Linux malware, sure it’s possible

Update 18th July 2009. If you want to read actual desktop environment developers (i.e. people who who know loads more than I do) discussing this vulnerability, then this 2006 thread from a Xorg mailing list may interest you. If you want to see the proof that it actually works, then go right ahead and read on.

I tried to ask questions about this on a forum and got banhammered for it. But never mind. I did a bit of research into it and discovered that a few people have already documented this possible vulnerability, and that it is somewhat legitimate. People love to say that the biggest security threat for computers is the users themselves, which is fair enough. Who needs to craft a drive-by download when you can just get the users to click on naked_chix.jpg.exe all by themselves? Linux makes it difficult, but not impossible, for malware to take hold, but it pays to be aware of the dangers, however slight they may be. I don’t personally believe that there is much of a threat at all, and the particular exploit I’m about to describe isn’t very special or clever, either, and can only affect a small number of people. The only thing that is somewhat interesting about it is that it can get root access without drawing attention to itself.

20,000 Windows computers to be destoyed.

According to a few articles around the web, that is. There have been a great many DDoS attacks lately. That stands forĀ  distributed denial of service. Basically, it’s a way of shutting down sites and servers by overloading them. If you get thousands computers all trying to download from a server all at once, bad things happen. These attacks appear to be politically motivated, and the search for the people responsible is under way and such. But the interesting thing about all this is that

the Korea Communications Commission (KCC) said it has been notified by South Korean computer vaccine company Ahn Lab that the DDoS virus responsible for initiating the attacks, was set to destroy at least 20,000 contaminated PCs across the nation.

Can I be the first to say,

Linux will get lots of viruses one day!

I’ve been seeing this meme quite a lot, lately. It is usually accompanied with, “And anyone who ignores the threat has their head in the sand,” and other platitudes. To any Linux users who might be spooked by this revelation, and to the trolls who spread it, I refer you to Feynman,

For a successful technology, reality must take precedence over public relations, for Nature cannot be fooled.

