8 ms·
Old-skool virus writers still exist.
- rbanffy 16y ago"- Microsoft hh86: love it"
- Luyt 16y agoWhy do all these virii start with 'W32.' ? ;-)
- rbanffy 16y agoTo honor the environment that lets them thrive.
- tptacek 16y agoWinAPI is no more hospitable to viruses than Linux is. What it is is popular enough to be worth targeting.
- davidcuddeback 16y agoThat's a fallacy that I'm frankly tired of hearing. Unix was designed from the start to run multi-user environments, whereas Windows grew out of DOS, which was initially built for single-user, non-networked environments. The difference in their initial goals led to wildly different security models. The average Unix user runs without superuser privileges most of the time. Typically, the less experienced a user is, the less privileges he has in a Unix environment [1]. At least as recently as Windows XP [2], the average Windows user ran his computer with an administrator account on a daily basis, which opens the user to much greater damages from malware. When I used Windows on my own computers, I always setup a non-administrator account for daily use, but I'm experienced enough to know (1) how to do that and (2) that it's a good idea. This suggests that Windows has an inversion of privileges compared to Unix. That is, the most experienced users grant their daily account the fewest privileges, whereas the least experienced users operate with administrator privileges. [1] http://librenix.com/?inode=21 http://librenix.com/?inode=21 [2] Windows XP is the latest version of Windows that I've had enough experience with to say what the average user's setup is like. I hear that the situation has improved a bit with Windows 7, but when I was an intern at Microsoft, every one seemed to run as an administrator on their Windows 7 machines, so I'm not convinced that it's any better.
- tptacek 16y agoThe idea that viruses need "superuser" to perpetuate themselves is itself a fallacy. Why do I want superuser if I can grab all your browser cookies, dump or exploit your address book, persist in ways no normal user can detect, and gain full access to the network you're connected to? I'm not a Windows user. Since age 13, I have spent a total of one (1) year in Windows, in 2000, when I ran a Solaris to WinAPI ACE_wrappers port for my startup. I cut my teeth on 386bsd, installed from approximately 900,000 3.5 inch floppy disks. What I am is a security person, and these arguments about Windows being a petri dish for viruses strike this security person as BS. Computers are a petri dish for viruses, and the smug Unix weenie attitude of "we solved that with su" drives me nuts even before we get to analyzing how long any Unix operating system has ever gone without a well-known privilege escalation flaw.
- davidcuddeback 16y agoHow will you infect an executable without superuser privileges? My executables in /bin and /usr/bin are r-xr-xr-x. If you're not infecting files on the filesystem, then what you have is not a virus [1]. Without a virus, you're left to exploit bugs in userspace software. If you have a way to exploit Chrome to read my cookies, how is that a virus and what does that have to do with the OS? I would expect that exploit to work on any platform that runs Chrome. In regards to your first post about popularity, do you think that all of those Unix web servers out there are not a juicy target? How valuable do you think it would be to a virus writer to be able to infect Google's datacenter? The rest of your comment is name-calling and self-congratulatory back-patting, which does nothing to present a cogent argument. [1] Executables aren't the only files that can be infected. You could infect a user's PDF, JPEG, or other files that are then interpreted by a vulnerable executable.
- tptacek 16y ago(a) You don't need to infect executables. .profile works nicely. (b) How valuable do you think it would be to a virus writer to infect Mastercard's data center? It isn't riddled with viruses. (c) If you have a population that accounts for 80% of the market which is only 20% saturated and another that accounts for 5% of the market, why would you ever, ever, ever write for the 5% market? We haven't hit "peak oil" for malware yet. (d) Your footnote makes my point. Thanks. (ps) the congratulatory back-patting is to head off the inevitable Linux advocacy "you're a shill for Microsoft" BS that comes bundled with these discussions.
- lelele 16y agoIt's not just popularity. "Admin by default" and "Easy-to-use over everything" is what doomed Windows. In *nix you always had to exploit bugs, in Windows you hadn't to. Nowadays Microsoft has built layer of abstraction over layer of abstraction to fix these previous decisions, but I think that such complexity has just made exploitable bugs more likely. Moreover, according to Secunia, in mainstream Linux distros every security bug gets fixed eventually. No such hope comforts Windows user.
- tptacek 16y agoSee above. Why, besides vanity, does superuser matter to a virus? The idea that Windows is harder to update than Linux will come as a surprise to enterprises who have been getting autoupdated fixes for almost a decade now.
- Locke1689 16y agoGiven that my hobby used to be exploiting various overflow exploits in Linux machines I agree with you, but do you think there are some things that Windows lagged on that hurt it? For example, there are a couple things like ASLR, NX/W^X bit, and stack canaries that I think they should have rolled out sooner. Do you think that made a difference or were SQL injection et al so easy by then that there was no point in bothering with overflow attacks if your goal was to make money and get information? Edit: Ah, and I forgot: Windows ACE's are pretty much as good as NFSv4 ACLs but Linux still doesn't support anything other than basic POSIX.1e ACLs out of the box.
- tptacek 16y agoMy perception is that at WinXPSP2, where Microsoft finally got serious about runtime protection, the state of the art in mainstream Unix deployments was not that much better. How resilient was Solaris to overflows in 2003?
- Locke1689 16y agoI think you're right; most UNIX installations weren't that much better (Linux especially). I think Solaris may have been one of the best simply because they were running on SPARC procs and the SPARCs have had optional NX support since '98 or so. That still relied on the admin enabling it though (so basically no one had it enabled).
- caf 16y agoThe other thing the Windows ecosystem has that makes it more hospital for executable file viruses is a culture of user-to-user sharing of binary executables. In the UNIX world, sharing source is the usual vector for copying programs user-to-user. This was particularly true back when executable file viruses were at their most prolific - back in those days, if you copied a game from your friend at high school, that binary was quite likely to be several tens of generations removed from the original source. Each generation was an opportunity for a virus to climb aboard. With internet distribution of illicit wares, you're much closer to the original source.
- Confusion 16y agovirii OT, but please: viruses. In Latin, 'virus' is like 'sand': it has no plural (and if it would've had a plural, it would've been 'viri'). http://stason.org/TULARC/security/computer-virus/14-Is-it-viruses-virii-or-what.html http://stason.org/TULARC/security/computer-virus/14-Is-it-vi...
- deleted 16y ago[deleted]
- lmkg 16y ago> and if it would've had a plural, it would've been 'viri' That's not immediately clear. Depending on whether you think it's second or fourth declension, and masculine or neuter, the various possibilities are virua, vira, virūs, and viri. My best guess is that the "correct" usage was one of the more exotic varients (virua or vira), but the word was so rare that many people didn't learn the nuances, and instead adopted it to the more common patterns. Similar to how "begs the question" is often used incorrectly, and that ends up becoming an accepted usage. However, the plural could not have been "virii."
- paulgerhardt 16y agohttp://www.ofb.net/~jlm/virus.html http://www.ofb.net/~jlm/virus.html More than either of you two probably want to know about the subject.
- ique 16y agoWhat exactly is "Old-skool" in virus-writing and what is new-school?
- Leynos 16y agoAs defined in this case, an "old-skool" virus would be one written in assembly whose primary vector of infection is by embedding itself in executable files.
- niels_olson 16y agoThat would be an element of the set, not the definition.
- gregschlom 16y agoBack in the days viruses had to hide themselves in executables to travel from machine to machine, undetected. Today, as most users don't care about what processes are running on their system, and since the most common vector of infection is through the internet, what we call "viruses" are actually worms: they don't infect other programs, they are just self-replicating, malicious, executables.
- nitrogen 16y agoIt's a shame that your parent comment isn't getting any up-votes, as your comment is informative enough to deserve a higher place on the page.
- axod 16y agoolder school: boot sector viruses which triggered when an infected floppy was left in a machine on bootup. They'd then TSR and infect any other floppys inserted into the machine, as well as any hard disk drives if the machine was an expensive newer model with a hard card.
- 16s 16y agoNew school is the web browser, JavaScript and interpreted languages (ruby, python, etc). Old school is assembly, C and C++. Like Web 2.0 versus Web 1.0. Old school isn't snazzy and exciting and has a higher entry point. You won't find many old school fart apps.
- Leynos 16y agoDo viruses of this type (exe infecting) still have much impact "in the wild"? Most news these days seems to be about worms and trojan horses. I presume this is because it's harder to transport a "useful" payload inside of a true virus, so they are more often than not written to satisfy the curiosity of the author.
- drdaeman 16y agoIn old days, software were copied (yeah, on floppies) from friend to friend. A true "sneakernet" P2P^W F2F-network. Nowadays, software is either obtained directly from authors (or packagers), or from more centralized P2P sources, and, in my personal perception, most of time flash drives are used is to transfer documents, not executables.
- alexsherrick 16y agowhy would you want to write viruses?
- tptacek 16y agoIt's a way to play Core Wars across the whole Internet with other people's computers.
- machrider 16y agoProbably the most important question, and it appeared nowhere in this interview. I was disappointed.
- deleted 16y ago[deleted]
- darkstar211 16y agoIts a way of having your work everywhere, imagine being able to know that millions of people have your work on there computer, and seeing it read and blogged about, i guess its exciting.
- cschep 16y agobecause .. fuck it?
- daeken 16y agoIt's fun. It's a whole lot of fun, in fact. Mind you, I've never released any (I did release a metamorphic code engine for .NET some years ago, but that's the closest I've come), but it's really fun to think through it and come up with clever ideas. It also helps you gain perspective for the security side of things.
- r11t 16y agoReminds me of another female virus writer "Gigabyte" who she references in the interview : http://en.wikipedia.org/wiki/Gigabyte_(virus_writer) http://en.wikipedia.org/wiki/Gigabyte_(virus_writer)
- gsivil 16y agoI think that the title of that post does not do justice to the interview. Old-skool vs New School is a tiny part of an interview representative of the psychology of a virus writer. Virus writing seems like the most brilliant way to kill your creativity. Or in other words making your creativity a slave of the most boring of all arts: destruction.
- tricky 16y agoI've always thought for some people, destruction is a form of self-expression. Sometimes it is the only way they know how to create.
- adimitrov 16y agoWell, you can destroy something blandly, or you can destroy it in an intricate, even intelligent fashion. Just as you can create something blandly — to just barely serve its purpose. See, destruction is also creation. She creates viruses. These things then go on to destroy other stuff. Destruction is not at all a boring art. It's as legitimate an art as creation. Somewhere around 10th grade I finally gave in to my urge to put a lot of energy behind a simple question: why do parasites exist? Why are there lice, ticks, bacteria and viruses? Turns out they do, just because they do. They're legitimate 'creations,' living beings. And in non-parasitic beings, they inspire toughness and survival strategies — if it can't adapt to the parasite (in one way or another) it'll die out. Really, I don't get why people are biased against 'evil' black hats. If they target you and your app failed, you better get some security going. It's better some 'artist' who just feels the need to destroy intricate systems in an ingenuous fashion makes me aware of my security holes than someone with a malicious intent. From the interview, I can't see anything sociopathic or even malevolent in her (granted, I haven't read the whole thing.)
- gsivil 16y agoThanks for sharing another point of view. The destructive force of kids, and their love to create traps and make pranks is something that I really like. The life of non-human parasites or microbes is at least amazing, I am with you in that. My point was that destruction is the most obvious form of expression, for these reason we see it every time in kids. Personally I find it boring(since it is obvious and in a sense natural)- I can not change that. Of course somebody could tell me how come I do not complain about people that make sophisticated weapons for example. This is a whole different discussion.
- waste 16y agoI am torn by these young tinkerers; on one hand they're exploring the technology around them unlike most their peers, but on the other hand they very often seem to be totally full of themselves.
- netatalk 16y ago- Dark Avanger Have not heard that name in a while! Admired his code