chesty wrote:
>
> > > > Hmm, wonder if the disgruntleds will sue. :-)
> > >
> > > Who?
> > > Really self inflicted isn't it?
> > > They've know about this situation for years in earlier MS mailers, but
> > > they've failed to develop correct procedures and train staff.
> >
> > But seriously, folks, what we've all known for years is:
> >
> > - Take a copy of [.*]x out of the box, install it, and the binary files in
> > /usr/bin, /usr/lib, /lib, etc, are world readable, and not world writeable.
> > Joe Average User can't launch a virus that writes to a system DLL.
>
> But you don't need write permissions to libs and bins to write a
> replicating email virus/worm.
The major issue with IL***Y** as opposed to M*l*ss* is that it not only
replicates through your e-mail system, but it stuffs with your files as
well. This includes the registry and certain system DLLs, as well as any
JPGs, etc, that it finds on your machine as well as the network.
It's not possible for a Unix virus run by an uneducated unprivileged
user to write to system ld.so's (barring some kind of buffer overflow or
similar attack).
Yeah, sure, I can write a perl script that reads your netscape address book,
and e-mails itself to everyone in the address book, and then include a note
saying "please run this perl script" in the e-mail, but the damage will
be limited.
----+------------------------+--------------------------
Del | mailto:[EMAIL PROTECTED] | Christchurch, New Zealand
----+------------------------+--------------------------
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text