Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > all things UNIX
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old April 11th, 2009, 05:54 PM
Searching_ _ _'s Avatar
Searching_ _ _ Searching_ _ _ is offline
Very Frequent Poster
 
Join Date: Jan 2008
Location: iAnywhere
Posts: 1,988
Default Re: E-mail altered in Ubuntu

Quote:
Originally Posted by lotuseclat79
Since the pdf file is an email attachment, Save it to your Desktop (right-click, and select Save As). Then double-click on the pdf file on your Desktop to launch the PDF Reader evince!
Isn't this potentially dangerous if the attatchment is malicious?

Quote:
The premise of this type of 'virus' is simple: Get a user to run an executable attachment you sent them via email.

Firstly, most email clients for Linux will not execute attachments. They might try to open them if they know the extension as an indication for a document or media type (.pdf or other documents for example). But that's about it.

Something that always gets executed when clicked on. And here then is one more step that needs to be taken by the user, which might reduce the success rate of this attack vector a little. The user has to first save the attachment and then double click on it. Because while the email client typically cannot run an executable file, the desktop environment very well can as we will see.
creating a Linux Virus
__________________
Americans are the enemy? Mil. can arrest you?
What the heck is going on?
  #27  
Old April 12th, 2009, 07:15 AM
Sputnik's Avatar
Sputnik Sputnik is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: Москва
Posts: 1,198
Default Re: E-mail altered in Ubuntu

Quote:
Originally Posted by Shankle
I am running Ubuntu 8.10. I searched for evince and it is there. "xpdf" is also there.
I would suggest you uninstall/remove "xpdf" and stick with the default Evince. You might also try using Evolution for your e-mail needs under Ubuntu. In my opinion Thunderbird is a buggy piece (Linux version suffers more errors then the Windows version actually). Evolution however is nice (KMail is recommended by me for KDE users).
__________________
"Proud openSUSE user."
  #28  
Old April 12th, 2009, 07:47 AM
Shankle Shankle is offline
Frequent Poster
 
Join Date: May 2006
Posts: 454
Default Re: E-mail altered in Ubuntu

Thanks for replying.
I will remove xpdf.

The reason I don't use Evolution is that they haven't fixed a problem that needs fixing
now for the past 6 months. The problem is that items in the trash CAN'T be deleted.
This is unacceptable. To the best of my knowledge I am not using KDE. I using the other one.
  #29  
Old April 12th, 2009, 09:08 AM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: E-mail altered in Ubuntu

Quote:
Originally Posted by Searching_ _ _
Isn't this potentially dangerous if the attatchment is malicious?

Not really.

You are referring (based on your link) to a well known "vulnerability" which allows .desktop "launcher" files to be executed without the x bit being set. This means a kiddie could hide some malicious code inside a .desktop file but change its extension to anything (like .pdf or even .mp3). As a result, the user sees his potential .pdf and he clicks it and it executes some shell script that tampers with the /home directory. What this attack essentially does is bypass one step of getting a script to run (it negates the need for the "chmod a+x" command).

Remember UNIX doesn't recognize file extensions -- that's a Windows thing -- so one can change the extension at will. Extensions in UNIX are only there for humans to see what a file probably is, not what it really is. Normally this is not a problem because even if the file is malicious it won't have executable privileges. And even if one gives it executable privileges, it will only run with the group and user permissions allowed in the DAC.

The problem with this attack, as even the author of the article admits, is that the malware would only compromise the /home directory and would not give the malware access to anything important. So, basically, it comes down to this question: What good is the attack? This is the question I am sure the KDE and Gnome developers have asked themselves, and is likely the reason they have intentionally *not* fixed this "vulnerability." About the only thing the malware could do is resend itself to other people listed in the e-mail client address book. But what good would that be? It would essentially be an "annoyance" type of malware.

About the only thing I can think of that it could be used for is to send spam or to delete files (pictures, mp3's, documents) in the /home directory. Sure, it's not fun having files deleted, but it would be trivial to find and exterminate the malware responsible (it would be a file in the /home directory in plain site) and the Linux hackers would quickly discover what is going on and would have it nipped by sunrise.
  #30  
Old April 12th, 2009, 10:46 AM
Sputnik's Avatar
Sputnik Sputnik is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: Москва
Posts: 1,198
Default Re: E-mail altered in Ubuntu

Quote:
Originally Posted by Shankle
The reason I don't use Evolution is that they haven't fixed a problem that needs fixing
now for the past 6 months. The problem is that items in the trash CAN'T be deleted.
This is unacceptable. To the best of my knowledge I am not using KDE. I using the other one.
You're using GNOME that's right. This problem with the trash seems to be Ubuntu specific to me. Some users report that by removing the "folders.db" file from "./evolution/mail/local" fixes the problem. Make sure you have Evolution closed while removing this file.
__________________
"Proud openSUSE user."

Last edited by Sputnik : April 12th, 2009 at 10:53 AM.
 

Wilders Security Forums > Software, Hardware and General Services > all things UNIX « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:54 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums