Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Server Daily
IT Management Daily
Subscribe News
Subscribe PR
Subscribe Security

internet.com
Internet News
Small Business

Advertise
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

Tech Comics: "Groundhog Day"

Want a Job? Learn Linux

PC-BSD 9 review – to FreeBSD what Ubuntu is to Debian

Time to dispel open source myths, says Liam Maxwell

SECURITY: Nmap Inside and Out

Eight features Windows 8 'borrowed' from Linux

Malware devs embrace open-source

A tale of two distros: Ubuntu and Linux Mint

Raspberry Pi benchmarked against Beagleboard, low price is long term

20 popular Ubuntu Linux apps you may want to try



Applications Management Engineer Sr (NYC)
Next Step Systems
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume
: Follow up: How to write a Linux virus
Follow up: How to write a Linux virus
Feb 12, 2009, 07 :31 UTC (11 Talkback[s]) (8073 reads)

"Commenter Burninator discovered that you don't even need the .desktop ending in the attachment. The Gnome and KDE desktops actually read the file, and don't base their decision to special-case the file on the file-name extension! So, the critical meta data here (make this something that can be executed) is NOT encoded in the filename, as some have suggested, it is actually derived by reading the first line of the file contents. So, in that respect the desktop environments are not quite as hapless as some had indicated and are not just making the same mistake as Windows has.

"On the flip-side of that same discovery: You can make your attachment now even less suspicious looking. Rather than naming it something like some_text.odt.desktop, you only need to name it some_text. That has two nice side effects: Firstly, email clients will now never know what to do with the file (no useful extension) and are more likely to prompt the user to save the file to disk. Thus, you don't need to get the user to explicitly do that anymore by putting proper wording in your email."

Complete Story

Related Stories:
How to write a Linux virus in 5 easy steps(Feb 11, 2009)
Kaspersky database exposed(Feb 09, 2009)
Windows worm numbers 'skyrocket'(Jan 19, 2009)
Virus sinks Royal Navy fleet comms(Jan 17, 2009)


Index Mode   |   Flat Mode   |   Thread Mode   |   Thread Flat  
  Talkback(s) Name  and Date
Well, look, I have been in the security  ...   The punchline   
Rainer Weikusat
Feb 12, 2009, 09:09:08
 
This is not a virus.  It doesn't mat ...   Not A Virus   
Tony OBryan
Feb 12, 2009, 13:44:14
 
Tony O'Bryan wrote: That a user will ...   More downplaying   
David F. Skoll
Feb 12, 2009, 14:48:33
 
First I don't think Tony is downplay ...   Probably a little cold but...   
Jeff Cobb
Feb 12, 2009, 16:22:36
 
I simply cannot imagine blindly clicking ...   Re: Probably a little cold but...   
David F. Skoll
Feb 12, 2009, 18:08:07
 
> I don't want to keep reposting my  ...   Re: Re: Probably a little cold but...   
TripleII
Feb 12, 2009, 18:38:30
 
> Again, you are downplaying the problem ...   Re: More downplaying   
Tony OBryan
Feb 12, 2009, 19:14:01
 
This is definitely not a virus, and that ...   Not a Virus, But Definitely an Issue   
C. Whitman
Feb 12, 2009, 19:20:06
 
> As I said, there is nothing we can do  ...   Re: Re: More downplaying   
David F. Skoll
Feb 12, 2009, 21:39:22
 
Will .desktop files execute if they are  ...   How about noexec mounts ?   
Jon Davis
Feb 13, 2009, 00:38:52
 
Will .desktop files execute if they are  ...   Re: How about noexec mounts ?   
C. Whitman
Feb 13, 2009, 15:29:59
 
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!

..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP