Courses:

Offensive Countermeasures: The Art Of Active Defense: SANSFIRE June 15-16, Blackhat USA July 27-28 & 29-30


Defensive Countermeasures: Foundations for Becoming A Devious Defender: Blackhat USA July 27-28 & 29-30


Conferences:

Check out the entire PaulDotCom crew at BsidesRI June 14-15th!



Subscribe:

Blog:
Videos:
Podcast:


PaulDotCom EspaƱol


Hack Naked TV


Hack Naked At Night


Stogie Geeks


Sponsored By:


www.coresecurity.com


www.tenablesecurity.com


www.sans.org



Follow Us On:


twitter.com/pauldotcom

PaulDotCom YouTube Channel


Proof of Concept virus can infect both Windows and Linux

| | Comments (2)

Kaspersky Labs are reporting that they have discovered a Proof of Concept (PoC) virus that can infect both Linus ELF files and Windows PE files. Kaspersky states that clearly this is only a PoC.

We have all seen this before - it doesn't take long for a PoC to become reality.  I'm wondering how long it takes for something like this to be come a reality, and in fact to be come "standard practice" for virus writers.

Just a reminder, just because you run OS X, Linux or other *nix variant, doesn't mean that you are immune form viruses.  Practice Defense in depth, because the threats are out there for every OS.

- Larry

New PoC virus can infect both Windows and Linux

2 Comments

I'm sure someone has reminded you guys by now, but apparently SC Mag's news agents run a "sleep 7776000". Kaspersky broke the story on April 7 here:
http://www.viruslist.com/en/weblog?weblogid=183651915

And in an interesting twist, Linus patched the kernel so that the PoC would run, as recounted here:
http://software.newsforge.com/article.pl?sid=06/04/18/1941251

BTW, having been a print subscriber to SC Mag some years ago, I'm not at all surprised to see that rag get it all wrong. It's a bunch of vendor glossies stapled together.

Love the show, keep up the great work and all that. -t

[Tim, we thought that is sounded familliar, and we even remarked about it on the show...oh well. - Larry]

This type of thing has been announced before. Usually the PoC demonstrators make some baseline assumptions don't work well in the real world, on either OS. I have doubts that this leads anywhere.