Malware Found Hidden In Screensaver On Gnome-Look
AndGodSed writes "OMG! UBUNTU! Reports the following: 'Malware has been found hidden inside an innocuous 'waterfall' screensaver .deb file made available on popular artwork sharing site Gnome-Look.org. The .deb file installs a script with elevated privileges designed to perform a DDoS attack as well as keep itself updated via downloads. The dodgy screensaver in question has since been removed from gnome-look, and this incident was a very basic, if potentially successful, attempt.'" A similar report at Digitizor.com says that similar malware was also found in a theme called Ninja Black. For those affected, both sites also provide instruction on cleansing your system.
It's been told to all the linux zealots so many times that Linux itself isn't really more secure against malware than Windows. It's only so because it's marketshare is like 0.5%, if even that, and it makes much more sense to make malware where the (non-geeky) users are.
This just shows that if ever linux did gain marketshare with casual people enough, the malware problem will be there too. Repositories won't help with that, because people want 3rd party programs and games.
The funny thing about this is the same that as with Mac OS X users. All of the zealots yelling that Linux/Mac OSX are secure about malware, which results in normal people thinking they can run whatever downloaded "because my OS is secure!".
And before everyone jumps on the "but you can't get infected by just browsing on porn sites on linux!", why not? What was the last time you got infected by Windows vulnerability? Those attacks are usually against 3rd party programs like PDF or Flash. And guess what, those apps are on Linux too and are just as well exploitable.
The only reason malware problems are smaller on Linux than Windows is because of the almost-non-existing desktop marketshare and that those who use it on desktop are usually more tech savvy.
This just shows that if Linux had 95% marketshare on desktop, and Windows 0.5%, it would be the same thing but just turned around.
Okay, this scares me.
1. What happens when a publisher includes auto-updating code, but not specific attack code, like the DDoS software in the mentioned examples? If discovered it will appear to be a security risk, but not specifically malicious...
2. What happens when a software developer produces some completely innocuous software, gets into the repositories - and then months down the road, produces an update with DDoS capability, and has the update pushed into the repositories and automatically distributed?
This makes me wonder how long it will be before some warning about a fake virus/trojan/worm succeeds in convincing a few Linux newbies to run some command to get rid of the fake malware which inevitably causes damage or actually downloads actual malware. Something along the lines of: "if you've been infected with virus.deb just run the following command: sudo rm -rf / usr/bin/virus" The only cure is education.
Sigs are too short to say anything truly profound so read the above post instead.
Why? Because it's a sane method of delivering software, which is becoming widely used (i.e. Steam, iTunes Store, etc) vs the traditional "Herpes" model used by Windows?
Mod me down, my New Earth Global Warmingist friends!
Well do you really want the iPhone like only-approved-software app store for your computer? With no way to download software from anywhere else than that said approved app store.
Before trolls start yelling about how "OMGZ LINUX ISN'T SECURE HAHAHA" and things like that, let me tell you something: because GNU/Linux is so open and configurable, malware like this can be very easily removed. All you have to do is run a few commands in a terminal to remove this.
Before trolls start yelling about how "OMGZ WINDOZE AV SOFTWARE IS COMPLICATED HAHAHA" and things like that, let me tell you something: because Windows is so accessible, AV software like this can be very easily deployed. All you have to do is click a few icons in the Start Menu to remove this. Blah, blah, blah
On Linux and the like, everything is simple if you already know what you want to do. Otherwise, you have to trust unaccountable internet entities to provide you abstruse commands to run and hope they aren't trying to trick you into doing even more damage to your system. It should be obvious why that is a no way to combat malware.
A confusing command line instruction which most people would Ctrl-C and Ctrl-Shift-V into their terminal is actually a pretty good way to get a virus onto a Linux newbie's computer.
Ah but here is the problem.
To you, removing a virus from Linux is easy, because you are obviously an intelligent Linux user.
(Someone posted above the removal instructions)
For you to write out: sudo rm -f /usr/bin/Auto.bash /usr/bin/run.bash /etc/profile.d/gnome.sh index.php run.bash && sudo dpkg -r app5552
seems like nothing at all, but what about the average computer user? Do you think they know what sudo is? Hell I don't use Linux and I have no idea what the shit any of that stuff means. So no, that would only work with someone who really knows what they are doing with Linux.
Now on the flip side, you say...
"On Windows and the like, things are so complicated that Anti-virus software is almost required to remove some of their malware"
Ah, but this is going off the assumption that we are dealing with an average Windows user, not an expert user (Such as your self with Linux)
An expert Windows user like myself would say "Removing Malware is easy, just go into the registry's run section, remove what looks suspicious, delete temp files, prefetch, and search for the malware running process (Example: virus.exe) in the registry, and delete it"
Ah see that to me is easy, I've done things like that all the time, and it's just cake.
So I guess the point I'm trying to make is that...To you, removing a virus like this from Linux can be really simple...to someone who knows Linux, but the same can be said to a Windows user...who knows about Windows.
The greatest revenge in life is massive success.
Oh, dude. When I'm forced to use a Windows machine my #2 pet peeve is the paste buffer. You don't realize how much middle clicking you do until you don't have it anymore.
Samsung took back my unlocked bootloader because Google wants me to rent movies. They're both evil.