RE: [Full-Disclosure] Re: Administrivia: Testing Emergency Virus Filter..

From: Drew Copley (dcopley_at_eeye.com)
Date: 08/21/03

  • Next message: Gaurav Kumar: "[Full-Disclosure] Google Private IP is 10.7.0.73 !!!!!!"
    To: <full-disclosure@lists.netsys.com>
    Date: Thu, 21 Aug 2003 11:01:29 -0700
    
    

    > -----Original Message-----
    > From: Gary E. Miller [mailto:gem@rellim.com]
    > Sent: Wednesday, August 20, 2003 5:38 PM
    > To: Drew Copley
    > Cc: full-disclosure@lists.netsys.com
    > Subject: RE: [Full-Disclosure] Re: Administrivia: Testing
    > Emergency Virus Filter..
    >
    >
    > Yo Drew!
    >
    > On Wed, 20 Aug 2003, Drew Copley wrote:
    >
    > > I don't know how that guy thought that the smtp client
    > portion of this
    > > code was an OS issue... How that is OS design. I don't know
    > why such
    > > people would be offering their opinion on this.
    >
    > The difference is this between and secure OS and an insecure one.
    >
    > On an Insecure OS, the virus gets in. glues itself on
    > anywhere in the machine. Maybe it attaches to a boot sector,
    > maybe appends itself to a system file, edits registry, maybe
    > all the above and a lot more, whatever. User logs out, the
    > virus still runs as admin or root.
    >
    > Some virii even have hooks to turn off personal firewalls in
    > an insecure OS.
    >
    > On a Secure OS, the virus can only write to the (normal)
    > users home directory. Easy to find. Easy to delete. Virus
    > can not write to registry, boot sector, system directories,
    > etc. Then when the user logs out his processes are
    > terminated or he is warned of something still running. So
    > virus does not continue after log out.
    >
    > On a secure OS, the (normal) user can not edit the personal
    > firewall setting so the cirus can not bypas that easily.
    >
    > Very secure OS can add even more restrictions on what a user
    > can do. Like prevent the user from running daemons, bots, etc...
    >
    > The makes a huge difference in how easy it is to be infected,
    > how easy it is to detect infection and how easy to disinfect.

    Yes, now, in these regards, this is true and accurate, thanks.

    As far as software goes, I would not argue that the personal firewall
    could be not bypassed, as there really is not such a system yet which
    protects against process injection and other hooking techniques... Well,
    except for some linux tools like systrace. (Granted, tools on Windows
    like securewave could, but that prevents anything untrusted from
    running).

    So, it is difficult to separate, but I believe the OS should be
    seperated from the software which runs on it... Which brings us back to
    secure class ratings, which your post hints at and which I believe is an
    excellent standard as to "how secure our OS" is. (Common Criteria
    ratings: http://www.commoncriteria.org/docs/aboutus.html).

    >
    > RGDS
    > GARY
    > --------------------------------------------------------------
    > -------------
    > Gary E. Miller Rellim 20340 Empire Blvd, Suite E-3, Bend, OR 97701
    > gem@rellim.com Tel:+1(541)382-8588 Fax: +1(541)382-8676
    >
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Gaurav Kumar: "[Full-Disclosure] Google Private IP is 10.7.0.73 !!!!!!"

    Relevant Pages

    • RE: [Full-Disclosure] Re: Administrivia: Testing Emergency Virus Filter..
      ... On Wed, 20 Aug 2003, Drew Copley wrote: ... The difference is this between and secure OS and an insecure one. ... User logs out, the virus still runs as admin or root. ...
      (Full-Disclosure)
    • Re: Opinion: I was just trying to sell OpenVMS
      ... and the open internet and you can run whatever platform you like. ... Anybody that thinks that windows is secure, will indeed be getting a very nasty surprise. ... M$ windows is insecure and security was never part of the original design. ... Got a virus right off the bat within a 1/2 hour. ...
      (comp.os.vms)
    • RE: [Full-Disclosure] Re: Administrivia: Testing Emergency Virus Filter..
      ... > The difference is this between and secure OS and an insecure one. ... User logs out, the virus still runs as admin or root. ...
      (Full-Disclosure)
    • Re: Symantec releases "demo" OSX virus
      ... concept virus that infects files in the current folder on the ... The fact is, OSX isn't "secure", as evidenced by the constant Security ... with Symantec for virus protection products. ...
      (comp.sys.mac.advocacy)
    • Re: Symantec releases "demo" OSX virus
      ... concept virus that infects files in the current folder on the ... The fact is, OSX isn't "secure", as evidenced by the constant Security ... with Symantec for virus protection products. ...
      (comp.sys.mac.advocacy)