LWN.net Logo

big deal

big deal

Posted Apr 9, 2006 6:18 UTC (Sun) by cate (subscriber, #1359)
In reply to: big deal by sbergman27
Parent article: Crossplatform virus - the latest proof of concept

Are not chkrootkit and rkhunter our ''antivirus'' ?


(Log in to post comments)

not enough to say you're just the messenger

Posted Apr 9, 2006 16:01 UTC (Sun) by copsewood (subscriber, #199) [Link]

Yes and ClamAV. It's not enough for a platform just to prevent threats to itself directly, unless it's only a client/desktop/workstation. If a Linux/Unix installation is used as a mail server, file server or router to relay and replicate (e.g. as in list email) messages sent between less well secured systems, then those like myself who are responsible for these servers need to take steps to avoid these being a part of the malware transmission problem even if we are just the messenger and not the sender. In principle this is very much the same kind of issue as applies to those running open mail relays which are not originating spam, but which by relaying and replicating it are disguising the origins of it and making the problem worse for the recipients. If one of my Mailman email lists receives a virus and replicates it, this is part of my problem, even if the virus is incapable of executing on my Linux server.

The same argument also applies to those responsible for routers which are carrying impossible source network addresses within IP packets used to carry out DDOS attacks to disguise the zombies responsible.

If handed a lemon, make lemonade

Posted Apr 10, 2006 15:33 UTC (Mon) by rickmoen (subscriber, #6943) [Link]

cate wrote:

Are not chkrootkit and rkhunter our ''antivirus''?

They are -- and the characteristics that make them so are the reason I've long advised people that they're in deep trouble if they use such things as anything but an afterthought double-check of separate, primary measures.

The best answer to any (e.g.) manager who want you to run "antiviral" software on Linux/BSD/etc. is that you already are -- and point to your setup of AIDE, Samhain, Prelude-IDS, or your other preferred flavour of file-based IDS. You needn't mention that such aren't exactly what they had in mind, but in fact are a lot more useful. What they don't know won't hurt them, and will help you.

Rick Moen
rick@linuxmafia.com

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds