Full Disclosure mailing list archives

RE: [inbox] Re: Show me the Virrii!


From: "Curt Purdy" <techman () inu net>
Date: Wed, 7 Jan 2004 11:18:11 -0600

Exibar wrote:

Why do you ultimately blame Windows/DOS for the virus
problem?  This is
simply not true.  Are there not SQL worms?  Was it not a SQL
worm that was
the fastest to spread in history?  Are there not many Linux worms and
viruses, and more being written each day?  Are there not
viruses and/or
worms that exploit Cisco products?

Jeeze, you know how many pages I had to delete off the end of this thing?
It doesn't take remembering PINE to know how to clean up your act.

OK, to business.  Your points: the SQL worm exploited ONLY MS SQL.  The
cisco worm exploited IIS that was the web interface in their DSL routers.
Yes, there are a few Linux worms but the numbers are tiny vs. MS.  And that
is NOT because MS is so prevelant, although of course that is a factor as
explained in the seminal work "Cyberinsecurity: The Cost of Monopoly".  The
primary reason for so many MS virii is the poorly written code that has
evolved into their current elephants of OS's.

All is not lost for MS, but it will take a ground-up rewrite to solve the
problems.  Unfortunately they seem to be taking the opposite tack of taking
W2K, the best OS they have come up with yet, and folded it into XP, the
biggest pile of dog doo since 3.1 and telling customers they can't get 2K
even if they prefer it.

Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA
Information Security Engineer
DP Solutions

----------------------------------------

If you spend more on coffee than on IT security, you will be hacked.
What's more, you deserve to be hacked.
-- White House cybersecurity adviser Richard Clarke



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: