OT curt

Jan 22, 2007 161 Replies

Charles Davis spake thus:

Well, that's for sure, especially when the default system comes with Internet Exploiter waving its sign, "Infect Me! Infect Me!".

Just wanted to point out that *no* systems--even ones with the vaunted Linux (notice capitalization)--are immune from attack, unless, as you point out, one takes precautions.

Reminds me of the attack at the place I used to work at, on one of our Linux servers connected to the Outside World. Actually, the attack, as described by our head techie, was quite impressive and a thing to admire.

The hacker(s) discovered a bug in the release of Linux we were running (which, of course, the server announced to the world), wherein if one tried to log in to the FTP client with a bogus user ID and password (didn't matter if it was valid or not), one could overflow the input buffer with a long string. So they gave a user ID and password (one or the other, don't remember which) that had executable code in it, then somehow (don't ask me how) found out where this overflow got stored in memory and got it to execute. That code, to make a long story short, allowed them to launch a massive DOS attack all over the world from our little server. Pretty clever, really.

The common factor that causes all the problems whether you use Linux, Windows, MacOS or OSX is that they all use TCP/IP for accessing the web. All of them. ALL OF THEM. Without exception.

Please also note, for the nitpickers here, I stated that they use it for accessing the WEB. Usenet is not the web. Unless you use Google Groups. Which Curt does. Ahem . . .

-- Ray

Could you elaborate on this point?

I don't know how it's released now but, when I installed my wifes system IE came with every bad thing enabled; java script was a bad one. Windows systems come (used to for sure) lying on their backs, legs spread begging.

Windows systems (last time I looked and it's been awhile) didn't seem to have any sense about evil network packets. It's no wonder they seem to be virus petri dishes.

BUT, that's just my take on how it was. I'm sure Vista is perfect ... it's so secure you can't use it.

Paul

Paul Newhouse spake thus:

Well, I should amend what I said a little. It's not so much the browser (IE) that's the problem as the mail client (Outhouse Express), which happily opens (or at least use to) every message the user selects to view and blithely opens any attachments included, which may contain Very Bad Things for your computer (virii, Trojan horses, other exploits).

Internet Exploiter also left the user wide-open to certain attacks as well, as Paul explained, but the more likely avenue of infection would be through OE.

I understand at least some of this may have been fixed, but I prefer to use open-source software (Mozilla) that has always been designed with security in mind, not as an afterthought.

Yes, I had forgotten Outlook, I have a fairly good firewall, mail handler infront of all the systems. So I tend to ignore Outlook's rather poor design/behavior.

I use the M$ platform only because I have to; 3PI, MPLAB, the club books and reading things that people send me in word.doc format that I think I want to look at. Otherwise I use my open source unix system. There I run almost everything with network exposure in a chroot'd jail so even if someone breaks in they are nowhere.

Microsoft doesn't strike me as learning very quickly by past mistakes.

Paul

oh, ok I thought it was somehow broadcasting some thing onto the internet to invite infection. Jb

How about a little explanation of how to do this to a Linux user? Plea= se email me if you think others would not be interested, but I suspect I'm= not the only one.

--=20 It's turtles, all the way down

someone breaks in they are nowhere.

Well, on NetBSD you do "chroot ". If any outside evil doer breaks in to the thing you are running in (apache, mozilla/firefox, sshd, ...) they are in a "chroot'd jail". Read up on chroot. The technique is especially useful for servers but, generally useful. It's not perfect but, it raises the effort bar for the bad guys quite a bit and reduces the reward potential. You are still running the same kernel so you need to make sure you have some sensible packet filtering in place (if it doesn't come setup by default) to zap short, misconfigured and such packets. Run something like portsentry auto identify scanning attempts and block those "up to no good" addresses.

I don't run Linux much so you'd be better off asking in a Linux oriented forum for specific details on Linux. There is probably some Security Forum for your flavor of Linux. They will be able to give you a lot of guidance.

The big advantage from my perspective is that even if you can do all of this for Windows you are still stuck with some, clearly demonstrated, lousy network applications that are so security porous that firewalling them is a much bigger, and perhaps futile, effort.

IMO, just by using one of the *ixes you are miles ahead security wise.

Good luck, Paul

Thanks. I'll try "chroot startx" and see if it works next time = I reboot.

--=20 It's turtles, all the way down

I did a little (realy precursory) reading on chroot. It is easy to understand why there are so many windows systems out there.

J Barnstorf spake thus:

Yes: do any of the Unix geeks really think the average computer user is going to put up with (let alone be able to handle) all the system administration that has to be done with a Unix box?

Not that Unix isn't a superior OS, but it's not ready to plug-n-play for the average human bean. A well-set-up Windows box can be, though. (Even Macs aren't easy to set up: I just recently helped a friend get her Fire Wire network going, and it was no easier than the equivalent task on any Windows system; so much for the overhyped "the computer for the rest of us" crap.)

Make sure that startx and all that it needs are somewhere in . If startx is is normally at /usr/X11R6/bin/startx then you need:

/usr/X11R6/bin/startx

also. Don't go linking them together. You don't want a pollutted /... to leak back into your base system.

Enjoy, Paul

Indirectly you are. Anyone who gets mail from you will see that you are using which could be Outlook and that's a pretty good clue that you are running some Mister Softee OS.

Browsers identify themselves so the web site can X-Newsreader: Microsoft Outlook Express 6.00.2900.3028

If I'm just looking for systems to attempt to infect I don't care that some misid themselves. If only 10% are being truthful that's a lot of machines that could be vulnerable.

You mean you understand why so many people default to Microsoft products? Or you understand why so many attempts have been made to do better?

There is no free lunch. I am amazed at how much crap I have to know about Microsoft Windows products in order to deal with them. M$ users somehow accept this as an acceptable level of required knowledge. Yet, a roughly equivalent level of knowledge to use one of the *ixes is unacceptable.

If we were talking about automobiles you are complaining about having to learn how to drive before getting behind the wheel. Just because you took drivers ed doesn't mean it's not dangerous to drive.

Paul

want=A0a=A0pollutted

Paul, that almost sounds like I'd have to duplicate the whole directory= tree.=20 If so, I haven't gained anything but a backup copy.

To the rest of you, I apologize for converting an off-topic thread to a= n even more off-topic thread :-).

--=20 It's turtles, all the way down

YUP!

No. While it's true you have a backup, you also have a pollutable copy. And if it gets infected it won't affect the rest of your system. Only the chrooted jail which means the infection is confined. This is most useful for servers but, can be used in other contexts.

I'm not going to feel very guilty about that; it was way/whey/weigh OT before we started this discussion.

Paul

Right. Although Microsoft Windows attempts to 'hide' the admin stuff, it is really all there. And most Microsoft Windows users do things that they really shouldn't, like use the adminstrator account for general usage (a really *bad* idea). Because Microsoft Windows doesn't handle system administration the way Linux/Unix does, Microsoft Windows is subject to all sorts of security and reliabity problems.

I know of several non-geeks who have no problem using Linux systems (which I set up for them). And know of a number of MacOSX users who are non-geeks who have had no problems with their Macs either. The issues of a 'well-set-up Windows box' also applies to a 'well-set-up Linux box' or a 'well-set-up MacOSX box'. Yes, it is non-trivial to achive a 'well-set-up (whatever)' box. The main problem people have is thinking that anyone can properly set up a Windows box, and only a geek can properly set up a Linux or MacOSX box. Most non-geeks probably cannot set up a Windows box any better than they can set up a Linux box, even though Microsoft suggests that they can. Neither Linux nor MacOSX make the (false) claims that anyone can install the O/S from scratch or upgrade the hardware or software, etc. at the click of a few buttons.

Yes, on a certain level neither Linux/UNIX nor MacOSX are plug-n-play, on the same level as MS-Windows. OTOH, that is (in the long run) a

*good* thing. The 'dumbed down' interface that MS-Windows pushes, is proving to be rather disasterious in many ways. MS-Windows is the *only* system subject to viruses, adware, spyware, other maleware. MS-Windows is notorious unstable and insecure. The only O/S that needs 'anti-virus' software installed. The only O/S that needs regular visits to a shop to be 'cleaned' and its file system 'defraged', etc. Linux/UNIX boxes and Macs run for *years* without being fussed with in that way. Linux/UNIX systems often stay up and running *continuiously* for *years*. (MacOSX boxes would too, except that they are rarely used as server boxes and most Mac uses don't leave their computers running all of the time.) How often have you rebooted your MS-Windows machine in the last week? *My* linux machine has been up and running non-stop for 26 days (I think there was a power failure about that long ago).

Paul Newhouse spake thus:

If you're implying that only Micro$oft mail clients identify themselves, you're mistaken. Most clients use either the User-Agent or X-Newsreader headers to identify the client. But you already knew that.

Actually, if you're talking about clients that *deliberately* misidentify themselves, Mozilla browsers, for one, are capable of that: my Firefox has a selector box right in the window that I can use to select the "user agent" string it sends out on the fly. Useful for masquerading as IE in cases where the sending site only works with that misbegotten line of browsers.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required