Re: ESET anti virus

Brad Barnett <[email protected]>
Newsgroups gmane.user-groups.linux.ottawa.general
Message-ID <[email protected]>
One last thing should be added.

Many kernel bugs are in place for months, sometimes *years*, and used by
skilled blackhats with discretion.  It is only when some white hat finds
the bug, or it makes it into the script kiddie realm, that bugs get
patched.

So, put another way, you are never, ever safe.  This is why good sysadmin
practises are so vital.  Firewalls won't protect you, virus checkers only
work on known vulnerabilities, and updates -- while vitally important,
are only a game of playing catchup.

This is why it is absolutely absurd that many offices even *have* access
to the web from their desktop.  99.9% of the people using computers to
do their jobs, have absolutely no reason to access the web.  They're at
work, if they want to check their mail, get a damned smartphone.

Sadly, especially in GoC circles, security takes a far, far second to
employees looking a Youtube at work.

On Wed, 13 Apr 2011 11:13:13 -0400
Mike <[email protected]> wrote:

> On Wednesday 13 April 2011 06:06:33 Jean-Francois Messier wrote:
> > OK
> > 
> > From the messages received so far, I conclude the following:
> > 
> > - Linux is NOT invulnerable and also has its weaknesses. Practising
> > safe computing is always a requirement.
> > 
> > - The free solutions are not up-to-date as quickly as commercial ones
> > 
> > - Vulnerabilities are not so much viruses, as they can also be
> > malware, traps and bots.
> > 
> > - One of the reasons Windows has so much malware is that it has a much
> > bigger market share, and so is a way more interesting targets for
> > attacks. If (ever) Linux becomes that popular, it will also become
> > such target.
> 
> A  big risk with windows is that most people run with full admin
> privileges, and windows update doesn't update all programs.  Secuna has
> a new program which does update everything. 
> 
> There was a kernel bug in  Ubuntu 9.10 that allowed escalation, it was
> nasty because it was an old bug that came back so the old attack code
> worked on it. It was quickly patched,  but if you had access to the
> machine and it wasn't patched yet you could get root.  
> 
> 
> If you browse the list of exploits that metasploit offers and the tools
> on BT4 You will see the common attacks.  
> 
> watch for weak passwords John can quickly get anything under 9
> characters
> 
> 
> 
> 
> -- 
> Collector of vintage computers http://www.ncf.ca/~ba600
> -- 
> OCLUG general discussion list
> [email protected]
> http://oclug.on.ca/mailman/listinfo/oclug
-- 
OCLUG general discussion list
[email protected]
http://oclug.on.ca/mailman/listinfo/oclug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.