x404.co.uk
http://www.x404.co.uk/forum/

Apple hacked by same group as Facebook
http://www.x404.co.uk/forum/viewtopic.php?f=19&t=18396
Page 1 of 1

Author:  big_D [ Wed Feb 20, 2013 8:42 am ]
Post subject:  Apple hacked by same group as Facebook

Quote:
The same group of hackers that attacked Facebook last month also successfully attacked Apple, the company revealed today.

The Cupertino, Calif.-based technology giant told the Reuters news agency that while its networks were successfully breached, there was "no evidence that any data left Apple."

It's almost exactly the same wording used by Facebook last week when it disclosed it had also been hacked.

A small number of the company's employees Mac computers were hit by the hack, which exploited a vulnerability in the Java Web plug-in.


http://www.zdnet.com/apple-hacked-by-sa ... 000011509/

Apple wrote:
Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plug-in for browsers. The malware was employed in an attack against Apple and other companies, and was spread through a website for software developers. We identified a small number of systems within Apple that were infected and isolated them from our network. There is no evidence that any data left Apple. We are working closely with law enforcement to find the source of the malware.

Since OS X Lion, Macs have shipped without Java installed, and as an added security measure OS X automatically disables Java if it has been unused for 35 days. To protect Mac users that have installed Java, today we are releasing an updated Java malware removal tool that will check Mac systems and remove this malware if found.

Author:  jonbwfc [ Wed Feb 20, 2013 9:32 am ]
Post subject:  Re: Apple hacked by same group as Facebook

big_D wrote:
Quote:
The same group of hackers that attacked Facebook last month also successfully attacked Apple, the company revealed today.

The Cupertino, Calif.-based technology giant told the Reuters news agency that while its networks were successfully breached, there was "no evidence that any data left Apple."

It's almost exactly the same wording used by Facebook last week when it disclosed it had also been hacked.

A small number of the company's employees Mac computers were hit by the hack, which exploited a vulnerability in the Java Web plug-in.


http://www.zdnet.com/apple-hacked-by-sa ... 000011509/

Apple wrote:
Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plug-in for browsers. The malware was employed in an attack against Apple and other companies, and was spread through a website for software developers. We identified a small number of systems within Apple that were infected and isolated them from our network. There is no evidence that any data left Apple. We are working closely with law enforcement to find the source of the malware.

Since OS X Lion, Macs have shipped without Java installed, and as an added security measure OS X automatically disables Java if it has been unused for 35 days. To protect Mac users that have installed Java, today we are releasing an updated Java malware removal tool that will check Mac systems and remove this malware if found.

Haven't seen the tool show up in Software updates, which would be the obvious place to distribute it. I think I do have java installed too (MInecraft y'know). However I'm not sure how shipping a malware removal tool to their users helps with a malware infection that happened to their internal developers...

Author:  ProfessorF [ Wed Feb 20, 2013 9:45 am ]
Post subject:  Re: Apple hacked by same group as Facebook

Just checked Software Update, and there's a Java update available: http://support.apple.com/kb/HT5573?viewlocale=en_US&locale=en_US

Author:  big_D [ Wed Feb 20, 2013 11:23 am ]
Post subject:  Re: Apple hacked by same group as Facebook

jonbwfc wrote:
Haven't seen the tool show up in Software updates, which would be the obvious place to distribute it. I think I do have java installed too (MInecraft y'know). However I'm not sure how shipping a malware removal tool to their users helps with a malware infection that happened to their internal developers...

They say that it is the same malware that was used against Twitter and Facebook, as well as many other corporations.

The malware was hosted on an infected iOS developer resource website, so any iOS developer who visited the site with a Mac and who hadn't disabled Java could be infected.

Author:  JJW009 [ Wed Feb 20, 2013 2:06 pm ]
Post subject:  Re: Apple hacked by same group as Facebook

big_D wrote:
The malware was hosted on an infected iOS developer resource website, so any iOS developer who visited the site with a Mac and who hadn't disabled Java could be infected.

This site, apparently: http://iphonedevsdk.com/

Don't worry, I'm sure it's fixed now!

Author:  Amnesia10 [ Wed Feb 20, 2013 11:31 pm ]
Post subject:  Re: Apple hacked by same group as Facebook

JJW009 wrote:
big_D wrote:
The malware was hosted on an infected iOS developer resource website, so any iOS developer who visited the site with a Mac and who hadn't disabled Java could be infected.

This site, apparently: http://iphonedevsdk.com/

Don't worry, I'm sure it's fixed now!

You hope. :lol:

It looks like a very targeted attack.

Author:  jonbwfc [ Wed Feb 20, 2013 11:44 pm ]
Post subject:  Re: Apple hacked by same group as Facebook

It's not fixed. The web site holders aren't very tech savvy and only realised their site had been hacked when they heard about it in the press. Apparently they're now working with Facebook's system engineers to clean& harden their site.. Stay away for the forseeable.

Author:  Amnesia10 [ Thu Feb 21, 2013 12:08 am ]
Post subject:  Re: Apple hacked by same group as Facebook

jonbwfc wrote:
It's not fixed. The web site holders aren't very tech savvy and only realised their site had been hacked when they heard about it in the press. Apparently they're now working with Facebook's system engineers to clean& harden their site.. Stay away for the forseeable.

I do not have java enabled and probably not installed either. So like most end users are probably not at risk, but then they probably are not going to a developers site anyway.

Site is safe again.

Quote:
Ian Sefferman runs iPhoneDevSDK, a widely used forum for developers interested in the iOS platform and App Store. The site has 200,000 registered accounts, and unknown hackers commandeered a single admin account on the forum to gain access to the site’s code and inject a sophisticated JavaScript exploit. “As the most widely read dedicated iOS developer forum, we’re targeted for attacks frequently,” said Sefferman in a forum post. What’s interesting is that Apple never reached out to Sefferman about the hack before going public with the news yesterday.

Author:  pcernie [ Sat Feb 23, 2013 11:11 am ]
Post subject:  Re: Apple hacked by same group as Facebook

MS too

http://www.bbc.co.uk/news/technology-21556611

Author:  Amnesia10 [ Sat Feb 23, 2013 1:21 pm ]
Post subject:  Re: Apple hacked by same group as Facebook


Not unexpected. Though You would hope that they might be more security aware.

Page 1 of 1 All times are UTC
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/