You are here: Home Personal My Blog Boost your Security

Boost your Security

by Harald Hoyer last modified Apr 23, 2008 02:33 PM
This blog entry should raise your security awareness.

The Threat

Not everybody is aware of the paper "Application-Specific Attacks: Leveraging the ActionScript Virtual Machine" written by Mark Dowd, in which he describes various techniques that promise to open up a class of exploits and vulnerability research previously thought to be prohibitively difficult. While the Flash vulnerability described in the paper [pdf] has been patched by Adobe, the presentation of a reliable exploit for NULL pointer dereferencing has the researchers who have read the paper fascinated. Thomas Ptacek has an explanation of Dowd's work, and Nathan McFeters at ZDNet is 'stunned by the technical details'. You should at least read the explanation.

What does that mean to the average desktop user?

If Adobe had not fixed the security issue, or if there are others in the flash plugin, your account could be infected by a virus, trojan or anything else while you watch a malicious video on youtube. And you wouldn't even recognize it, because the flash player keeps playing the video. This exploit works on the Windows plugin as well as the Linux version, because inside Adobe uses the same code. So, you say: "infecting a normal user account does not fully compromise my system". But if you are a single user, you most likely call "sudo" or enter your password or root's password in consolehelper to run system-config tools. A virus/trojan can run itself every time you login, by adding itself to .bash_profile or the gnome-session, log/sniff all keystrokes and send them to his master. You would not recognize that in the first place. By recording your passwords, root access can be gained easily. There goes your system. With recent techniques your computer may boot first a trojan, which runs all other operating system then in a "virtual" machine. Boom.

What can you do?

Turn on SELinux. Install nspluginwrapper. Don't install untrusted third party software. Listen to Daniel Walsh and help him. Confine the flash plugin and your user account. Help to improve the SELinux policies.

Filed under: , , ,

RE: Boost your Security

Avatar Posted by Frank at Apr 23, 2008 03:09 PM
Ok, there is a lot of us "normal" users of Fedora/linux out there, you know, the ones that just USE fedora and manage to get by.

I'm one of these type of users, and read often and on about Trojans and linux. Coming from a windows world many years ago, my paranoia has followed me, so i run RKhunter and chkrootkit.

One thing really concerns me though. Windows ( with all its flaws ) has a way to remove viruses when a machine is infected. This is what is advertised anyway so lets assume it works as they say.

But linux on the other hand has no way to really remove trojans from an infected machine. This is troubling.

Thanks for listening :-)

Fred

RE: RE: Boost your Security

Avatar Posted by Harald Hoyer at Apr 23, 2008 04:22 PM
Well, you can never be sure, you have removed _everything_. Tripwire, rpm and similar things can help, but even then, you cannot be sure, if the rootkit infected your kernel and even your master boot record. So either reinstall, or not let it happen in the first place.

Add comment

You can add a comment by filling out the form below. Plain text formatting.

(Required)
Please enter your name.
(Required)
(Required)
(Required)
Enter the word