15 ms·
Transmission BitTorrent app contained malware
- zymhan 11y agoAlong with the recent Linux Mint hijack, this really illustrates the need for people to verify programs they download. Though I think most people can't be bothered to verify the checksum on a file every time they download it. On the other hand, the Windows and OS X App Stores are awful. Linux package managers are looking like one of the only straightforward ways to distribute applications securely.
- rcthompson 11y agoMost people download software from websites using GUI browsers, while performing a checksum generally requires opening a terminal, changing directories to where the file was downloaded, and running the checksum program there. Maybe the web browser should provide a UI for doing checksums directly in the download manager. For example, each download entry could have a blank "checksum" text box where you can paste in the checksum given on the page.
- CiPHPerCoder 11y agoThis doesn't solve the problem. At all. A checksum is NOT a substitute for a digital signature. https://paragonie.com/blog/2015/08/you-wouldnt-base64-a-password-cryptography-decoded https://paragonie.com/blog/2015/08/you-wouldnt-base64-a-pass...
- deleted 11y ago[deleted]
- Hydraulix989 11y agoRight. All I have to do is distribute the correct hash for my binary as a malicious software distributor because there's no authenticity verification at all, only that the bits in my binary blob match a certain pattern.
- rhizome 11y agoIs that supposed to be sarcasm? Hard to tell.
- CiPHPerCoder 11y agoI suspect not.
- __david__ 11y agoIt is given the following attack scenario: attacker is man-in-the-middling, and the SHA (but not the actual binary) is delivered via https. In the case where the attacked has direct control over the website then you're right, it doesn't help at all.
- CiPHPerCoder 11y ago> In the case where the attacked has direct control over the website then you're right, it doesn't help at all. I was pretty sure that's the threat model we were discussing: Software authenticity. The only way to automatically know if a piece of software is legitimate is to have a trusted public key that can verify a signature. Also, HTTPS is implied these days. If you're not using HTTPS, you are either malicious, negligent, incompetent, or working for someone who is some or all of the above.
- __david__ 11y ago> If you're not using HTTPS, you are either malicious, negligent, incompetent… Or poor. Hosting large amounts of binaries over https isn't cheap. I just priced Amazon S3 and cloudfront and for the amount of data that I serve it would cost $300 per month. That's a lot to commit for a GPL-ed binary that brings in practically zero revenue. Maybe there's a cut rate VPS out there that can handle 150GB of data and 3TB of bandwidth per month on the cheap, but I haven't found it yet.
- kruczek 11y agoHow much is it for the same volume of non-HTTPS traffic?
- deleted 11y ago[deleted]
- saganus 11y agoThat would be a useful extension/plugin for browsers actually. Maybe like pointed out in another reply, not for checksums but for signatures. So you just copy/paste the signature after selecting a file, and then it can verify it's validity. Is there no such extension yet? it seems like there should be one already.
- ikeboy 11y agoTried to search, found https://tails.boum.org/blueprint/bootstrapping/extension/ https://tails.boum.org/blueprint/bootstrapping/extension/, and links to https://chrome.google.com/webstore/detail/satori/oncomejlklhkbffpdhpmhldlfambmjlf https://chrome.google.com/webstore/detail/satori/oncomejlklh..., with code at https://github.com/glamrock/satori https://github.com/glamrock/satori
- TickleSteve 11y agoyeah, maybe they should call it something like.... https??
- toyg 11y agoMaybe something like: - have a database of common downloads and all their crypto info, which developers can update once they are validated - have browser extensions that will check packages on download and alert if suspicious You could pay for it with some sort of sponsorship from apps themselves, who have an interest in not getting compromised like this (it's terrible publicity).
- jpalomaki 11y agoIf the website is compromised, the checksum could be changed as well. With digital signatures the problem is that I don't often know who is the official author of the app.
- mhurron 11y ago> Linux package managers are looking like one of the only straightforward ways to distribute applications securely. Linux distributions package what is released upstream. If upstream is compromised, so is the Linux package.
- r0muald 11y agoNo, Linux distributions offer packages and operating systems that are the result of painstaking work in which all upstream code is reviewed, patched for any inconsistency, and often blocked from going into public archives until known bugs are fixed.
- regularfry 11y agoThat's... optimistic.
- cyphar 11y agoThat's how OpenSUSE works. Debian too AFAIK.
- regularfry 11y agoIt's the aspirational ideal behind how these projects work.
- owaislone 11y agoActually, most have scripts that pull the upstream source and build new binaries without any manual intervention. It is the responsibility of the package maintainer to review every change in code.
- finnn 11y agoGenerally, Linux package maintainers grab the upstream source, while most of these compromises seem to be of the binaries. And, of course, the maintainers generally review the changes before publishing them
- resoluteteeth 11y ago> Along with the recent Linux Mint hijack, this really illustrates the need for people to verify programs they download. Though I think most people can't be bothered to verify the checksum on a file every time they download it. Barring a situation where a CDN hosting the download is compromised but the main site is not hosted on the CDN, it's extremely unlikely that someone would have the ability to inject malware into the download and not have the ability to make the checksum match. Posting checksums is actually pretty useless, and was something that used to be used to deal with the possibility of malicious mirrors, but doesn't provide any security against mitm attacks (unless the main site is secure but the downloads aren't which is idiotic by 2016 standards anyway), the site getting hacked, etc. Digital signatures are a little bit better if the key is kept safe, since hacking the site and replacing the binary won't allow a random person to produce a valid signature, although ability to modify the source code would still allow someone to introduce backdoors into the next version, but there's still a huge problem where you need some way to determine what key was supposed to be used to sign the binary in the first place, so just posting a signature on a website is also basically useless. Digital signatures can work if there's some sort of centralized distribution method, or for safely updating software that's already installed.
- ikeboy 11y ago>unless the main site is secure but the downloads aren't which is idiotic by 2016 standards anyway https adds a performance hit. The security of "checksum over https and actual file over http", if the checksum is checked, is the same as "actual file over https", barring preimage attacks.
- ianlevesque 11y agoThis is a persistent myth https://istlsfastyet.com https://istlsfastyet.com
- ikeboy 11y agoI've seen whonix say this https://www.whonix.org/wiki/Download_Security https://www.whonix.org/wiki/Download_Security >Practically it is difficult to provide SSL protected downloads at all. Many important software projects can only be downloaded in the clear, such as Ubuntu, Debian, Tails, Qubes OS, etc. This is because someone has to pay the bill and SSL (encryption) makes it more expensive. At the moment we don't have any mirror supporting SSL. We're looking for SSL supported mirrors to share the load. Is it not true that mirrors supporting SSL are more expensive?
- crazysim 11y agoThe Linux Mint hijacker changed the checksum too.
- zepto 11y agoHow is the OSX App Store 'awful' compared to a Linux package manager?
- gcb0 11y agoapp store: anyone gets a id. sign whatever. just have to get past the automated detection. Debian: have to also fool several people involved in the packaging of said package upstream and everyone using it and building from source
- zepto 11y agoFair point. How is a compromised package revoked in the Debian case?
- coldtea 11y ago>Though I think most people can't be bothered to verify the checksum on a file every time they download it. This wouldn't help anyway. If the malicious party had access to alter the downloads (as they did here) they could just as well change the checksum shown on the page to. >On the other hand, the Windows and OS X App Stores are awful. Haven't used the Windows one, but what's "awful" about the OS X one? Quick, one click, installations, isolated, signed, easy updates. Might be bad for the application developers somehow, but I don't see anything much bad about it from a user perspective -- except maybe the lack of trials. Then again I've been able to get a refund any time I bought an app that was subpar and written to Apple (that was 2 times).
- azernik 11y agoIn the original thread, the initial reporters specifically pointed out that the files they had downloaded did not match the checksums on the Transmission page. My guess would be that the attackers compromised a mirror, but not the web server serving up the user-visible page with the checksum.
- danieldk 11y agoLinux package managers are looking like one of the only straightforward ways to distribute applications securely. Unless you are a small independent app developer. Virtually no distribution wants to take proprietary software. And you have to package for a wide variety of different distributions. On the other hand, the Windows and OS X App Stores are awful. The Mac App store works pretty much effortless for me. It's sometimes a bit slow, but other than that it's pretty trivial to use.
- JetSpiegel 11y agoYou can run your own repo. It's basically a folder with some metadata. DEB and RPM variants should get you 80% of the way.
- theinternetman 11y agoHow is that any more secure than just providing a download?
- samuellb 11y agoIt's not at the time of installation, but prior to updates the package management system will check signatures of the packages. (And it will only accept packages signed with your key, so the attack used against Transmission wouldn't work)
- cyphar 11y agoThe question is whether we should trust proprietary software even if it is downloaded securely. I consider "hard to get proprietary software into the official repos" as a feature. Unfortunately it's not as hard as you make it sound in most distributions.
- rhizome 11y agoAlong with the recent Linux Mint hijack, this really illustrates the need for people to verify programs they download. I'm game, but I need a little help. What are your favorite techniques for verifying downloaded programs?
- samuellb 11y agoThere's no completely secure way, except for getting the public key directly from the developer over a trusted channel (or in person). And even that won't protect you in case the developer's keys gets compromised. But there are a number of things that can be done: - always verify the checksum (if available), in case the download mirror (but not the web site itself) got compromised. - check for strange strings in the binary (use "strings" and "grep"). E.g. URLs - scan the downloaded file on Jotti or VirusTotal. - unpack the binary manually with 7-zip or similar if it's a self-extracting file. - check installation scripts, build files, etc. (if applicable). - if downloading source code, check a couple of files at random. Will most likely not protect you, but if everyone does it, it helps detecting embedded malware (or bugs) early. - run "strace" (Linux/Unix) or "FileMon" (Windows) or similar software and log what the software does when you install and run it for the first time. - and check Hacker New regularly ;)
- Mandatum 11y agoThe app made it onto the OSX App Store and the author's certs were revoked. This isn't a case of verify source, verify application. This is a case of anything can be infected and it's damn near impossible to check everything.
- jads 11y agoTransmission wasn't on the Mac App Store, though the app was signed. Apple offers developers the ability to sign their apps distributed outside the Mac App Store to certify them as an Apple-identified developer https://developer.apple.com/library/ios/documentation/IDEs/Conceptual/AppDistributionGuide/DistributingApplicationsOutside/DistributingApplicationsOutside.html https://developer.apple.com/library/ios/documentation/IDEs/C... As such, checking the source is still very much relevant here since this wasn't a compromised app in the Mac App Store, it's an app distributed outside it.
- ascorbic 11y agoIt was signed, but wasn't in the Mac App Store.
- Angostura 11y agoIn what respect is the OS X AppStore awful?
- TheCoreh 11y ago- The APIs exposed to Mac App Store apps are more limited (because the OS X sandbox is not completely comprehensive in what it provides). This limits the types of apps that can be sold on the store. - There's no means of providing paid upgrades. E.g. for a major version bump, which a lot of developers rely on to keep their business afloat. - The store interface and navigation are also much slower than the iOS counterpart. - Recently some certificate issues rendered users unable to open their apps. - Not 100% sure on this one: You can't download older app versions if your OS is no longer supported.
- Aloisius 11y ago- There's no means of providing paid upgrades. E.g. for a major version bump, which a lot of developers rely on to keep their business afloat. Apple and other do this by simply numbering the names of apps. They don't allow you to specify special "upgrade" pricing, but the effect of this was that developers no longer really have full retail pricing and everything is just set to the upgrade price. Logic Pro 8 for instance used to retail at $499. The upgrade price was $199. Now Logic Pro X on the Mac App Store is just $199 regardless of whether you are first time user or someone who had the previous version. - The store interface and navigation are also much slower than the iOS counterpart. I haven't really found that the Mac Store is any slower. I've found that they are both slow. - Not 100% sure on this one: You can't download older app versions if your OS is no longer supported. I don't believe it will even show you newer versions of the apps as long as the developer properly specifies the minimum OS version.
- andreamazz 11y agoThe guys at Bohemian coding discussed (even if not too in detail) it here: http://blog.sketchapp.com/post/134322691555/leaving-the-mac-app-store http://blog.sketchapp.com/post/134322691555/leaving-the-mac-...
- thrillgore 11y agoWhat amazes me is that this process can be totally automated and made invisible to the user. Alas, nobody wants to invest the day or so in actually writing the methods to do it.
- capripot 11y agoWhy there isn't a default protocol for sending a the SHA key and verifying the downloaded file automatically?
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- darfs 11y agoIsn't it quite popular on Debian and derivates too? It's Pre-installed with GNOME there as far as I know. Fair enough, it's extremly interesteing. Never saw such an infection in the "free World", outside the laboratory. I hope they can find the source.
- mhurron 11y agoIt's quite popular everywhere. Interesting that 2.90 just showed up in Fedora updates.
- cesarb 11y agoAt least Linux distributions usually compile from source. I wonder if the source was also modified, or only the binaries. EDIT: I downloaded the Transmission 0.90 and 0.91 source code and took a look. The diff between them is quite small, with nothing suspicious being removed, and the 0.90 .tar.xz MD5 matches what Fedora used (according to http://pkgs.fedoraproject.org/cgit/rpms/transmission.git/commit/?h=f23&id=640c669434ea7f7b92449a50aba118f4b7335354 http://pkgs.fedoraproject.org/cgit/rpms/transmission.git/com...). So, unless there was also a malicious source code change the developer didn't catch, Fedora's package should be clean.
- mhurron 11y ago> I wonder if the source was also modified, or only the binaries. Personally, pending further information, I've removed Transmission from my machine.
- en4bz 11y agoIt seems the most recent version is 2.84 on ubuntu 15.10. The last update to the package was on July 2015.
- pfg 11y agoThere's a fairly popular PPA which is currently on 2.90[1]. However, it seems like only OS X binaries included malware (... hopefully). [1]: https://launchpad.net/~transmissionbt/+archive/ubuntu/ppa https://launchpad.net/~transmissionbt/+archive/ubuntu/ppa
- oxguy3 11y agoDo the developers have an explanation anywhere as to how this happened? The homepage ( https://transmissionbt.com/ https://transmissionbt.com/ ) has a big red warning to upgrade to 2.91, but I can't find any info about how someone went about putting malware in the download.
- carlosrg 11y agoYep, this deserves a more detailed explanation (or maybe they still don't know what happened). I updated from the previous version to 2.90 through the app built-in update, and I don't seem to have any "kernel_service" process running. Can someone that has that process in their system tell us where they downloaded the program?
- nkulig 11y agoI also did not have that process running in the background. I just updated through the app to 2.91 and it's still not there. So, I am also curious where they got Transmission from.
- s_kilk 11y ago> I updated from the previous version to 2.90 through the app built-in update... Same, and I also don't see any `kernel_service` process running. Fingers crossed for the in-app update not being affected by the hack.
- ikeboy 11y agoHm. https://trac.transmissionbt.com/wiki/Changes#version-2.91 https://trac.transmissionbt.com/wiki/Changes#version-2.91 lists the following under Mac changes for 2.90 >Allow downloading files from http servers (not https) on OS X 10.11+ Mac version affected in OP was 10.10, though. Maybe it had something to do with >Change Sparkle Update URL to use HTTPS instead of HTTP (addresses Sparkle vulnerability) ? Edit: it appears the infection was downloaded from a website, in which case this doesn't help. But one did say the in-app update failed on incorrect signature first.
- wlesieutre 11y ago>Allow downloading files from http servers (not https) on OS X 10.11+ This reads like they disabled Apple's "App Transport Security", which only allows HTTPS connections unless a program explicitly makes an exception. Introduced in iOS 9 and OS 10.11 (El Capitan). I bet the failing HTTP connections caused a bug in Transmission, and it was an easier fix to disable ATS than to transition whatever connection to HTTPS. https://developer.apple.com/library/prerelease/ios/documentation/General/Reference/InfoPlistKeyReference/Articles/CocoaKeys.html#//apple_ref/doc/uid/TP40009251-SW33 https://developer.apple.com/library/prerelease/ios/documenta...
- the_mitsuhiko 11y ago> and it was an easier fix to disable ATS than to transition whatever connection to HTTPS. Pretty sure this is for arbitrary downloads. Unless you want to prevent transmission to download from http based sources out of principle it makes no sense to do anything other than opting out of this behavior.
- wlesieutre 11y agoRight, being a web connected app based on a distributed community of other clients, it's very possible that the encryption isn't possible to implement on their end. IIRC it's only blocking HTTP connections, so the torrent transfers themselves aren't affected (unless it's masking that as HTTP traffic to avoid easy inspection?), but there may be other things that require HTTP. Connections to trackers maybe? On the other hand, El Capitan came out last September. If this just changed in 2.9.0, the restricted HTTP connections can't have been that big of a problem.
- mmgutz 11y agoDoes installing 2.9.1 remove it completely or just from the Transmission app? I'm concerned the malware is still there.
- wlesieutre 11y agoAdditionally, what does the malware do? "OSX.KeRanger.A" appears to be a name that Apple assigned it in their malware definitions, but Google doesn't know anything except the pages about Transmission. I'm curious what sort of malware we're looking at. Botnet? General remote access/control? Harvesting keychains?
- sandstrom 11y agoAccording to this article it's ransomware. http://www.cnbc.com/2016/03/06/reuters-america-apple-users-targeted-in-first-known-mac-ransomware-campaign.html http://www.cnbc.com/2016/03/06/reuters-america-apple-users-t...
- wlesieutre 11y agoThanks! Guess my search was too specific. The important bit: > The malware is programmed to encrypt files on an infected personal computer three days after the original infection, according to Olson. Anyone who may have been hit, update your backups NOW so you can restore the files.
- joosters 11y agoCareful not to backup the malware infection though...
- wlesieutre 11y agoOf course, and if you only have the one backup drive, be wary of connecting it to an infected computer with read/write access. Link posted in another comment suggests that this malware has encryption of Time Machine backups in development (should be safe this time around?). Safer option would be to create a write-only network share on another computer and copy files to that.
- rMBP 11y agoI'm on 2.90 and can't find any weird processes running. I'll hold off on 2.91 until they've explained what happened.
- make3 11y agothat feels like a pretty week standard for knowing if your machine is infected. I will look for a virus scanner myself, and seriously think about reinstalling if it finds anything
- rMBP 11y agoYeah I know, it is the lowest effort. But I'm not running it on my main system. Worst case I'll have to reinstall (unless it messes with the hardware, firmware changes for example).
- SG- 11y agoI believe only manual downloads of 2.90 were infected, the in-app update should have been clean.
- julie1 11y agoThe strength of a chain is the strength of its weakest link, and the more "apps" are provided as the system the longer and more vulnerable is the chain. When it comes to checksums with have the chicken egg problem plus the collision attack of md5. MD5 has been the standard for too long (and is deprecated since 10 years for crypto checksum). And for next generation of softwares to install that don't do modern checksum how can they trust the download of the package required to check for whatever the new format? Plus the new format is less likely to be checked without errors. A off by one character could easily be discarded in checking given the number of packages that are now required to be installed and the human limitation in focus. Human are the limiting factors, and security is modeling the user in a kind of grotesque caricature of a robot that can check thousands of informations perfectly and remember 20 characters passwords for tens of appliances. There is a tyranny of computer engineers regarding what is safe for people having a life not concerned about geeky technology that is a tad annoying. People have the right to be human and to fail is human. The burden put on human to make the system safe in order to avoid costly for the bosses human interactions is way to high. And since computer security always blame failure on human behaviour I begin to positively dislike it.
- Razengan 11y ago> There is a tyranny of computer engineers regarding what is safe for people having a life not concerned about geeky technology that is a tad annoying. You know you can make that complaint about any tool or technology, right? "Gosh why do I have to follow all these rules and observe traffic lights to drive a car?" (something that actually intimidates me, in fact, because I've never driven a car.) "Why do I have to worry about cutting or burning myself or someone else while trying to cook a meal?" "Why are all these procedures and protocols, like schools and banks and taxes, required to function at all in contemporary society?" Until computers advance to the point of being artificially intelligent familiars that can figure out exactly what we want from a simple vocal command and do something even better, we're gonna have to put in a little effort from our end to make them work the way we want them to.
- julie1 11y agoYou know all engineers do not always blame users? There are fields of engineering where an accident even due to human causes is systematically seen as an engineering problem. And that may be the reason why traveling by plane and train are safer than by car. But US engineers made a great job at convincing legal department that poorly engineered goods where not the causes of accidents.
- justsaysmthng 11y agoI've become increasingly paranoid lately, given that things like these happen and major bugs are uncovered in software that I use almost every day. It's good that the Transmission developer reacted quickly and made waves so that people can at least be aware that they might have been exposed.. But I wonder how many more applications from the hundreds that I have installed on my machines contain weird stuff - either intentional (for money) or unintentionally (result of a hack). Open source software is especially vulnerable to this kind of stuff. If a hacker gets access to a server holding the binaries for an open source app (which most people download), the hacker can just compile the program from sources and add his own code in there and place the installer online. Given that many big governments are now involved in the information wars, this scenario is quite likely.
- kpcyrd 11y agoIt's trivial to do this with closed source applications as well.
- franciscop 11y ago> "Open source software is especially vulnerable to this kind of stuff." I am sorry, what? Why would open source contain more bugs/hacks than closed source specifically? It is more often in the news for few reasons, including that many projects are widely used. However it's against any PR from companies to have their security issues disclosed like they are in open source so they try to minimize the exposure. See [1] [1] http://www.techrepublic.com/article/open-source-vs-proprietary/ http://www.techrepublic.com/article/open-source-vs-proprieta...
- bluedino 11y agoNot because of the fact that it's open source, but because of the distribution models used. SourceForge has been linked to bundled malware and hijacked projects like GIMP and FileZilla.
- the_af 11y agoI don't follow, what does it matter for the "distribution model" if the software is open- or closed-source? The problem with SourceForge were its malware-riddled installers, how would it be any better if the downloads were proprietary software?
- teamhappy 11y ago2.90 was released a couple of days ago[1], so if you haven't used Transmission in a couple of weeks this doesn't affect you. [1]: https://en.wikipedia.org/wiki/Transmission_%28BitTorrent_client%29 https://en.wikipedia.org/wiki/Transmission_%28BitTorrent_cli...
- sandstrom 11y agoCNBC isn't a website I'd expect to read anything tech-related on, but there are actually a few details in this article: http://www.cnbc.com/2016/03/06/reuters-america-apple-users-targeted-in-first-known-mac-ransomware-campaign.html http://www.cnbc.com/2016/03/06/reuters-america-apple-users-t... - It's Ransomware. - Seems to be a 3 day grace-period (chance to remove it, possibly). - The Transmission developer certificate [Gatekeeper] has been revoked.
- moyix 11y agoVirusTotal has some more info, including the files it writes: https://www.virustotal.com/en/file/d1ac55a4e610380f0ab239fcc1c5f5a42722e8ee1554cba8074bbae4a5f6dbe1/analysis/ https://www.virustotal.com/en/file/d1ac55a4e610380f0ab239fcc... (Look under the "Behavioural information" tab) Written Files and Created Processes are interesting: [Transmission] /Users/user1/Library/kernel_service (successful) [unknown] /Users/user1/Library/.kernel_pid (successful) [unknown] /Users/user1/Library/Saved Application State/org.m0k.transmission.savedState/window_1.data (successful) [Transmission] /Users/user1/Library/Saved Application State/org.m0k.transmission.savedState/data.data (successful) [Transmission] /Users/user1/Library/Saved Application State/org.m0k.transmission.savedState/windows.plist (successful) [kernel_service] /Users/user1/Library/.kernel_time (successful) Created processes /Volumes/Transmission/Transmission.app/Contents/MacOS/Transmission (successful) /Users/user1/Library/kernel_service (successful) kernel_service (successful) Edited to add: If anyone has a copy of the DMG, sha1 5f8ae46ae82e346000f366c3eabdafbec76e99e9, please link me a copy via email (brendandg@nyu.edu) or twitter DM (@moyix).
- 0x0 11y agoMaybe take a look around https://build.transmissionbt.com/ https://build.transmissionbt.com/ - but then again maybe the svn repo wasn't compromised? I tried a "svn diff svn://svn.transmissionbt.com/Transmission/tags/2.90 svn://svn.transmissionbt.com/Transmission/tags/2.91" and didn't see anything suspicious on a fast scroll-through
- yeukhon 11y agoSide topic: probably not a good idea to expose Jenkins externally, especially if you don't keep Jenkins up-to-date all the time (for transmission bt it is up-to-date right now). This Jenkins probably contain the key to the svn server, so if someone finds a hole...
- ycmbntrthrwaway 11y ago> Jenkins probably contain the key to the svn server Why should it? For open-source software build-server can even be ran by a third party.
- s_kilk 11y agoWhile we're here, can anyone recommend a good antivirus for OSX? I've just been looking at BitDefender, which looks promising, but would rather get this right than faff around with potentially crappy AV tools.
- tarsinge 11y agoIt seems an up to date OS is the way to go (as in this case it was detected by OSX)
- noondip 11y ago> can anyone recommend a good antivirus for OSX? Common Sense 2016, see https://github.com/drduh/OS-X-Security-and-Privacy-Guide https://github.com/drduh/OS-X-Security-and-Privacy-Guide
- s_kilk 11y agoThanks, that's some good readin'
- Artemis2 11y agoIronically this recommends Transmission as a BT client.
- x0 11y agoCommon Sense 2016 would not have prevented a malicious Transmission update though
- noondip 11y agoAgreed - it would not defend against this presumed watering-hole attack. However, neither would have AV: https://www.virustotal.com/en/file/d1ac55a4e610380f0ab239fcc1c5f5a42722e8ee1554cba8074bbae4a5f6dbe1/analysis/ https://www.virustotal.com/en/file/d1ac55a4e610380f0ab239fcc... Nevertheless, I still believe Common Sense to be a better alternative to bloated, vulnerable anti-virus programs.
- JabavuAdams 11y ago
- marvel_boy 11y agoIt seems that is a ransomware campaign http://www.reuters.com/article/us-apple-ransomware-idUSKCN0W80VX http://www.reuters.com/article/us-apple-ransomware-idUSKCN0W... Next monday, tomorrow could pave terror on the office.
- Matt3o12_ 11y agoCan anyone tell me if this also applies to brew's cask's builds? I needed to download CentOS the other day and wanted to go with a torrent. I got pretty pissed after I realized that BitTorrent installed some adware called Spigot. I tried to remove it as good as possible (I mainly killed the process, removed `Library/Application Support/Spigot` and ran a `sudo find / | grep -i Spigot`). Ironically I decided to use the good, ol', trusted open source alternative transmission because I just read on HN that Transmission gets updated again...
- orik 11y agoMy build from cask didn't start the process but force removed it anyways and am waiting for cask room to point towards 2.91.
- Amorymeltzer 11y agohomebrew-cask updated with version 2.92 and https
- avendael 11y agoLooks like it. The homebrew cask download url is using http instead of https, which was one of the problems stated in the forum discussion. There's currently an open PR to fix it https://github.com/caskroom/homebrew-cask/pull/19506/files https://github.com/caskroom/homebrew-cask/pull/19506/files.
- Amorymeltzer 11y agoFor anybody stumbling upon this, installation via homebrew-cask was _always_ safe[1] thanks to checksum verification. The caskfile has been updated to https[2] and version 2.92[3]. 1: https://github.com/caskroom/homebrew-cask/issues/19504#issuecomment-192992223 https://github.com/caskroom/homebrew-cask/issues/19504#issue... 2: https://github.com/caskroom/homebrew-cask/pull/19506 https://github.com/caskroom/homebrew-cask/pull/19506 3: https://github.com/caskroom/homebrew-cask/pull/19508 https://github.com/caskroom/homebrew-cask/pull/19508
- dave2000 11y agoAll that stuff - bittorrent, soulseek, calibre etc - lives in a vm, with access to the host only via samba shares. I'll decide what you see and where you can write. Yes, it's great you download stuff. No, you can't write to the stuff I'm sharing. Yes, having a web-server serving up books to the outside world is great. No, you can't serve up anything from my filesystem to anyone who feels like it. When you can't (be bothered to) vet the source code, stick it in a vm. On a sensible machine with an ssd it's only 10 seconds away. Why risk it. Especially if the software you want/need to run only works under windows.
- TazeTSchnitzel 11y agoBeware that VMs are not necessarily secure. They can be escaped!
- dave2000 11y agoSure, in theory. Are there any current exploits for VirtualBox? The way I see it, they're more secure that running the same apps on bare metal. Ubuntu host running a Fedora VM; the latter (with Transmission etc) only running when I need the apps running - seems an almost entirely painless way of providing a lot of security.
- nevir 11y agoUnsure if there are any currently publicly known exploits, but it sure isn't unheard of for VirtualBox: * http://arstechnica.com/security/2015/05/extremely-serious-virtual-machine-bug-threatens-cloud-providers-everywhere/ http://arstechnica.com/security/2015/05/extremely-serious-vi... * http://www.securityfocus.com/archive/1/495095 http://www.securityfocus.com/archive/1/495095 * https://www.cert.be/advisories/oracle-vm-virtualbox-two-privilege-escalation-vulnerabilities https://www.cert.be/advisories/oracle-vm-virtualbox-two-priv... * http://www.coresecurity.com/content/virtualbox-privilege-escalation-vulnerability http://www.coresecurity.com/content/virtualbox-privilege-esc...
- 11y ago
- cabbeer 11y agoI uninstalled the app, but is there a way I can check if i've been affected?
- chmwils 11y agoThis article explains how to check if for infection: http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-ransomware-keranger-infected-transmission-bittorrent-client-installer/ http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-...
- joeblau 11y agoThis article[1] says Transmission is doing to offer a way to check, but I'm not sure it's on the site yet. Apparently tomorrow is the ransomware activation date for people who installed the infected version on Friday. [1] - http://www.reuters.com/article/us-apple-ransomware-idUSKCN0W80VX http://www.reuters.com/article/us-apple-ransomware-idUSKCN0W...
- Heis 11y agoCan someone please confirm that the in-app update is not affected by the hack?
- Orizimal 11y agoI performed the in-app update to 2.90 last night. Just found about this. Doesn't appear that I am infected, amazingly enough.
- theinternetman 11y agoI updated in app and don't seem to be, an official confirmation of how this happened and why in-app updates were seemingly not affected would go a long way.
- xnyhps 11y agoReports indicate it isn't, but they're still including a vulnerable version of Sparkle [1], so I wouldn't trust the auto-update at all [2]. [1] = https://sparkle-project.org/documentation/security/ https://sparkle-project.org/documentation/security/ [2] = https://trac.transmissionbt.com/log/tags/2.92/macosx/Sparkle.framework https://trac.transmissionbt.com/log/tags/2.92/macosx/Sparkle...
- nitrogen 11y agoThe headline should probably say "at least Mac". I hope we soon learn the source of the compromise, but nothing so far indicates that Linux distributions' packages would be affected by a Mac malware.
- logicrook 11y agoThe headline should definitely say "at least Mac". It so annoying to hear about "computer viruses"... (protip: it's Windows, Osx, well, maybe even Linux virus).
- azernik 11y agoLooking more at this issue, it seems like the problem may have been (hard to tell, not a lot of information) a compromise of a third-party mirror to which https://www.transmissionbt.com/ https://www.transmissionbt.com/ redirected users; the checksum on the HTTPS site was unaltered, and was used to identify the altered download. Perhaps a defense against this kind of attack would be an altered version of HSTS - one that protected the content of download links, and not just of sub-resources included on the page.
- chimeracoder 11y agoIt might be worth updating the title to specify the vulnerable version (2.90) and the platform (OS X - from what I can tell, this is not a vulnerability on Linux or Windows).
- MichaelGG 11y agoIt's not. Condoms aren't used against a hostile opponent. If your partner is intent on exposing you, a condom won't provide any protection.
- nikanj 11y agoI can't think of a more hostile opponent than an HIV virus. And we're still not sure if Transmission was spreading the virii intentionally, making the condom analogy even more fitting.
- TazeTSchnitzel 11y agoHIV is not a threat crafted by an active adversary, it's a product of evolution.
- jdc 11y agoI think the point is that viruses can exploit properties of their hosts regardless of how they came to do so.
- tedks 11y agoBut humans and viruses aren't competing in the same game. A better metaphor for the adversary in that situation is the person you're having sex with poking a hole in your condom.
- finchisko 11y agoWondering if brew cask can be solution for this.
- Amorymeltzer 11y agoInded, see my comment here: https://github.com/caskroom/homebrew-cask/pull/19508 https://github.com/caskroom/homebrew-cask/pull/19508 Installation via brew cask was never at risk thanks to checksum verification, and at anyrate is now updated.
- finchisko 11y agoThat's really nice. I was in doubt, because it downloads Transmission DMG from their site, but checksums solves it. We should use it more. :-)
- svetly0 11y agoTransmission put up a new version - 2.92 that supposedly checks for and removes the malware.
- jariz 11y agoThrew away Transmission as soon as I read this (even though I was running a old version), my trust is pretty much gone now, never installing it again. Shame because it really was a nice app.
- fefifofu 11y agoI don't even trust websites and emails, so not sure why you would trust a bittorrent client. I still use these tools, but with some some caution. Your level of caution is up to you. Other posters suggested things such as verifying checksum and virtual machines.
- snom380 11y agoIsn't it open source? So clone the last release version you trusted, build that from source and be happy?
- jsn117 11y agoflying the day after 9/11 was the safest time, I really doubt this sort of thing will happen again to the same software
- theinternetman 11y agoThis would be true if they knew how it was compromised, they've been silent on that issue so far. The current version could be being compromised this minute for all we know.
- mordocai 11y agoNot an official comment, but from other parts of the hacker news thread it sounds like one of the mirrors the main site redirects to was hacked, not the main site itself. The SHA sums on the main site where apparently unaltered. So it sounds like the only fault on the developers is trusting that mirror.
- dzhiurgis 11y agoPopular Mac rumour/news site 9to5mac (that is rapidly decreasing in quality) actually posted about this malicious update few days ago. Somehow I found it out of place, especially as they have never posted about TransmissionBT before. They sure did get lots of people to update after putting in on front page.
- lukasb 11y agoGood for them.
- deleted 11y ago[deleted]
- diebir 11y agoThis is a good illustration of why you should not install apps as administrator. Specifically, you should not install Mac OS packages, which allow for arbitrary pre- and post- install scripts to be executed as root. Same is true for Windows and Linux. There are privilege escalation bugs in any OS, but it is usually not a given. Throw the application into ~/Applications as a Mac bundle, worst that will happen is your account will be compromised. Much easier to detect and clean. Most trojans won't even succeed. We are going to have these problems until the developer community realizes that executing a randomly downloaded package installer as a privileged user is giving away the keys to the kingdom. Application stores is one solution, but really is not an open one. I'd rather see the apps distributed in a form similar to Apple app bundles, where a non-privileged user can just install the app into their home.
- NN88 11y agoso how do I get around this if most apps I want require this?
- diebir 11y ago1. Petition vendors to stop distributing .pkg's 2. Most packages can be extracted with pkgutil and then just copied into ~/Applications. It is infrequent that somebody needs to modify your OS and if they do, then they better explain why.
- Nullabillity 11y ago> Throw the application into ~/Applications as a Mac bundle, worst that will happen is your account will be compromised. On a typical single-user setup, there's not much difference between an account compromise and a machine compromise anyway.
- woodman 11y agoThat is only true if you have no interest in recovery post compromise. A user level account shouldn't be able to put the system in such a state that online recovery is impossible, whereas a system level account easily can - think loadable kernel modules. Only offline recovery works once you lose trust in the kernel. That is the difference between "Alright grandma, lemme remote in" and "Sorry old lady, better start looking for the factory install CDs". Lets not even get into how screwed we are with UEFI...
- Philipp__ 11y agoCan someone explain me what Xprotect.plist contains? Are those malware's that are recognized by Apple and are blocked and dealt with? I saw some post on forum where dude said how his Xprotect now contains at the top OSX.KeRanger.A entry, and said how it means he got infected. It didn't made much sense to me, but I checked mine this morning and found the same entry? Does it mean I am infected too? But I didn't download anything from their website like 3 months back, I just did the update to 2.90 in Thursday or Friday can't remember, and yesterday as soon as I saw the news I update everything and checked for malicious files and processes which weren't present on my machine.
- russjr08 11y agoIf I recall correctly, they are file signatures that OS X uses to identify and remove malware. Not sure when and how the files on your drive are checked (potentially right before they are opened?), but the XProtect.plist file is automatically updated by Apple, and that's what you're seeing. The entry doesn't exactly mean you're infected, but just that your copy of the file was updated. I have the entry for instance, but I was never infected. You can check your copy of XProtect with this command (I have 2076): defaults read /System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/XProtect.meta Version Edit: Looks like you do get a message before launching an app, if it's identified by XProtect/File Quarantine.
- Philipp__ 11y agoYeah, I have 2076 too. Now after the update of Xprotect you get the message, but what if you ran the app for example on Friday (4th) and got infected then? Checked on IRC, it seems that sparkles prevented infection for those who updated their app, like I did. Screw all this, as I read in one of the comments here, I will run transmission through Docker container on RPi running FreeBSD.
- russjr08 11y agoIf you ran the app before the XProtect definitions were updated, then it would've ran with no problem and you would've been infected.
- jws 11y agoJust an anecdatum: I got infected by this yesterday when I installed Transmission to download a Debian install CD. When I read about this at MacRumors I checked and had the kernel_service process running and the two hidden files hiding in Library. I've unplugged and archived the TimeMachine backup disk and done the prescribed cleanup actions to remove he malware. I guess time will tell if it had any other tricks up its sleeve.
- leonroy 11y agoDo a search for any files in /Users and connected volumes which are suffixed with .encrypted. Apparently that's the interim filename suffix used by the malware.
- jws 11y agoThanks, I appear to be clear of .encrypted files. The good of this mess is that I realized I only had one Time Machine backup going on that machine. I had turned off the remote backup a month ago while shoving backups around on the remote server to make more room and hadn't restored it. One backup is too few. The weakness exposed is that if the remote were mounted, this malware would have nailed it too. I'll have to look at having the remote make filesystem snapshots on its end so malware can't corrupt my older backups.
- adidalal 11y agoIf you installed/updated via Homebrew-Cask [1], you should not be affected. 2.90 was not always compromised, and looking at Caskroom history, the checksum was only updated for the 2.84 -> 2.90 bump once [2]. It is updated and at 2.92 now, also [3]. (I'm one of the maintainers of Homebrew Cask) [1] https://github.com/caskroom/homebrew-cask https://github.com/caskroom/homebrew-cask [2] https://github.com/caskroom/homebrew-cask/issues/19504#issuecomment-192992223 https://github.com/caskroom/homebrew-cask/issues/19504#issue... [3] https://github.com/caskroom/homebrew-cask/pull/19508 https://github.com/caskroom/homebrew-cask/pull/19508
- soraminazuki 11y agoHomebrew Cask is awesome, but I still think security is an issue here because you still have to trust the upstream binaries are safe, each built and hosted by totally different people. Verifying checksums is certainly better than not checking them, but you still haven't escaped from the trust-whatever-binary-you-downloaded-from-the-internet-style of doing things. I really wish package managers like Homebrew Cask offer some level of trust by building applications from source and signing them, like Debian.
- adidalal 11y agoYou are absolutely correct. Homebrew-Cask favors convenience and availability of as many applications as possible, though we make reasonable efforts to avoid malicious actors by verifying checksums, download links, and (soon) GPG verification where possible. You may be interested in https://www.macports.org https://www.macports.org for a build-from-source solution for OSS projects.
- codezero 11y agoIt looks like they've since changed the upgrade to 2.92 (it was previously 2.91 this morning), wonder why that happened?
- switch007 11y agoThe update dialog says: "Everyone running 2.90 on OS X should immediately upgrade to and run 2.92, as they may have downloaded a malware-infected file. This new version will make sure that the “OSX.KeRanger.A” ransomware (more information available here) is correctly removed from you're computer. Users of 2.91 should also immediately upgrade to and run 2.92. Even though 2.91 was never infected, it did not automatically remove the malware-infected file. "
- codezero 11y agoThanks, I dug out the diff and found that too :) https://trac.transmissionbt.com/changeset?old_path=%2F&old=14711&new_path=%2F&new=14713&sfp_email=&sfph_mail= https://trac.transmissionbt.com/changeset?old_path=%2F&old=1...
- ywecur 11y agoSorry, but how did this happen? Was the website breached?
- flerchin 11y agoOn a related note, Windows Defender detects malware when downloading the windows putty installer. Trojan: Win32/Varpes.J!plock http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html http://www.chiark.greenend.org.uk/~sgtatham/putty/download.h... Not sure how to report.
- conceit 11y agotry uploading the file to virustotal, avira etc. Windows Defender should in the alert have a button to report to microsoft.
- Intermernet 11y agoLooks clean. Maybe false positive from Windows Defender... https://www.virustotal.com/en/url/73d82ff580cd445b907c6334c7d7bd0b14107a6fc2a821cada334944edc7e25f/analysis/ https://www.virustotal.com/en/url/73d82ff580cd445b907c6334c7...
- orionblastar 11y agoI used to Transmission in Linux but switched to qBitTorrent instead when I switched to Windows 10. It has an OSX version if you don't trust Transmission anymore. http://www.qbittorrent.org/ http://www.qbittorrent.org/ http://www.qbittorrent.org/download.php http://www.qbittorrent.org/download.php
- jasonjei 11y agoIf they indeed used a legit code signing certificate, what is the fix? It seems very difficult to just blindly trust signed binaries anymore. Short of setting up a registry of vetted code signing certificates, it seems that signed code is just as easily manipulated as unsigned code. And even then, the keys to the certificate could be mishandled.
- Dorian-Gray 11y agoAm I the only one who saw the app and thought "Why the heck is TPB releasing an app?" Makes them more of a target, less stable platform, more easily interfered with , ect.
- Philipp__ 11y agoOh dear god. Used 2.90 past week, when I saw the news I updated immediately, checked for all the files, found nothing. I hope my MacBook will stay fine tomorrow. I got it backed up on Time Machine anyway. Where do we go from here, since I lost the trust, what are the alternatives? And from now one, I'll go with Brew Cask for everything possible. F* GUI /s
- kazazes 11y agoWould brew cask have helped you here? It doesn't build from source, it just downloads a precompiled binary.
- adidalal 11y agoIn this case, yes, as it verifies the download against a (best-effort) known-good checksum. It's not a perfect system, but did work out in this case. GPG verification where available and refusing to install Casks without a checksum is also in the pipeline. (I'm one of the maintainers of Homebrew Cask)
- tomlong 11y agoPosted by one of the researchers that discovered the malware... "#Transmission just pushed 2.92 update that includes code to > detect and to remove the #KeRanger ransomware. Update it before Monday 11:00am." https://twitter.com/claud_xiao/status/706579264036950016 https://twitter.com/claud_xiao/status/706579264036950016
- voltagex_ 11y agoI'm not sure how I feel about that. How long will that code live in Transmission? It's not really Transmission's job to remove malware.
- maknz 11y agoChecked my install of 2.9.0 from auto-update, it's clean (none of the suspect files are in Contents/Resources). According to a post on the Transmission forums, when a person was (probably) delivered an infected binary, there was a checksum failure as you'd expect. So it seems as though you won't be infected if you used the auto-updater.
- software_radio 11y agoOn the mac? Macs don't have viruses!
- nodesocket 11y agoSomething that is not entirely clear. Does updating to 2.9.2 attempt to clean KeRanger up automatically? Or is some manual cleanup still needed after updating?
- russjr08 11y agoThe newest update removes it automatically.
- nodesocket 11y agoIf the file /System/Library/CoreServices/XProtect.bundle/Contents/Resources/XProtect.plist contains: <dict> <key>Description</key> <string>OSX.KeRanger.A</string> <key>LaunchServices</key> <dict> <key>LSItemContentType</key> <string>com.apple.application-bundle</string> </dict> <key>Matches</key> <array> <dict> <key>MatchFile</key> <dict> <key>NSURLTypeIdentifierKey</key> <string>public.unix-executable</string> </dict> <key>MatchType</key> <string>Match</string> <key>Pattern</key> <string>488DBDD0EFFFFFBE00000000BA0004000031C04989D8*31F64C89E7*83F8FF7457C785C4EBFFFF00000000</string> </dict> </array> </dict> Does that mean I am infected?
- brians 11y agoNo. That means you have up to date protection against being infected.
- unfamiliar 11y agoWhat does the <string> match pattern mean exactly, how is it used to identify the executable?
- tomschlick 11y agoThe match type is saying that to match a file it must be fingerprint (hash) match using the Key provided below it.
- z3t4 11y agoYet another reason why you should have a (offline) backup of all your important files.
- zobby 11y agoIt happens to the bests: compromised server and infected updates ( can you hear me, PROFTPD? )
- pilif 11y agoThe fact that the binary was infected, I can somewhat understand. However, the way communication happened/is happening on this issue is very disconcerning and basically makes it impossible to know whether it's safe to currently download 2.92 from their site. Questions like - how did the compromised binary get there? Was the source code hijacked or was the binary altered after it had been built? - Were the SHA256 hashes on the site also compromised (btw: Having hashes on the site is good enough for making sure you're not installing a corrupted binary. It doesn't do anything against intentional alterations of the binary though. These hashes need to be stored on an external site)? - How did the compromise happen? - what steps were taken to ensure that the same compromise doesn't happen to new binaries posted? - Did the attacker leave any foothold on the compromised system(s)? - How were such footholds removed? All questions that need to be answered before it's safe to upgrade transmission either from the website or with the AutoUpdate feature. A red warning telling me that one binary was infected and that I have to download another binary isn't good enough. I know the transmission people are volunteer developers and no PR people and I can totally accept that, but there's some things that just need to be made clear before we can safely update to later versions (and thankfully, 2.8 keeps running just fine)
- gwbas1c 11y agoIt will probably take time to get all of the answers, but in this case, automatic updates are safe. Although I'm not a Transmission developer, I develop software that uses the same automatic update mechanism. It appears that the hacker did not update the MD5 present in the automatic update mechanism. (Sparkle) Thus, when the automatic update mechanism downloaded the hacked version of Transmission, it reported it as a corrupted download. You can see the comment here: https://forum.transmissionbt.com/viewtopic.php?f=4&t=17834#p73036 https://forum.transmissionbt.com/viewtopic.php?f=4&t=17834#p...
- pilif 11y ago> It appears that the hacker did not update the MD5 present in the automatic update mechanism. (Sparkle) Thus, when the automatic update mechanism downloaded the hacked version of Transmission, it reported it as a corrupted download yeah. But not knowing how the attacker got access, we have no idea whether they have changed the current 2.92 binary again, this time remembering to update the hash in the appcast or whether this time around the binary is actually pristine. The fact that the site was never down between this happening and the red warning text appearing makes me suspect that only a hasty cleanup was performed and that the actual security flaw might still exist.
- pjf 11y agoany reason why it's correlated with dht.transmissionbt.com loosing its AAAA record? it's the only IPv6 DHT bootstrap node on the Internet
- zZorgz 11y agoThis is really bad but there are two good security defenses that came out of that forum thread (which is better than not having them at all). 1. Apple revoked the certificate already. Thus people that have gatekeeper on are safer. 2. Sparkle (for auto updater) denied the malware infected update. Thus downloading from the main website is not necessarily safer, even with the recent mitm sparkle vulnerability.
- thrillgore 11y agoI checked my version of Transmission and i'm still on 2.84. I guess I dodged a big bullet, but tonight i'll go through the diagnostics to see if any versions prior to 2.90 were infected. I may do it sooner if I get a quiet moment at work. I'm also running the usual litany of tools to check for activity (Wireshark on my WAN Tap, Anti-virus, etc) My Synology NAS uses transmissiond for its BT Client, so I will be contacting them to see if they are affected by this issue.