Talk About Network

Google




Electronic Equipment > Cell Phone Tech > Re: Security, L...
Latest [ Topics | Posts ] Archive Post A New Topic Post a Reply
<< Topic < Post Post 13 of 14 Topic 489 of 536
Post > Topic >>

Re: Security, Linux and the Roving Bug

by Roger Blake <rogblake10@[EMAIL PROTECTED] > Jun 29, 2007 at 03:43 AM

In article <bJCdnZBigMvgjRnbnZ2dnUVZ_veinZ2d@[EMAIL PROTECTED]
>, Cassandra wrote:
> Linux advocate's reply is that, Linux's architecture makes it impossible
to
> hack.

Dead on arrival in the first paragraph. Nobody who actually knows anything
about operating system architecture and/or security would make such a
claim.

The threats against Linux tend to be of a different nature than those
against Windows. The latter tend to be aimed at end users due to Windows'
architecture which requires most users to work full-time in an
administrative
account to make use of their systems. This combined with the active
scripting that Microsoft is so fond of embedding in all types of content
makes Windows a virus writer's dream environment in terms of attacking
through end users. (Remember the first major wave of PC-based viruses?
It was when Microsoft introduced the "auto-execute macro" in Word
do***ents,
initially with no way to disable them. This turned ordinary do***ents
into potential vectors for infections.)

In contrast, the threats against Linux (and other Unix-based systems)
tend to be based on attacking public services. As you may recall, the
first Internet worm in 1988 virtually shut down the entire Net by taking
advantage of a bug in the finger daemon in Berkeley-derived variants of
Unix. Unix-based utilities such as sendmail, bind, and others have a long
history of security flaws.  Anyone with any sense will tell you that if
you hook up an old, unmaintained Linux system running public services to
the Internet it will likely be hacked and rooted in short order. On the
other hand, Windows-style attacks on end users are much less fruitful
due to user accounts with limited privileges and a lower incidence of
script-triggered automation features in end-user applications.

-- 
  Roger Blake
  (Subtract 10s for email.)
 




 14 Posts in Topic:
Security, Linux and the Roving Bug
"Cassandra" <  2007-06-28 15:43:19 
Re: Security, Linux and the Roving Bug
CptDondo <yan@[EMAIL P  2007-06-28 13:11:12 
Re: Security, Linux and the Roving Bug
"Nedd Ludd" <  2007-06-28 17:05:01 
Re: Security, Linux and the Roving Bug
CptDondo <yan@[EMAIL P  2007-06-28 14:11:10 
Re: Security, Linux and the Roving Bug
Oldtech <me@[EMAIL PRO  2007-06-28 17:40:47 
Re: Security, Linux and the Roving Bug
CptDondo <yan@[EMAIL P  2007-06-28 14:40:16 
Re: Security, Linux and the Roving Bug
"David L. Johnson&qu  2007-06-28 20:56:09 
Re: Security, Linux and the Roving Bug
CBFalconer <cbfalconer  2007-06-28 20:19:31 
Re: Security, Linux and the Roving Bug
"The Man" <t  2007-06-28 17:41:02 
Re: Security, Linux and the Roving Bug
CptDondo <yan@[EMAIL P  2007-06-29 09:03:33 
Re: Security, Linux and the Roving Bug
Matt Simpson <net-news  2007-06-29 09:55:54 
Re: Security, Linux and the Roving Bug
chrisv <chrisv@[EMAIL   2007-06-28 16:34:28 
Re: Security, Linux and the Roving Bug
Roger Blake <rogblake1  2007-06-29 03:43:55 
Re: Security, Linux and the Roving Bug
Jamie Hart <usenet@[EM  2007-06-29 08:31:54 

Post A Reply:
  Go here to Signup

AddThis Feed Button


About - Advertising - Contact - Frequently Asked Questions - Privacy Policy - Terms of Use - Signup

Contact
localhost-V2008-12-19 Tue Jan 6 1:14:47 PST 2009.