internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Norton AntiVirus 2008

Most Popular Software Downloads
Ad-Aware 2008 Free
Windows XP Service Pack 3
Internet Explorer 7
QuickTime for Windows
Adobe Flash Player
AVG Anti-Virus Free
Paint Shop Pro
Windows Live Suite
CCleaner (Crap Cleaner)
Winamp

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

The Surge in Mac Attacks
Popularity Has Its Pitfalls
David Miller

Just as Apple Computer launched a new ad touting OS X's resilience against viruses, the Macintosh operating system and applications have come under fire for harboring serious security flaws.

Security software vendor McAfee, The SANS Institute and independent researchers have all recently published reports slamming Mac security.

It's a big switch for the computer company that has long enjoyed a reputation for creating software that's immune to the nastier aspects of "iLife."

Security vendor McAfee released a whitepaper on Friday on the state of Mac security.

According to McAfee, from 2003 to 2005 the annual rate of vulnerability discovery on Apple's Mac OS platform has increased by 228 percent, compared to Microsoft's products, which only saw a 73 percent increase.

That may be comparing Apples to oranges, but McAfee also noted that, "as demonstrated by its March 2006 patch, which corrected 20 vulnerabilities, Apple's Mac OS platform is just as vulnerable to targeted malware attacks as other operating systems."

On May 1 the SANS Institute, a computer-security organization, listed "rapid growth in critical vulnerabilities being discovered in Mac OS X" as the No. 1 concern on its list of the 20 most important threats in computer security.

The report went on to say "OS X still remains safer than Windows, but its reputation for offering a bulletproof alternative to Windows is in tatters."

A lot of people have been thinking of Apple as not having any vulnerabilities, said Rohit Dhamankar, editor of @RISK and the SANS Top 20, and manager of security research at 3Com.

"People generally think that if you don't see viruses or widespread malware that a computing platform is safe. However, you can still have vulnerabilities that people can exploit."

Apple was unavailable for comment on the McAfee and SANS reports.

In February, three exploits surfaced targeting Macs.

"Leap-A" was buried in jpeg images purporting to be screenshots of the next version of Mac OS X. Once active on a machine, the worm replicated by sending itself to names in the infected computer's iChat buddy list.

"OSX.Inqtana.A" was programmed to spread through a vulnerability in Bluetooth wireless technology.

Like many PC threats, both of those exploits turned out to be duds. But a third vulnerability reported in late February is potentially serious.

Apple's Safari Web browser allowed downloaded files to open as soon as the download is complete. If a file contained malicious programming commands, Macs could be tricked into running those commands.

In March, security researcher Tom Ferris blogged about a slew of "zero-day" vulnerabilities that he believes hackers are using to target OS X.

A zero-day vulnerability is a new security flaw that a software vendor is either unaware of or attempting to fix. An attacker who manages to develop a method to exploit such a flaw has a potent covert weapon, one that networks and IT staff cannot easily defend against.

Ferris told Apple about the flaws, some of which involve iTunes and QuickTime software, in early January.

Ferris thinks that the recent defacement of Apple's Korean online store was carried out by a hacker using a zero-day exploit that gave him administrator access to the server housing the Web site. Popularity Has Its Pitfalls

"Apple's products are now becoming more of a target of hackers because more people use OS X now," said Ferris. "Also the fact that Apple now has a commercial saying that OS X is virus-free is just asking for it.

"It kind of reminds me of when Oracle said their database was 'Unbreakable,' and within a week a researcher had released multiple flaws within their products."

Ferris said that many security researchers he knows have recently shifted gears and are now spending a significant amount of time looking for OS X flaws.

Increased scrutiny and a small spike in market share may dissolve the "security by obscurity" that some experts believe helped to shield Macs from hack attacks.

Apple is still generally regarded as more secure than PCs running Windows operating systems because OS X, like other Unix-based systems, will not usually run programs that will alter the operating system without explicit permission from the machine's system administrator.

Windows users typically operate their machines under the administrator account by default.

"Yes, the more OS X is discussed, the more likely there will be viruses, worms and so on. But the frequency and the damage from these will be, in my opinion, much less than on a comparable Windows platform," said Mike Sweeney, owner of Packet Attack, a security services company.

"OS X is more secure out of the box than Windows. OS X and Windows were designed in different ways," Sweeney said.

"Windows was designed for personal computers, before the broad public adoption of the Internet. OS X is based in part of BSD, which is one of the most secure Unix types of operating systems, and designed for use in a networked environment."

But Sweeney and others believe that Mac security could be compromised by users who are blissfully unaware of the threats that lurk online.

Apple users tend not to worry about whether they should or shouldn't open e-mail attachments or if they should click "OK" on dubious pop-ups. They trust their Macs.

"A prudent man always locks his doors no matter where he lives," said Sweeney. "Any operating system can be hacked. OS X is no different, so it is always better to take precautions."

Experts encourage Mac users to ensure they are up to date with Apple's security patches and to practice basic safe computing by following Apple's security tips.

News courtesy of internetnews.com

May 8, 2006

View All Anti-Malware Software

View All Anti-Virus Software

Contents:
1. Popularity Has Its Pitfalls






JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES