Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Lawmakers slam anti-virus biz
Kevin Poulsen, SecurityFocus 2000-05-10

Love Letter worm was an "utter, abject failure" of industry, says one Congressman. Industry blames liberal judges.

Comments Mode:
Virus? 2000-05-11
Anonymous (1 replies)
Virus? 2000-05-11
Anonymous (1 replies)
Not a virus, a feature! 2000-05-12
Anonymous
Well. the industry is *sort* of right.... 2000-05-11
Anonymous (1 replies)
laws 2000-05-11
Anonymous (1 replies)
laws 2000-05-12
Anonymous
There IS a magic bullet, common sense. 2000-05-11
Anonymous (3 replies)
There IS a magic bullet, common sense. 2000-05-11
Anonymous (1 replies)
There IS a magic bullet, common sense. 2000-05-12
Anonymous (1 replies)
There IS a magic bullet, common sense. 2000-05-15
Anonymous
Firstly, the fact that normal common sense doesn't stop this virus has been thoroughly explained in other follow-ups.

What I would like to point out is that any multi-user-Unix-like system is NOT intrinsically more secure in this case. All the access the worm would need would be to the user's local address book. A bash shell script attached to an email could easily do just the same as ILOVEYOU. In fact it's possible to argue that such a virus could do MORE harm on a *nix once executed. It wouldn't need the user to have a specific e-mail program. There are more ways and easier ways for a script to find "interesting" addresses to mail itself to (e.g. /etc/passwd), and the script could obviously just use sendmail regardless of what e-mail-package the user received it in.

Of course such a worm targeted at *nix systems is unlikely to pop up, and would probably spread less rampantly, for several reasons:

- *nix systems are less common than MS systems by several orders of magnitude.

- The average *nix user is more experienced than the average MS user by several orders of magnitude. Most of them would probably even read the script.

But if 95 % of the John Doe's out there used e.g. Linux, I'm quite sure we'd see a similar worm targeted at them.

yt,

Gaute Lund

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/32/1881#1881
not a/v politics to blame 2000-05-11
Anonymous (1 replies)
Put the blame where it belongs 2000-05-11
Anonymous (1 replies)
Put the blame where it belongs 2000-05-11
Anonymous
The US Gov. CAN'T be that stupid! 2000-05-11
Anonymous (1 replies)
The US Gov. CAN'T be that stupid! 2000-05-11
Anonymous
This is ridiculous! 2000-05-11
Anonymous
Valuable Employees 2000-05-11
Anonymous
Listen to the panel 2000-05-11
Anonymous
who does he think he is? 2000-05-11
Anonymous
Virus? 2000-05-11
Anonymous
Civil Rights 2000-05-12
Anonymous
Awareness 2000-05-12
Anonymous
Misinformed public 2000-05-12
Anonymous
Try this... 2000-05-12
Anonymous
oh my heavens 2000-05-12
Anonymous (1 replies)
oh my heavens 2000-05-12
Anonymous (1 replies)
oh my heavens 2000-05-15
<ntaddict (at) hotmail (dot) com [email concealed]>
Anti-Virus companies to blame? please 2000-05-12
Anonymous (1 replies)
"figured out a way to block this" 2000-05-12
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus