Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Begs a question: AV in Linux |
|---|---|
| Date: | Fri, 27 Jan 2006 10:18:03 -0600 |
Quoting Moderator <mod-linux@securityfocus.com>:
The following message was submitted to the list by Alexander Klimov.[...]
Since there are quite a few replies let me elaborate. There are two types of viruses: those that exploit software vulnerabilities and those that exploit wetware (that is a PEBKAC).
And there are _many_ kinds of linux systems and users.
the virus is released. Unlike some other OSes, with any good Linux distribution it is quite easy to live most of the time without known vulnerabilities in your system.
If you run wine, zen, mach, vmware, or anything that runs or can run windows (or another vulnerable OS), than you should run AV in at least the virtual machine, and preferably in both linux and virtual machine.
If you run openoffice, you are open to macro viruses and all the same things that hit MS Office apps, and you should run an AV if you don't want to be a hit by them, or spread them to others.
Now if you have a system with no vulnerabilities exploitable by known viruses none of them can compromise your system -- you cannot get better results from an AV (AFAIK `unknown virus detection' is more marketing than reality).
True. But you can help spread them. Of course there is the obvious examples of linux machines which are file servers and mail servers and the like. Why would you want these spreading viruses? But even regular office user linux machines can spread around viruses via file transfers (forwarding e-mail, swaping floppies or usb devices, burning cd-roms, etc). Maybe not a big deal if you only deal with other linux machines, but if you interact with people using other OS's do you really want to be the one who passed a virus on to them?
root to solve it: wget ...'. I am not sure I understand how sharing files with Windows can be dangerous but probably it is in this category as well
It is dangerous for other windows users you give the file to, or dangerous to you if you run windows in a VM environment in linux, or run OpenOffice or other windows-software emulation software.
BTW do not get me wrong: if I say that AV is useless (or, worse, it can have its own vulnerabilities) it does not mean that you should not use a firewall in both directions or check integrity of system files.
AV software _may_ be useless depending on your environment. I run it on my linux mail server, and it is not worthless to me or my users, since half my users run Windows and Mac machines. They thank me for not exposing them to the viruses via their e-mail. You could make the same type of arguments for file servers, etc.
Yes, you _may_ not need a AV product on your linux machine. Then again, you _may_ need one. It depends on how you use the machine, what you run on the machine, and how you and that machine interact with others.
The real-world example is how it is illegal most places to knowingly infect other people with a human virus that you know you carry. It does not matter if you are immune to it or not, the law reflects the fact that others are not and that you should not knowingly spread it to them as you know it can cause them harm.
Use a similar principle in computers and networks. If you know your computer has or is likely to spread viruses to others and could cause harm to them, then the _responsible_ thing to do is to run AV software on your machine to try to prevent that. If you know your computer is _highly unlikely_ to spread viruses to others, and should not pose any virus risk to others, then there is no need to run AV software if you don't want to (and may be very good reasons not to, in fact).
-- Regards, ASK
-- Eric Rostetter The Department of Physics The University of Texas at Austin
Go Longhorns!
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Begs a question: AV in Linux, Moderator |
|---|---|
| Next by Date: | Re: Begs a question: AV in Linux, Reimundo Heluani |
| Previous by Thread: | Re: Begs a question: AV in Linux, Moderator |
| Next by Thread: | Re: Begs a question: AV in Linux, Reimundo Heluani |
| Indexes: | [Date] [Thread] [Top] [All Lists] |