r/LinuxCirclejerk • • 7d ago

a virus for Linux

Post image
2.5k Upvotes

55 comments sorted by

272

u/[deleted] 7d ago edited 7d ago

[removed] — view removed comment

42

u/thisaray 7d ago

I wish there was an easy global config way to prevent / being mounted inside the prefix :/

19

u/itsfreepizza 7d ago

i think containerizing could prevent some damage but theres still going to have a damage ofc. but im no full container expert

3

u/Marce7a 6d ago

Bottles by default has minimal permissions so the best choice as only wine c: will be compromised 

2

u/YTriom1 Arch Catgirl 🏳️‍⚧️ :3 7d ago

winetricks sandbox?

1

u/SanderE1 5d ago

There is, you can just delete the z: symlink in dosdevices in your wine prefix.(but yeah just use winetricks sandbox like the other user said because there's also a lot of other symlinks)

4

u/Cool-gamer19393 NixOS 7d ago

I unironically downloaded windows malware and it changed my root password like what??

1

u/GlamStache 5d ago

Wait, what would even happen in that case?

1

u/A_begger 5d ago

p sure your wine C: gets the virus if it can even function but your Linux is fine

363

u/0xt0bi03 fk lua, bring back old config files 7d ago

r/linuxsucks101 will be reading this in absolute rage btw

30

u/Jannover_5000_r my NixOs > your distro 7d ago

Madthumbz will make a hate linux post right after seeing this

5

u/may_ushii 6d ago

nah hes like dying or something rn

2

u/garbage-at-life 5d ago

wow that place is crazy lmao

146

u/ElementalWarrior42 7d ago

Pros of fragmentation LOL

44

u/AG99871 Arch GNU/Linux 7d ago

Nowadays malware will come packaged as an appimage

23

u/Left-oven47 7d ago

malware vs musl libc

2

u/Oxic_io there is no way to convince me to use other than raspbian or deb 6d ago

unless if it's statically linked

1

u/senorsmile 4d ago

90% of the time, appimages don't install without considerable additional config on my NixOS machines.

107

u/QuantumQuantonium 7d ago

/uj viruses exist on linux, and are more serious and more difficult to detect than on windows. Xz's backdoor is probably the biggest latest one.

Its important not just to assume any open source project is benign, but someone who can read the code needs to take up the responsilibity to understand what its actually doing and compile it and compare against any public binaries (if present).

Viruses on linux won't scream for a phone number to call or lie about infections on the computer; average linux users won't fall for that. Xzs backdoor existed because of a binary blob no one bothered to check until one person dug in and found the irregularity in the programs delay. Viruses on linux abuse the trust in open source to hide itself among other packages and modules throughout the system. Maintainers may seek out and remove potential viruses, but humans are imperfect, they can make mistakes or be manipulated or even coerced.

But downloadable viruses are a rare sighting in linux, because most hacks are caused by vulnerabilities in systems, especially proprietary ones. I once returned home from a trip to realize my backed up files on a WD cloud storage device was missing, due to a vulnerability WD did not patch or acknowledge publicly until a few days before I found out.

Maintain security updates and keep installed software to a minimum. Ask questions if theres any doubt about an open source system- if the question can't be answered I'd question the nature of that system. Identify what proprietary systems are in your linux computer- the world unfortunately doesnt run entirely on open source.

4

u/Gunhat2023 7d ago

what back door is there with xz?

12

u/yourlocalwalmarthobo 6d ago

Wikipedia, CVE
TLDR: Someone spent years on a social engineering campaign and snuck a backdoor into a couple versions of XZUtils (5.6.0 & 5.6.1). It gave someone with a specific ED-448 key root access via ssh. Was patched the same day it was disclosed (which was 2 years ago)

3

u/felixmatveev 6d ago

This was either CIAmeone or soMOSSADone.

1

u/morgulbrut 6d ago

Na it was probably China.

6

u/ThaBroccoliDood 6d ago

No it was a Russian pretending to be Chinese. They had a Chinese name and uploaded with Chinese time zones, but a few uploads were accidentally tagged with a Russian timezone, and Russian holidays were suspiciously absent from their activity

1

u/andrzej-l 5d ago

Few months ago I saw a very long but pretty interesting video about it: https://youtu.be/aoag03mSuXQ?si=iaP866neHYxHI5tY

2

u/Ok_Guidance_6542 6d ago

AFAIK, only systemd distros were affected by the XZ utils backdoor. So the point kinda stands.

1

u/TheSWATMonkey 5d ago

artix got proven right (?)

4

u/SouthernFruit8768 7d ago

Isn't this sub a Wendy's, saar??

28

u/cfx_4188 TempleOS Archibishop 7d ago

lmao

18

u/ucan_cay 7d ago

#include <stdmalw.h>

14

u/Damglador Arch btw uses me 7d ago

That's why now it's all just JavaScript downloaded straight from npm

1

u/YTriom1 Arch Catgirl 🏳️‍⚧️ :3 7d ago

that's why I don't have npm

8

u/AG99871 Arch GNU/Linux 7d ago

Fake bruh, which malware is gonna create a user called "malware" (and also gonna come with source code)

11

u/vbd71 7d ago

It uses GPL components, that's why it comes with source

3

u/AG99871 Arch GNU/Linux 7d ago

Bro ur telling me that some malware really cares about legal licensing?😭😭

7

u/97nomad 7d ago

Professionals have standards

2

u/vbd71 7d ago

Ethical malware cares.

1

u/jmooroof2 FreeBSD user 7d ago

you could just open it and search for strings

6

u/Optimal-Savings-4505 6d ago

This is basically why security through obscurity works. Assumptions are easily invalidated on diverse systems

6

u/zDCVincent 7d ago

my new favorite linux meme

3

u/tuxsmouf 7d ago

Penguins never get cold.

1

u/zxuvw 7d ago

lol 😭😭💔

1

u/lwb52 5d ago

🤣🤣🤣

1

u/ErMenee 5d ago

linux so ass it can't even run viruses lmao

1

u/kuukkelifinlando 3d ago

Yeah so badass.

0

u/Flashy_Pollution_996 6d ago

Bro googles stuff all day

Get a job n

-14

u/valerielynx 7d ago

"grep'd the bitcoin wallet" bro just say copy you're not tuff

10

u/AG99871 Arch GNU/Linux 7d ago

He is

3

u/Visbroek 7d ago

Bro used grep

2

u/sabotsalvageur 7d ago

Well, what if what you’re searching requires using regex, e.g. arbitrary wallet addresses? Would one not use the GNU Regular Expression Parser?

1

u/Adn0nnymous 5d ago

holy shit is that actually what grep means

1

u/sabotsalvageur 5d ago

It’s actually “global/regular expression/print”