Great Circle Associates Firewalls
(April 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: NT Viruses
From: "A. Padgett Peterson P.E. Information Security" <PADGETT @ hobbes . orl . mmc . com>
Date: Tue, 23 Apr 1996 11:11:15 -0400 (EDT)
To: firewalls @ greatcircle . com

>>     I believe there are a few.  NT, like other multi-user based operating 
>> systems make it harder for viruses to survive due to their security based 
>> file systems.  However, the chance of infection isn't eliminated, just 
>> reduced.

>I would have thought that the protected memory scheme would be the biggest
>stopping block?

Well if you only consider viruses that attack files/file systems this would 
be true, however the most common viruses do not. Low level viruses attack
before the protected memory scheme is in place (when it boots, an Intel 
processor is in "real" or 8086 emulation mode with no protection). The
rings are not a problem since they are not there at all.

Coming up fast, the "macro" viruses also are not impeded in any way since
they do not rely on the NT environment to function, using instead the
context of the application to spread (WORD being the most "popular").

Finally, the fact that virus writers have not targetted NT as yet just 
means exactly that and probably for the same reason that OS/2 is relatively
virus free (with the same caveats as above), not that it is inherantly
uninfectable.
						Warmly,
							Padgett

Indexed By Date Previous: RE: NT & C2
From: Chris Pugrud <ChrisP @ steldyn . com>
Next: Re: 1st http load gets error
From: peter @ baileynm . com (Peter da Silva)
Indexed By Thread Previous: Re: subnet mask problem
From: michelem @ sundc . East . Sun . COM (Michele Mullins - Commercial SE-Sun-Vienna VA)
Next: Firewall Blocking of JAVA
From: bobk @ manzanita . DEV . 3Com . COM (Bob Konigsberg)

Google
 
Search Internet Search www.greatcircle.com