Charles Davis spake thus:
Well, that's for sure, especially when the default system comes with Internet Exploiter waving its sign, "Infect Me! Infect Me!".
Just wanted to point out that *no* systems--even ones with the vaunted Linux (notice capitalization)--are immune from attack, unless, as you point out, one takes precautions.
Reminds me of the attack at the place I used to work at, on one of our Linux servers connected to the Outside World. Actually, the attack, as described by our head techie, was quite impressive and a thing to admire.
The hacker(s) discovered a bug in the release of Linux we were running (which, of course, the server announced to the world), wherein if one tried to log in to the FTP client with a bogus user ID and password (didn't matter if it was valid or not), one could overflow the input buffer with a long string. So they gave a user ID and password (one or the other, don't remember which) that had executable code in it, then somehow (don't ask me how) found out where this overflow got stored in memory and got it to execute. That code, to make a long story short, allowed them to launch a massive DOS attack all over the world from our little server. Pretty clever, really.