MAAS History
Archives
« Flash Player, Adobe Reader and Acrobat Vulnerability Exploited in Wild | Main | Adobe Photoshop CS4 Security Update »
Tuesday
Jun012010

OSX/OpinionSpy Discovered by Intergo

Intego, which makes a host of excellent Mac security products, is reporting the discovery of spyware named OSX/OpinionSpy which installs with a host of freely available Mac screensavers and software. The spyware reports back various machine, user and file information after executing with root privileges. It leaves the system open to a host of malicious operations including executing code at root privileges without the users knowledge and maintaining a back door using port 8254, 80 and 443. 

Users should update their Intego virus definitions. Users can also do a search for "PremierOpinion" which is what the spyware is installed updater. Intego has updated a list of products that contain the spyware software which can be viewed here. Port scanning information for 8254 can be found here.

There is never any reason to install any screensavers or survey software since usually the terms allow the vendor access to private information. It is important to remember that Mac OSX has a built in screen saver for user to use. In  addition the screen saver should lock idle system at the very least, users/administrators should set the following in the Security Preference Setting Panel:

 

  • Require Password Immediately after screen saver begins
  • User secure virtual memory

Users/Administrators should set an automatic log out time and lock access to Prefernce Panes.

 

PrintView Printer Friendly Version

EmailEmail Article to Friend

References (2)

References allow you to track sources for this article, as well as articles that were written in response to this article.

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.
Member Account Required
You must have a member account on this website in order to post comments. Log in to your account to enable posting.