Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Safari 5.1 suddenly cannot connect to server when accessing Google?

I have always had my homepage set to www.google.co.uk but all of a sudden when I launch Safari 5.1 it's throwing up there error message 'Safari can't connect to the server', any ideas?

iMac 24" intel, Mac OS X (10.6.4)

Posted on Aug 7, 2011 3:27 AM

Reply
68 replies

Aug 9, 2011 1:52 PM in response to macboydesign

macboydesign wrote:


I uploaded the software then did a secure trash of it but didnt get the upload ID im afrai

It should be in your browser history. Just paste the url here and it will be easy for anybody interested to go there.


If you can't do that then perhaps you recall whether the exact name of the file was "FlashPlayer.pkg" or something else.

Aug 9, 2011 2:18 PM in response to macboydesign

macboydesign wrote:


Cant see it

It would look something like this one which was uploaded on 7/25 and matches the one that F-Secure says they found http://www.virustotal.com/file-scan/report.html?id=9469c1afe1a2031f082de610b026b 5ed46fbbdd51a23871935034fdcc4086f45-1311595973

I downloaded it on 22/07/11 however I only began to experience problems a few days ago, seems it takes a while to kick in. Still unsure as to why a hacker might want to hijack a users google access?

Yes you should have had Google issues as soon as you installed it. BTW, Adobe apparently updated Flash for real today.


Theory is that it's simply to provide advertisments of some sort. Since the fake site is still inactive it's really hard to say what they are up to. The use of a Flash update may give others some more agressive ideas, so it's always wise to make certain you're on Adobe's site when you download.

Aug 15, 2011 6:39 PM in response to macboydesign

http://www.f-secure.com/v-descs/trojan_bash_qhost_wb.shtml


Has the answer. Somehow a Trojan posing as a FLASH installer. (See Steve Jobs is right about Flash) modifies the /etc/hosts file. This file basically says Check ME as the DNS authority BEFORE you go to any DNS on the net and check for Google's legitimate address (74.125.113.106) .


As with ALL Macs, one had to install something (to give it Administrative rights) to actually allow changes to the /etc/hosts file. In other words one could NOT get this trojan by just visiting a web site or openning an email. At some point or another, a fake Flash installer showed up on your screen and said install? And asked for the Administrator's password. When the password was entered the deed was done.


Since this happenned to my daughter's computer, and I HAVE NO IDEA if anything else was modified, I am going to wipe the computer clean with a clean install of Snow Leopard. That will be the ONLY way to know that any other files modified are removed.


Sorry to bring you this bad news.

Aug 15, 2011 6:51 PM in response to gnew18

Yes, we discussed this last week. I am still looking for a sample of the installer packadpge to be uploaded to VirusTotal and clamav so that AV software can be programed to detect it on computers that have already installed it and Macs which are still running older systems that do not detect it. If the Trojan, probably called "Flashplayer.pkg" or the .zip file originally downloaded is still on her machine the community could greatly benefit from a copy.

Aug 18, 2011 6:13 PM in response to Benson Yeh

Benson Yeh wrote:


I found this thread after I found the solution. However, I have the website that I got the flash installer...

Thanks. We are aware of the site. It's the same one they used to show the fake Google pages and it's been down ever since.

I uploaded the file and uploaded the link. Not sure exactly which site linked this file, but I think it was an mp3 of america the beautiful that I was trying to listen to...

Sorry, I'm not clear on where you uploaded the file to. If you still have it can you obtain a mailbox from http://mailinator.com/, upload a copy to it and post the name of the mailbox here please.


If you uploaded it to virustotal.com, please provide the ID you were given. It should appear in the URL of the page where you were able to observe the results.

Aug 18, 2011 6:17 PM in response to Linc Davis

Linc Davis wrote:


Of course, merely detecting the trojan is not enough. Someone needs to analyze the installer package, and if necessary, install it on a tripwired system to see what it does. I will do that if someone sends a link to a Mailinator address and posts a notice in this thread.

Linc,


I found another possible this afternoon at why can I not connect to google pages? and repeated your appeal. You many want to track it.

Safari 5.1 suddenly cannot connect to server when accessing Google?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.