Interesting People mailing list archives

more on Viruses


From: David Farber <dave () farber net>
Date: Sun, 22 May 2005 09:48:46 -0400



Begin forwarded message:

From: Jason Weisberger <jweisberger () mac com>
Date: May 21, 2005 8:37:14 PM EDT
To: dave () farber net
Cc: Ip ip <ip () v2 listbox com>
Subject: Re: [IP] Viruses


Dave,

The answer people seem to be looking for isn't one about "can" a virus be written for Mac OS X, but really about the threat model. There are so many millions of Windows users out there that they offer the entire playing field of whatever a virus author is looking for. While there are plenty of OS X users out there, there are far fewer - and the virus just won't be as productive. This is why, even tho previous correspondents here have been clear to point out, you can easily write a virus for SCO - we just never see or hear about them. Who the hell wants to be the guy that took down all 50 of those SCO boxes, the guy who stole all $50k the SCO users had in their personal files, etc. You can get many, many times the impact - be it stealing passwords, credit card numbers or resending funny emails by picking on Windows users.

If anyone on the list can conduct threat model assessments, I'd love to see a comparo. Seems like it'd be a market analysis on each OS's users tho and characterizing them may be hard as there are so many segments.

Jason
--


On May 21, 2005, at 4:33 AM, David Farber wrote:




Begin forwarded message:

From: Spafford Gene <spaf () cerias purdue edu>
Date: May 20, 2005 10:47:23 PM EDT
To: David Farber <dave () farber net>
Subject: Viruses


Basically, any system that has writable store that can allow written files to be executed, and which does not run mandatory access control (MAC) according to an appropriate integrity policy (ala the Biba model), can be infected by a virus.

The Mac OS X does not use MAC and policies such as Biba. Therefore, it can support a virus.

It is trivial to write a virus for Unix. Back in 1989, two articles were published in the (now defunct) journal "Computing Systems" (Volume 2, Number 2, Spring, 1989) that described Unix viruses. The articles were by Tom Duff and Doug McIlroy. Doug's article, "Virology 101" is available in many places on the WWW; I didn't find a copy of Tom's in a cursory search.

Linux viruses have been written and published.

Now, more to the point is how easy is it to craft a virus that is appropriately stealthy and also will spread reasonably well? Those are more difficult issues to address rather than simply writing something that can replicate. This may be where the Mac OS has some defensive advantages.

However, there is no question that viruses can be written for Mac OS or any other standard Unix-like system.


-------------------------------------
You are subscribed as jweisberger () mac com
To manage your subscription, go to
 http://v2.listbox.com/member/?listname=ip

Archives at: http://www.interesting-people.org/archives/interesting- people/





-------------------------------------
You are subscribed as lists-ip () insecure org
To manage your subscription, go to
 http://v2.listbox.com/member/?listname=ip

Archives at: http://www.interesting-people.org/archives/interesting-people/


Current thread: