home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.org.eff.talk
- Path: sparky!uunet!paladin.american.edu!gatech!emory!nastar!phardie
- From: phardie@nastar.uucp (Pete Hardie)
- Subject: Re: Beneficial Virus?
- Message-ID: <1993Jan11.165511.6851@nastar.uucp>
- Organization: Digital Transmission Systems, Duluth, GA.
- References: <1993Jan6.152243.22472@nastar.uucp> <ym03wB3w165w@ruth.UUCP>
- Date: Mon, 11 Jan 1993 16:55:11 GMT
- Lines: 85
-
- In article <ym03wB3w165w@ruth.UUCP> rat@ruth.UUCP (David Douthitt) writes:
- >phardie@nastar.uucp (Pete Hardie) writes:
- >
- >| Consider a multi-user system where another user installed the virus, and I
- >| want to transfer a file to my home system, and need to transfer the marker
- >| file, but I do not know which file it is.
- >
- >A. If a USER on a multi-user system is able to install the virus, then you've
- > got REAL problems, I say.... unless the virus is written with that in
- > mind - and only attaches itself to the user's file.
-
- The virus is described as a marker file and an executable containing the virus
- code - I assume that the initial vector is a "Hello, world" program. Nowhere
- is it stated that the virus does any checking on the executable other than
- for existing infection. I assume that if it *can* rewrite an executable, it
- DOES rewrite it.
-
- >B. You wont need to transfer the marker file - the file will auto-uncompress
- > with or without the marker. The marker only prevents the spreading
- > of the auto-uncompress code.
-
- Agreed. But see the discussion of this on the definition 'virus', and on the
- transfer of an infected file to another system.
-
- >C. You don't NEED to know what file it is - just reinstall the virus
- > software at home. Of course, with the sensitivity of such a product,
- > I would expect the file to be named in the manual somewhere.
-
- Install it? From where? I have an account on Mary's Public access BBS, and
- I copy my neato-keen 'dir' program for UNIX, so I can type 'dir' and get
- a listing just like on my old PC....I type 'dir' the next day and get:
-
-
- Notice: The Beneficial Compression Virus has not detected the correct
- marker file 'BCVIRUS.OK'. This program will NOT be recompressed on
- termination.
-
- Now, I can call Mary back and ask for the marker file, etc. But if she did not
- install the virus, she won't know where the file is either.
-
- Manual? Which manual? The virus manual? Why make it a virus if you need
- a manual to use it?
-
- >| Sure, no more files are infected once
- >| I delete the marker file (assuming I know which file it is), ....
- >
- >Again, you don't NEED to know what file it is - if you want to remove it,
- >run the provided (one would expect!) Beneficial Virus De-Install utility.
-
- So lesee now....I have the virus program, the marker file/compression program,
- the install program, the de-install program....
-
- Sounds like a lot for a virus that is supposed to do this thing for you without
- any visible effect save smaller executables.
-
- >| ...but suppose I
- >| want/need to transfer a file to another system that is required to be virus-
- >| free? How to I get an uninfected copy of my file?
- >
- >Is there a difference between a virus that DOES NOT EXECUTE and no virus at
- >all? If the auto-decompress program checks for a marker, then calls the
- >virus IF the marker is present, then if no marker is present no virus is
- >called.
-
- Ask any virus-checker program. A file that is modified (size or write time-
- stamp) is suspect. It would be impossible to check for the 'beneficial'
- virus in any programmable manner and allow it through, but stop any 'harmful'
- viirii.
-
- A program with code that will write that code into another program is a carrier,
- pure and simple. Once such a program is on a machine, someone can write a
- false marker file with the compression code replaced by a disk eraser, and
- wipe the system clean.
-
- >Another point - if the virus code is *IN* the marker.... then no marker,
- >no virus - PERIOD.
-
- Trivially true. It becomes PCZIP.EXE, or compress - in other words, another
- file compression/decompression utility.
-
- --
- Pete Hardie: phardie@nastar (voice) (404) 497-0101
- Digital Transmission Systems, Inc., Duluth GA
- Member, DTS Dart Team | cat * | egrep -v "signature virus|infection"
- Position: Goalie |
-