Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Community Lounge > Wibble
FedoraForum Search

Forgot Password? Join Us!

Wibble A place to have a sensible chat, about anything non linux related. Please remember that political and religious topics are not permitted.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 29th August 2012, 08:40 PM
billybob linux Offline
Registered User
 
Join Date: Sep 2011
Posts: 337
linuxfirefox
FIRST ever' Linux, Mac OS X-only password sniffing Trojan spotted

http://www.theregister.co.uk/2012/08...ux_mac_trojan/

Quote:
The program also grabs passwords submitted to Opera, Firefox, Chrome and Chromium web browsers, and credentials stored by applications including email client Thunderbird, web suite SeaMonkey, and chat app Pidgin. The malware then attempts to upload the gathered data to a server hosted in the Netherlands.
Just a heads up on this, but it sounds nasty
Reply With Quote
  #2  
Old 29th August 2012, 09:11 PM
GoinEasy9's Avatar
GoinEasy9 Online
Registered User
 
Join Date: May 2009
Location: Manorville, New York, USA
Posts: 1,581
linuxfirefox
Re: FIRST ever' Linux, Mac OS X-only password sniffing Trojan spotted

It only says "Once installed on a compromised machine". So, it's FUD until they explain how it gets installed.
__________________
Registered Linux User #348347
Have you been seduced by siduction? http://siduction.org/index.php
Running Fedora 17/18, siduction and openSUSE Tumbleweed with KDE
Reply With Quote
  #3  
Old 29th August 2012, 10:47 PM
Dutchy Offline
Registered User
 
Join Date: Aug 2011
Posts: 697
linuxfirefox
Re: FIRST ever' Linux, Mac OS X-only password sniffing Trojan spotted

Go Netherlands woohoo!
But seriously, it is unfortunate that it isn't yet clear how it spreads but I guess that it theoretically could be a payload of the current Windows/Mac OSx/Linux Java vulnerebility
Quote:
Oracle Java Runtime Environment (JRE) 1.7 contains a vulnerability that may allow an applet to call setSecurityManager in a way that allows setting of arbitrary permissions.
Let's hope a patched OpenJDK hits the repos soon, till then it is best to disable any java plugins.
Reply With Quote
  #4  
Old 29th August 2012, 11:17 PM
bigflopper2's Avatar
bigflopper2 Offline
Registered User
 
Join Date: Dec 2011
Posts: 213
linuxfirefox
Re: FIRST ever' Linux, Mac OS X-only password sniffing Trojan spotted

Never rly had a look at the installed firefox-plugins, only addons

I just have the following plugins on firefox installed:
divx webplayer (necessary?)
IcedTea-web-plugin (executes java applets) (THIS should be disabled, I guess)
itunes application detector (pfff, delete that one)
quick-time
shockwave-flash
vlc multimedia plugin (comp. totem)
windows media player plugin 10 (compatible totem)

There might be a couple of plugins I can delete I guess?
Reply With Quote
  #5  
Old 30th August 2012, 12:45 AM
BBQdave's Avatar
BBQdave Offline
Gnome-gasmic by choice!
 
Join Date: Aug 2011
Location: North Carolina
Age: 45
Posts: 1,052
linuxfirefox
Re: FIRST ever' Linux, Mac OS X-only password sniffing Trojan spotted

Quote:
Originally Posted by billybob linux View Post
Once installed on a compromised machine, Wirenet-1 opens a backdoor to a remote command server, and logs key presses to capture passwords and sensitive information typed by victims.

So going on this little bit of information, one needs to first install this piece of crapware to be compromised

Why would you install it? And it's not in the Repos right?
__________________
On quest for blue smoke and red rings...
Reply With Quote
  #6  
Old 30th August 2012, 08:05 AM
bigflopper2's Avatar
bigflopper2 Offline
Registered User
 
Join Date: Dec 2011
Posts: 213
linuxfirefox
Re: FIRST ever' Linux, Mac OS X-only password sniffing Trojan spotted

Quote:
Originally Posted by BBQdave View Post
So going on this little bit of information, one needs to first install this piece of crapware to be compromised

Why would you install it? And it's not in the Repos right?

Yup, thought so. Like GoinEasy9 said, it's FUD.



Quote:
Originally Posted by Dutchy View Post
Let's hope a patched OpenJDK hits the repos soon, till then it is best to disable any java plugins.
Update today:

Quote:
java-1.7.0-openjdk x86_64 1:1.7.0.6-2.3.fc17.2
Reply With Quote
  #7  
Old 30th August 2012, 06:35 PM
billybob linux Offline
Registered User
 
Join Date: Sep 2011
Posts: 337
linuxfirefox
Re: FIRST ever' Linux, Mac OS X-only password sniffing Trojan spotted

Quote:
Yup, thought so. Like GoinEasy9 said, it's FUD.


Yes it could be FUD but .I have done a little bit of research on it and it is being reported in quite a few Russian tech journals (as Backdoor wirenet1). But they are not saying anything new , apart from one that is. With the wonders of Google Translate i found this:

http://open-club.net/

They have a short article about it :
Quote:
Из приложений, в которые троянское ПО способно внедрятся и перехватывать пароли отмечаются Opera, Firefox, Chrome, Chromium, Thunderbird, SeaMonkey и Pidgin (подробности не сообщаются, но, судя по всему, троян внедряется под видом плагина). При активации вредоносное ПО размещает свою копию в поддиректории WIFIADAPT в домашнем каталоге пользователя (в Mac OS X - WIFIADAPT.app.app). Для передачи перехваченных паролей BackDoor.Wirenet.1 использует сетевое соединение с удаленным командным центром, которое шифруется с использованием стандарта AES. Механизм распространения троянского ПО пока находится на стадии изучения и не афишируется
Translated as:


Quote:
Of applications that are able to implement the Trojan software and intercept passwords marked Opera, Firefox, Chrome, Chromium, Thunderbird, SeaMonkey, and Pidgin (details were not disclosed, but, apparently, the Trojan is being introduced under the guise of the plugin). When activated malware places his copy WIFIADAPT subdirectory in your home directory (in Mac OS X - WIFIADAPT.app.app). To transmit the intercepted passwords BackDoor.Wirenet.1 uses a network connection to a remote command center, which is encrypted using standard AES. Trojan software distribution mechanism is still under study and is not advertised
They use the word "plugin" now I don't know if that's a translation issue, or a known fact or an assumption, or a wild guess, however as it is still "under study" who knows ? But that's what I found so far .

Last edited by billybob linux; 30th August 2012 at 06:45 PM.
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Cross-platform Trojan attacks Windows, Intel Macs, Linux pete_1967 Security and Privacy 26 2nd August 2012 05:29 PM
Android users hit by new trojan(again). Worst linux out there? birdwatcher Reviews, Rants & Things That Make You Scream 2 30th January 2012 10:35 AM
Spyware, Adware, Trojan Scanner Recommendation for Linux? dealmaker Using Fedora 2 16th October 2005 11:24 AM
UFO spotted in mexico ewdi Wibble 10 13th May 2004 05:06 PM
wireless sniffing tools ewdi Servers & Networking 3 21st February 2004 04:22 AM


Current GMT-time: 17:05 (Friday, 24-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat