Re: ESET anti virus
Brad Barnett <[email protected]>
| Newsgroups | gmane.user-groups.linux.ottawa.general |
|---|---|
| Message-ID | <[email protected]> |
One last thing should be added. Many kernel bugs are in place for months, sometimes *years*, and used by skilled blackhats with discretion. It is only when some white hat finds the bug, or it makes it into the script kiddie realm, that bugs get patched. So, put another way, you are never, ever safe. This is why good sysadmin practises are so vital. Firewalls won't protect you, virus checkers only work on known vulnerabilities, and updates -- while vitally important, are only a game of playing catchup. This is why it is absolutely absurd that many offices even *have* access to the web from their desktop. 99.9% of the people using computers to do their jobs, have absolutely no reason to access the web. They're at work, if they want to check their mail, get a damned smartphone. Sadly, especially in GoC circles, security takes a far, far second to employees looking a Youtube at work. On Wed, 13 Apr 2011 11:13:13 -0400 Mike <[email protected]> wrote: > On Wednesday 13 April 2011 06:06:33 Jean-Francois Messier wrote: > > OK > > > > From the messages received so far, I conclude the following: > > > > - Linux is NOT invulnerable and also has its weaknesses. Practising > > safe computing is always a requirement. > > > > - The free solutions are not up-to-date as quickly as commercial ones > > > > - Vulnerabilities are not so much viruses, as they can also be > > malware, traps and bots. > > > > - One of the reasons Windows has so much malware is that it has a much > > bigger market share, and so is a way more interesting targets for > > attacks. If (ever) Linux becomes that popular, it will also become > > such target. > > A big risk with windows is that most people run with full admin > privileges, and windows update doesn't update all programs. Secuna has > a new program which does update everything. > > There was a kernel bug in Ubuntu 9.10 that allowed escalation, it was > nasty because it was an old bug that came back so the old attack code > worked on it. It was quickly patched, but if you had access to the > machine and it wasn't patched yet you could get root. > > > If you browse the list of exploits that metasploit offers and the tools > on BT4 You will see the common attacks. > > watch for weak passwords John can quickly get anything under 9 > characters > > > > > -- > Collector of vintage computers http://www.ncf.ca/~ba600 > -- > OCLUG general discussion list > [email protected] > http://oclug.on.ca/mailman/listinfo/oclug -- OCLUG general discussion list [email protected] http://oclug.on.ca/mailman/listinfo/oclug