Koozali.org: home of the SME Server

Biwili.A malicious code infects PE ELF

Offline rexgaylord

  • **
  • 59
  • +0/-0
    • http://www.backuplasvegas.com
Biwili.A malicious code infects PE ELF
« on: April 16, 2006, 09:23:08 PM »
Biwili malicious code infects PE (Portable Executable) and ELF (Executable and Linking Format).  Is that something that we need to look into to protect the SME 6/7 distro?  Since it infects both Linux and Windows, I would imagine somebody will use this proof of concept soon to launch a new virus soon...
......................................................

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: Biwili.A malicious code infects PE ELF
« Reply #1 on: April 20, 2006, 01:06:57 AM »
Quote from: "rexgaylord"
Biwili malicious code infects PE (Portable Executable) and ELF (Executable and Linking Format).  Is that something that we need to look into to protect the SME 6/7 distro?  Since it infects both Linux and Windows, I would imagine somebody will use this proof of concept soon to launch a new virus soon...


The short answer is "no". The ELF executables running on SME server are all owned by "root", and none of the programs which handle mail messages are running as "root", so no mail program, even if compromised, will be able to modify the existing executables.

The noise about this virus threat is mostly likely just an attempt to drum up business by an anti-virus software vendor.