View previous topic :: View next topic |
Author |
Message |
comprookie2000 Retired Dev
Joined: 25 Jul 2004 Posts: 925 Location: Sun City Center, Florida
|
Posted: Sat Feb 21, 2009 3:11 pm Post subject: Linux Malware |
|
|
I have been following the discussion on the gnome developer mailing list here “desktop-devel-list-bounces@gnome.org” and they were talking about the blog post located here; http://www.geekzone.co.nz/foobar/6229
It got me to thinking about all the new Linux users, that with the ease of installation with distros such as Ubuntu I can see this as really working and it is really easy to set up. In summary you would need to get someone to save an email attachment to there desktop. This will only work if you are using gnome or kde as it uses the way they set up launchers from the desktop. From there you could obtain root access by attaching a script to another program that uses gksu for gnome or kdesu for kde, and once they enter their password the script could run with root privileges. I have also been told but not confirmed that ubuntu and opensuse use passwordless sudo. Just to see how easy it would be I tried it and created a short screencast of how I think it could be done. I am not posting anything that is new, this has been around for a while but I had never heard about it before. Here is the screencast;
http://linuxcrazy.com/?q=node/61 _________________ http://dev.gentoo.org/~dabbott/ |
|
Back to top |
|
|
aidanjt Veteran
Joined: 20 Feb 2005 Posts: 1118 Location: Rep. of Ireland
|
Posted: Sat Feb 21, 2009 3:24 pm Post subject: |
|
|
Duped with: https://forums.gentoo.org/viewtopic-t-738506.html _________________
juniper wrote: | you experience political reality dilation when travelling at american political speeds. it's in einstein's formulas. it's not their fault. |
|
|
Back to top |
|
|
think4urs11 Bodhisattva
Joined: 25 Jun 2003 Posts: 6659 Location: above the cloud
|
Posted: Sat Feb 21, 2009 5:06 pm Post subject: |
|
|
DUPed for the above _________________ Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself |
|
Back to top |
|
|
|