home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!paladin.american.edu!gatech!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: Viral Based Distribution System
- Message-ID: <0020.9212221358.AA03720@barnabas.cert.org>
- Date: 21 Dec 92 12:35:04 GMT
- Sender: virus-l@lehigh.edu
- Lines: 53
- Approved: news@netnews.cc.lehigh.edu
-
- ygoland@edison.SEAS.UCLA.EDU (The Jester) writes:
-
- > If the purpose of the program is to automatically cause some
- > 'change' in various computers, then the program must execute from a
- > loader or an infected file. If its being launched from a loader then
- > the need for the distribution system is nullified. Assuming the goal
- > is to still keep absolute system security, then the loader will be
- > 'allowed' in by the administrator but the virus it is loading won't
- > be allowed to attach itself to another program, just make the change
- > for the single user that activated the loader.
-
- Yes, this is exactly how the current products with virus-like
- distribution work. The "loader" is the system login script of Novell
- NetWare. When the user logs in, the script checks whether his/her
- workstation has an up-to-date version of the software, and if not
- copies the newest version of the software from a secure directory on
- the server to the workstation and requests a reboot.
-
- > If this is an
- > effective means of distribution then why use a virus at all?
-
- The question is incorrect. According to Dr. Cohen's definition, "this"
- - -is- a virus. And, since you are using it to do something you would
- like to be done, it is obviously a benevolent virus. Do you see the
- misunderstanding now? It's all matter of definitions...
-
- > In conclusion, a system that changes in an unpredictable manner,
- > that uses hard to track mechanisms of change, is a security
- > nightmare.
-
- Yup... Ever tried MS Windows?... :-)
-
- > Just as self modifying programs have been given a very
- > bad reputation for very good reasons, a viral based distribution
- > system deserves a similarly bad reputation.
-
- Does it? Why? Because of the word "virus"? But they just don't use
- that word when selling you the package! They call it "Installs and
- Updates Hundreds of PCs on a Network in One Easy Step" (Symantec),
- "Completely Centralized Anti-Virus Strategy" (Central Point Software)
- or others some such...
-
- > The Jester-PGP Ver2 upon Request
-
- Please consider this a request... :-)
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.1 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-