
<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Wikinerd&#039;z &#187; CS4</title>
	<atom:link href="http://wikinerd.net/tag/cs4/feed/" rel="self" type="application/rss+xml" />
	<link>http://wikinerd.net</link>
	<description>Complexity for a simple mind</description>
	<lastBuildDate>Fri, 26 Mar 2010 04:49:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Security concerns?</title>
		<link>http://wikinerd.net/2009/02/security-concerns/</link>
		<comments>http://wikinerd.net/2009/02/security-concerns/#comments</comments>
		<pubDate>Tue, 03 Feb 2009 13:13:04 +0000</pubDate>
		<dc:creator>wikinerd</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[CS4]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[iWork]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://wikinerd.wordpress.com/?p=21</guid>
		<description><![CDATA[Google gets it's first major crash while OS X gets it's first trojans. Includes iServices.a disassembly.]]></description>
			<content:encoded><![CDATA[<p>Recently, Google had been taken down by &#8216;human error&#8217;. While some thought that Google was taken down by crackers, the <a href="http://googleblog.blogspot.com/2009/01/this-site-may-harm-your-computer-on.html">statement released</a> says that it was caused by an employee accidentally typing &#8220;/&#8221; into the malicious sites list. &#8220;/&#8221;, of course, expands to include every website, so any search would lead you to a &#8220;This site may harm your computer&#8221; message.</p>
<p>While Google solves their problems, Mac OS X, with it&#8217;s new 10% market share, gets it&#8217;s first malicious trojan. <strong>iServices.a </strong>came to the attention to the technological community <a href="http://www.intego.com/news/ism0901.asp">through Intego</a> which reports that copies of iWork &#8216;09 pirated through bittorrent<br />
<a href="http://thepiratebay.org/torrent/4630952/WARNING_iWork.09_complete_with_iWorkServices_TROJAN">like this one</a> contains a trojan that &#8220;is installed as a startup item (in /System/Library/StartupItems/iWorkServices, a location reserved normally for Apple startup items), where it has read-write-execute permissions for root. The malicious software connects to a remote server over the Internet; this means that a malicious user will be alerted that this Trojan horse is installed on different Macs, and will have the ability to connect to them and perform various actions remotely. The Trojan horse may also download additional components to an infected Mac.&#8221;</p>
<p>It&#8217;s x86 disassembly code can be found <a href="http://rs470.rapidshare.com/files/188210597/iworkservices_x86.txt.zip">here</a>. (<a href="http://www.mediafire.com/?sharekey=32bf9e7b24b7d011ab1eab3e9fa335ca224c34f6740827f4">Alternate</a><a href="http://www.mediafire.com/?sharekey=32bf9e7b24b7d011ab1eab3e9fa335ca224c34f6740827f4"> download site</a>)</p>
<p>A variation of this virus was <a href="http://www.intego.com/news/ism0902.asp" target="_blank">also found</a> in pirated copies of Adobe Photoshop CS4. This version is called <strong>iServices.b</strong>.<br />
&#8230;Looks like it&#8217;s time for you to get Mac antiviral/security software; it&#8217;s coming.</p>
]]></content:encoded>
			<wfw:commentRss>http://wikinerd.net/2009/02/security-concerns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
