On Sun, May 07, 2000 at 03:59:03PM +1000, Rachel Polanskis wrote:
> On Sun, 7 May 2000, chesty wrote:
> 
> > I think the potential for a replicating linux email virus is there, but at
> > the moment we're projected by the number of linux users and their high education.
> 
> 
> It would not be hard to write a script in shell that executed 
> changing your environment variables around and then force loaded 
> shared libraries that contained passwd sniffers or whatever 
> if you loaded netscape or whatever.
> 
> What makes it less dangerous is that it can't damage the system, 
> only files owned by the user and of course on UNIX systems 
> there is no c:\windows\system that can be exploited. 

There is no c:\windows\system on Windows _NT_. Let compare apples to apples
here. Windows NT claims to have as good as, if not a better, security model
than Unix (and therefore Linux).

> 
> Also it would presume that all "address books" would be in the 
> same format and called the same thing.  You would have to write 
> a script for pine, mutt, elm, dtmail and postilion as well as the 100 
> or so other mail clients out there as well

So you see the Unix advantage is that there is no dominant way to specifying
addressbooks? Someone sufficently motivated could write converters for these.

I think you'll find that the formats break down into only 5 (or 6) different
styles. 

> as working out how to hack 
> into sendmail to spoof itself and so on. 

Sendmail is dominant in the Unix world; determining a means to sabotage it
would be enough.

> The problem in the MS world is it's homogenised application chain 
> which solely depends on the presence of certain linkages via 
> OLE or whatever they call it these days which allows the virus 
> unfettered access to the system.

You write eloquantly but I don't believe you are writing from experience here.
MS's applications depend on certain DLLs (equivalent to Unix .so's) to exist
but many Unix programs depend on various libraries to exist (e.g. libXt).

The problem has nothing to do with OLE or the fact that Office/Outlook are
widely used.

>  Of course on a multiuser (sic) 

multiuser is spelt correctly ...

> NT system the problem escalates as programs like exchange have no defence 
> against such a bug.  

that would be because Exchange is not suspectible to this bug; this is an
MUA (Mail User Agent) issue.

> UNIX has it's security problems but they are more often 
> easily defended against on a well run system but a typical windows box 

Any security issue is easily defnended against on a well run system. It
just so happens Unix machines are, typically, more well run than Windows ones.

> is wide open by default and nearly always in it's production role.

I don't believe this is correcty wrt to Windows NT.

Anand

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to