Zero-zuva rekushandisa rinowanikwa mu OS X 10.10 Yosemite iyo yaizobvumira malware kuiswa pasina kudikanwa kwepassword

Malware-zero-zuva-os x 10.10-0

Izvi zvinoshandisa zvakawanikwa nekambani yeMalwarebytes, imwe yeanonyanya kuzivikanwa maererano nekutsvagisa software yakaipa, inotaura mune chirevo icho yawana malware installer iyo yaizotora mukana weiyo nyowani yekukanganisa kutema maficha akaunzwa mune yazvino vhezheni ye OS X.

Kunyanya, iwe waizowana mvumo-yematanho mvumo nekugadzirisa iyo sudoers yekumisikidza faira yeMac iri mubvunzo, vachisiya isina kudzivirira uye yakavhurika kuisa adware senge VSearch, misiyano yeGenieo, uye MacKeeper.

Malware-zero-zuva-os x 10.10-1

Tinokusiira kuzivisa chaiko kweMalwarebyte pazasi:

Sezvauri kuona kubva kukodhi snippet inoratidzwa pano, iyo script inoputika iyo DYLD_PRINT_TO_FILE kushomeka iyo inonyorera kune iyo faira uye yozoiita. Chikamu chekushandurwa chinobviswa kana chapedza kunyora kune iyo faira.

Chikamu chakakosha chekushandurwa uku chiri mune yekudaira faira. Iyo script inoita shanduko iyo inobvumidza mirairo yeShell kuti iitwe semidzi uchishandisa Sudo, pasina chaicho chinodiwa chekupinda password.

Iwo script anobva ashandisa Sudo nyowani password isina maitiro kuvhura iyo VSInstaller application, inowanikwa mune yakavanda dhairekitori pane iyo inosimudza diski mufananidzo, ichichipa superuser mvumo uye nekudaro kugona kuisa chero chinhu chero kupi. (Ichi chishandiso chinotarisirwa kuiswa kweVSearch adware.)

Ars Technica yakatanga kutaurwa pamusoro peiyi bug yakawanikwa ne muongorori Stefan Esser svondo rapfuura, vachitaura kuti vagadziri vakatadza kushandisa zvakajairwa OS X zviga zvekuchengetedza ne dyld. Esser akati kushushikana kuripo muApple yazvino vhezheni yeOS X 10.10.4 uye mune dzichangoburwa beta vhezheni dzeOS X 10.10.5, isati yatove mu OS X 10.11.


Iva wekutanga kutaura

Siya yako yekutaura

Your kero e havazobvumirwi ichibudiswa. Raida minda anozivikanwa ne *

*

*

  1. Inotarisira iyo data: Miguel Ángel Gatón
  2. Chinangwa cheiyo data: Kudzora SPAM, manejimendi manejimendi.
  3. Legitimation: Kubvuma kwako
  4. Kutaurirana kwedata
  5. Dhata yekuchengetedza: Dhatabhesi inobatwa neOccentus Networks (EU)
  6. Kodzero: Panguva ipi neipi iwe unogona kudzora, kupora uye kudzima ruzivo rwako