Welcome | Sign In
LinuxInsider.com
News

iPod Proof-of-Concept Virus: No Teeth, No Legs

Print Version
E-Mail Article
Reprints
iPod Proof-of-Concept Virus: No Teeth, No Legs

Podloso, the iPod proof-of-concept virus discovered by Kaspersky Lab, doesn't amount to a significant threat, since it can't spread and it affects only Linux iPods. However, it hints at dark days to come for fans of the popular music and video player if more-insidious types of iPod malware should be developed.


It was only a matter of time before someone developed a proof-of-concept virus aimed at the iPod. Discovered by Kaspersky Lab, the virus is a file that can be launched and run on an iPod.

The good news for the majority of iPod users is that Linux must be installed on the device for the virus to function; iPods running Linux are a decidedly smaller subset. If the virus, dubbed "Podloso," should manage to latch onto such an iPod, it would install itself in the folder that contains the program demo versions.

Once launched, according to Kaspersky Lab, the virus scans the device's hard disk and infects all executable .elf format files. When the user tries to access these files, a message is displayed on the screen that says, "You are infected with Oslo the first iPodLinux Virus."

Podloso is a typical proof-of-concept virus, according to Kaspersky, created in order to show that it is possible to infect a specific platform. Like most of the ballyhooed mobile phone viruses, Podloso is unable to spread.

Eroding Aura

Still, its emergence is disconcerting to Apple (Nasdaq: AAPL) users who have watched the company's reputation for impeccable security become sullied over the past 18 months or so.

In 2006, the first worm targeting its iChat messaging system surfaced. Later, users were less than enchanted by revelations of Safari vulnerabilities.

iPods were the next Apple product to be visited by security woes. Last year, a small number of video iPods produced after Sept. 12, 2006, were reported to be harboring the RavMonE virus.

It didn't harm the iPod, but it theoretically could have affected Windows PCs when the device was plugged into a PC. Though Apple issued a formal apology for the glitch, it also pointed a finger at Microsoft (Nasdaq: MSFT).

The Next Vector

In general, USB (universal serial bus)-based devices are an accident waiting to happen, said Paul Henry, vice president of technology evangelism at Secure Computing.

"What is happening with the iPods does not surprise me," he told MacNewsWorld. "There have been a number of different threats emerging over the last few years in this area."

These threats -- software programs or hacking tools -- either target the USB port or the PC as a vector for malware and leave a company vulnerable to Sarbanes-Oxley violations or the mishandling of consumer data.

"Hacking tools are being devised so if you can get physical access to a PC in a network you can wreak all kinds of havoc without leaving a trace," Henry said.


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Salesforce.com Spreads Chatter to Mobile Devices
September 08, 2010
Salesforce.com is giving its Chatter business networking app some legs, with versions tailored for a variety of mobile devices set to come out later this year and early in 2011. Chatter acts a lot like Facebook, but its purpose is to facilitate collaboration through feeds that keep employees up to date on projects, prospects and accounts.
Sparks Already Flying as Oracle Brings Hurd Into Fold
September 07, 2010
HP reportedly has already initiated legal action against its former bad-boy CEO Mark Hurd -- who has been named a co-president of Oracle -- citing violation of a provision in Hurd's exit agreement. That's not likely to be an insuperable barrier to Oracle's plans for its newest exec, but Hurd may be bringing other baggage with him that could be more problematic.
Rabid Consumer Watchdog Attacks Google CEO
September 03, 2010
Consumer Watchdog has created quite a stir with its Times Square jumbotron attack ad depicting Google CEO Eric Schmidt as a child predator. The so-called lampoon is designed to provoke outrage against Google's perceived privacy intrusions, but some viewers may find the privacy group's tactics even more outrageous.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Secure Your Online Business
Save 50% with Entrust SSL Certificates
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network