[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Boot Virus



On Mon, Oct 02, 2000 at 07:45:06AM -0400, Christopher Dryburgh wrote:
> Thank you Steve Bowman:
> 
> My understanding of Linux was that it was extremely hard to get viruses but
> it was still vulnerable to boot viruses since they would take hold before
> Linux was started. Apparently I was wrong. Since turning off the BOIS virus
> checker the boot process has gone very smoothly.

Glad it fixed your problem.  It's still possible to get a boot virus in
linux, but you'd have to have enabled write access to your boot partition
or have been rooted.  Or if you connect to the internet while running a,
hmmm, "less secure" OS you open some doors.  Typically, the BIOS just
complains because it notices your boot block has been changed to mbr
or lilo or something it doesn't recognize.  In other words, you're not
really wrong that you could get a boot virus, it's just that (typically)
that's not what the BIOS is really complaining about.

Good luck,
Steve

> -----Original Message-----
> From: Steve Bowman [mailto:sbowman@frostwork.net]
> Sent: September 29, 2000 2:16 AM
> To: cdryburgh@grtech.net
> Cc: debian-boot@lists.debian.org
> Subject: Re: Boot Virus
> 
> 
> On Fri, Sep 29, 2000 at 12:40:33AM -0400, Adam Di Carlo wrote:
> > "Christopher Dryburgh" <cdryburgh@grtech.net> writes:
> >
> > [snip]
> > I've run Linux since 1995 and I've never had a boot virus on a linux
> > box.  It's only single-users insecure operating systems which have
> > this problem.  The user is correct, disable the BIOS warning.
> >
> > that may or may not fix your problem.  If not, I would look at the
> > partition tables again and make sure they are kosher.  But given the
> > boot from floppy vs boot from hd scenario, I'm quite sure your
> > overachieving BIOS is to blame.
> 
> Furthermore, the installation instructions tell you to turn off BIOS
> virus protection (section 3.3.4).  I assume there's a reason someone
> bothered to put it in the instructions.

-- 
Steve Bowman  <sbowman@frostwork.net> (preferred)
Buckeye, AZ   <sbowman@goodnet.com> <bowmanc@acm.org>
              <http://www.goodnet.com/~sbowman/>

Powered by Debian GNU/Linux and GNU/Hurd <http://www.debian.org>



Reply to: