Great Circle Associates Firewalls
(June 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: Can a virus affect NT/UNIX firewalls?
From: "Paul D. Robertson" <proberts @ clark . net>
Date: Fri, 21 Jun 1996 11:04:10 -0400 (EDT)
To: Russ <Russ . Cooper @ RC . Toronto . on . ca>
Cc: "Firewalls @ GreatCircle . COM" <Firewalls @ GreatCircle . COM>
In-reply-to: <01BB5F31 . 75EB1F00 @ rwcooper . rc . toronto . on . ca>

On Fri, 21 Jun 1996, Russ wrote:

> "The potential exists.  I'd think that in general trojans were more 
> worrysome than viruses.  Last I'd looked, there were no known Unix viruses 
> actally "in the wild", and only a couple of NT specific ones (though some 
> DOS and Windows ones still work, I believe)."
> 
> Could you tell me the NT-specific ones?

Boza is the name of one of them, which goes after the NT/95 executiable
format.  It's EXE infector from '.au'.  Various people put it in
and not in the wild.  It took me all of 20 minutes to locate what seems to
be a valid 96,674 byte zip file on the net (after a seemingly bogus 2520
byte one turned out to be a nogo).  As soon as I get a 95 or NT machine to
play on, I'll know for sure.

I recall the other being called something that starts with a 'C', but
can't seem to grep specifics in my notes, and rather than being accused of
rumor mongering, I'll retract my statement to "one known NT virus".

I'm by no means a virus expert, I don't hang out in the Virus or
Anti-Virus communities, and my collection is basically one of those
curiosity/sorta_work_related kind of things.

The DOS ones that seem to be particualrly effective against NT are boot
sector viruses when can corrupt an NTFS to be unreadable.  As always,
frequent verified back-ups are your best protection.

Hope this helps,

Paul
-----------------------------------------------------------------------------
Paul D. Robertson      "My statements in this message are personal opinions
proberts @
 clark .
 net      which may have no basis whatsoever in fact."
                                                                     PSB#9280



References:
Indexed By Date Previous: Brent re firewalls mailing list
From: Cynthia Deno <cynthia @ usenix . ORG>
Next: RE: Security Check Program(s)
From: Alex Filacchione <alexf @ iss . net>
Indexed By Thread Previous: RE: Can a virus affect NT/UNIX firewalls?
From: Russ <Russ . Cooper @ RC . Toronto . on . ca>
Next: Firewalls-Digest V5 #378
From: srzpem @ swissre . ch (Martin Peter)

Google
 
Search Internet Search www.greatcircle.com