home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ogicse!reed!horde
- From: horde@reed.edu (Mr. Heiji Horde)
- Newsgroups: comp.sys.next.sysadmin
- Subject: Re: Virus via mail
- Keywords: Is it possible?
- Message-ID: <1992Aug19.232002.17662@reed.edu>
- Date: 19 Aug 92 23:20:02 GMT
- Article-I.D.: reed.1992Aug19.232002.17662
- References: <1992Aug19.145655.8372@magnus.acs.ohio-state.edu>
- Organization: Twisted Genius Rehabilitation Center, a Division of MHE
- Lines: 40
-
- In article <1992Aug19.145655.8372@magnus.acs.ohio-state.edu> szatezal@magnus.acs.ohio-state.edu (Shane M Zatezalo) writes:
- >Would it be possible for someone to spread a virus via NeXTMail?
- >It seems as though if a person threw a destructive program in the mail,
- >and an unknowing user launched it right from his/her mailbox, a lot of
- >damage could be done.
-
- Assuming the person was unknowing and launched anything they got in the mail.
-
- That seems easy enough. Although it seems more trojan horse than virus.
- To be effective, you'd need the virus, once launched, that way do things like:
- 1) [deleted]
- 2) [deleted]
- 3) [deleted]
- 4) [deleted]
-
- Soon you should have many people with very full mailboxes.
-
- There have also been rumours of people working on Postscript viruses.
- But those would only work if you are a public window server (I think).
-
- A possible kludge for this would be to have NeXTMail check for dangerous
- commands to execute (like Cnews does now) since it must extract/uudecode
- the inclusion before executing it.
-
- =====
-
- After further thought, I deleted the exact procedure of how you would write
- a NeXTmail virus above. I don't want to cause people any inconvienience.
- But, if you think hard enough, it takes about 1/2 hour to write.
-
- DISCLAIMER: I do not condone this type of activity. I am only posting this
- because I believe this to be a very important security problem that was
- created _unintentionally_ (as most security holes are. And this needs to
- be addressed.
-
- --
- ===========================================================================
- Mr. Heiji Horde (Non NeXT mail only please) e-mail: horde@reed.edu
- All insane acts are done in affiliation with Madd Hacker Enterprises
- "ALL ABOARD, the lunacy train is pulling out."
-