Linux and Viruses

Posted: Minggu, 02 Mei 2010 by VIruS Of WinDoWS in Label:
0


Linux and Viruses

You are sure to hear much fuss about the threat of viruses these days. Computer viruses come in many different forms, from infections that are programmed to attack programs and files to those designed to the corrupt the critical sectors of your hard drive. What you seldom hear is what platforms these infections target. Microsoft Windows, the most popular operating system, is the number one target for most virus writers.

Linux is perhaps the biggest rival of the Windows operating system. While it isn't as widely used, Linux has established a reputation for being much more reliable and secure. This is true for several reasons, most of which experienced Linux users are already familiar with. For those of you new to the system, this article detail how Linux stacks the deck against a typical computer virus.

How Viruses Attack Linux Systems

In order for a virus to infect binary executables on a Linux system, those files must be written by the user attempting to execute the infection. This situation in itself is very unlikely. In most cases, these programs are controlled by the root user and being run from a non-privileged account. In a Linux environment, a user with the least experience is less likely to control an executable program. Because of this, the users with little knowledge about viruses are less likely to have home directories susceptible to infection.

Most Linux networking programs are specifically designed without the high-level macros which have allowed many Windows-based viruses to spread at such a rapid rate. This is not an inherent feature, but simply a reflection of the major differences between the two system,s as well as differences in the products aimed at those platforms.

Linux Bliss

Although Linux has been known for its high level of security, there have been a few notable outbreaks. One such threat was Bliss, the second virus written for the Linux platform. Like most viruses, Bliss attempted to attach itself to executables, files regular users typically do not have access. It has been speculated that this infection was scripted simply to prove that Linux could be compromised. However, the Bliss virus doesn't have the ability to propagate with efficiency due to the complex structure of the user privilege system. Though it is one of the only Linux viruses to be seen in the wild, Bliss never reached widespread popularity.

Upon being released, many anti-virus companies distributed a number of reports stating that Linux users should implement anti-virus software due to the Bliss outbreak. This practice never caught on, as Bliss never caused any major damage.

Experts believe that the reason we haven't witnessed a true Linux virus outbreak is because an infection cannot reach its full potential in the system's hostile environment. At the same time, there is always the possibility that the virus coders will get it right one day. It does, however, speak highly of the system's well-crafted design, indicating that a virus must be rather sophisticated to thrive on the Linux platform.

The First Linux Virus

Posted: by VIruS Of WinDoWS in Label:
0


The First Linux Virus


From the outside looking in, one would believe that viruses were an equal threat to all computer users. While this is true in a sense, some users are much more vulnerable than others. For years, Linux has been known as the more secure option for an operating system. Although the Windows platform is designed with many useful features, Linux was designed with security in mind, making the system superior in the minds of its users.
Even though Linux isn't a prime target for malicious coders, it has been successfully exploited by a few computer infections. Staog was the first virus ever scripted for the Linux operating system. It was initially detected in the fall of 1996, with the exploited vulnerabilities being discovered shortly thereafter. Considering the system's strong design, experts in the software security industry were stunned.
Staog was able to exploit Linux despite the system's design which calls for users and applications to login before any questionable operations can occur. The virus functioned by exploiting vulnerabilities in the kernel, which enabled it to stay resident in the memory. From there, it infected executable binary files. Because it mainly relied on bugs, software upgrades made the system immune to the virus. This factor, along with its weak method of distributing itself, made Staog fairly easy to manage.
Staog was written by VLAD, a well known group from the hacking community. This Australian-based group is also responsible for scripting Boza, the first virus written for Windows 95. The first Linux virus has not been listed in the wild since the initial outbreak. Despite that brief threat of Staog, viruses typically have limited ability to change or severely impact the system.
The Truth about Linux Viruses
One the biggest vulnerabilities of the Linux system are the users who have the misconception that it cannot be infected by computer viruses. Several people believe that any non-Windows system is secure and doesn't need the aid of additional software to ward off viruses. This is far from the truth and a major reason why more viruses are being written for the system.
Many security experts believe that the growth in Linux malware is the result of its evolution and popularity, particularly as a desktop system. Shane Coursen, a senior technical consultant for Kasperky Lab, believes that more users are turning to Linux because of the interest in learning how to write malware for the system.
Most viruses written for Linux pose a potential, yet minimal threat to the system. If a virus infected binary file is run, the entire system could be infected. The distribution of the infection depends on which particular user with what level of privileges executed the binary. A binary run under the systems root account would have the ability to infect the entire system.
There are many other solutions for protecting Linux other than anti-virus software. For instance, software repositories greatly reduces the chance of viruses and other malware. These repositories are throughly checked before distribution to ensure that they are malware free.
Just like with any system, the best protection against common threats is prevention. This includes carefully surfing the web and handling emails on your Linux computer.

Mac OS X Virus

Posted: Kamis, 29 April 2010 by VIruS Of WinDoWS in Label:
0


Mac OS X: The First Virus

Throughout time, Windows has been known as the most virus-prone of all operating systems. Vulnerabilities in the Microsoft Windows Explorer web browser and the Windows system itself exposes this platform to a wide range of threats from viruses and worms to spyware. For this reason, more users have turned to other systems for an infection-free computing environment.

Up until recently, Windows was thought to be the only system capable of contracting viruses and other malware. However, Linux has also been infected and Apple's Mac OS X is the latest victim of the infamous malicious code.

The Virus Discovery

On February 16, 2006, SophosLabs announced the detection of the very first virus written for the Mac OS X platform. OSXLeap-A, often referred to as OSX/Oompa-A, is an infection that spreads via the Macintosh iChat instant messaging system. It operates by forwarding itself as a "LATESTPICS.TGZ" file to the contacts on the buddy list of an infected user. When the archived file is opened, its contents are disguised with a graphic icon in JPEG format, which attempts to trick the recipient into believing it is a harmless file. The virus uses the "OOMPA" text as a marker in the forks of the infected program which prevents it from compromising the same files.

Is it a Virus or Trojan?

Following word of the infection, several members of the Macintosh community stated that Leap was actually a Trojan horse and not a virus. Their reason being was that the infection required user intervention, which is receiving the file in iChat, choosing to manually open it and executing the payload. However, this is not how a Trojan functions. A Trojan is a seemingly useful program purposely designed to damage a computer or install other malicious applications. Additionally, a Trojan does not self replicate and includes no mechanisms that enables it to spread itself. In most cases, it is deliberately incorporated onto a website, accidently distributed by another user or sent via spam email. Aside from that, the malicious code of Trojan contains nothing that will allow it to be automatically distributed to other victims.

OSXLeap-A is specifically designed to use the iChat messaging system to propagate itself to other users. It also requires action by the user in order to be executed and further spread the infection, therefore it is aptly termed as a computer virus.

Staying Smart

While several Macintosh computer users once had the belief that their system was incapable of harboring viruses, Leap proves that the threat of malware on this platform is real. Security experts suggest that the Mac users can no longer live worry free, as caution must now be practiced at all times, just as if you were running a Windows operating system.

Experts also advise all Mac OS X computer users to practice safe computing by cautiously surfing the web and keeping their anti-virus software updated with the latest virus definitions.

Anti-Virus Solutions for the Mac OS X

- Norton Internet Security for Macintosh

- McAfee Virus Scan for Mac

- Sophos Anti-virus

- Intego Virus Barrier

- ClamXav

RFID Viruses

Posted: by VIruS Of WinDoWS in Label:
0

Threat of RFID Viruses

Viruses pose a threat to more than the Windows operating system. They are becoming more common on systems that once seemed impervious to infection, along with other devices such as cell phones and MP3 players. The most alarming presence is found in common products using RFID technology.

What is RFID?

RFID (Radio Frequency Identification) is one of the latest trends in computer miniaturization. An RFID transponder is a tiny, high-powered computer with limited resources. It contains an RFID tag, which is inductively powered by an external reading device. Once activated, the RFID tag decodes incoming queries and generates an accurate response using the energy of incoming radio waves, which powers the chip just long enough to respond. In general, an RFID tag has a limited amount of processing power and capacity at 1024 bits of storage.

RFID is useful in many different applications, including those for automated payments, supply chain management, counterfeit prevention, airline luggage management, and physical access control. RFID tags are also commonly implanted in various consumer goods, such as toll collection devices, public transportation passes, passports and much more. This technology has even been approved by the Food and Drug Administration with a product known as Veriship, a device deployed commercially and in the medical field.

The Viruses Attacking RFID

While RFID has revolutionized the world of computers, several malicious individuals have taken an interest in this technology as well. Members of the hacker community have learned to take advantage of RFID, causing these tags to behave in questionable ways by inserting viral codes. Below we have composed an example of just how scary this exploit can be.

Several airports have been in discussion with plans to expedite luggage handling by attaching RFID-supported labels to bags as they are checked in. This will make labels much easier to read from a greater distance than the bar-coded labels currently in use. Now consider this - a shady airline traveler attaches a virus-inserted RFID tag to the luggage of a random victim just before they check in. When the airline's RFID reader scans the tag to determine where it should be routed, it responds with the virus, which infects the entire baggage database. From there, all subsequent passengers checking in their luggage may also be infected.

Just being infected is a mild example. An RFID virus may contain a payload that could completely wipe out a database, causing luggage to be re-routed and possibly aid the process of drug smuggling. What's even more troubling is the fact that many State Departments have began to distribute RFID-supported passports. Considering where this technology is being deployed, RFID becomes both a computer security and economic concern. So why are these vulnerabilities being so openly publicized? According to researchers, revealing the threat of RFID viruses and worms will eventually teach consumers antivirus efforst that will prevent them from spreading.

RFID infections seem inevitable as many computer systems are vulnerable to viruses. At the same time, we still use them regardless of the lingering threat which will is bound to be the case with RFID-supported items. Let's just hope that this new research will prompt the industry to enhance the security of readers, tags and back-end systems before RFID viruses evolve from theory to a dreadful reality.

Recovering Virus Infection

Posted: by VIruS Of WinDoWS in Label:
0

Recovering from a Worm or Virus Infection

How do you know if your network has been infected by a malicious program such as a worm or virus? Unfortunately, there are no identifying standards, but there are a number of telling symptoms. You may have noticed performance issues with your computer. Perhaps your web browser keeps crashing. Maybe some of your files or programs will not open. When these conditions occur, it's time to investigate and trace the route of the problem.

More often than not, worms and viruses have some type of impact on your computer, whether it's subtly impacting the normal functions or completely erasing files. The best way to learn if you've truly been infected is to run an anti-virus scanner, which will alert you of malicious codes. If harmful items are detected, you need to take immediate action to minimize the damage, get on the road to recovery and stay protected.

What You Should Do to Recover from an Infection

If the infection occurs in a network setting, you should instantly contact the IT department or system administrators. The sooner the investigation begins, the sooner your computer and other machines in the network can be restored. If the infection occurs at home, immediately disconnect your laptop or desktop computer from the internet. This will prevent viruses and intruders from accessing data and making changes to the system, essentially giving you a bit of control.

After taking the first step, you must work on ridding the system of infection. If an anti-virus program is installed on your computer, you should manually perform a full-system scan. In some cases, a worm or virus can have such an impact that it renders anti-virus software useless.

If the program cannot detect or remove the infection, you may need to completely reinstall the operating system, a move that is liable to erase every file and program on your computer. After reinstalling the operating system, be sure to implement another anti-virus program along with patches for all known system vulnerabilities. Furthermore, your anti-virus solution should be kept current with the latest updates in order to protect the latest threats.

Limiting the Chance of Another Infection

Dealing with the recovery efforts caused by a worm or virus can be very frustrating. These troublesome infections can cost your business a lot of time, money and sensitive data. The following precautions can be taken to protect yourself against future infections:

Change all passwords - Regardless if you lost any sensitive data or not, your original passwords may have been compromised during the time of infection. For this reason, you should immediately change every system password including those corresponding to web sites.

Put up a firewall - A firewall will help to prevent many infections by restricting access from malicious traffic. When installing a program, be sure that your firewall is always turned "ON."

Use anti-spyware program - Your anti-virus program may protect you from worms and viruses, but what about other threats? Since malicious programs such as spyware have the ability to download viruses and other infections, it's wise to implement additional technology.

Last but not least, you can take extra precautions by backing up sensitive data on an external storage medium. This will enable you to rebound quickly if worms or viruses happen to strike again.

Computer Viruses Future

Posted: by VIruS Of WinDoWS in Label:
0

Good Computer Viruses: The Future?

Even with all the damage viruses have inflicted over the years, a handful of experts believe that computer viruses could actually be used for good one day. How is this possible? Similar to the ethical worm, these viruses would mainly be used to distribute network patches to repair vulnerabilities. Here is a bit more on the theory.

The Function of a "Good" Computer Virus

First of all, the virus would have to exclude the primary function of a typical virus, which is running on a victimized machine without authorization. The propagation would be similar to the one used for malicious purposes, but instead deliver a good payload, opposed to one that is destructive. Because of this, experts believe that anyone found guilty of distributing a good virus should be charged with the same offense as someone distributing malicious code, though with reduced penalties, as the damage is liable to be not as severe.

However, this supposed good virus would not only spread and execute itself without permission, but also consume bandwidth, disk space, memory and processor cycles. All of these factors could possibly result in the denial of the those resources to system administrators, a condition more commonly termed as a DoS (denial-of-service) attack.

Good vs. Malicious Viruses

Another problem would be distinguishing the good virus from malicious programs. While identifying a known virus is fairly easy with the right technology, separating it from the unknown good code may be difficult. Since a good number of legitimate programs have been known to damage and mistakenly remove files, this ability alone isn't enough to truly identify malware. Perhaps this good virus would be limited to removing programs, as it can combine its code with an individual program. However, this would certainly be an inconvenience for those developing self-extracting archive software. Assuming this as the major obstacle, how would a good virus distinguish another from a malicious program? Both would behave similarly with the tendency to damage or destroy other files. One would only hope that creators of these viruses carefully script their codes to identify other good variants, a task that seems difficult or next to impossible when considering polymorphism.

Good viruses would have to be written to near perfection for a number of reasons. If they happen to mistakenly delete software and operating system patches, they would essentially be just as much trouble as malicious viruses. There is also the strong possibly of unscrupulous characters mutating the good virus with evil strains. These new strains are likely to be identified as good viruses, even though they contain a destructive payload, one capable of destroying all other identifiable good viruses.

With so much still in the air, we may find ourselves reflecting on the day when good viruses first invaded our systems, strengthening the malicious epidemic. If these viruses of the future aren't written properly, they could inevitably improve the breed of destructive programs just before being wiped out by variants of their own code. While this is certainly a hot topic, many security experts believe that spreading good viruses could eventually end up causing more harm than good.

Virus Scan

Posted: by VIruS Of WinDoWS in Label:
0

How to Run a Virus Scan

You simply can't put a price on security these days. Any computer with an online connection must be shielded from the many threats lurking on the internet. Just imagine a malicious program slithering into your system, executing itself and offsetting a wave of destruction within a matter of minutes. The impact of an infection may range from subtle to devastating; slowing down the performance of your computer or deleting all of your important files and rendering your applications inoperable. Without implementing the proper security measures, all of the above could be your reality.

When malicious items such a virus, worm or Trojan enters your system, it may be days or even weeks before you're aware of the problem. The best way to learn if your computer has been infected is to run a virus scan on all system files and directories. A scan is a basic function performed by anti-virus software. This component thoroughly combs the hard drive of your computer in search of harmful or unwanted items. If questionable items are detected, the scanner displays a description of the file and the nature of the infection.

Simple Steps for Long-Term Protection

Running a virus scan is a simple yet essential step towards protecting your computer. As internet threats continue to evolve into huge problems, technology has enabled security experts to fight back with advanced solutions. There are now many available options for running a virus scan on your computer. You may begin by signing online and performing a scan over the internet. In this case, the scanner typically searches and detects infections but requires you to buy the full version of a particular program to the eradicate the threat. You also have totally free software such as products by ClamWin and AVG. These programs run a complete scan of your system, are thorough at detecting threats and removing them as well. The most reliable protection is much more expensive yet well worth it when considering the level of security implementation. Programs developed by leading brand name vendors such as McAfee, Symantec and Kaspersky offer all-in-one solutions capable of detecting viruses, spyware and more complex types of malware. They are often coupled with firewall components to keep intruders out of your system and also receive daily updates to keep you protected against the latest threats roaming the web.

Start with a Virus Scanner

By installing a virus scanner, you're essentially activating 24/7 protection for your computer. The scan engine can be easily configured to run on a predetermined schedule or right at your command. It may also function continuously in the background as you knockout important everyday tasks, an automated process that keeps you productive and safe at the same time.

With a virus scanner on deck, the chances of contracting a nasty infection are drastically reduced. This allows you to surf the web in confidence, tend to all of your emails and download important files without being concerned with malicious threats. More importantly, it brings a piece of mind by knowing your computer will perform like a champ over a significant period of time.