home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.org.eff.talk
- Path: sparky!uunet!cis.ohio-state.edu!zaphod.mps.ohio-state.edu!rpi!gatech!paladin.american.edu!europa.asd.contel.com!emory!nastar!phardie
- From: phardie@nastar.uucp (Pete Hardie)
- Subject: Re: Beneficial Virus?
- Message-ID: <1993Jan6.152243.22472@nastar.uucp>
- Organization: Digital Transmission Systems, Duluth, GA.
- References: <67iRwB1w165w@ruth.UUCP> <1993Jan5.153018.18935@nastar.uucp> <C0EJAu.HuI@panix.com>
- Date: Wed, 6 Jan 1993 15:22:43 GMT
- Lines: 41
-
- In article <C0EJAu.HuI@panix.com> rpowers@panix.com (Richard Powers) writes:
- >In <1993Jan5.153018.18935@nastar.uucp> phardie@nastar.uucp (Pete Hardie) writes:
- >>My point is that you do not necessarily know which file is the marker.
- >
- >How would this be possible? You would have to have installed the
- >marker file in the first place to enable the virus to operate on your
- >system! There is no way you could not know which it is. The whole
- >point of this thing is that you have to deliberately let the virus
- >have access to your system. They way you would do this is by placing
- >a specific file on your system that the virus would look for.
- >Otherwise it simply does not propogate.
-
- Consider a multi-user system where another user installed the virus, and I
- want to transfer a file to my home system, and need to transfer the marker
- file, but I do not know which file it is.
-
- >The files are not changed by being without the marker!! The only
- >thing which is changed is that the virus will no longer spread itself.
- >The compressed file _still_ has the virus prepended. Thus it will
- >_still_ be able to decompress the file upon execution. It will then:
- >[commit hari-kari/notify the user/do nothing] (discussed elsewhere).
-
- This is noted. See below.
-
- >>Still, the question arises - suppose I decide I don't want those files stored
- >>compressed any more. How would I get rid of the virus?
- >
- >Simple. You remove the marker. That is what the marker is for!
-
- But the virus still remains embedded in the compressed files. Unless the
- virus code is remove on decompression, and re-inserted on write-to-disk, it
- remains in the file, albeit dormant. Sure, no more files are infected once
- I delete the marker file (assuming I know which file it is), but suppose I
- want/need to transfer a file to another system that is required to be virus-
- free? How to I get an uninfected copy of my file?
-
- --
- Pete Hardie: phardie@nastar (voice) (404) 497-0101
- Digital Transmission Systems, Inc., Duluth GA
- Member, DTS Dart Team | cat * | egrep -v "signature virus|infection"
- Position: Goalie |
-