I roll my eyes every time I see the announcement of a new "Mac OS X Trojan". Only the idiots who download illegal crap from filesharing sites are at risk, and the fact that it's another OS X "Trojan" is so misleading: anything can be a Trojan if you want it to.
#!/bin/sh
echo "Hi! Welcome to MyAwesomeProgram's installer. Please enter your password to begin the installation:"
sudo rm -rf /
Save that in a file, name it MyAwesomeProgram, and put it on a web server. Anyone who downloads, executes it that has sudo privileges to rm will have their root wiped out. I've just created a Unix Trojan! Once you manage to convince someone (with the help of social engineering) to give you an administration password, any 'vulnerabilities' of the OS can now be considered invalid, since anything with root can pretty much do whatever the hell it wants.
John A
Vampirical Lurker
7,633 posts since Apr 2006
Reputation Points: 2,233
Solved Threads: 340
Skill Endorsements: 7