Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 17 Jan 1998 14:55:47 -0500 (EST)
From:      "Adrian T. Filipi-Martin" <atf3r@cs.virginia.edu>
To:        Wei Weng <wweng@stevens-tech.edu>
Cc:        Jason Wik <jwik@best.net>, freebsd-questions@FreeBSD.ORG
Subject:   Re: VIRUS
Message-ID:  <Pine.SOL.3.96.980117144507.158D-100000@mamba.cs.Virginia.EDU>
In-Reply-To: <Pine.SGI.3.96.980117084427.20909B-100000@attila.stevens-tech.edu>

next in thread | previous in thread | raw e-mail | index | archive | help

	I really doubt there is a virus on their system; there just aren't
any unix viri out there.  I have only heard of a very few proof of concept
unix viri.  In all likelihood, you have a trojan or some other security
problem.  And that's how you should apprach this; as a security problem. 
If files are being modified on the system, someone has gained privlidges
beyond what they ought to have.

	BTW, there is a virus checker from McAfee that runs native under
FreeBSD, but it is meant for checking MS-DOS/Windoze files for viruses.  A
lot of people use unix file servers because NT servers suck.  This make is
eash to check all files on the server wihtout moving themover the network
to a DOS box to check for viruses. 

	Adrian
--
adrian@virginia.edu        ---->>>>| If I were stranded on a desert island, and
System Administrator         --->>>| I could only have one OS for my computer,
Neurosurgical Visualzation Lab -->>| it would be FreeBSD.  Think about it.....
http://www.nvl.virginia.edu/     ->|      http://www.freebsd.org/


On Sat, 17 Jan 1998, Wei Weng wrote:

> well...
> If u have the root access, a rm -rf is a deadly virus. 
> There are lots of ways to trick root, no need to make a virus. 
> If u realy want to find one, mcafee claims they have made an antivirus
> program for linux. You can try to run it on your freebsd box.
> 
> Wei Weng wweng@stevens-tech.edu
> http://attila.stevens-tech.edu/~wweng
> --------------------------------------------------------------------------
> Darkness beyond twilight, crimson beyond blood that flows ... buried in
> the flow of time ... in the great name, I pledge myself to darkness, all
> the fools who stand in our way shall be destroyed ... by the power you and
> I possess, DRAGON SLAVE! 
> --------------------------------------------------------------------------
> main(a,b){a="main(a,b){a=%c%s%c;b='%c';printf(a,b,a,b,b);}";b='"';printf
> (a,b,a,b,b);}main(a){a="main(a){a=%c%s%c;printf(a,34,a,34);}";printf(a,34,a,
> 34);}main(a){printf(a="main(a){printf(a=%c%s%c,34,a,34);}",34,a,34);}
> ---------------------------------------------------------------------------
> 
> On Sat, 17 Jan 1998, Jason Wik wrote:
> 
> > I Have a question one of our clients uses freeBSD and claims to have a
> > virus. Is there an antiviral program that can be used on FreeBSD for
> > FreeBSD. I am aware of the limitations of a virus in a unix O/S. But it
> > wouldn't suprise me. Hope you can help me out. 
> > 
> >                   Thanks,
> >                   Jason
> > 
> 




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.SOL.3.96.980117144507.158D-100000>