• Omega@discuss.online
      link
      fedilink
      arrow-up
      1
      ·
      2 hours ago

      Wayland and Flatpak actually somewhat protects you though, as long as you know to NOT give it the permissions to read all of /home

  • Fushuan [he/him]@lemm.ee
    link
    fedilink
    arrow-up
    17
    arrow-down
    1
    ·
    5 hours ago

    A single .sh file with exec permission that asks for sudo will easily download appimage keyloggers and then set a cron job to run it every X time to keep it alive and sends it all to whatever remote location. Or whatever else you let the appimage do.

    95% of regular users will double click that, and then write their pass in the popup without blinking twice and that will work in most Linux systems.

    Most viruses don’t target Linux, sure, but that’s wishful thinking. Always be creful with what you run.

  • eldain@feddit.nl
    link
    fedilink
    arrow-up
    19
    ·
    edit-2
    8 hours ago

    Everyone should think about threats to their data. Cloud backup and laptops better be encrypted, services with open ports be shielded. Linux viruses do exist, especially for android and routers. But also whatever system has an outdated dokuwiki open in the wild is a welcome addition to a botnet. The value of a botnet is in number of infected systems and you don’t need root access to mine monero or take part in a ddos on a machine. Linux security is sincerely undervalued. Selinux, the grsec kernel patches, chrootjail, tripwire… do exist, but are a hassle to setup and maintain. The new container options are nice (docker or flatpack) having your webbrowser contained is not a bad idea.

    Update your router, your desktop is spoiled for updates. I stop my 1 am ramblings here.

  • bleistift2@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    41
    ·
    13 hours ago

    A few years ago I found a text (probably as image) where somebody ‘tried’ to run a virus on linux. It went something like this:

    Wanted to install a virus on Ubuntu, but it was only available as an aur package. Tried converting. Didn’t work … Tried make virus, but didn’t work. Upgraded cmake, tried again, but some libraries were missing.

    Tried installing libraries, but they were very outdated and I couldn’t find proper versions.

    Checked the source to see what the libs were doing and replaced them.

    and so on.

    Does someone know what I’m talking about and possibly has the source?

  • Dizzy Devil Ducky@lemm.ee
    link
    fedilink
    English
    arrow-up
    21
    ·
    12 hours ago

    As someone who may obtain games and shows/movies through less than rights holder approved methods, ClamAV is a necessity.

    • Maiq@lemy.lol
      link
      fedilink
      arrow-up
      16
      ·
      11 hours ago

      Not just for the pirate though. If you share any files between nix and win OS’s. I wouldn’t want to share any computer std with those I care for, friend, family or business.

      There are also cool tools like chkrootkit and rkhunter that might come in handy.

  • Screen_Shatter@lemmy.world
    link
    fedilink
    arrow-up
    11
    ·
    11 hours ago

    I just switched to linux and totally forgot about this. Do I really not need one? 99% of what I do is steam gaming anyway so I’m not too worried, worst case I just format and reinstall, but still…

    • azha@lemm.eeOP
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      9 hours ago

      better be safe than sorry so get Clamav and scan your system frequently

    • JoYo@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 hours ago

      is that the goal with immutable distros? i thought they were primarily used for rollbacks.

        • EnsignWashout@startrek.website
          link
          fedilink
          arrow-up
          1
          ·
          4 hours ago

          Immutable distros can usually be set to mutable with the correct privileged command.

          It’s essentially security by obscurity. But I disagree with “no benefit”. An infection miss through dumb luck is still a miss, after all.

  • wizzim@infosec.pub
    link
    fedilink
    arrow-up
    6
    ·
    edit-2
    12 hours ago

    Does anyone have an idea what would happen if one runs a Windows virus with Wine ?

          • 乇ㄥ乇¢ㄒ尺ㄖ@infosec.pub
            link
            fedilink
            arrow-up
            5
            ·
            12 hours ago

            Probably because FileZilla requires special access to personal files and WD probably knows It’ll try to send them elsewhere

            The things that trigger antivirus software aren’t just hashes anymore, it’s the behavior of the software on your machine… That’s why I said it’s better now…

              • 乇ㄥ乇¢ㄒ尺ㄖ@infosec.pub
                link
                fedilink
                arrow-up
                3
                ·
                11 hours ago

                Oh, wait… I just remembered… users have reported that Filezilla does by itself install malware/bundleware, unless you’re very careful to untick some boxes during the installation… IT IS malicious that they install other stuff on your machine and it’s hard for you to find what exactly they installed…

                See the Negative reviews on Alternativeto

                • go $fsck yourself@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  9 hours ago

                  The detection happens with the update download, which does not have any bundled software. It also detects the installer that specifically does not have the option for installing bundled software.

        • azha@lemm.eeOP
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          2
          ·
          12 hours ago

          i dont know I still dont trust microsoft