OompaLocker 1.0 is Available--Are Oompa Loompa Trojan Horse Remedies Really Needed?
A simple AppleScript front-end to Terminal actions that change the permissions on the user InputManagers folder to root only. This should prevent Leap-A (a.k.a. "Oompa Loompa") malware and its derivatives from installing. Released free under the GPL. Source code available.
But has the Oompa Loompa Trojan horse (aka Leap-A) been overrated? Yesterday, we posted a link to a Q&A by Intego and here is Symantec's Web page covering it. Both would lead one to believe that Oompa Loompa disables Mac OS X native applications and that it can be easily sent to one's friends via iChat to visit its misery on them. That might be enough to cause many prudent Mac OS X users to rush out and buy their products which they claimed had been updated to protect against the Oompa Loompa Trojan horse.
Rob Griffiths tested Oompa Loompa (Leap-A) with a colleague on their Macs. They reported their results on this Macworld Web page. First, they found that cocoa-native application disability is limited to applications "owned" by the user. Second, it propagated by iChat only under very limited and unusual circumstances. Based on their tests, we would say that the threat of damage posed by the Oompa Loompa Trojan horse has been vastly overrated. There is, however, still a threat.Still, w We believe it's worth knowing about, looking out for and taking measures to prevent damage. [Bill Fox]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?