<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>LindauerMacs Blog &#187; Security</title>
	<atom:link href="http://lindauermacs.com/wordpress/category/macintosh-information/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://lindauermacs.com/wordpress</link>
	<description>Macintosh News, Info, and tips</description>
	<lastBuildDate>Wed, 11 Jan 2012 18:05:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>DevilRobber Trojan disguised as PixelMator</title>
		<link>http://lindauermacs.com/wordpress/2011/11/17/devilrobber-trojan-disguised-as-pixelmator/</link>
		<comments>http://lindauermacs.com/wordpress/2011/11/17/devilrobber-trojan-disguised-as-pixelmator/#comments</comments>
		<pubDate>Thu, 17 Nov 2011 17:14:28 +0000</pubDate>
		<dc:creator>Charles Lindauer</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://lindauermacs.com/wordpress/?p=959</guid>
		<description><![CDATA[A new attempt to steal data from Mac users is a bot called DevilRobber. The original version ran embedded in versions of Graphic Converter, but this one only pretends to be PixelMator, and contains none of the legitimate PixelMator code. This new variant tries to steal and generate Bitcoins as the original did, but it [...]
Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/05/14/apple-security-center-malware-targets-macs/' rel='bookmark' title='&#8220;Apple Security Center&#8221; malware targets Macs'>&#8220;Apple Security Center&#8221; malware targets Macs</a> <small>When you&#8217;re using your web browser, whether it be Safari,...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/06/04/dismantling-the-trojan-horse-or-why-macguard-isn%e2%80%99t-a-concern/' rel='bookmark' title='Dismantling the Trojan Horse (or why MacGuard isn’t a concern)'>Dismantling the Trojan Horse (or why MacGuard isn’t a concern)</a> <small>The Other World Computing blog has a great post, with...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/06/01/new-security-update-provides-more-malware-protection-for-snow-leopard/' rel='bookmark' title='New Security Update provides more malware protection for Snow Leopard'>New Security Update provides more malware protection for Snow Leopard</a> <small>Security Update 2011-003 was released a couple of days ago...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p></p><p>A new attempt to steal data from Mac users is a bot called <a href="http://reviews.cnet.com/8301-13727_7-20128065-263/devilrobber-trojan-steals-bitcoins-and-data/?tag=mncol;txt">DevilRobber</a>. The original version ran embedded in versions of Graphic Converter, but this one only pretends to be PixelMator, and contains none of the legitimate PixelMator code.</p>
<p>This new variant tries to steal and generate Bitcoins as the original did, but it also tries to steal passwords from 1Password (my favorite password utility) and grab system log files and Terminal command history files.</p>
<p>MacFixit has a more complete post <a href="http://reviews.cnet.com/8301-13727_7-57326322-263/devilrobber-trojan-now-disguised-as-pixelmator/?tag=txt;title">here</a>. Please protect yourself by only downloading software from legitimate sources… this and the previous version of DevilRobber are distributed as pirated software. If you download software from reputable sites, such as Download.com or MacUpdate.com, or from the Mac App store, you won&#8217;t run the risk of being infected with this trojan.</p>
<p>If you&#8217;re concerned about malware on the Mac, I use and recommend <a href="http://www.intego.com/virusbarrier/">Intego Virusbarrier</a> and <a href="http://www.obdev.at/products/littlesnitch/index.html">Little Snitch</a> to protect yourself.</p>
<p>Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/05/14/apple-security-center-malware-targets-macs/' rel='bookmark' title='&#8220;Apple Security Center&#8221; malware targets Macs'>&#8220;Apple Security Center&#8221; malware targets Macs</a> <small>When you&#8217;re using your web browser, whether it be Safari,...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/06/04/dismantling-the-trojan-horse-or-why-macguard-isn%e2%80%99t-a-concern/' rel='bookmark' title='Dismantling the Trojan Horse (or why MacGuard isn’t a concern)'>Dismantling the Trojan Horse (or why MacGuard isn’t a concern)</a> <small>The Other World Computing blog has a great post, with...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/06/01/new-security-update-provides-more-malware-protection-for-snow-leopard/' rel='bookmark' title='New Security Update provides more malware protection for Snow Leopard'>New Security Update provides more malware protection for Snow Leopard</a> <small>Security Update 2011-003 was released a couple of days ago...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://lindauermacs.com/wordpress/2011/11/17/devilrobber-trojan-disguised-as-pixelmator/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iOS 4.3.5 released &#8211; Important security update</title>
		<link>http://lindauermacs.com/wordpress/2011/08/01/ios-4-3-5-released-important-security-update/</link>
		<comments>http://lindauermacs.com/wordpress/2011/08/01/ios-4-3-5-released-important-security-update/#comments</comments>
		<pubDate>Mon, 01 Aug 2011 17:10:37 +0000</pubDate>
		<dc:creator>Charles Lindauer</dc:creator>
				<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPod]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://lindauermacs.com/wordpress/?p=935</guid>
		<description><![CDATA[Apple patched a security vulnerability last week with the iOS 4.3.5 release. Certificate validation vulnerabilities were the issue, while 4.3.4 patched PDF vulnerabilities. 4.3.5 applies to the iPad and iPad2, iPod Touch (generation 3 and 4) and the iPhone 3GS and 4 (GSM). The Verizon iPHone4 will upgrade to iOS 4.2.10. I highly recommend all [...]
Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/06/01/new-security-update-provides-more-malware-protection-for-snow-leopard/' rel='bookmark' title='New Security Update provides more malware protection for Snow Leopard'>New Security Update provides more malware protection for Snow Leopard</a> <small>Security Update 2011-003 was released a couple of days ago...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/02/18/drupal-security-update-phishing-scam/' rel='bookmark' title='&#8220;Drupal Security Update&#8221; phishing scam'>&#8220;Drupal Security Update&#8221; phishing scam</a> <small>Emails are being received supposedly from Drupal Security drupal_s@yahoo.com as...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p></p><p>Apple patched a security vulnerability last week with the iOS 4.3.5 release. Certificate validation vulnerabilities were the issue, while 4.3.4 patched PDF vulnerabilities.</p>
<p>4.3.5 applies to the iPad and iPad2, iPod Touch (generation 3 and 4) and the iPhone 3GS and 4 (GSM). The Verizon iPHone4 will upgrade to iOS 4.2.10.</p>
<p>I highly recommend all security updates, and these can be done by connecting your device to your computer and opening iTunes. Check for updates and follow the prompts.</p>
<p>Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/06/01/new-security-update-provides-more-malware-protection-for-snow-leopard/' rel='bookmark' title='New Security Update provides more malware protection for Snow Leopard'>New Security Update provides more malware protection for Snow Leopard</a> <small>Security Update 2011-003 was released a couple of days ago...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/02/18/drupal-security-update-phishing-scam/' rel='bookmark' title='&#8220;Drupal Security Update&#8221; phishing scam'>&#8220;Drupal Security Update&#8221; phishing scam</a> <small>Emails are being received supposedly from Drupal Security drupal_s@yahoo.com as...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://lindauermacs.com/wordpress/2011/08/01/ios-4-3-5-released-important-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another phishing scheme&#8230; fake UPS email!</title>
		<link>http://lindauermacs.com/wordpress/2011/06/13/another-phishing-scheme-fake-ups-email/</link>
		<comments>http://lindauermacs.com/wordpress/2011/06/13/another-phishing-scheme-fake-ups-email/#comments</comments>
		<pubDate>Tue, 14 Jun 2011 00:15:11 +0000</pubDate>
		<dc:creator>Charles Lindauer</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://lindauermacs.com/wordpress/?p=910</guid>
		<description><![CDATA[Technolog has a story from June 9 about email purporting to be from UPS regarding an upcoming delivery, which contains a hidden attached file that can infect computers (PCs, ad far as I know) with malware that could put up a fake anti-virus warning. The idea is to get the user to spend $50 or [...]
Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/04/11/what-to-do-if-your-email-and-name-were-exposed/' rel='bookmark' title='What to do if your email and name were exposed?'>What to do if your email and name were exposed?</a> <small>Macworld&#8217;s Christopher Breen wrote an article last week with suggestions...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/04/26/virusbarrier-plus-available-at-the-mac-app-store/' rel='bookmark' title='VirusBarrier Plus available at the Mac App Store'>VirusBarrier Plus available at the Mac App Store</a> <small>Intego released a new product to scan both Mac and...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/25/apple-patch-against-macdefender-coming-soon/' rel='bookmark' title='Apple patch against MacDefender coming soon'>Apple patch against MacDefender coming soon</a> <small>Apple issued a support document last night stating that it...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p></p><p>Technolog has a story from June 9 about email purporting to be from UPS regarding an upcoming delivery, which contains a hidden attached file that can infect computers (PCs, ad far as I know) with malware that could put up a fake anti-virus warning. The idea is to get the user to spend $50 or $100 or whatever to get their computer secure.</p>
<p>It&#8217;s a scam. Firstly, if you&#8217;re a Mac user, it&#8217;s not likely that you&#8217;re going to get notifications about malware other than from the Mac OS X 10.6.7 (or later) operating system, or from anti-malware software apps you purchase and install.</p>
<p>UPS says that fraud and misrepresentation of it&#8217;s services are a &#8220;continuing global issue&#8221;. They post fraud protection and virus warnings on their <a href="http://www.ups.com/fraudprotection">site</a>.</p>
<p>UPS provides an address to forward suspicious email to: fraud@ups.com</p>
<p>Among the ways to tell if a UPS email is fraudulent, the company says:</p>
<ul>
<li>Design flaws: Distorted or irregularly sized logos</li>
<li>Poor grammar: Grammatical errors and excessive use of exclamation points</li>
<li>Misspellings: Not only incorrectly spelled words, but links to websites that may be modifications or variations of the legitimate www.ups.com website address such as www.unitedparcelservices.com</li>
<li>Sense of urgency: Alarming messaging requesting immediate action
</li>
<li>Unexpected requests: A request attempting to obtain money, financial information or pesonal information in exchange for the delivery of a package</li>
<li>Communication gaps: An e-mail that does not provide an alternative method for communicating the requested information (telephone, mail or physical locations).</li>
</ul>
<p>Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/04/11/what-to-do-if-your-email-and-name-were-exposed/' rel='bookmark' title='What to do if your email and name were exposed?'>What to do if your email and name were exposed?</a> <small>Macworld&#8217;s Christopher Breen wrote an article last week with suggestions...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/04/26/virusbarrier-plus-available-at-the-mac-app-store/' rel='bookmark' title='VirusBarrier Plus available at the Mac App Store'>VirusBarrier Plus available at the Mac App Store</a> <small>Intego released a new product to scan both Mac and...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/25/apple-patch-against-macdefender-coming-soon/' rel='bookmark' title='Apple patch against MacDefender coming soon'>Apple patch against MacDefender coming soon</a> <small>Apple issued a support document last night stating that it...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://lindauermacs.com/wordpress/2011/06/13/another-phishing-scheme-fake-ups-email/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Adobe to release Reader and Acrobat security patches tomorrow</title>
		<link>http://lindauermacs.com/wordpress/2011/06/13/adobe-to-release-reader-and-acrobat-security-patches-tomorrow/</link>
		<comments>http://lindauermacs.com/wordpress/2011/06/13/adobe-to-release-reader-and-acrobat-security-patches-tomorrow/#comments</comments>
		<pubDate>Mon, 13 Jun 2011 14:46:59 +0000</pubDate>
		<dc:creator>Charles Lindauer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://lindauermacs.com/wordpress/?p=904</guid>
		<description><![CDATA[A &#8220;pre-notification&#8221; from Adobe announced patches for &#8220;critical&#8221; security flaws in Adobe Acrobat and Adobe Reader for Mac and Windows. The updates are scheduled to be available tomorrow. Adobe is planning to release updates for Adobe Reader X (10.0.1) and earlier versions for Windows, Adobe Reader X (10.0.3) and earlier versions for Macintosh, and Adobe [...]
Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/06/01/new-security-update-provides-more-malware-protection-for-snow-leopard/' rel='bookmark' title='New Security Update provides more malware protection for Snow Leopard'>New Security Update provides more malware protection for Snow Leopard</a> <small>Security Update 2011-003 was released a couple of days ago...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p></p><p>A &#8220;pre-notification&#8221; from Adobe announced patches for &#8220;critical&#8221; security flaws in Adobe Acrobat and Adobe Reader for Mac and Windows. The updates are scheduled to be available tomorrow.</p>
<blockquote><p>Adobe is planning to release updates for Adobe Reader X (10.0.1) and earlier versions for Windows, Adobe Reader X (10.0.3) and earlier versions for Macintosh, and Adobe Acrobat X (10.0.3) and earlier versions for Windows and Macintosh to resolve critical security issues. Adobe expects to make these updates available on Tuesday, June 14, 2011. </p>
<p>Affected software versions </p>
<ul>
<li>Adobe Reader X (10.0.1) and earlier 10.x versions for Windows</li>
<li>Adobe Reader X (10.0.3) and earlier 10.x versions for Macintosh</li>
<li>Adobe Reader 9.4.3 and earlier 9.x versions for Windows and Macintosh </li>
<li>Adobe Reader 8.2.6 and earlier 8.x versions for Windows and Macintosh</li>
<li>Adobe Acrobat X (10.0.3) and earlier 10.x versions for Windows and Macintosh </li>
<li>Adobe Acrobat 9.4.3 and earlier 9.x versions for Windows and Macintosh </li>
<li>Adobe Acrobat 8.2.6 and earlier 8.x versions for Windows and Macintosh</li>
</ul>
</blockquote>
<p>Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/06/01/new-security-update-provides-more-malware-protection-for-snow-leopard/' rel='bookmark' title='New Security Update provides more malware protection for Snow Leopard'>New Security Update provides more malware protection for Snow Leopard</a> <small>Security Update 2011-003 was released a couple of days ago...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://lindauermacs.com/wordpress/2011/06/13/adobe-to-release-reader-and-acrobat-security-patches-tomorrow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gmail users may be at risk from a Flash bug</title>
		<link>http://lindauermacs.com/wordpress/2011/06/07/gmail-users-may-be-at-risk-from-a-flash-bug/</link>
		<comments>http://lindauermacs.com/wordpress/2011/06/07/gmail-users-may-be-at-risk-from-a-flash-bug/#comments</comments>
		<pubDate>Tue, 07 Jun 2011 19:28:43 +0000</pubDate>
		<dc:creator>Charles Lindauer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://lindauermacs.com/wordpress/?p=896</guid>
		<description><![CDATA[&#160;Yesterday (06/06/11) Adobe told the world that the Flash Player bug patched in a release the day before is a risk to Gmail users. Hackers have used it to steal login credentials, which would provide access to email and any other data stored in a Google account. The patch was an emergency fix, as this [...]
Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/04/11/what-to-do-if-your-email-and-name-were-exposed/' rel='bookmark' title='What to do if your email and name were exposed?'>What to do if your email and name were exposed?</a> <small>Macworld&#8217;s Christopher Breen wrote an article last week with suggestions...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/14/apple-security-center-malware-targets-macs/' rel='bookmark' title='&#8220;Apple Security Center&#8221; malware targets Macs'>&#8220;Apple Security Center&#8221; malware targets Macs</a> <small>When you&#8217;re using your web browser, whether it be Safari,...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p></p><p><img src="http://lindauermacs.com/wordpress/wp-content/uploads/2011/06/NewImage.png" alt="NewImage" border="0" width="65" height="65" style="float:left<br />
;" />&nbsp;Yesterday (06/06/11) Adobe told the world that the Flash Player bug patched in a release the day before is a risk to Gmail users. Hackers have used it to steal login credentials, which would provide access to email and any other data stored in a Google account.</p>
<p>The patch was an emergency fix, as this was potentially a disasterous vulnerability. This security hole IS being used by crooks who are targeting users by tricking them to click a link in an email message. So far it seems that the attack is on Gmail users specifically, but Adobe says that they are not sure if other Web mail services are at risk or not.</p>
<h4>Download the new Flash Player NOW!</h4>
<p>The <a href="http://www.google.com/chrome/intl/en/make/download-mac.html?brand=CHKZ">Chrome browser</a> was just updated Sunday, with a patched version of Flash built in. Adobe is providing the patch for other browsers <a href="http://get.adobe.com/flashplayer/">here</a>. </p>
<p>Don&#8217;t delay, download the patch immediately if you use webmail. Even if you don&#8217;t read your email in a web browser, download the patches, please!</p>
<p>Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/04/11/what-to-do-if-your-email-and-name-were-exposed/' rel='bookmark' title='What to do if your email and name were exposed?'>What to do if your email and name were exposed?</a> <small>Macworld&#8217;s Christopher Breen wrote an article last week with suggestions...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/14/apple-security-center-malware-targets-macs/' rel='bookmark' title='&#8220;Apple Security Center&#8221; malware targets Macs'>&#8220;Apple Security Center&#8221; malware targets Macs</a> <small>When you&#8217;re using your web browser, whether it be Safari,...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://lindauermacs.com/wordpress/2011/06/07/gmail-users-may-be-at-risk-from-a-flash-bug/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mac Defender, now Mac Guard &#8211; beware!</title>
		<link>http://lindauermacs.com/wordpress/2011/06/02/mac-defender-now-mac-guard-beware/</link>
		<comments>http://lindauermacs.com/wordpress/2011/06/02/mac-defender-now-mac-guard-beware/#comments</comments>
		<pubDate>Thu, 02 Jun 2011 17:52:06 +0000</pubDate>
		<dc:creator>Charles Lindauer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://lindauermacs.com/wordpress/?p=891</guid>
		<description><![CDATA[Apple released its security update to protect against MacDefender (or Mac Defender) trojan infection, but now there&#8217;s Mac Guard, which does not require a password to install. It shows up on web pages that pretend to scan for malware, and inform users that they must install software to clean their Mac. If the &#8220;Open safe [...]
Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/05/02/new-malware-threat-macdefender/' rel='bookmark' title='New Malware Threat &#8211; MACDefender'>New Malware Threat &#8211; MACDefender</a> <small>Intego posted an article early this morning with details of...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/14/apple-security-center-malware-targets-macs/' rel='bookmark' title='&#8220;Apple Security Center&#8221; malware targets Macs'>&#8220;Apple Security Center&#8221; malware targets Macs</a> <small>When you&#8217;re using your web browser, whether it be Safari,...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/03/crimekit-malware-threat/' rel='bookmark' title='Crimekit malware threat'>Crimekit malware threat</a> <small>The recent success reported by Apple in it&#8217;s first quarter...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p></p><p>Apple released its security update to protect against MacDefender (or Mac Defender) trojan infection, but now there&#8217;s Mac Guard, which does not require a password to install. </p>
<p>It shows up on web pages that pretend to scan for malware, and inform users that they must install software to clean their Mac.</p>
<p>If the &#8220;Open safe files&#8221; checkbox is checked in Safari or other browser&#8217;s preferences, Mac Guard will install and show phoney threat warnings, and will open porn sites on your browser.</p>
<p>The whole point of this malware is to get a user to provide credit card numbers to buy non-existant antivirus software.</p>
<p>It&#8217;s important to be aware of the threat of phishing emails and of web sites that supposedly scan and find virus or trojans on your Mac (or PC). These can be quite sophisticated, although they are sometimes absurdly crude. In any case, it&#8217;s easy to fall into the trap if we&#8217;re not well informed. I&#8217;ll continue to post on the subject as more info becomes available.</p>
<p>Be safe out there!</p>
<p>Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/05/02/new-malware-threat-macdefender/' rel='bookmark' title='New Malware Threat &#8211; MACDefender'>New Malware Threat &#8211; MACDefender</a> <small>Intego posted an article early this morning with details of...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/14/apple-security-center-malware-targets-macs/' rel='bookmark' title='&#8220;Apple Security Center&#8221; malware targets Macs'>&#8220;Apple Security Center&#8221; malware targets Macs</a> <small>When you&#8217;re using your web browser, whether it be Safari,...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/03/crimekit-malware-threat/' rel='bookmark' title='Crimekit malware threat'>Crimekit malware threat</a> <small>The recent success reported by Apple in it&#8217;s first quarter...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://lindauermacs.com/wordpress/2011/06/02/mac-defender-now-mac-guard-beware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Security Update provides more malware protection for Snow Leopard</title>
		<link>http://lindauermacs.com/wordpress/2011/06/01/new-security-update-provides-more-malware-protection-for-snow-leopard/</link>
		<comments>http://lindauermacs.com/wordpress/2011/06/01/new-security-update-provides-more-malware-protection-for-snow-leopard/#comments</comments>
		<pubDate>Wed, 01 Jun 2011 19:50:58 +0000</pubDate>
		<dc:creator>Charles Lindauer</dc:creator>
				<category><![CDATA[Apple News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Snow Leopard]]></category>

		<guid isPermaLink="false">http://lindauermacs.com/wordpress/?p=885</guid>
		<description><![CDATA[Security Update 2011-003 was released a couple of days ago to help protect against malware such as the Mac Defender trojan horse, and to help protect against future malware. Update! as of today (6/1/11), MacDefender developers have circumvented the detection ability of the current definitions. Browse carefully! More details on how the new security update [...]
Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/05/14/apple-security-center-malware-targets-macs/' rel='bookmark' title='&#8220;Apple Security Center&#8221; malware targets Macs'>&#8220;Apple Security Center&#8221; malware targets Macs</a> <small>When you&#8217;re using your web browser, whether it be Safari,...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/04/27/snow-leopard-font-bug-addressed/' rel='bookmark' title='Snow Leopard Font Bug addressed'>Snow Leopard Font Bug addressed</a> <small>Apple released an update to Mac OS X 10.6.7 to...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/03/crimekit-malware-threat/' rel='bookmark' title='Crimekit malware threat'>Crimekit malware threat</a> <small>The recent success reported by Apple in it&#8217;s first quarter...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p></p><p><a href="http://support.apple.com/kb/DL1387">Security Update 2011-003</a> was released a couple of days ago to help protect against malware such as the Mac Defender trojan horse, and to help protect against future malware.</p>
<p><strong>Update! as of today (6/1/11), MacDefender developers have circumvented the detection ability of the current definitions. Browse carefully!</strong></p>
<p>More details on how the new security update works can be found in a Macworld.com article found <a href="http://www.macworld.com/article/160191/2011/05/snow_leopard_malware_protection.html#lsrc.nl_mwnws_h_crawl">here</a>.</p>
<p>Snow Leopard has had built-in malware protection since the beginning, but it only had two definitions then, and only four more have been added until now. Apple&#8217;s beefed it&#8217;s built-in File Quarantine protection to detect the A and B variants of Mac Defender.</p>
<p>Daily definition updates are now possible, without users having to use Software Update to manually download them. Users can opt out by unchecking a box in the Security preference pane labeled &#8220;Automatically update safe downloads list&#8221;. I do NOT recommend doing this.</p>
<p>Snow Leopard can also remove the Mac Defender trojan if it&#8217;s found on your system. Apple says that the OS will look for the trojan, and if it&#8217;s found, SL will force it to quit, and will remove any persistent files. It will also fix any changes made to your system, and notify you of it&#8217;s removal.</p>
<p>The Mac Defender/Protector trojan is malicious and pernicious. (Those are fun words to use in the same sentence!). If you find yourself redirected to a site that looks like this, close the window immediately, and if you have your browser prefs are set to open &#8220;safe&#8221; files, follow Apple&#8217;s <a href="http://support.apple.com/kb/HT4650">instructions</a> for removing the malware that just installed itself, or tried to. Remember, a web site cannot scan your Mac for malware. It&#8217;s a scam, and a vicious one.</p>
<p><img src="http://lindauermacs.com/wordpress/wp-content/uploads/2011/06/Screen-shot-2011-06-01-at-11.49.jpg" alt="Screen shot 2011 06 01 at 11 49" border="0" width="600" height="515" style="float:right;" /></p>
<p>Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/05/14/apple-security-center-malware-targets-macs/' rel='bookmark' title='&#8220;Apple Security Center&#8221; malware targets Macs'>&#8220;Apple Security Center&#8221; malware targets Macs</a> <small>When you&#8217;re using your web browser, whether it be Safari,...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/04/27/snow-leopard-font-bug-addressed/' rel='bookmark' title='Snow Leopard Font Bug addressed'>Snow Leopard Font Bug addressed</a> <small>Apple released an update to Mac OS X 10.6.7 to...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/03/crimekit-malware-threat/' rel='bookmark' title='Crimekit malware threat'>Crimekit malware threat</a> <small>The recent success reported by Apple in it&#8217;s first quarter...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://lindauermacs.com/wordpress/2011/06/01/new-security-update-provides-more-malware-protection-for-snow-leopard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple patch against MacDefender coming soon</title>
		<link>http://lindauermacs.com/wordpress/2011/05/25/apple-patch-against-macdefender-coming-soon/</link>
		<comments>http://lindauermacs.com/wordpress/2011/05/25/apple-patch-against-macdefender-coming-soon/#comments</comments>
		<pubDate>Wed, 25 May 2011 15:53:31 +0000</pubDate>
		<dc:creator>Charles Lindauer</dc:creator>
				<category><![CDATA[Apple News]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://lindauermacs.com/wordpress/?p=880</guid>
		<description><![CDATA[Apple issued a support document last night stating that it was going to issue a patch that will prevent the MacDefender trojan from reaching our Macs. I expect the patch to be available in the next few days, so please check Software Update (click the Apple menu in the menu bar, it&#8217;s the second item) [...]
Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/05/02/new-malware-threat-macdefender/' rel='bookmark' title='New Malware Threat &#8211; MACDefender'>New Malware Threat &#8211; MACDefender</a> <small>Intego posted an article early this morning with details of...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/19/protect-yourself-from-macdefender/' rel='bookmark' title='Protect yourself from MacDefender'>Protect yourself from MacDefender</a> <small>There&#8217;s been a lot of noise on the &#8216;net about...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/14/apple-security-center-malware-targets-macs/' rel='bookmark' title='&#8220;Apple Security Center&#8221; malware targets Macs'>&#8220;Apple Security Center&#8221; malware targets Macs</a> <small>When you&#8217;re using your web browser, whether it be Safari,...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p></p><p>Apple issued a <a href="http://support.apple.com/kb/HT4650">support document</a> last night stating that it was going to issue a patch that will prevent the MacDefender trojan from reaching our Macs.</p>
<p>I expect the patch to be available in the next few days, so please check Software Update (click the Apple menu in the menu bar, it&#8217;s the second item) to download the patch as soon as it&#8217;s available.</p>
<p>The document also provides a simple method to remove MacDefender if you&#8217;ve inadvertently installed it, by opening Activity Monitor (in the Utilities folder, inside the Applications folder) and entering MacDefender in the search field. Then use the Quit Process button to quit each of the processes, then delete the app from your system and removing login items it created. It&#8217;s a fairly easy process.</p>
<p>Content of the <a href="http://support.apple.com/kb/HT4650">Apple Support document</a> follows:</p>
<blockquote><p>A recent phishing scam has targeted Mac users by redirecting them from legitimate websites to fake websites which tell them that their computer is infected with a virus. The user is then offered Mac Defender &quot;anti-virus&quot; software to solve the issue. </p>
<p>This &ldquo;anti-virus&rdquo; software is malware (i.e. malicious software).&nbsp; Its ultimate goal is to get the user&#8217;s credit card information which may be used for fraudulent purposes. </p>
<p>The most common names for this malware are MacDefender, MacProtector and MacSecurity.&nbsp; </p>
<p>In the coming days, Apple will deliver a Mac OS X software update that will automatically find and remove Mac Defender malware and its known variants.&nbsp; The update will also help protect users by providing an explicit warning if they download this malware.&nbsp; </p>
<p>In the meantime, the Resolution section below provides step-by-step instructions on how to avoid or manually remove this malware.</p>
<h2>Resolution</h2>
<p><u><strong>How to avoid installing this malware</strong></u></p>
<p>If any notifications about viruses or security software appear, quit Safari or any other browser that you are using. If a normal attempt at quitting the browser doesn&rsquo;t work, then <a href="http://support.apple.com/kb/ht3411">Force Quit</a> the browser.</p>
<p>In some cases, your browser may automatically download and launch the installer for this malicious software.&nbsp; If this happens, cancel the installation process; do not enter your administrator password.&nbsp; Delete the installer immediately using the steps below.</p>
<ol>
<li>Go into the Downloads folder or your preferred download location.</li>
<li>Drag the installer to the Trash.&nbsp;</li>
<li>Empty the Trash.</li>
</ol>
<p><u><strong>How to remove this malware</strong></u></p>
<p>If the malware has been installed, we recommend the following actions:</p>
<ul>
<li>Do not provide your credit card information under any circumstances.</li>
<li>Use the Removal Steps below.</li>
</ul>
<p><u><strong>Removal steps</strong></u></p>
<ul>
<li>Move or close the Scan Window</li>
<li>Go to the Utilities folder in the Applications folder and launch Activity Monitor &nbsp;</li>
<li>Choose All Processes from the pop up menu in the upper right corner of the window</li>
<li>Under the Process Name column, look for the name of the app and click to select it; common app names include: MacDefender, MacSecurity or MacProtector</li>
<li>Click the Quit Process button in the upper left corner of the window and select Quit</li>
<li>Quit Activity Monitor application</li>
<li>Open the Applications folder</li>
<li>Locate the app ex. MacDefender, MacSecurity, MacProtector or other name</li>
<li>Drag to Trash, and empty Trash</li>
</ul>
<p>Malware also installs a login item in your account in System Preferences. Removal of the login item is not necessary, but you can remove it by following the steps below.</p>
<ul>
<li>Open System Preferences, select Accounts, then Login Items</li>
<li>Select the name of the app you removed in the steps above ex. MacDefender, MacSecurity, MacProtector</li>
<li>Click the minus button</li>
</ul>
<p>Use the steps in the &ldquo;How to avoid installing this malware&rdquo; section above to remove the installer from the download location.</p>
<p><strong>Note:</strong> Apple provides security updates for the Mac exclusively through Software Update and the <a href="http://support.apple.com/downloads/">Apple Support Downloads</a> site. User should exercise caution any time they are asked to enter sensitive personal information online.<br />
&nbsp;</p>
</blockquote>
<p>Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/05/02/new-malware-threat-macdefender/' rel='bookmark' title='New Malware Threat &#8211; MACDefender'>New Malware Threat &#8211; MACDefender</a> <small>Intego posted an article early this morning with details of...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/19/protect-yourself-from-macdefender/' rel='bookmark' title='Protect yourself from MacDefender'>Protect yourself from MacDefender</a> <small>There&#8217;s been a lot of noise on the &#8216;net about...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/14/apple-security-center-malware-targets-macs/' rel='bookmark' title='&#8220;Apple Security Center&#8221; malware targets Macs'>&#8220;Apple Security Center&#8221; malware targets Macs</a> <small>When you&#8217;re using your web browser, whether it be Safari,...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://lindauermacs.com/wordpress/2011/05/25/apple-patch-against-macdefender-coming-soon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Apple Security Center&#8221; malware targets Macs</title>
		<link>http://lindauermacs.com/wordpress/2011/05/14/apple-security-center-malware-targets-macs/</link>
		<comments>http://lindauermacs.com/wordpress/2011/05/14/apple-security-center-malware-targets-macs/#comments</comments>
		<pubDate>Sat, 14 May 2011 16:33:01 +0000</pubDate>
		<dc:creator>Charles Lindauer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://lindauermacs.com/wordpress/?p=874</guid>
		<description><![CDATA[When you&#8217;re using your web browser, whether it be Safari, Firefox, Chrome or another browser, you may see an &#8220;alert&#8221; come up on your monitor warning you of a virus or other malware infection. You&#8217;re urged to download a virus protection application immediately. If you look closely, they almost always are Windows specific. They are [...]
Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/05/02/new-malware-threat-macdefender/' rel='bookmark' title='New Malware Threat &#8211; MACDefender'>New Malware Threat &#8211; MACDefender</a> <small>Intego posted an article early this morning with details of...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/04/26/virusbarrier-plus-available-at-the-mac-app-store/' rel='bookmark' title='VirusBarrier Plus available at the Mac App Store'>VirusBarrier Plus available at the Mac App Store</a> <small>Intego released a new product to scan both Mac and...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/09/malware-on-macs/' rel='bookmark' title='Malware on Macs?'>Malware on Macs?</a> <small>I&#8217;ve written more about malware and anti-virus software recently than...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p></p><p>When you&#8217;re using your web browser, whether it be Safari, Firefox, Chrome or another browser, you may see an &#8220;alert&#8221; come up on your monitor warning you of a virus or other malware infection. You&#8217;re urged to download a virus protection application immediately.</p>
<p>If you look closely, they almost always are Windows specific. They are also always hoaxes, intended to have you download software that will do something malicious&#8230; usually steal information so they can steal money, or to use your computer as a spam-bot, spewing spam emails out without your knowledge.</p>
<p>These slime-balls are now targeting Mac users, with attacks through a page titled &#8220;Apple security center&#8221; that seems to be running a scan of your Mac, and that will list files that are supposed to be infected&#8230; files that are not on your Mac at all.</p>
<p>Legitimate malware scanners on your Mac will not ask you to download or pay for upgrades to do it&#8217;s work. If you&#8217;re asked to provide passwords, or to click on a link to download a solution from a web page &#8211; don&#8217;t! A legit application (Not a web page!) may ask to have virus definitions updated, but will not ask for payment or your password.</p>
<h3>Reality Check!</h3>
<p>There is no way any web site can do a virus or malware scan over the Internet. Any site or page that says you are infected can be ignored, and if you&#8217;re concerned, download <a href="http://itunes.apple.com/us/app/virusbarrier-express/id411642093?mt=12">Intego VirusBarrier Express</a> (free, scans and deals with Mac malware only) or <a href="http://itunes.apple.com/us/app/virusbarrier-plus/id430337549?mt=12">Intego VirusBarrier Plus</a> to scan your Mac ($9.99) from the Mac App Store.</p>
<p>If you&#8217;re not using Mac OS X 10.6.4 or later, there are other options available, and you can contact me for more info.</p>
<h4>If it&#8217;s not a web page&#8230;</h4>
<p>If you see an alert dialogue box on your Mac, NOT on a web page, pay attention. It could come from a malware scanner you&#8217;ve installed. Kaspersky, for example, is available as a download from Comcast&#8230; Sophos, Intego, Norton all have malware scanners you may have installed. If so, pay attention!</p>
<p>If you&#8217;ve never installed any of these applications, the only other real possibility is that Apple&#8217;s XProtect, a rudimentary virus scanner that Apple provides can issue a warning if you try to open a file it finds suspicious.</p>
<h3>Are Macs at risk?</h3>
<p>OS X is not at risk (currently) from viruses and worms, but there are &#8220;trojan horse&#8221; risks. These require the user to actually install the malware, usually by clicking on a link to download something, more recently by clicking an image (<a href="http://lindauermacs.com/wordpress/2011/05/02/new-malware-threat-macdefender/">MacDefender</a>) which will download a file that can open and install bad stuff (the technical term) on your machine.</p>
<p>If you set browser preferences to NOT open &#8220;safe&#8221; files then you&#8217;ll be asked if you want to open any files downloaded. That way, should you click on one of these malicious links, and see an unexpected &#8220;do you want to open&#8230;&#8221; dialogue box, simply select &#8220;No&#8221;.</p>
<p>Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/05/02/new-malware-threat-macdefender/' rel='bookmark' title='New Malware Threat &#8211; MACDefender'>New Malware Threat &#8211; MACDefender</a> <small>Intego posted an article early this morning with details of...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/04/26/virusbarrier-plus-available-at-the-mac-app-store/' rel='bookmark' title='VirusBarrier Plus available at the Mac App Store'>VirusBarrier Plus available at the Mac App Store</a> <small>Intego released a new product to scan both Mac and...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/09/malware-on-macs/' rel='bookmark' title='Malware on Macs?'>Malware on Macs?</a> <small>I&#8217;ve written more about malware and anti-virus software recently than...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://lindauermacs.com/wordpress/2011/05/14/apple-security-center-malware-targets-macs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware on Macs?</title>
		<link>http://lindauermacs.com/wordpress/2011/05/09/malware-on-macs/</link>
		<comments>http://lindauermacs.com/wordpress/2011/05/09/malware-on-macs/#comments</comments>
		<pubDate>Mon, 09 May 2011 16:33:44 +0000</pubDate>
		<dc:creator>Charles Lindauer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://lindauermacs.com/wordpress/?p=868</guid>
		<description><![CDATA[I&#8217;ve written more about malware and anti-virus software recently than in the past 10 years. Partly it&#8217;s because I feel it necessary to keep my clients and readers up to speed with any potential threats&#8230; and partly because the popularity of the Mac platform in business has raised it&#8217;s profile dramatically. This popularity certainly increases [...]
Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/05/03/crimekit-malware-threat/' rel='bookmark' title='Crimekit malware threat'>Crimekit malware threat</a> <small>The recent success reported by Apple in it&#8217;s first quarter...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/02/new-malware-threat-macdefender/' rel='bookmark' title='New Malware Threat &#8211; MACDefender'>New Malware Threat &#8211; MACDefender</a> <small>Intego posted an article early this morning with details of...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p></p><p>I&#8217;ve written more about malware and anti-virus software recently than in the past 10 years. Partly it&#8217;s because I feel it necessary to keep my clients and readers up to speed with any potential threats&#8230; and partly because the popularity of the Mac platform in business has raised it&#8217;s profile dramatically. This popularity certainly increases the likelihood of increased attacks on Mac OS X installations.</p>
<p>Most current malware is directed at making money, rather than the malicious attacks of the past, where hackers just &#8220;wanted to have fun&#8221;. Now it&#8217;s criminals who want your money, or want to use your computer to send out advertising, etc.</p>
<p>Chron.com&#8217;s techblog has a <a href="http://blog.chron.com/techblog/2011/05/macs-malware-and-wolves-a-follow-up/">very good article</a> posted May 7, by Doug Silverman. Doug includes links and quotes from various sources to provide a very cogent picture of what the current threat level is, and where it may go in the future.</p>
<blockquote><p>The availability of a point-and-click software development kit for Mac malware – which goes for about $1,000 – is a new development&#8230; It uses the same malware engine driving many of the Windows rogue antispyware attacks, and uses the same techniques. These are effective because they exploit the biggest security flaw: Hapless users who agree to install the malware.</p></blockquote>
<p>Rather than rehash his work, I&#8217;d recommend anyone concerned about security on the Mac platform have a look.</p>
<p>Related posts:<ol>
<li><a href='http://lindauermacs.com/wordpress/2011/05/03/crimekit-malware-threat/' rel='bookmark' title='Crimekit malware threat'>Crimekit malware threat</a> <small>The recent success reported by Apple in it&#8217;s first quarter...</small></li>
<li><a href='http://lindauermacs.com/wordpress/2011/05/02/new-malware-threat-macdefender/' rel='bookmark' title='New Malware Threat &#8211; MACDefender'>New Malware Threat &#8211; MACDefender</a> <small>Intego posted an article early this morning with details of...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://lindauermacs.com/wordpress/2011/05/09/malware-on-macs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

