D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Scam emails

 

On Tue, Mar 11, 2014 at 02:19:29PM +0000, bad apple wrote:
> 100% this - the old days of "I run Linux, I'm immune to all security
> threats" are not only gone, they never existed in the first place. Java
> is installed by default on most Linux distros these days and is by
> definition almost definitely compromisable. State agents and
> professional criminal organisations have been targeting Linux for a long
> time now and there are countless crimeware kits, APTs and flash/java/PDF
> exploits available over the counter to anyone who wants them on any
> operating system.

This is all true of course. (My email was a reply to Neil's question
who was merely curious what would happen if he were to open such an
attachment on his Linux machine.)

> I haven't been so 'lucky' as to receive a copy of this particular scam
> yet so if anyone can email me a copy I'll set to work ripping it apart
> and having a look at the internals. I have a fleet of victim VMs set
> aside in their own little VLAN for just such things.

I'm sure I could find you a copy of the emails if you're really
interested. I don't expect it to be 'interesting' in any way - and
probably analysed to death already. Though perhaps it manages to detect
whether you're running it on a virtual machine and thus won't run at
all.

Martijn.


-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq