Hi Chesty,

There is one flaw with this.  How many people read and run attachments as
root?  Not many that I know of.  Yes it is possible to write something
which replicates itself, but it can do no more damage than to remove all
the files that have been created by the user, as opposed to wiping the
entire disk.

Do the same on Windows (95,98, NT? 2000?) however, and you better find the
god of returning obliterated data because you'll need him when everything
goes byebye.

As a side point, I have two questions relating to WinNT/2000 regarding
obliterating things:
1) On a default install, can a non-administrator user wipe out the WinNT
dir?
2) Are you able to change everything in WinNT\System32 and most files in
WinNT\ to be read only to any non-admin user.  Would this affect how NT
runs?

Not that it does much, because my NT user account at work is in the Admin
group due to the nature of my job.  Although I try not to run unsolicited
attachments where possible :-)

Cheers,
Kieran



On Sun, 7 May 2000, chesty wrote:

> > > > Hmm, wonder if the disgruntleds will sue. :-)
> > > 
> > > Who?
> > > Really self inflicted isn't it?
> > > They've know about this situation for years in earlier MS mailers, but
> > > they've failed to develop correct procedures and train staff.
> > 
> > But seriously, folks, what we've all known for years is:
> > 
> > - Take a copy of [.*]x out of the box, install it, and the binary files in
> >   /usr/bin, /usr/lib, /lib, etc, are world readable, and not world writeable.
> >   Joe Average User can't launch a virus that writes to a system DLL.
> 
> But you don't need write permissions to libs and bins to write a
> replicating email virus/worm.
> Its been mentioned a few times, the problem is as much about
> uneducated users as about the OS.
> 
> What if pine detached and ran any shell or perl attachments 
> automatically, or even if it didn't, what if it was normal 
> practice for the users to launch any attachments received via 
> email?
> 
> Someone could write a script that emails the virus/worm to everyone 
> in your address book, /etc/passwd, and searched through your
> home directory for any email addresses, and append a line to 
> .bashrc (perhaps theres a better place which is more portable?) 
> to do it every time you log in.
> 
> You would have to write portable code, etc, but its still possible 
> if unix users had unsafe email applications or practices.
> 
> 
> -- 
>       chesty
> 
> --
> SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> To unsubscribe send email to [EMAIL PROTECTED] with
> unsubscribe in the text
> 

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to