Page 1 of 10 123 ... LastLast
Results 1 to 10 of 99

Thread: Reminder: Social engineering still works on Linux

  1. #1
    Join Date
    May 2007
    Beans
    58
    Distro
    Ubuntu 8.04 Hardy Heron

    Reminder: Social engineering still works on Linux

    I just searched for some of the latest Ubuntu clips on Youtube and this one caught my eye.

    http://www.youtube.com/watch?v=9HxFGQ8OpYw

    This guy shows a demo of successfully getting hold of a user's personal data from Firefox (by saving an attached file from a mail in Evolution to the desktop and clicking on it) and later getting root access to delete everything on the partition all done in a Virtualbox session.

    The title for this video is: The Linux desktop is not much more secure than Windows

    The morale of the story is easy. Producing malware for Linux is apparently possible. Avoiding it comes down to the user himself. Don't download and run anything that you shouldn't. But how can you know?

  2. #2
    Join Date
    Jun 2006
    Location
    Israel
    Beans
    292

    Re: Malware tested on Linux - bringing it down to its knees

    Yeah, I can only see an Ubuntu user getting infected like that, haha.

    (given the fact that the user himself has to save the strange attachment, then run it, in this particular case)

  3. #3
    Join Date
    Apr 2005
    Beans
    514
    Distro
    Ubuntu 9.10 Karmic Koala

    Re: Malware tested on Linux - bringing it down to its knees

    There are people out there who will do ANYTHING and make up ANYTHING in their attempt to discredit something they don't like (e.g. conspiracy theorists, people who think President Obama is Muslim, etc.). I'd start asking questions: What Firefox version is this person using? Is this person fully patched? Can this be reproduced in a similarly-configured version of Windows (same Firefox version, fully patched)? Ultimately, the user is the weakest link as that worm required user intervention to trigger. Still, I've seen worms in Windows that did not require user intervention. What does that say about security in Windows compared to Linux? QED
    Think before you type: If anybody asks you to type anything with rm -rf on the CLI, DO NOT do it! As a matter of fact, if you don't know what a set of commands will do, ask for clarification from other members.
    My home page: www.cyeungrun.com

  4. #4
    Join Date
    Dec 2006
    Location
    Australia
    Beans
    1,097
    Distro
    Xubuntu 15.10 Wily Werewolf

    Re: Malware tested on Linux - bringing it down to its knees

    Quote Originally Posted by conphara View Post
    The morale of the story is easy. Producing malware for Linux is apparently possible. Avoiding it comes down to the user himself. Don't download and run anything that you shouldn't. But how can you know?
    "The price of freedom is eternal vigilance." - Thomas Jefferson

    Linux users would do well to remember it. Don't get complacent. Linux is not magically more secure than Windows. It has weaknesses like any operating system, and the biggest weakness is a complacent user.

  5. #5
    Join Date
    Nov 2007
    Beans
    Hidden!

    Re: Malware tested on Linux - bringing it down to its knees

    Guys, deal with it. Ubuntu isn't invincible, nor Linux at large. If it's a computer, it can be broken. Linux may be harder, but let's not kid ourselves: we're benefiting from Linux's relative lack of popularity and "computer geek" image right now. The people who make worms that are built to steal personal info know that if they want it to work it'll be better to write one for 85% of the user base than the <5% that are likely very computer savvy.
    Want me to punchisize your face, For free??

  6. #6
    Join Date
    May 2007
    Location
    East Yorkshire, England
    Beans
    Hidden!

    Re: Malware tested on Linux - bringing it down to its knees

    Isn't it common sense to not just run any file you get via email?
    Website | Blog | The Arch Hurd Project

    If you want to ask about something I posted, send a PM, as I don't watch many threads

  7. #7
    Join Date
    Jul 2008
    Location
    4newOtherOSTalk4umCsig
    Beans
    555

    Re: Malware tested on Linux - bringing it down to its knees

    Quote Originally Posted by Barrucadu View Post
    Isn't it common sense to not just run any file you get via email?
    If common sense is so uncommon that we are always asking where it went, why do we call it "common sense"?
    PhenomII 720x4@3.65gHz w/Zalman cooler,PNY Nvidia GTX260, 4GB, Arch64

    14 is NOT a random number!!!!!
    Arch Linux | new Other OS Talk forum

  8. #8
    Join Date
    Dec 2006
    Location
    Australia
    Beans
    1,097
    Distro
    Xubuntu 15.10 Wily Werewolf

    Re: Malware tested on Linux - bringing it down to its knees

    Quote Originally Posted by Barrucadu View Post
    Isn't it common sense to not just run any file you get via email?
    Only for security-savvy users, which 99% of computer users are NOT.

    Common sense is not common.

  9. #9
    Join Date
    Oct 2007
    Location
    Zagreb, Croatia, Europe
    Beans
    513
    Distro
    Ubuntu 9.10 Karmic Koala

    Re: Malware tested on Linux - bringing it down to its knees

    Quote Originally Posted by dasunst3r View Post
    There are people out there who will do ANYTHING and make up ANYTHING in their attempt to discredit something they don't like (e.g. conspiracy theorists, people who think President Obama is Muslim, etc.). I'd start asking questions: What Firefox version is this person using? Is this person fully patched? Can this be reproduced in a similarly-configured version of Windows (same Firefox version, fully patched)? Ultimately, the user is the weakest link as that worm required user intervention to trigger. Still, I've seen worms in Windows that did not require user intervention. What does that say about security in Windows compared to Linux? QED

    Someone should fix this...

    Don't fix security holes as MS! (if there is a hole, don't fix it just sell some AV software)
    Dear god, I would like to file a bug report.

    increase Firefox startup speed and speed of Smart Location Bar:
    http://ubuntuforums.org/showthread.php?t=1088094

  10. #10
    Join Date
    Oct 2008
    Location
    UK
    Beans
    67
    Distro
    Ubuntu 9.10 Karmic Koala

    Re: Malware tested on Linux - bringing it down to its knees

    How does this get around AppArmour?

Page 1 of 10 123 ... LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •