home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.os.os2.apps:6005 comp.security.misc:1222
- Path: sparky!uunet!wupost!zaphod.mps.ohio-state.edu!sdd.hp.com!uakari.primate.wisc.edu!usenet.coe.montana.edu!news.u.washington.edu!ogicse!qiclab!leonard
- From: leonard@qiclab.scn.rain.com (Leonard Erickson)
- Newsgroups: comp.os.os2.apps,comp.security.misc
- Subject: Re: Self-Extracting Binaries dangerous? (Was: REXXShip: Self-Extracting UUEncode!)
- Message-ID: <1992Sep10.020949.27563@qiclab.scn.rain.com>
- Date: 10 Sep 92 02:09:49 GMT
- Article-I.D.: qiclab.1992Sep10.020949.27563
- References: <1992Sep6.025645.5101@midway.uchicago.edu> <18cf8rINNmpl@agate.berkeley.edu> <dank.715798089@blacks>
- Reply-To: 70465.203@compuserve.com
- Organization: SCN Research/Qic Laboratories of Tigard, Oregon.
- Lines: 33
-
- dank@blacks.jpl.nasa.gov (Daniel R. Kegel) writes:
-
- >sip1@ellis.uchicago.edu (Timothy F. Sipples) writes:
- >>Archive-name: auto/comp.os.os2.apps/REXXShip-1-0-Released-Self-Extracting-UUEncode
- >>The file rxship10.cmd is a self extracting REXX script which, when
- >>run, produces REXXShip.Cmd. REXXShip 1.0 is a REXX program which will
- >>take any binary file as input and produce an ASCII text version which
- >>is self extracting. Run the resulting ASCII text version through any
- >>REXX interpreter, including OS/2 2.0's, and you get the binary file
- >>back.
-
- >Is it just me, or do other people shudder at the thought of
- >self-extracting binary archives? They seem dangerous to me
- >because they involve running a raw program straight off the net
- >without any visibility as to what it's doing.
-
- This is practically the *standard* way programs get distributed to
- "low end" users of personal computers. Lots of stuff for the PC comes
- as an EXE or COM file that when run extracts the archive hidden
- inside the file. Me, I use a program that strips off the extractor on
- most of these and leaves me with an archive that I can process through
- a more trusted program.
-
- For that matter, I also own a machine with the OS (MS-DOS) in ROM. If
- I'm feeling *really* paranoid, I boot it from the ROM, and use software
- from write protected disks to extract the new files (I reserve this
- degree of paranoia for things like new releases of antivirus software)
-
- --
- Leonard Erickson leonard@qiclab.scn.rain.com
- CIS: [70465,203] 70465.203@compuserve.com
- FIDO: 1:105/51 Leonard.Erickson@f51.n105.z1.fidonet.org
- (The CIS & Fido addresses are preferred)
-