Ads by TechWords

See your link here
Receive the latest technology news and information.
Macintosh
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Apple adds basic anti-malware to Snow Leopard

New OS designed to sniff out a pair of Mac-specific Trojans

August 26, 2009 11:00 PM ET

Computerworld - Apple has expanded a download warning feature in Mac OS X 10.5 to create rudimentary anti-malware detection in the new Snow Leopard operating system due out Friday, sources have confirmed.

Out of the box, Snow Leopard will be able to detect only two Trojan horses, although Apple will be able to push other signatures to users through the Mac operating system's Software Update service, those sources said.

The confirmation came after reports that Snow Leopard had taken its predecessor's File Quarantine feature a step further, and actually scans files downloaded by Safari, Mail or iChat for malicious code. Where Leopard only warned users that a file had been obtained from the Internet -- and thus was potentially dangerous -- Snow Leopard scans files for possible malware.

According to a screenshot posted Monday by Mac-only antivirus maker Intego, Snow Leopard sniffs out the malware, then puts up a warning that recommends users dump the downloaded file in the Trash rather than open it.

Neither of the two Trojans -- dubbed "RSPlug.a" and "Iservice" by Symantec -- that Snow Leopard currently detects is new. The former was first spotted in October 2007, while the latter debuted in January.

RSPlug made news in late 2007 when security researchers found the malware on numerous pornographic Web sites; if downloaded to a Mac, the Trojan changes the machine's DNS (Domain Name System) settings to redirect users to alternate or spoofed sites. Iservice, on the other hand, was spotted earlier this year piggybacking on pirated copies of iWork '09, Apple's productivity suite, by users who had downloaded the software from file-sharing sites.

Several researchers and bloggers, including Computerworld's Seth Weintraub, spotted a new .plist file in Snow Leopard that the OS uses to store malware signatures. That file, "XProtect.plist," has been tucked into the "/System/Library/CoreServices/CoreTypes.bundle/Contents/Resources" folder.

Future signature updates will presumably be added to the XProtect.plist file.

Because Apple regularly bashes Microsoft over the flood of Trojans, worms and viruses that target Windows -- most recently in a new television ad -- its admission that malware affects Macs is a setback, albeit small, to its marketing, said one analyst.

"If Apple includes anti-malware, weak or strong, it does undermine Apple's marketing message, but only slightly," said Ezra Gottheil, an analyst with Technology Business Research. "Apple doesn't claim that Macs cannot be successfully attacked; it claims that they are not often successfully attacked, and that is true. So if adding basic anti-malware software helps keep Macs relatively clean, given their lower [attack] profile, that helps Apple's primary message: Macs are less hassle."

Snow Leopard goes on sale Friday, and requires an Intel-based Mac. People upgrading from Leopard can purchase a $29 single-license, or a $49 five-license Family Pack. Users running Mac OS X 10.4, aka Tiger, must instead purchase the more expensive Box Set, which costs $169 for a single license and $229 for a five-license pack. The Box Set also includes the iLife '09 creativity bundle and the iWork '09 productivity suite.

Read more about macintosh os in Computerworld's Macintosh OS Knowledge Center.



Jump to comments

Apple

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

The Workday User Experience Video
Watch Workday's Creative Director, Scott Lietzke, discuss the business-centered design philosophy at Workday.

Business Process Framework Demo
Learn about Configurable Business Processes and Calculated Fields. Watch Now!

Manager Experience Demo
Go beyond self-service solutions to perform more effectively. Watch Now.


IT Jobs