Re: PhD Topic suggestions

Kurt Huwig <[email protected]> Fri, 19 Dec 2003 11:46:26 +0100
Newsgroups gmane.comp.security.virus.openantivirus.general
Message-ID <[email protected]>
Fridrik Skulason wrote:
>>Yes, it is for this reason alone that this wont work.  
> 
> 
> Not *alone*.  Another reason would be that anyone stupid enough to "update" machines
> without authorization would be in violation of the laws in many places.
> 
> 
>>Now it would be nice to have a worm that could identify infected or vulnerable 
>>computers and inform the user with an email or something and maybe shutting down
>>the computer but that would be exploited by spammers at the very least.
> 
> 
> It would not be "nice".  It would be incredibly idiotic.

I second this. It is a fact that there are about 10-20 current security 
holes in Microsoft products, that there are exploits and 
proof-of-concept available in the wild. For example you can find here:

http://www.heise.de/security/dienste/browsercheck/demos/ie/

3 working exploits for IE that execute arbitraty code on the target 
machine and there are no patches available yet to fix them.

But still you can protect yourself by using a special http-proxy that 
filters the malicious codes. So it would be very idiotic to shut down 
these machines although they cannot be infected at all. And besides 
this, you would be fired after you did this the first time with one of 
the executive's machines.


Kurt
-- 
Kurt Huwig             iKu Systemhaus AG        http://www.iku-ag.de/
Vorstand               Am Römerkastell 4        Telefon 0681/96751-0
                        66121 Saarbrücken        Telefax 0681/96751-66
GnuPG 1024D/99DD9468 64B1 0C5B 82BC E16E 8940  EB6D 4C32 F908 99DD 9468
signature.asc (application/pgp-signature, 252 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQE/4tcCTDL5CJndlGgRArApAJ0TiH7NAZJ4aV4EjvnzSdW2p0VDIgCeL8/4
BMuk9ptv0RzF1ToKiwqd4bc=
=Xf7m
-----END PGP SIGNATURE-----