securite informatique

Malware question


Newsgroup: comp.os.linux.security ( Qu'est-ce qu'un Newsgroup et comment y participer ? )
Sujet: Malware question
De: Ac (aec$news@candt.clara.co.uk)
Date: 05 Aout 2007
In a recent discussion about the possible use of a virus checker in a
linux distro (I have ubuntu in mind) it was suggested in another group
that for example, a weakness may exist because a User may install
software into their account which could modify their .bashrc file to
allow some more malware to install a password sniffer to capture info
the next time they typed 'sudo > xxx' ('sudo' could be redefined in the
.bashrc file). Then the malware would be free to create chaos. Including
the use of other accounts for browser or email activities.

I guess this is a well known possibility, although I am new to this area
of experience.
What would safeguards include?
tia
--
ac
Liens connexes
 Les réponses au message de Ac (aec$news@candt.clara.co.uk)
Vulnerabilite.com ne peut être tenu responsable des propos tenus dans le Newsgroup comp.os.linux.security

 
La Signature électronique
Par Thierry Piette-Coudol (Litec)
 
Malware Intrusion Detection
Par Morton G. Swimmer (Books on Demand GmbH)
 
Incident Response
Par Kenneth R. Van Wyk, Richard Forno ( Associates)
Business Place
© 2000-2006 Vulnerabilite.com - Le portail des professionnels de la sécurité informatique
Edité par la société  ISECURELABS | Notice légale | Contact | Sitemap
Liens Promo : Disque dur - optimisation windows xp - Astuces Vista - Meilleurs prix