Re: Why are there few viruses for UNIX/Linux systems?

From: /dev/rob0 (rob0_at_gmx.co.uk)
Date: 08/16/03


Date: Sat, 16 Aug 2003 09:51:19 -0700

In article <5ef%a.1003$N37.912@nwrdny02.gnilink.net>,
  Nico Kadel-Garcia wrote:
>> http://www.linuxmafia.com/~rick/faq/#virus
>
> Unfortunately, that analysis tells a few serious lies, namely:
>
>> Any program on a Linux box, viruses included, can only do what the user
>> who ran it can do. Real users aren't allowed to hurt the system (only
>> the root user can), so neither can programs they run.
>
> This is, of course, not true. The damage a non-root user can do is much,
> much, much less. But by abusing unsecured setups and by exploiting
> not-yet-patched-on-that-machine holes, it's often possible for a skilled
> attacker to gain root privileges.

I believe I understand your distinction, but I do not see how it makes
the quote above untrue. In essence IIUC you're saying that a virus would
enter as non-root, at which point it or a human attacker would have to
find and exploit a second, unspecified vulnerability.

Even at its worst, this doesn't sound that bad. Whereas on Windows a
single vulnerability can destroy the OS, here it takes at least two,
possibly with human assistance required.

Can you explain where is the "serious lie" above? In the phrase:
    Real users aren't allowed to hurt the system
I read "system" to mean "reasonably well-configured system," and ISTM to
hold true. Do you think that all or most Linux systems have known,
exploitable weaknesses? I doubt it. At least I hope mine do not. :)

I think the most damage a non-root user's processes could hope to
inflict would be a DoS. There are numerous ways in which this might be
done, but even many of those can be prevented with fs quotas and process
restrictions.

> It's vastly *easier* to do that under
> Mickey$oft^H^H^H various other OS's, but being Linux doesn't make it
> impossible.

Of course not. If it was impossible we wouldn't need this newsgroup. :)

One thing worthy of mention is that although privilege restrictions may
prevent the destruction of the OS, a Linux virus could be every bit as
painful to the user as a Windows one. If I lost all my $HOME files, the
fact that the OS is intact would provide little consolation. I don't
bother to back up the OS other than /etc, because I know I can easily
reinstall it. $HOME is what matters.

Nonetheless I doubt we'll ever see a serious Unix virus problem. The MS
world is dominated by marketing, and as a result they get software like
Outlook Express and Office: insecure OOTB and difficult to secure at
all. We'll probably never fall under that kind of control, so our
software is less likely to develop in such directions.

-- 
  /dev/rob0 - preferred_email=i$((28*28+28))@softhome.net
  or put "not-spam" or "/dev/rob0" in Subject header to reply


Relevant Pages

  • Re: what does "serialization" mean?
    ... Randy provided, in commonly accepted fashion, the information you ... why should I let your lies stand? ... > Microsoft software, and not incompatible versions of Linux. ... a large number of businesses are turning to Linux to provide ...
    (comp.programming)
  • Re: Linux on Laptop?
    ... proprietary Linux C compiler outperforming gcc on many code ... There are a lot of "consumer level" scanners that SANE doesn't support ... When Joe User buys a Foobar 300 scanner for $49.99 at Wal-Mart, ... Three kinds of lies: ...
    (comp.os.linux.misc)
  • Re: How many Linux Users in the World?
    ... Now watch the lies from Tweedledee and Tweedle Dum Dum along with their usual insults and profanity. ... Linux has doubled from a little under one per cent to over 2 per cent. ... a far cry from your lame assertion that nobody uses Linux. ...
    (microsoft.public.windows.vista.general)
  • Re: Mac OS X v10.4 Tiger - Anything similar on Linux
    ... >> I used a Mac for the first time in many years, ... Are there any similar Linux based OS's? ... Well, OO2 is not even out yet, but if you really want to get past the lies ... of a Mactard... ...
    (comp.os.linux.misc)
  • Re: Linux is garbage compared to Windows. It cant even be given away for free!
    ... Varicad is supposedly one of the better programs supporting Linux, ... Senator Waxman's searchable database of iraq war lies. ... A good portal to more lies and Bush stupidity is to be found at ... himself with fellow liars. ...
    (alt.os.linux)

Quantcast