Email: Password: Remember Me | Create Account (Free)

Back to Subject List

Old thread has been locked -- no new posts accepted in this thread
???
11/17/07 14:21
Read: times


 
#147118 - Not Targets
Responding to: ???'s previous message
Hi Steve,

Many (most ?) of the biggest websites in world run Apache on Linux hardware - these systems are effectively open to attack all the time, yet I don't see them being compromised ?


I submit that just because they're the biggest websites doesn't make them the biggest targets. I tend to agree that Windows is most targeted because it's the most prevalent. Have you ever read "The Cuckoo's Egg?"

I suspect that the most significant vulnerability of either OS is the naivete of the user. For example, was it Jeff who wrote that a Windows machine can be infected just by "receiving" an infected email? But as I understand it, the truth is that the actual vector of attack is the attachment, not the email itself. And the attachment can't do anything until and unless you open it. (Sound familiar? Did you read "The Cuckoo's Egg?")

And there is one other problem I see with one of the arguments proffered here. It has been suggested that since everybody has access to the source code, security patches would be much more quickly realized. But who would actually, intentionally, modify their OS with something that was "making the email rounds?" And if it became the norm to do so, how long would it take the hackers to exploit this new behavior as a vector of attack?

Talk about an easy-in to infect countless machines. Just send out a "new security patch" email, especially one that actually addresses a real vulnerability, and then wait for as many people as will to install it on their own machines and send it on to their friends.

Of course, after this happened once or twice (or thrice) people would quickly stop installing "email patches." Then those discovered vulnerabilities would remain known and open for years.

Just a thought,

Joe

List of 36 messages in thread
TopicAuthorDate
Says it better than I can            01/01/70 00:00      
   re 'evangelism'            01/01/70 00:00      
      So limited            01/01/70 00:00      
         I believe it's obvious            01/01/70 00:00      
         If YOU would read what I posted            01/01/70 00:00      
      Wine and VirtualBox            01/01/70 00:00      
         and you suggest that for DEVELOPMENT???            01/01/70 00:00      
   Don't know about Linux but love your D52.EXE            01/01/70 00:00      
      Why ?            01/01/70 00:00      
   What makes Linux less vunerable?            01/01/70 00:00      
      Design            01/01/70 00:00      
         that's great, but ...            01/01/70 00:00      
            Yes, it is            01/01/70 00:00      
               Huh?            01/01/70 00:00      
                  Re: Huh?            01/01/70 00:00      
                     Linux vs Windows            01/01/70 00:00      
                        What sort of Linux do you have, Craig?            01/01/70 00:00      
                        Oh yea ?            01/01/70 00:00      
                           True            01/01/70 00:00      
                           Looks like...            01/01/70 00:00      
         Security            01/01/70 00:00      
         AMEN!            01/01/70 00:00      
         Everybody should use linux!            01/01/70 00:00      
            Linux attacks            01/01/70 00:00      
               Not Targets            01/01/70 00:00      
                  Caveat Emptor            01/01/70 00:00      
                     email vulnerability            01/01/70 00:00      
                        Kleinstein            01/01/70 00:00      
                  Linux is the "solution" ... for now ...            01/01/70 00:00      
                  Concur            01/01/70 00:00      
                     Layers            01/01/70 00:00      
                        Perhaps            01/01/70 00:00      
                           Separation            01/01/70 00:00      
   If Linux was an airline            01/01/70 00:00      
      Keep reading            01/01/70 00:00      
   Bad logic            01/01/70 00:00      

Back to Subject List