Results 1 to 9 of 9

Thread: Ubuntu desktop not much more secure than Windows?

  1. #1
    Join Date
    Dec 2012
    Beans
    0

    Question Ubuntu desktop not much more secure than Windows?

    A buddy of mine sent me this YouTube vid as prove that Linux is just as vulnerable to malware as Windows, but wouldn’t you be asked for root access by the system to run this script or at least get a warning message? Is the demo clearly rigged?

    http://www.youtube.com/watch?v=9HxFGQ8OpYw

  2. #2
    Join Date
    Jun 2011
    Location
    The Shadow Gallery
    Beans
    6,744

    Re: Ubuntu desktop not much more secure than Windows?

    it is a demonstration of privelege escalation through exploitation of the .desktop file.

    This is well known

    you can read more info here http://www.geekzone.co.nz/foobar/6229

    All end user OS are only as secure as their user, no end user OS is "secure" they are all roughtly EAL4 by common criteria making them all usable and functional and secure with reason, anything more and they lose function or usability.

    As a whole Linux is not as susceptible to "malware" as Windows but it is not immune. However malware is often nuisance based and not necessarily exploitation based and one of the many methods of gaining access to a system.
    Last edited by haqking; January 10th, 2013 at 10:41 PM.
    Backtrack - Giving machine guns to monkeys since 2006
    Kali-Linux - Adding a grenade launcher to the machine guns since 2013

  3. #3
    Join Date
    Jun 2010
    Location
    London, England
    Beans
    Hidden!
    Distro
    Ubuntu Development Release

    Re: Ubuntu desktop not much more secure than Windows?

    1) Do not let anyone pack your suitcase for you when returning from a trip abroad.
    2) Do not carry anybody else's stuff through customs.
    3) Do not open email attachments from anyone you do not trust.
    4) When someone says it is impossible, don't believe them. Generals who assume that something is impossible usually lose the battle.

    Regards.
    It is a machine. It is more stupid than we are. It will not stop us from doing stupid things.
    Ubuntu user #33,200. Linux user #530,530


  4. #4
    Join Date
    Feb 2011
    Location
    Columbus, OH
    Beans
    119
    Distro
    Kubuntu 12.04 Precise Pangolin

    Re: Ubuntu desktop not much more secure than Windows?

    Notice how many stars had to align for the Distro used to become infected.

    On Windows, surf the wrong url linked Website, and you may be infected.

    As mentioned, Linux isn't as susceptible to malware, no-one ever said completely immune.
    Toshiba Satellite L875-s7230 / A6 2.7ghz dual-core piledriver w/ ATI Radeon HD 7520G / 8GB Corsair Vengeance DDR3-1600 RAM / 500 GB Seagate Momentus XT formatted JFS. >Wifi Drivers for this machine< My Deviant Screenshots

  5. #5
    Join Date
    Jan 2007
    Location
    in sunny & hot UK
    Beans
    214

    Re: Ubuntu desktop not much more secure than Windows?

    Quote Originally Posted by grahammechanical View Post
    1)
    3) Do not open email attachments from anyone you do not trust.
    unless you encrypt/signature every message (and your friends are doing the same) with pgp-like solutions, you cannot know is that email sent by the person who claims it.

  6. #6
    Join Date
    Jun 2009
    Location
    0:0:0:0:0:0:0:1
    Beans
    5,169
    Distro
    Kubuntu

    Re: Ubuntu desktop not much more secure than Windows?

    i don't believe modern version let you execute a .desktop file without making it executable
    i am using xubuntu 12.10 and i get this dialog window which would raise a red flag

    i would me more concerned about java letting something get command line access than a email attachment
    this is why i never install java/icedtea unless it is absolutely necessary

    firefox lets you password protect your saved passwords and stuff if you choose

    with windows you can get infected from opening regular files like a .doc (ms-word) as long as something does not get command line access on linux it is safe
    Attached Images Attached Images
    Last edited by pqwoerituytrueiwoq; January 11th, 2013 at 01:52 AM.
    Laptop: ASUS A54C-NB91 (Storage: WD3200BEKT + MKNSSDCR60GB-DX); Desktop: Custom Build - Images included; rPi Server
    Putting your Networked Printer's scanner software to shame PHP Scanner Server
    I frequently edit my post when I have the last post

  7. #7
    Join Date
    Dec 2012
    Beans
    0

    Re: Ubuntu desktop not much more secure than Windows?

    Quote Originally Posted by haqking View Post
    it is a demonstration of privelege escalation through exploitation of the .desktop file.

    This is well known

    you can read more info here http://www.geekzone.co.nz/foobar/6229

    Great read, thanks for the info!

  8. #8
    Join Date
    Dec 2005
    Location
    Western Australia
    Beans
    11,480
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: Ubuntu desktop not much more secure than Windows?

    This video you linked to, from 2009, actually demonstrates how much more secure Ubuntu is than Windows or the Mac OS.

    Shortly after the first public announcement of this little scenario, the Gnome developers implemented the warning dialog that pqwoerituytrueiwoq posted about in message #6 above.

    If this was Windows, you'd need to wait up to a month.

    If this was Mac OS X, you'd probably be waiting between three and six months.

    There's also every possibility that Microsoft and Apple wouldn't bother about patching this, as it requires the malicious program to already be running, i.e. the user must double-click on it. The user also needs to be a sudo'er otherwise it won't work. They also must be using one of the affected desktops; not all Linux desktops are affected.

    The flaw has long since been fixed in all distros. There's also a movement away from gksudo and toward Policykit (nothing to do with that flaw, just a general tighting of security that began in 2007) which would probably make this all harder to do.
    I try to treat the cause, not the symptom. I avoid the terminal in instructions, unless it's easier or necessary. My instructions will work within the Ubuntu system, instead of breaking or subverting it. Those are the three guarantees to the helpee.

  9. #9
    QwUo173Hy is offline Grande Half-n-Half Cinnamon Ubuntu
    Join Date
    Feb 2006
    Location
    Ireland
    Beans
    867
    Distro
    Ubuntu

    Re: Ubuntu desktop not much more secure than Windows?

    I'm curious, since Windows has been using User Access Control since vista, isn't it basically on par with Ubuntu now? Isn't that the same as sudo?

    Apologies for digging up an old thread but it seems wrong to clutter the forums with similar threads.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •