On The Insider: Taylor Swift Blushes on Ellen
BNET Business Network:
BNET
TechRepublic
ZDNet

January 27th, 2009

Little Snitch tattles on trojans

Posted by Jason D. O'Grady @ 8:32 am

Categories: General

Tags: Software, Apple Macintosh, Network, Window, Trojan Horse, Spyware, Spyware, Adware & Malware, Construction, Viruses And Worms, Desktops

Network MonitorIn case you missed it, your Mac may be under attack. Especially if you have a taste for downloading Mac software that isn’t exactly, ahem, legal.

Last week I reported that a trojan horse called “iWorkServices” has was found in a pirated version of iWork ‘09 floating around on BitTorrent. Yesterday it came to light that another trojan has been found in a pirated version of Photoshop CS4.

Whether you play fast and loose with your software licenses is on your conscience (I certainly don’t recommend it) but one way to keep tabs on software that likes to call home is with Objective Development’s Little Snitch 2.0 ($29.95). I hadn’t used it since version 1 and the recent rash of Mac trojans gave me a prefect excuse to try v.2.

Little Snitch informs you whenever a program attempts to establish an outgoing Internet connection. You can then choose to allow or deny this connection, or define a rule how to handle similar, future connection attempts. This reliably prevents private data from being sent out without your knowledge. Little Snitch runs inconspicuously in the background and it can also detect network related activity of viruses, trojans and other malware.

Once installed you’ll be amazed at all the things on your Mac that connect to the Internet in the background. Most of them probably have your approval, like all the apps that you allowed to “check for updates at startup?” and things like Software Update, dotmacsyncclient and Bonjour’s mDNSresponder. Those ones are safe to “allow” but if Little Snitch asks for approval for something unknown, deny the request then Google the name to see if it’s kosher.

Be warned though, the first time you install Little Snitch, you’ll be inundated with allow/deny requests and it can be exhaustive. (Hint: you can confirm an alert with Command-Return, Control-Return and Return-Escape). Clicking the Forever button helps you ignore approved outbound connections and it’s a small price to pay to be able to keep tabs on potentially malicious code.

A new Network Monitor feature (pictured) has been added in version 2 which alone is worth the price of admission. The beautifully designed window displays detailed information about all of the incoming and outgoing network traffic on your Mac. It only pops up when connections are active unless you check the small “stay visible” box at the top of the window. I find myself leaving the Network Monitor window visible and watching in awe as the packets flow by. If you decide to close it a subtle menu bar item will also keep you apprised.

Nice, tight bit of code. Highly recommended.

Jason D. O'GradyJason D. O'Grady is the editor of PowerPage.org, which has been publishing daily mobile technology news since December 1995. For disclosures on Jason's industry affiliations, click here or to view Jason's full profile click here.

Email Jason D. O'Grady

Subscribe to The Apple Core via Email alerts or RSS.

  • Talkback
  • Most Recent of 18 Talkback(s)
not as cool
As Zone Alarm. Much better name, imo. Wow, it's for a PC. I just
exploded your brain, didn't I?

Windows, Mac and Linux fanboys alike fail at life.... (Read the rest)
Posted by: homant@... Posted on: 02/18/09  (Edited: 02/18/09 @ 11:27) You are currently: a Guest | | Terms of Use
So no trojans in non pirated OS X software?  NonZealot | 01/27/09
Not in any reputable companies software.  Win3.1 | 01/27/09
Then there is no reason to switch any more  NonZealot | 01/27/09
It is not just the infected user that pays  Michael Fournier | 01/30/09
It's ignorance not stupidity  Neutron Man | 01/30/09
Very droll  Neutron Man | 01/30/09
RE: Little Snitch tattles on trojans  Samic | 01/27/09
Unlike Vista's UAC  MyMac | 01/27/09
Err...  Sleeper Service | 01/27/09
Then it's not ver useful  honeymonster | 01/27/09
Re: Then it's not ver useful  PottHead | 01/27/09
RE: Little Snitch tattles on trojans  Ian.Betteridge | 01/27/09
So it works a almost like Vistas built-in firewall then?  honeymonster | 01/27/09
Today it's in pirated software, tommorrow...  Narg | 01/30/09
No reason to change?  geekbrit | 01/30/09
RE: Little Snitch tattles on trojans  whitecat | 01/30/09
not as cool  homant@... | 02/18/09
Back in the last Century  techrepublic@... | 01/30/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here