lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
From: dfs at roaringpenguin.com (David F. Skoll)
Subject: Re: January 15 is Personal Firewall Day, help
 the cause

On Fri, 16 Jan 2004, Wes Noonan wrote:

> This is not quite correct. Nachia and Blaster, as well as Code Red and its
> variants are all detectable and preventable with virus protection.

All of those are Windows viruses, no?

> While
> they may not stop the worm on the network, they can and do stop systems from
> becoming infected and propagating the worm.

So does mounting /tmp noexec, and it doesn't involve shelling out money
to AV vendors.  Mounting /tmp noexec also protects against future threats,
not just ones that happen to be in the AV database.

(I know that someone recently released code to do a "user-space" exec,
so mounting /tmp noexec is not 100% foolproof, but it's pretty good
protection.)

--
David.


Powered by blists - more mailing lists