LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-27-2009, 06:51 PM   #1
AllanB
LQ Newbie
 
Registered: Jun 2006
Location: Titirangi, Auckland, New Zealand
Distribution: Ubuntu 10.04LTS
Posts: 24

Rep: Reputation: 0
Ubuntu 8.04 and the UPS Trojan


Early October 2008 an email was received on my system with the subject: [NO REPLY] UPS Tracking Number followed by 8 digits. Included was an attached file UPS_letter.zip As I was away my wife opened this believing I had a package coming from UPS.
The computer runs Ubuntu 8.04, the e mailer is Thunderbird 2.0.0.21 and hasn't been used since, as its obviously the UPS Trojan. I now want to use this machine. It was being run as an ordinary user, not as root.
My understanding from reading the publically available information is that this Trojan is only a windows one, and that the structure and safeguards in Linux will prevent it from damaging my system and propagating elsewhere on the web.
An I correct, if not what next?
 
Old 03-27-2009, 07:27 PM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by AllanB View Post
Early October 2008 an email was received on my system with the subject: [NO REPLY] UPS Tracking Number followed by 8 digits. Included was an attached file UPS_letter.zip As I was away my wife opened this believing I had a package coming from UPS.
The computer runs Ubuntu 8.04, the e mailer is Thunderbird 2.0.0.21 and hasn't been used since, as its obviously the UPS Trojan. I now want to use this machine. It was being run as an ordinary user, not as root.
My understanding from reading the publically available information is that this Trojan is only a windows one, and that the structure and safeguards in Linux will prevent it from damaging my system and propagating elsewhere on the web.
An I correct, if not what next?
Trend Micro's page for this trojan doesn't list GNU/Linux as an affected platform. In addition, the descriptions I've read on the Web would support the theory that this is strictly Windows-only. Normally, this would inhibit the malicious actions of said programs to the point where GNU/Linux security features wouldn't come into play, since the payload wouldn't be properly delivered in the first place. If you're still concerned, you could backup your wife's documents and nuke her account (then create a new one for her).

Last edited by win32sux; 03-27-2009 at 07:35 PM.
 
Old 03-27-2009, 08:57 PM   #3
AllanB
LQ Newbie
 
Registered: Jun 2006
Location: Titirangi, Auckland, New Zealand
Distribution: Ubuntu 10.04LTS
Posts: 24

Original Poster
Rep: Reputation: 0
Many thanks for confirming what I thought was the case, I should learn more of the detail of Linux instead of just using it.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
APC UPS backup-ups ES RJ-45 augurseer Linux - Hardware 3 11-18-2009 11:32 PM
UPS Monitoring software for Ubuntu bahadirtonguc Linux - Server 4 11-30-2008 09:34 AM
LXer: Eaton Announces UPS Support for Ubuntu LXer Syndicated Linux News 0 11-30-2007 05:11 AM
APC Smart Ups & Ubuntu 5.10 renaissance Ubuntu 1 04-29-2006 03:46 AM
Possible Trojan ! FreeFox Linux - General 4 08-03-2003 08:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration