Skip to main content

Ethics of Releasing Non-Malicious Linux Malware?

posted onDecember 1, 2009
by hitbsecnews

I was fed up with the general consensus that Linux is oh-so-secure and has no malware. After a week of work, I finished a package of malware for Unix/Linux.

Its whole purpose is to help white-hat hackers point out that a Linux system can be turned into a botnet client, by simply downloading BOINC and attaching it to a user account, to help scientific projects. The malware does not exploit any security holes, only loose security configurations and mindless execution of unverified downloads: I tested it to be injected by a PHP script (even circumventing safe mode), so that the Web server runs it; I even got a proxy server that injects it into shell scripts and makefiles in tarballs on the fly, and adds onto Windows executables for execution in Wine. If executed by the user, the malware can persist itself in cron, bashrc and other files.

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th