Re: Can Windows attack my Linux

From: prg (rdgentry1_at_cablelynx.com)
Date: 01/10/05


Date: 10 Jan 2005 09:10:11 -0800


Ray Green wrote:
> I currently only use Linux and do not possess Windows in any shape or
form.
>
> However, I intend to get a new pc with two drives, one for Linux and
one
> with Windows XP which my job needs because I occassionally need to
boot
> Windows to run Internet Explorer to view a couple of websites I look
after.
> I don't want to waste effort and money keeping XP patched up but am
> concerned that if XP gets infected with something nasty it can
destroy my
> Linux installation. Is this a real concern and if so what can I do to
> protect myself?
>
> (I'm not bothered if XP destroys itself because I'll just reinstall
it)
[and overwrite the MBR _every_ time :( ]

Any -- that's _any_ -- computer connected to the internet needs to be
protected for both your protection, the protection of the computers you
connect to and for the rest of us, as an unprotected XP box would make
a great platform for laundering/launching attacks onto the net. Where
do you think all your spam comes from?

As others have said there are cheaper/better(?) solutions, but you may
want/need a new machine just to treat yourself ;-)

XP's SP2 includes a (wholesale?) reworking of the firewall (now called
WF -- Windows Firewall) and it's a pretty decent _host_ fw. Disables
the UPnP announcements, is statefull, allows much better management of
packet filtering rules, and used in conjunction with a network fw --
you are using one aren't you? -- would go a long way to protect
youself. If not pre-loaded insist they include an SP2 CD so you don't
have to download and burn your own copy.

To avoid the temptation of using XP's IE to do some surfing, only allow
outgoing http traffic to the _sites_ you _need_ to work with and
disallow _all_ other outgoing connection attempts (except for DHCP and
maybe DNS). Do _not_ allow _all_ IE based traffic out by using the App
Allowed Exceptions.

Incoming connection attempts are automatically (default) blocked, but
double check that your changes have not opened a hole.

Also, there is _much_ better, customizable logging with the new fw so
you can monitor yourself (and your box).

Firewall links:

http://www.microsoft.com/technet/community/columns/cableguy/cg0104.mspx#EHAA
http://www.microsoft.com/technet/community/columns/cableguy/cg0204.mspx
http://support.microsoft.com/default.aspx?scid=kb;en-us;886185

BTW, this is not an ad for MS or advocating that you go this route --
strictly background so you know what's up. Personally, I wouldn't
trust IE/Outlook even disconnected from the net.

But whatever you do, don't connect a Win box on the net without some
protection. There's enough spam out there already ;-)
hth,
prg
email above disabled



Relevant Pages

  • Re: Browser security under Linux
    ... Explorer 7 on Windows Vista has a distinct advantage in protecting ... And no browser on Linux can write to any file / directory for which the user ... Vista provides compile- and run-time protection ...
    (comp.os.linux.misc)
  • Re: Antivirus in FC3?
    ... > Does linux really need antivirus? ... > the protection of the windows box. ... Virus protection by the Windows definition is not really needed except ... package that can run on Linux for this purpose. ...
    (Fedora)
  • Re: Virus Checker Question
    ... In alt.os.linux Peter T. Breuer: ... > linux, filtering mail of WINDOWS malware and checking WINDOWS partitions ... protection, if he insists on using the crap. ...
    (alt.os.linux)
  • Re: base line XP kernal protection and folder protection, any?
    ... The windows protection is the "DLLCACHE protector engine built into the ... It protects the kernel but there are a few viruses that can attach this ... Just 1 week class in Linux kernel design and then windows will show you ...
    (microsoft.public.security)
  • Re: Future of IT in Lebanon
    ... working knowledge of Indian programmers DNA, nor of their intuitive Java ... > So Longhorn is not an experiment and Linux is an experiment? ... another chapter in the Windows story, and the Microsoft marketing machine is ... > application opens, Check the about, it says Microsoft Visual Basic 6.3. ...
    (soc.culture.lebanon)

Quantcast