Reply to topic  [ 10 posts ] 
Apple hacked by same group as Facebook 
Author Message
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
Quote:
The same group of hackers that attacked Facebook last month also successfully attacked Apple, the company revealed today.

The Cupertino, Calif.-based technology giant told the Reuters news agency that while its networks were successfully breached, there was "no evidence that any data left Apple."

It's almost exactly the same wording used by Facebook last week when it disclosed it had also been hacked.

A small number of the company's employees Mac computers were hit by the hack, which exploited a vulnerability in the Java Web plug-in.


http://www.zdnet.com/apple-hacked-by-sa ... 000011509/

Apple wrote:
Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plug-in for browsers. The malware was employed in an attack against Apple and other companies, and was spread through a website for software developers. We identified a small number of systems within Apple that were infected and isolated them from our network. There is no evidence that any data left Apple. We are working closely with law enforcement to find the source of the malware.

Since OS X Lion, Macs have shipped without Java installed, and as an added security measure OS X automatically disables Java if it has been unused for 35 days. To protect Mac users that have installed Java, today we are releasing an updated Java malware removal tool that will check Mac systems and remove this malware if found.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Wed Feb 20, 2013 8:42 am
Profile ICQ
What's a life?
User avatar

Joined: Thu Apr 23, 2009 7:26 pm
Posts: 17040
Reply with quote
big_D wrote:
Quote:
The same group of hackers that attacked Facebook last month also successfully attacked Apple, the company revealed today.

The Cupertino, Calif.-based technology giant told the Reuters news agency that while its networks were successfully breached, there was "no evidence that any data left Apple."

It's almost exactly the same wording used by Facebook last week when it disclosed it had also been hacked.

A small number of the company's employees Mac computers were hit by the hack, which exploited a vulnerability in the Java Web plug-in.


http://www.zdnet.com/apple-hacked-by-sa ... 000011509/

Apple wrote:
Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plug-in for browsers. The malware was employed in an attack against Apple and other companies, and was spread through a website for software developers. We identified a small number of systems within Apple that were infected and isolated them from our network. There is no evidence that any data left Apple. We are working closely with law enforcement to find the source of the malware.

Since OS X Lion, Macs have shipped without Java installed, and as an added security measure OS X automatically disables Java if it has been unused for 35 days. To protect Mac users that have installed Java, today we are releasing an updated Java malware removal tool that will check Mac systems and remove this malware if found.

Haven't seen the tool show up in Software updates, which would be the obvious place to distribute it. I think I do have java installed too (MInecraft y'know). However I'm not sure how shipping a malware removal tool to their users helps with a malware infection that happened to their internal developers...


Wed Feb 20, 2013 9:32 am
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 7:56 pm
Posts: 12030
Reply with quote
Just checked Software Update, and there's a Java update available: http://support.apple.com/kb/HT5573?viewlocale=en_US&locale=en_US

_________________
www.alexsmall.co.uk

Charlie Brooker wrote:
Windows works for me. But I'd never recommend it to anybody else, ever.


Wed Feb 20, 2013 9:45 am
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
jonbwfc wrote:
Haven't seen the tool show up in Software updates, which would be the obvious place to distribute it. I think I do have java installed too (MInecraft y'know). However I'm not sure how shipping a malware removal tool to their users helps with a malware infection that happened to their internal developers...

They say that it is the same malware that was used against Twitter and Facebook, as well as many other corporations.

The malware was hosted on an infected iOS developer resource website, so any iOS developer who visited the site with a Mac and who hadn't disabled Java could be infected.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Wed Feb 20, 2013 11:23 am
Profile ICQ
I haven't seen my friends in so long
User avatar

Joined: Thu Apr 23, 2009 6:58 pm
Posts: 8767
Location: behind the sofa
Reply with quote
big_D wrote:
The malware was hosted on an infected iOS developer resource website, so any iOS developer who visited the site with a Mac and who hadn't disabled Java could be infected.

This site, apparently: http://iphonedevsdk.com/

Don't worry, I'm sure it's fixed now!

_________________
jonbwfc's law: "In any forum thread someone will, no matter what the subject, mention Firefly."

When you're feeling too silly for x404, youRwired.net


Wed Feb 20, 2013 2:06 pm
Profile WWW
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
JJW009 wrote:
big_D wrote:
The malware was hosted on an infected iOS developer resource website, so any iOS developer who visited the site with a Mac and who hadn't disabled Java could be infected.

This site, apparently: http://iphonedevsdk.com/

Don't worry, I'm sure it's fixed now!

You hope. :lol:

It looks like a very targeted attack.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Wed Feb 20, 2013 11:31 pm
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 7:26 pm
Posts: 17040
Reply with quote
It's not fixed. The web site holders aren't very tech savvy and only realised their site had been hacked when they heard about it in the press. Apparently they're now working with Facebook's system engineers to clean& harden their site.. Stay away for the forseeable.


Wed Feb 20, 2013 11:44 pm
Profile
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
jonbwfc wrote:
It's not fixed. The web site holders aren't very tech savvy and only realised their site had been hacked when they heard about it in the press. Apparently they're now working with Facebook's system engineers to clean& harden their site.. Stay away for the forseeable.

I do not have java enabled and probably not installed either. So like most end users are probably not at risk, but then they probably are not going to a developers site anyway.

Site is safe again.

Quote:
Ian Sefferman runs iPhoneDevSDK, a widely used forum for developers interested in the iOS platform and App Store. The site has 200,000 registered accounts, and unknown hackers commandeered a single admin account on the forum to gain access to the site’s code and inject a sophisticated JavaScript exploit. “As the most widely read dedicated iOS developer forum, we’re targeted for attacks frequently,” said Sefferman in a forum post. What’s interesting is that Apple never reached out to Sefferman about the hack before going public with the news yesterday.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Thu Feb 21, 2013 12:08 am
Profile
Legend

Joined: Sun Apr 26, 2009 12:30 pm
Posts: 45931
Location: Belfast
Reply with quote
MS too

http://www.bbc.co.uk/news/technology-21556611

_________________
Plain English advice on everything money, purchase and service related:

http://www.moneysavingexpert.com/


Sat Feb 23, 2013 11:11 am
Profile
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote

Not unexpected. Though You would hope that they might be more security aware.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Sat Feb 23, 2013 1:21 pm
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 10 posts ] 

Who is online

Users browsing this forum: No registered users and 13 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.