th, 2009 at 8:41 am and is filed under Conferences. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    1.      by
    2.      by
    3.      by
    4.      by
    • (1) comments
    • |
    • Add your comments




RSS feed to this site
Jerome Segura is a Security Researcher at ParetoLogic.

Twitter

 

Malicious URLs

ParetoLogic, a Microsoft Certified Partner

 

 

Links

  • Malicious URLs
  • Phishing Emails
  • Free PDF Scanner
  • About
  • MalwareDiaries in the press
  • Contact Us



Archives

  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (3)
  • Banker Trojans (4)
  • Botnets (9)
  • Conferences (7)
  • DDos (2)
  • Debates (2)
  • Exploits (68)
  • Fake codecs (48)
  • Gaming (1)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (3)
  • Mac security (15)
  • Malware Trends (71)
  • P2P (1)
  • Phishing (47)
  • Podcast (1)
  • ransomware (7)
  • Research (68)
  • Rogue software (58)
  • Rootkits (2)
  • scams (13)
  • Social Networking (7)
  • Spam (4)
  • Uncategorized (122)
  • Wireless Security (2)
  • world map (1)



 
 
 
Microsoft is a registered trademark of Microsoft Corporation in the United States and/or other countries.

© 2010 ParetoLogic Inc.