home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!cis.ohio-state.edu!rutgers!uwvax!gorgon!fullfeed!ruth!rat
- From: rat@ruth.UUCP (David Douthitt)
- Newsgroups: comp.org.eff.talk
- Subject: Re: Beneficial Virus?
- Message-ID: <m093wB2w165w@ruth.UUCP>
- Date: 9 Jan 93 02:40:09 GMT
- References: <BETSYS.93Jan5233720@ra.cs.umb.edu>
- Organization: Network XXIII - +1 608 222 9253
- Lines: 43
-
- betsys@cs.umb.edu (Elizabeth Schwartz) writes:
-
- | You are missing a basic point. For a virus to "check for the presence
- | of a marker file" that virus has to be executing on my system, whether
- | or not I have authorized it to.
-
- Interesting point and one to consider.... does this extend to "hidden"
- de-compression code attached to executables? Does this mean that all
- auto-uncompressing executables should be eliminated?
-
- | Besides, how does the virus *get* to my system? Either it cracked my
- | security, again without my permission, or it was hidden on a file
- | imported onto my system, without my knowledge (if I *know* about it,
- | and import it deliberately, then packaging it as a virus was not
- | necessary.)
-
- This discussion is not relevent to "cracking security" -- the benificial
- virus we've taken to discussing is NOT going to crack security.
-
- As for being "hidden on a file" - you mean just like the way
- auto-uncompression code is "hidden"? There are only two ways the
- virus could arrive on your system:
-
- 1. You installed the viral software. The file marker VIRUSOK!.MRK is
- present, and the virus is okayed. When a compressed file runs,
- the file is uncompressed, then the virus takes up residence in
- memory if not already there, and watches for a chance to compress
- a new executable file.
-
- 2. You did not install the viral software - there is no marker.
- The file decompresses, and the virus deactivates itself and
- does NOT take up residence in memory and does NOT run. This
- virus could also erase itself from the self-uncompressing code,
- automatically causing it to die out when removed from its host
- (interesting biological analogy there.... somewhere :-)
-
-
- --
- UUCP: ....!fullfeed.com!ruth!rat | Network XXIII - +1 608 222 9253
- InterNet: rat@ruth.UUCP | 80Megs+ of Usenet/Fido programs!
- Fidonet: David Douthitt 1:121/23 | ... Files via Fidonet FREQ,
- "...because appealing to the masses has | anon uucp, first time login,
- never appealed to us." | mail to fileserver@ruth.uucp
-