ZDNet is covering the emergence of iAdware, a “proof of concept” malware that was sent to Finnish security company F-Secure. Moral implications aside, one of the more-interesting issues presented by this “application” is that it doesn’t require the user to provide a password or otherwise give it permission to install itself.
“We won’t disclose the exact technique used here, it’s a feature not a bug, but let’s just say that installing a System Library shouldn’t be allowed without prompting the user,” according to the F-Secure blog on Thursday. “In theory, this program could be silently installed to your user account and hooked to each application you use. This particular sample successfully launched the Mac’s web browser when we used any of a number of applications.” More …