security not a problem? was Re: 5 business advantages of Linux Kernel

Gerhard Mack (gmack@imag.net)
Tue, 22 Sep 1998 19:12:05 -0700 (PDT)


On Tue, 22 Sep 1998, Etienne Lorrain wrote:

> > I would like your opinions on the 5 most desireable business advantages
> > of the Linux Kernel for an upcoming book.
>
> I still wonder:
> Could someone selling you the package "editor + mail
> reader + WWW browser + operating system + network stack
> + firewall" put a backdoor in your computer(s) to:

It's always important to only purchase products from reputable companies.

> - remote control or remote crash it, or generate malfuctions,
> on all the computer of a temporary unfriendly company.

Back Orifice for windoze

> - redirect temporary save of your documents onto the network
> instead of the local disk (an infortunate bug, the destination
> I.P. been a random computer in whatever unknown country) if:
> - the document contains words: patent, shares, $<number>
> with <number> greater than 100,000
> - the mail reader identifies the owner as a "director of
> something"
> - the internet browser shown that more then 100 Kbytes
> are tranfered every day, mostly using WWW - so the
> unfortunate bug encapsulate data onto valid HTTP
> requests.
> - There is only one operating system on the computer,
> and nobody is watching the network (Winmodem?)
> - add whatever you want there, pgp-crypt if you want.

back orifice ..

> - redirect some mail - unfortunate bugs in the mailservers...
>
> I also still wonder why there is no more new viruses
> on the market - what are the old virus programmer doing
> and where are they ? It should be quite easy to attack
> a system which is completly standardized.

Where have you been the past year ?

All for windows:

script.ini file used my mirc irc client for windows auto sends itself
script.ini2 same only it deltrees your hd when you try to remove it
dmsetup trojan auto-sends itself using it's own version of script.ini
dmsetup2 same only it change names randomly
Back Orifice trojan www.cultdeadcow.com "remote system administration
tool"

> Ok, I am looking too many science fiction films,
> security is not a problem and has never been a feature.

The danger always has and always will be there, but Linux makes it a lot
harder. Nothing is ever 100% especially where user stupidity is
concerned.

Gerhard

--
Gerhard Mack
irc-admin skyline.starchat.net
	
gmack@imag.net
InnerFIRE@starchat.net

As a computer I find your faith in technology amusing.

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/