Currently Being ModeratedApr 5, 2012 12:37 PM (in response to Irisflo)
If you think you are alrready infected, try this site:
The protection afainst Trojan Horse malware is not to use an Admin account for daily ise, and doenload updates only from trusted site. Flash comes from adobe.com, nowhere else.Mac Pro (Early 2009), Mac OS X (10.6.8), & Server, PPC, & AppleTalk Printers
Currently Being ModeratedApr 5, 2012 12:54 PM (in response to Irisflo)
You can disable in the browser you are using and/or more globally using the Java Preferences too (in Utilities), General tab (uncheck the checkboxes).
If it turns out you need it for some specific application or web site that you trust then turn it on only when running that application or visiting that site.
Flashback is a moving target with lots of strains (various versions, permutations) and changing all the time. So who knows what's next?
Incidentally, it is not "Adobe Flashback". Just Flashback. It got the name because one of the original strains of this trojan came from bogus versions of the Adobe Flash installer. The current strains are way beyond that now and have nothing to do with the flash installer.
Currently Being ModeratedApr 5, 2012 12:55 PM (in response to Grant Bennet-Alder)
Clever, nasty, little bug, isn't it?
Currently Being ModeratedApr 5, 2012 1:31 PM (in response to The hatter)
Security hole exposes Android, iOS to Facebook identity theft
Summary: A new security vulnerability discovered in Facebook for Android and Facebook for iOS means your Facebook identity can be stolen if you use an Android phone, Android tablet, iPhone, and/or iPad.
Wright detailed the issue in a blog post titled “Facebook Mobile Security Hole allows Identity theft.” He explained that all a hacker needs is to grab your Facebook plist file (.plist is the extension used for a property list file, often used to store a user’s settings), which Facebook reportedly sets not to expire for another 2,000 years.
Here’s what happened when Wright sent his .plist over to his friend and blogger, Scoopz:
After backing up his own plist and logging out of Facebook he copied mine over to his device and opened the Facebook app…
My jaw dropped as over the next few minutes I watched posts appear on my wall, private messages sent, webpages liked and applications added.
Scoopz then opened Draw Something on his iPad which logged him straight into my account where he sent some pictures back to my friends.
In his post, Wright outlined five proof of concepts for the attack:
iPod touch, iOS 5, Windows 8 Preview x64 3.2GHz
- A hidden application which runs on shared PC’s Any device plugged in to charge has the Plist copied.
- A recompile of an open source iphone explorer like program with the added code.
- A saved game editing tool with the added code.
- A credit card sized hardware solution that takes all of two seconds to copy the plist should you have physical access to an iDevice.
- A modified speaker dock.
Currently Being ModeratedApr 5, 2012 1:39 PM (in response to X423424X)
If you do need to run Java, be sure that you pick up the Java Software Update 7 posted recently that takes 10.6 and 10.7 up to Java SE 6 revision 31Mac Pro (Early 2009), Mac OS X (10.6.8), & Server, PPC, & AppleTalk Printers
Currently Being ModeratedApr 5, 2012 2:04 PM (in response to Grant Bennet-Alder)
Are you suggesting I add that in the future versions of that reply?
Currently Being ModeratedApr 5, 2012 3:49 PM (in response to X423424X)
That update, made available in the last few days, seems to plug the current vulnerability, but maybe not future ones.
Some programs demand Java to run, especially Adobe Creative Suite, so it may not be optional for some users.
So yes, if you are building a "standard reply", I think that should be added.Mac Pro (Early 2009), Mac OS X (10.6.8), & Server, PPC, & AppleTalk Printers
Currently Being ModeratedApr 6, 2012 9:03 AM (in response to Irisflo)