Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Ramokgopa bullish on energy outlook as new projects get green light - Kgosientsho Ramokgopa

      Ramokgopa bullish on energy outlook as new projects get green light

      15 December 2025
      Wiocc lands R1.1-billion in debt funding for data centre, fibre expansion - Chris Wood

      Wiocc lands R1.1-billion in debt funding for data centre, fibre expansion

      15 December 2025
      Rand hits strongest level in three years

      Rand hits its strongest level in three years

      15 December 2025
      Presidency backs Solly Malatsi in BEE reform fight - Cyril Ramaphosa

      Presidency backs Solly Malatsi in BEE reform fight

      15 December 2025
      ICT BEE fight deepens as MK, EFF target Malatsi - Colleen Makhubele

      ICT BEE fight deepens as MK, EFF target Malatsi

      15 December 2025
    • World
      Oracle’s AI ambitions face scrutiny on earnings miss

      Oracle’s AI ambitions face scrutiny on earnings miss

      11 December 2025
      China will get Nvidia H200 chips - but not without paying Washington first

      China will get Nvidia H200 chips – but not without paying Washington first

      9 December 2025
      IBM reportedly close to $11-billion deal to buy Confluent - Arvind Krishna

      IBM reportedly close to $11-billion deal to buy Confluent

      8 December 2025
      Amazon and Google launch multi-cloud service for faster connectivity

      Amazon and Google launch multi-cloud service for faster connectivity

      1 December 2025
      Google makes final court plea to stop US breakup

      Google makes final court plea to stop US breakup

      21 November 2025
    • In-depth
      Black Friday goes digital in South Africa as online spending surges to record high

      Black Friday goes digital in South Africa as online spending surges to record high

      4 December 2025
      Canal+ plays hardball - and DStv viewers feel the pain

      Canal+ plays hardball – and DStv viewers feel the pain

      3 December 2025
      Jensen Huang Nvidia

      So, will China really win the AI race?

      14 November 2025
      Valve's Linux console takes aim at Microsoft's gaming empire

      Valve’s Linux console takes aim at Microsoft’s gaming empire

      13 November 2025
      iOCO's extraordinary comeback plan - Rhys Summerton

      iOCO’s extraordinary comeback plan

      28 October 2025
    • TCS
      TCS+ | Africa's digital transformation - unlocking AI through cloud and culture - Cliff de Wit Accelera Digital Group

      TCS+ | Cloud without culture won’t deliver AI: Accelera’s Cliff de Wit

      12 December 2025
      TCS+ | How Cloud on Demand helps partners thrive in the AWS ecosystem - Odwa Ndyaluvane and Xenia Rhode

      TCS+ | How Cloud On Demand helps partners thrive in the AWS ecosystem

      4 December 2025
      TCS | MTN Group CEO Ralph Mupita on competition, AI and the future of mobile

      TCS | Ralph Mupita on competition, AI and the future of mobile

      28 November 2025
      TCS | Dominic Cull on fixing South Africa's ICT policy bottlenecks

      TCS | Dominic Cull on fixing South Africa’s ICT policy bottlenecks

      21 November 2025
      TCS | BMW CEO Peter van Binsbergen on the future of South Africa's automotive industry

      TCS | BMW CEO Peter van Binsbergen on the future of South Africa’s automotive industry

      6 November 2025
    • Opinion
      Netflix, Warner Bros deal raises fresh headaches for MultiChoice - Duncan McLeod

      Netflix, Warner Bros deal raises fresh headaches for MultiChoice

      5 December 2025
      BIN scans, DDoS and the next cybercrime wave hitting South Africa's banks - Entersekt Gerhard Oosthuizen

      BIN scans, DDoS and the next cybercrime wave hitting South Africa’s banks

      3 December 2025
      Your data, your hardware: the DIY AI revolution is coming - Duncan McLeod

      Your data, your hardware: the DIY AI revolution is coming

      20 November 2025
      Zero Carbon Charge founder Joubert Roux

      The energy revolution South Africa can’t afford to miss

      20 November 2025
      It's time for a new approach to government IT spend in South Africa - Richard Firth

      It’s time for a new approach to government IT spend in South Africa

      19 November 2025
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CambriLearn
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • LSD Open
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Top » A worm in the Apple

    A worm in the Apple

    By Editor17 April 2012
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    A common dig at Apple-desktop users is that they are delusional about its operating system’s resistance to viruses, worms and other malware.

    Your correspondent has been a Mac owner since 1985, and has lived through the original waves of viruses and worms, which targeted the Mac long before Windows. He and many other IT wonks have been anticipating a major exploit for some time. That day arrived at last in the form of a malicious bit of software which affected one in 100 Macintoshes running the vulnerable software, according to Dr Web and several other security firms. That is equivalent to more than 600 000 users. (By 11 April, the number had dropped below 300 000.)

    The Flashback malware, which in its present form can extract passwords and other information from the Safari browser, first appeared in 2011 in the form of a Trojan horse, or a piece of software that alleges to be benign, but masks malice. Flashback got its name because it mimicked an Adobe Flash installer, even though the malware had nothing to do with Flash. In its early form, users had to download, and then run the installer software and enter a password in order to proceed. Precise numbers of those hoodwinked this way are unknown.

    Flashback’s developers subsequently created a nastier mutation, capable of so-called “drive-by” attacks. Now a user merely needed to visit a malicious Web page — no one seems sure which ones — and the malware was installed automatically. The new version used Web-page scripts to exploit a flaw in Apple’s version of Java that allowed the malware to install itself in the system.

    Apple has eschewed Java in its mobile devices. Its current Mac operating system release 10.7, dubbed Lion, also is none too keen on it. Lion comes with neither Java (nor Adobe Flash) preinstalled. The first time a user needs Java, the system offers to download and activate the software. Thus, the virus was only able to penetrate users of the previous release, 10.6 (Snow Leopard), or any Lion users with Java purposely installed.

    The particular flaw in Java that the malware exploited was known to Oracle, which acquired Java together with its orginal developer, Sun Microsystems, in 2009. Oracle patched the bug two months ago on every platform that it supports, either mobile or desktop, including Windows. But this did not extend to Apple, which used to build its own version of Java. In late 2010, Apple agreed to let Oracle do most of the work. But it still needs to tweak whatever Oracle provides in order to ensure it works in Mac OS X.

    In this case, Apple did not release the update with critical bug fixes from Oracle until 3 April. At that point it was too late, as the Flashback virus had already used Java to insinuate itself into hundreds of thousands of Macs. It was not until 14 April that Apple created and distributed a Flashback removal tool.

    Java itself is not the source of the problem. Apple’s OS X is a mass of in-house, licensed, open-source and free software knitted together. The company is not bad at fixing flaws in code before they have been exploited or publicly exposed. But it has a spotty record for hopping on those that need to be fixed instantly — and, that have already been repaired on other platforms. In 2008, for instance, one flaw (which threatened the Internet’s domain-naming system) was repaired on the day it came to light by every major software-maker except Apple.

    That Apple has managed to dodge the malware bullet for so long is in large part down to luck. Even in this case, Flashback was only mildly malicious and easily removed; mischief-makers did not have time to make it nastier. But Apple should not count on such good fortune lasting for ever. It has been warned.  — (c) 2012 The Economist



    Apple
    Subscribe to TechCentral Subscribe to TechCentral
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleWindows 8 to be offered in three main flavours
    Next Article Breaking SA’s final broadband bottleneck

    Related Posts

    Samsung goes trifold while Apple folds its arms

    Samsung goes trifold while Apple folds its arms

    2 December 2025
    Samsung's first trifold smartphone is here

    Samsung’s first trifold smartphone is here

    2 December 2025
    Your data, your hardware: the DIY AI revolution is coming - Duncan McLeod

    Your data, your hardware: the DIY AI revolution is coming

    20 November 2025
    Company News
    AI, cloud and the great IT rationalisation - Craig Stephens SAS South Africa

    AI, cloud and the great IT rationalisation

    15 December 2025
    New Vox partner programme helps ISPs expand without the heavy lifting

    New Vox partner programme helps ISPs expand without the heavy lifting

    15 December 2025
    How alternative credit models can unlock South Africa's hidden economy - Cameron Kyle-Perumal M-KOPA South Africa

    How alternative credit models can unlock South Africa’s hidden economy

    15 December 2025
    Opinion
    Netflix, Warner Bros deal raises fresh headaches for MultiChoice - Duncan McLeod

    Netflix, Warner Bros deal raises fresh headaches for MultiChoice

    5 December 2025
    BIN scans, DDoS and the next cybercrime wave hitting South Africa's banks - Entersekt Gerhard Oosthuizen

    BIN scans, DDoS and the next cybercrime wave hitting South Africa’s banks

    3 December 2025
    Your data, your hardware: the DIY AI revolution is coming - Duncan McLeod

    Your data, your hardware: the DIY AI revolution is coming

    20 November 2025

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Ramokgopa bullish on energy outlook as new projects get green light - Kgosientsho Ramokgopa

    Ramokgopa bullish on energy outlook as new projects get green light

    15 December 2025
    Wiocc lands R1.1-billion in debt funding for data centre, fibre expansion - Chris Wood

    Wiocc lands R1.1-billion in debt funding for data centre, fibre expansion

    15 December 2025
    Rand hits strongest level in three years

    Rand hits its strongest level in three years

    15 December 2025
    Presidency backs Solly Malatsi in BEE reform fight - Cyril Ramaphosa

    Presidency backs Solly Malatsi in BEE reform fight

    15 December 2025
    © 2009 - 2025 NewsCentral Media
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}