.
Feedback

How Computer Viruses Took a Bite Out of Apple

DNS Changer and Flashback show just how computer viruses have changed. You may have one and not know it.

It used to be computer viruses were simple. Your PC (never a Mac) became infected and, depending on the virus, your computer would die, would run slowly, or possibly open up gazillions of web pages every time you started your web browser. You knew when your computer was infected.

Now things are not so clear. Macs are no longer immune. Malware like Trojans or worms sneak in to a PC or Mac just by visiting a web page. Hundreds of thousands of infected computers, called botnets, are commanded to attack a web site in unison. Usernames and passwords are stolen.

Domain Name System (DNS) is hijacked, so that what should be a perfectly safe web address a user types in is redirected to a sketchy web neighborhood.

Two recent malware news stories making the rounds serve to illustrate and inform about this state of affairs: DNS Changer and Flashback.

DNS Changer

The first might be a good news story, except that because of an earlier infection hundreds of thousands of PC and Mac users could be in for a brutal surprise come July 9, when their Internet connections will stop functioning correctly because the FBI seemingly turned them off.

That's right, the FBI, which is in the business of running Domain Name Service computer servers -- but does not want to be. In November, a ring of six Estonian hackers known as Rove Digital was busted for infecting more than a half million computers worldwide with malware that surreptitiously redirected them to websites they ran, which had advertising that paid them for each ad impression.

DNS servers are the post office of the Internet. They take an address that users type in to their browsers or use to send an email and change it behind the scenes to a numerical address that computers can understand. So, for instance, the numerical address for Patch.com, known as an IP address, is 205.188.95.51. Typing that number into a browser will take a user to the same page as typing Patch.com.

The DNS Changer malware redirected users' computers to a network of DNS servers run by the hackers. Popular addresses, say, Google.com, would then be redirected to an IP address for the hackers' sites instead of the intended site. The FBI says the ring made at least $14 million on ad impressions this way.

When authorities took down the ring, the FBI faced a quandary. Removing the rogue DNS servers from service would mean that a half-million PCs would suddenly seem unable to access the Internet at all. In reality, the IP addresses would work, but who would know or want to type 205.188.95.51 instead of Patch.com?

"If we just pulled the plug on their criminal infrastructure and threw everybody in jail, the victims of this were going to be without Internet service," Tom Grasso, an FBI supervisory special agent, said in a statement. "The average user would open up Internet Explorer and get 'page not found' and think the Internet is broken."

So the FBI hired an Internet service provider to replace the rogue DNS servers with good ones. The agency plans to pull the plug on those servers July 9, so it's warning PC users to check their PCs. The good news is that it's as simple as visiting the DNS Changer Working Group website, www.dcwg.org, to find out whether a PC is infected and to remove DNS Changer if it is.

Flashback

Flashback exploits a hole in Java to install itself on Macs that visit compromised web pages. It is believed to have originated on Wordpress blogs, disguising itself as an automatic update for Adobe Flash. Just visiting a compromised blog page with a Mac was enough to become infected with this type of malware, which is known as a Trojan.

The original intent appeared to be to steal usernames and passwords, which then were sent on to bad-guy servers. Now the intent is not as clear. What is known is that an infected Mac will attempt to contact one of these servers daily, at a constantly changing URL, to receive instructions on what to do next.

Often these botnets are used in attacks on websites, by flooding a targeted site with tens of thousands of simultaneous and incessant requests for pages. The attack, known as a Distributed Denial of Service attack, or DDoS, typically overwhelms the site and makes it inaccessible.

The big surprise has been that Flashback has infected so many Macs, as many as 640,000 by one estimate, and that it occurred so easily on a platform that many had considered free of such trouble.

Flashback exploits a hole in Java. In fact the Trojan was first discovered last fall, and Oracle issued an update for Java that blocked it on Windows PCs. But Apple does not allow third parties to directly update Macs, and didn't distribute the patch itself until earlier this month when the extent of the infection on Macs began to be reported.

Apple's patch also removes the malware, and the extent of the infection had been thought to be decreasing. But security researchers last week detected a variant of Flashback that Apple's patch will not remove, and some believe the infection again is spreading.

What's clear in both Flashback and DNS Changer is the importance of keeping a computer, whether a PC or a Mac, up-to-date and protected with anti-virus software. It's also important to keep your data backed up in case something should go wrong.

Newsletter & Alerts

Get the best stories each day and important breaking news

Subscribe

Not from Imperial Beach Patch? Find your Local Patch »

Loading comments ...
Note Article
Just a short thought to get the word out quickly about anything in your neighborhood.
Share something with your neighbors. Write a new post... What's up? Make an announcement, speak your mind, or sell something
Pop Quiz May 22, 2013 at 07:20 pm
When the City council voted to give $30,000 of general fund money for a study of pedestrian lightingRead More (lit up palm trees) on Seacoast, not one Little League person showed up or spoke up. If you don't attend every meeting (except the secret ones) they do whatever the City Manager wants. The residents and kids are not a priority. Go to the meetings or live with the stupidity
Vincent Farnsworth May 22, 2013 at 11:56 am
We are going to lose our Sports Park, our free skate park and rec center, if we don't get active.Read More If you live in IB, get involved!
Kay Kardian-Porter May 21, 2013 at 08:43 am
When you pop shots of tequilla and a beer for a chaser several times and then get into your car andRead More drive you are endangering people. I do not believe it is an invasion of privacy its a lack of concern for his responsabilites and the community that he represents. On weekends its a standard practice for the couple to go bar hopping that is when they are not vacationing in carbo. I wonder if he gets DUI tickets? I doubt it!!
Khari Johnson (Editor) May 17, 2013 at 03:36 pm
He's on vacation.Read More http://imperialbeach.patch.com/groups/politics-and-elections/p/city-council-oks-30-million-budget-for-20132015
caesarina keri May 17, 2013 at 12:42 pm
Nope..he's a Public Figure...and as such must be accessible to us...and actually should be......asRead More it is he is unable to be found..never holds public hearings to give his assessment on what's happening with this Grand Jury thing or about anything. So I guess now we know where he is. Hey Mr Mayor, mind telling us what your hours at The Plank are so we might approach you about our concerns ....sounds like what we used to call in the Air Force a ROAD (Retired on Active Duty)
Ed Sorrels May 21, 2013 at 04:19 pm
Tammy, LOL The twelth of never !
Tammy Petersen Jenkins May 20, 2013 at 03:45 pm
New site looks great! Does anyone know if IB will have fireworks for 4th of July? And what isRead More latest completion date for hotel?
Marcus Boyd May 16, 2013 at 03:55 pm
And comment links no longer work... That's going cause less spam, and negatively effect SEO!
www.SouthBayDriveIn.com
Fayette (Davis) Driskell May 22, 2013 at 09:05 pm
Thank you for the MH info..I have started thinking about maybe moving back, its still just "aRead More thought", but I want to get ideas anyway..been many yrs since I have lived there, 47 yrs to be exact!! :)..was there in Sept-12 for our 50th, many chngs, but still like home..I didn't think abt CV pks..maybe I will ck thm out..again, thank you..have a safe Memorial Day...
Mary Vollrath May 22, 2013 at 10:40 am
The South Bay DI is on Coronado Ave. The Big Sky DI was at Main St and I 5. I actually live in aRead More mobile home park in Chula Vista on Orange Ave near 4th. There are many MH parks in the immediate area 2 in the 400 block of Orange and 3 in the 400 block of Anita St. All are senior parks. On Palm Ave there are 2 on the north side of Palm --the one on the curve to Coronado is now an RV park only
Fayette (Davis) Driskell May 21, 2013 at 08:57 pm
Oh, ok...I'm sorry..it was the one on Palm Ave. It's ok, I still hope it makes a great hit in theRead More community..the teens of IB need someplace to go that is safe for them..the memories I have as a teen growing up in IB in the 50-60's are awesome..thank you Mary, for the info..I do have a question for you tho..if you were a Senior citizen, living in a mobile home pk., which park would you suggest?..I remember 3, 2 across from each other on Palm, & the other on Palm up on the curve towards Coronado..they used to be nice, clean, & well run..thanks for your input...have a great Thurs..
G Beit-Ishoo May 22, 2013 at 01:56 pm
Just a suggestion for us old folks who can't see well. Please change your blue print to a darkerRead More blue so it's easier to read. And yes, I do wear glasses. Thank you.
Where in IB is this?
Marcus Boyd May 18, 2013 at 09:52 am
It's on the west side of the new American Legion building. At first glance it reminded me of myRead More last duty station, the USS Independence CV-62...
Marcus Boyd May 18, 2013 at 09:49 am
Nice! You obviously know your multi-unit building code...
Ed Kravitz May 17, 2013 at 07:42 am
OUTSIDE A BUILDING THAT HAS TWO HOT WATER HEATER OVERFLOW VALVES AND DISCHARGE LINES. PROBABLY ANRead More APARTMENT BUILDING OR OTHER MULTI-UNIT BUILDING?
Khari Johnson (Editor) May 15, 2013 at 04:33 pm
Thanks, Nancy. It's always nice to hear from you. The new site is easier to use but emailRead More khari.johnson@patch.com if you have any questions, need help or want to share a news tip.
Marcus Boyd May 16, 2013 at 02:05 pm
Then, yesterday - throughout the day - one client after another said they were pulled over forRead More everything from fix-it-tickets to scratching their head(accused of talking on a NON-EXISTENT CELL PHONE!!!)
Marcus Boyd May 16, 2013 at 02:03 pm
I agree, except what made me notice the motorcycle cops was one running a stop sign and me having toRead More slam on my brakes to avoid hitting him... Then he proceeded to run a stop light to pull someone over...
Marcus Boyd May 16, 2013 at 02:02 pm
@JohnGalt "Stopping at a Stop sign is usually a good idea."
Frank H. Robles May 15, 2013 at 06:51 pm
No southwest state is looking forward to the Fire Season, were all short of fire funding Funds...!!!
Ed Sorrels May 14, 2013 at 05:55 pm
Forcing the blame back on the court's for the release of these felon's will not solve the problemRead More tho, A workable answer is to de=criminalize all state marijuana laws and release all those convicted of marijuana except thos ewith a conviction for distributing over 10 Lbs. Then take all those with federal convictions and drop them off at a federal court for them to deal; with ! We can not afford to keep minor marijuana prisoners in state jails any longer. These tow actions would make all the room we need in outr state prisons !
Erika Lowery April 11, 2013 at 07:23 pm
Candy, Spriggs and Patton are supposed to be researching a Youth Advisory Committee (including aRead More name with a better acronym). Sign me up for a Youth committee. With 3 kids, from teen to toddler, I have a very vested interest in keeping activities for all ages. Plus Marc wants on. As a teen he can be a leader to younger kids - like he is in Coronado. It is just those of us who want to work for our city's betterment, seem to be shot down.
IB Candy '74 April 11, 2013 at 07:01 pm
I agree!
IB Candy '74 April 11, 2013 at 07:00 pm
Why can't the Sportspark offer the same type of programs that the YMCA does? I think it would beRead More great for the City to have have a Parks and Rec's Advisory Committee. The advisory committee could help the rec center establish some new programs and apply for the 1000's of grants available out there. Lets not forget about the over 800 people in IB who signed a petition and still want a dog park. What about the need for a park in the Oneonta area? A Parks and Rec's Advisory Board could help council with funding and also take some of the work load off of staff. This wouldn't cost the City a dime, sounds like a win-win to me. If the advisory board had some dedicated volunteers, they could establish themselves as a non-profit and apply for grants themselves and help the City pay for these projects. That would free up money in the general fund and allow us to keep our Sportspark, Skatepark and Little Leagues to ourselves. Out sourcing should be our last resort.
Dante Pamintuan April 26, 2013 at 12:18 pm
This is an encouraging effort to attract more families to Imperial Beach. Home ownership andRead More families in Imperial Beach is a positive step in the right direction for our wonderful little beach town. Thanks and kudos to all of the realtors and volunteers who are helping to make these dreams come true. The BEST is before us!