Finalmente Linux come Windows!!

Postate qui per tutte le discussioni legate a Linux in generale.

Moderatore: Staff

Regole del forum
1) Citare sempre la versione di Slackware usata, la versione del Kernel e magari anche la versione della libreria coinvolta. Questi dati aiutano le persone che possono rispondere.
2) Per evitare confusione prego inserire in questo forum solo topic che riguardano appunto Gnu/Linux in genere, se l'argomento è specifico alla Slackware usate uno dei forum Slackware o Slackware64.
3) Leggere attentamente le risposte ricevute
4) Scrivere i messaggi con il colore di default, evitare altri colori.
5) Scrivere in Italiano o in Inglese, se possibile grammaticalmente corretto, evitate stili di scrittura poco chiari, quindi nessuna abbreviazione tipo telegramma o scrittura stile SMS o CHAT.
6) Appena registrati è consigliato presentarsi nel forum dedicato.

La non osservanza delle regole porta a provvedimenti di vari tipo da parte dello staff, in particolare la non osservanza della regola 5 porta alla cancellazione del post e alla segnalazione dell'utente. In caso di recidività l'utente rischia il ban temporaneo.
Avatar utente
marghe
Linux 3.x
Linux 3.x
Messaggi: 525
Iscritto il: lun 7 ago 2006, 23:39

Messaggio da marghe »

Luci0 ha scritto:In genere gli utenti Linux non usano OOo loggati come root ...
si, certo, sono pienamente d'accordo

ma se il tuo sistema è vulnerabile, uno script potrebbe tentare una scalata ai privilegi e tramite qualche bug ottenerli

continuo a sostenere comunque che è molto improbabile prendere un virus, soprattutto se si osservano le normali regole di sicurezza che gli utonti non osservano, e se si aggiorna per tempo il sistema

Avatar utente
gnubit
Linux 3.x
Linux 3.x
Messaggi: 751
Iscritto il: lun 17 apr 2006, 0:16
Località: Verona
Contatta:

Messaggio da gnubit »

Chiediamo a gohanz di fare il tgz anche del virus, altrimenti secondo me è alquanto improbabile che un utente di slackware con più di due giorni di esperienza possa prendersi il virus.

Installarsi il virus è troppo complicato, almeno col tgz ci si mette un attimo.

Avatar utente
Luci0
Staff
Staff
Messaggi: 3591
Iscritto il: lun 27 giu 2005, 0:00
Nome Cognome: Gabriele Santanché
Slackware: 12.2 14.0
Kernel: 2.6.27.46- gen 3.2.29
Desktop: KDE 3.5.10 Xfce
Località: Forte dei Marmi
Contatta:

Messaggio da Luci0 »

Si potrebbe mettere nel repository ... il pacchetto con uno Slackbuild almeno se cambia versione di Slackware uno se lo può ricompilare agevolmente e avere un bel virus personalizzato ... :badgrin: :badgrin: :badgrin:

Avatar utente
gohanz
Staff
Staff
Messaggi: 5832
Iscritto il: mar 30 nov 2004, 0:00

Messaggio da gohanz »

Ecco ci manca pure il Virus pacchettizzato! :D

Avatar utente
albatros
Iper Master
Iper Master
Messaggi: 2098
Iscritto il: sab 4 feb 2006, 13:59
Kernel: 6.18.0
Desktop: gnome and lxqt
Distribuzione: Ubuntu 24.04 & FC 41
Località: Darmstadt - Germania

Messaggio da albatros »

Copio e incollo per informazione la mail che mi è arrivata dalla newsletter di openoffice:
From: "John McCreesh" <jpmcc@openoffice.org>
To: announce@openoffice.org
Reply-To: announce@openoffice.org
Subject: [ooo-announce] Press reports regarding "SB/BadBunny-A" virus
Date: Wed, 23 May 2007 18:11:46 +0100 (BST)
User-Agent: SquirrelMail/1.4.9a

There has been press comment recently about the "SB/BadBunny-A" virus
affecting OpenOffice.org reported by an anti-virus company.[1]

Industry best practice would have been for the anti-virus company to
report the virus to the OpenOffice.org security team before making this
information public. Unfortunately this did not happen in this case.
OpenOffice.org will issue a detailed analysis once a copy of the virus has
been received. However, due to the volume of interest in the media, the
Community would like to issue the following comments, based on the
information available.

Macros are a useful part of any office suite, allowing users to automate
repetitive tasks. These tasks include potentially destructive actions such
as modifying and deleting files, which is why macros are of interest to
virus writers.

It is possible in any capable macro language, including those in
OpenOffice.org, to write simple 'virus-like' programs. Currently,
OpenOffice.org follows industry best practice to mitigate the risk. If the
software detects macros in a document being opened, by default it displays
a warning and will only run the macro if the user specifically agrees. In
any macro-capable tool, it is essential to verify the origin and
authenticity of the document before executing macros. To this end,
OpenOffice.org has also included advanced digital signature capabilities.

The OpenOffice.org engineers take the security of the software very
seriously, and will react promptly to any new issues. To do this, they
require access to the source code for the alleged virus. From information
currently available, it is unlikely that this new virus contains any novel
features which would require a software patch. Technically, it is not even
a virus, as it is not "self-replicating" - with OpenOffice.org's default
settings, it cannot spread without user intervention.

However, the OpenOffice.org community repeats the consistent message from
security experts that users should never accept files from unknown
sources. For any security issue, please visit OpenOffice.org's Security
Team page [2] and send a note to security-team@openoffice.org.

[1] http://www.sophos.com/security/analyses ... unnya.html
[2] http://www.openoffice.org/security/

Rispondi