Тёмный

Amit Serper - OSX.Pirrit: The blue balls of mac Adware @ Layerone 2016 

Beats and Bits - Amit Serper
Подписаться 122
Просмотров 1,8 тыс.
50% 1

Not a lot was said about adware, especially not about adware for Mac. Adware is usually dismissed for being too benign and not interesting. After all - it just displays ads. But what if you were hit with an aggressive variant with malware-like features that has root access to your machine and has the ability to do what ever its creators wanted it to do?
A Mac OS X port of the Pirrit adware includes properties like hidden users, traffic redirection, persistence, and weird DGA-looking domains, all showing that an aggressive malvertiser is now targeting Macs. In the case of OSX.Pirrit, it uses simple social engineering to escalate its privileges and eventually take total control of your Mac. And with control of your machine, Pirrit’s creators could have done pretty much anything, like stolen your company’s secret sauce or installed a keylogger to capture the log-in credentials for your bank account. The creators of Pirrit were trying very hard to avoid being detected by antiviruses, personal firewalls and even from some advanced users.
In this talk, we’ll review OSX/Pirrit, dissect its methods and show it could have carried out much more sinister activities besides bombard a browser with ads.

Опубликовано:

 

5 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 5   
@silencioharris9427
@silencioharris9427 6 лет назад
Will you be posting your LayerOne 2018 talk from last month soon?
@amit_serper
@amit_serper 6 лет назад
Silencio Harris I don't have the files from layer one, however I gave the same talk at baides charm ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-tM5DYMY8Qjk.html
@silencioharris9427
@silencioharris9427 6 лет назад
Thanks
@pberson
@pberson 7 лет назад
Nice talk, every platform is susceptible to attacks, Windows is just a larger attack surface as you know. I was surprised a bit at package manager allow pre scripts to run. I guess it is the same as dpkg (Debain/Ubuntu) which also has pre/post scripts in their package manager.
@amit_serper
@amit_serper 7 лет назад
Peter Berson hey, thanks! yeah, it's pretty much the same. I ended up discovering who was behind this. I will be speaking about it in RSA conference
Далее
How are holograms possible? | Optics puzzles 5
46:24
Просмотров 206 тыс.
Cracking Enigma in 2021 - Computerphile
21:20
Просмотров 2,5 млн
CrowdStrike IT Outage Explained by a Windows Developer
13:40
The Tragic Fall Of µTorrent
24:42
Просмотров 2,5 млн
Linux is a MAJOR Rabbit Hole
36:40
Просмотров 669 тыс.
When you Accidentally Compromise every CPU on Earth
15:59