Re: Mac OS Trojan, will this affect Linux?



David Bolt wrote:

On Fri, 17 Feb 2006, houghi <houghi@xxxxxxxxxxxxxxxxxx> wrote:-

David Bolt wrote:
Since that's apparently how most of the Windows "viruses" are caught,
there's bound to be some users that swap over to a Linux system and
follow the same procedure. Luckily, it'll take a little more than a
simple double-click-to-run-and-you're-screwed to get a Linux system but,
in some cases, not a great deal more.

People have been asked to unpack a zipped file, enter a password and
excecute the code.

Social engineering can do all sorts of things. In this case, quite often
the files they were asked to execute had an embedded icon to make it
look like a "safe" file[0]. Combined with the wonderfully "friendly"
hide-known-extensions[1], makes it easy for people who are not paying
too much attention, or just don't know about this wonderful "friendly
feature," to open up something that they shouldn't.

I don't, if I haven't asked for an attachment it goes straight in the bin,
and if there is an attachment I requested, I open by opening the program it
should be used in, with script execution turned off - after first virus
checking it.

Any system will be vurlerable to such abuse,
including Linux.

True. But it's still going to be a bit of extra work to make it work on
multiple distributions. Actually, thinking about it, compiling any
"virus" as a static program and using i386 as the base architecture and
processor type, should ensure it will run on the maximum number of Linux
systems. All that would then be required would be an exploit that gives
root access and/or a bit of social engineering.

As houghi said, you can do it with a simple bash script, it isn't rocket
sceince and it isn't platform dependent.


[0] So far, the most common icons are used for JPEG or DOC, which are
assumed by most people to be safe.

[1] Which, even if you turn off, still hides some extensions used by
"executable" files. Showing these requires a registry hack, with all the
dire warnings that accompany such a procedure.
<snip sig>

I assume when you are talking registry you are referring to Windows, as OS X
is Unix based, so I would assume it doesn't have a registry... In Windows
showing file extensions can be turned on with an option from the Explorer
window, Tools-Folder Options->View (Ansicht on my German Windows) and
uncheck the "Erweiterungen bei bekannten Dateitypen ausblenden" (Hide
extensions for known file types )

Dave

--
"I got to go figure," the tenant said. "We all got to figure. There's some
way to stop this. It's not like lightning or earthquakes. We've got a bad
thing made by men, and by God that's something we can change."
- The Grapes of Wrath, by John Steinbeck
.



Relevant Pages

  • Re: Haze Gray and Underway - Trojan Warning
    ... Registry, who uses an operating system with a registry? ... group of UNIX/Linux guys working on a server product that interfaces with Exchange 2007. ... When PC's came along we ported to SCO Unix and Linux. ... to run Windows XP and Windows 7 because my customers demand it. ...
    (sci.military.naval)
  • Re: [SLE] Partition Magic vs. Linux partitioner
    ... drive is multiboot it only boots it is a LINUX system only ... and was created as a LINUX system. ... 2.the Windows partition is larger than about 8 GB (more ...
    (SuSE)
  • Re: emulate Registry of WIndows in Linux
    ... Registry on Linux or your idea of having Central registry on Linux.Can we ... emulate registry of Windows on Linux? ...
    (comp.os.linux)
  • Re: square bullets
    ... are from people who DON'T READ MANUALS OR HELP FILES. ... WAAAAY easier to maintain and operate than Linux GUIs. ... Ever try to fix a Windows registry problem? ...
    (sci.electronics.design)
  • Re: Security using VMs
    ... Being new to linux, I am somewhat concerned about security too - I do not want to bring Windows holes into my linux system. ... I've setup Sun VirtualBox and WinXP Pro as a guest, updated it to SP3 and all the rest of its million security fixes and completely disabled any access to the internet for the VM - all I need is to be able to edit my old CorelDRAW files, as I do my new stuff in Inkscape now... ...
    (uk.comp.os.linux)