r/linuxmint • u/LicenseToPost Powered by Cinnamon š • 1d ago
Fluff Task Failed Successfully š§ļø
You're welcome to general reposti this OC for the cause š¤ļø
210
u/taosecurity Mint | Bazzite | PikaOS | CachyOS | Debian | FreeBSD | Windows 1d ago
If you think Linux is not vulnerable to malware, or even PDF malware, I have a link I'd like you to click.
Also, stop the attempts to flex. Just focus on Linux.
60
5
u/30porn87 1d ago
I mean, almost all attacks are broad, general attacks.
I've never seen a Linux payload in such an attack, even through http which exposes your OS.
So you'd need to get spear fished, in which case the target should be aware that it is a potential target (of trolls, the state etc.)4
u/taosecurity Mint | Bazzite | PikaOS | CachyOS | Debian | FreeBSD | Windows 1d ago
Watch this. Just one example of a Linux RAT.
-42
u/CautiousLength6423 1d ago
Stop the attemps to flex says the person with a flair with all the mainstream distros. Nvm u do u
1
-24
130
u/brickyboy124 1d ago
Linux isnāt inherently protected, the only reason less viruses work is because of lack of user base. Aka itās not worth a virus bothering to attack Linux. As soon as Linux has a big enough user base (year of the Linux desktop fr) it will be just as vulnerable as Mac or Windows.Ā
Also you shouldnāt rely on a virus not bothering to hack you, you should not risk running a virus in the first place.Ā
30
u/LVL90DRU1D :sloth: Ubuntu 18.04 LTS 1d ago
remember that MacOS had no viruses before some period of time as well
1
u/toffuuu3050101 18h ago
Not true even the way older classics ones did have Viruses and Malware, but yes, not as many like Windows, Linux which has had ever since it was in general the first release of. Time is all it needs for one to be made by someone. I come from at first with use of Mac OS 7.6, 8 and 9 as well as Mac OS X until i switched and my own build away from OSX 10.5 and ridiculous Apple Prices even back then. And thats even worse now. lol
26
u/kudlitan 1d ago edited 1d ago
The meme says the payload is an .exe, which doesn't work in Linux.
Linux does have additional levels of protection:
the virus cannot harm the system-level files without your password; and
the executable bit must be turned on to actually run.
32
u/brickyboy124 1d ago
the payload is an exe
Yeah and if Linux gets more popular⦠virusās will start having .sh or .deb or whatever. My point is that Linuxās security through ānot worth itā is a temporary state of existence.Ā
the virus cannot harm system-level files without the password
Same for windows? Yet people still get hacked on windows. Also most targets of viruses, such as chrome logged in cookies, are not system level files.Ā
6
u/SnowyRVulpix 1d ago
Windows users typically run as admin. Linux users don't
7
u/brickyboy124 1d ago
You donāt need sudo to hack someoneās chrome cookies for their discord account. Or their crypto wallet.Ā
3
1
3
u/Llandu-gor 1d ago
yeah but on windows almost anything you do will ask admin, launch a game it ask admin for deps, launch adobe it ask for admin to update. so opening a pdf seing adobe icon and people are like "again an update ? here your admin"
on linux you need to run for admin and the only time it's needed is for installing system app or driver / update them
19
u/LXC37 1d ago
The meme says the payload is an .exe, which doesn't work in Linux.
Unless it has wine, which is good enough to run some malware, which will then be able to harm linux even without being aware it exists. If not the OS itself then at least user data, which is what most malware targets this days anyway.
the virus cannot harm the system-level files without your password;
Unless it exploits one of thousands software or hardware vulnerabilities.
the executable bit must be turned on to actually run.
Which is trivially easy to bypass as you can set it on your own files.
1
u/kudlitan 1d ago edited 1d ago
but then these still reduce the probability of being infected, since the premise of the post I replied to was popularity is the only variable that affects probability of being infected. see the context.
0
u/Bernsteinn 1d ago
Vulnerabilities aren't really an issue on Linux particularly not on Debian/Ubuntu based distros with their extremely fast release circles. And if something does get through, there's always Linux Defender watching your back (no, Clam isn't even in the same league).
3
u/SilverCutePony 1d ago
- Same for windows, it can't modify system files without admin rights. Even if any user have them, apps still runs without them by default, unless the user agrees to give access
- Lots of ways to bypass. Not all formats needs additional steps. Plus, even if they do, you can just pack it with an already enabled attribute into an archive format that saves them
3
1
u/Francois-C 1d ago
This may be the first time I've come to Apple's defense, but this meme doesn't make much sense: an .exeāso presumably a Windows PE executable beginning with 'MZ'āwouldn't run on macOS either. They use ELF files too, I assume.
2
u/sabledrakon 1d ago
Linux does have an advantage though. The base security model isn't anywhere near as permissive as Windows is. One of my old teachers summed it up like this:
On Windows, you can do anything, unless you can't. On Linux, you can't do anything, unless you can.
Most of the 'trick' is not blindly allowing escalations of privilege. For Windows, it's trivial, as it's usually one click away and most people aren't fully paying attention to UAC. Meanwhile, on Linux, you need to give it your password. It's meant to make you sit up and pay attention, so you're a little more vigilant about anything asking for password confirmation.
5
u/brickyboy124 1d ago
Iāve seen windows UAC ask my grandma for her password, yet it didnāt stop her running a malicious file.Ā
0
u/Hettyc_Tracyn Cachyos | Hyprland | rolling release 1d ago
Which is why you donāt let people who donāt do the research and install random nonsense have admin accessā¦
2
u/brickyboy124 1d ago
Windows makes you an admin by default when you set it upā¦Ā
almost no one who uses windows is going to bother demoting themselves, or has someone to do it for them.
0
u/Hettyc_Tracyn Cachyos | Hyprland | rolling release 1d ago
Well, if an old person, who doesnāt know how to stay safe online, has a computer, itās the duty of their children/grandchildren to prevent stuff like ransomware, etc as they (the old person) are more likely to fall for itā¦
2
u/brickyboy124 1d ago
Sure but thatās besides my point: people (not just dumb people) run malicious files and accept UAC all the time. They just have to think the file is installing something legit.Ā
1
-1
u/Cent_Quatre 1d ago
Aside from the different design and smaller userbase, linux has the avantage of having a much more savvy userbase as well.
5
-1
57
u/Goldman7911 1d ago
Also, wine currently is so good that even some windows malware has a chance of causing problems
6
u/khunset127 1d ago
another W for non-gamers who don't use or need wine
1
u/nekogasuki143 1d ago
We still have snapshot (the recovery thing) which restores the PC to last snapshot if it gets corrupted.
2
u/TomOnABudget 16h ago
That shit never helped me. I hope it'll finally become usable for normal users.
1
u/nekogasuki143 16h ago
well Linux has a learning curve......
2
u/TomOnABudget 16h ago
It's more like a mountain ridge. It's got ups, downs and the occasional sheer drop.
And a fanbase of mountaineers that'll tell you it's so easy their grandma and children climb (in the Linux community, use Linux). Meanwhile they all know someone who disappeared in an avalanche.
1
u/nekogasuki143 16h ago
so trueee, I wanted to try arch and other popular distros after a few weeks with my Mint. But when mint started giving me the L with wifi and speaker drivers.... I pretend linux mint is the only linux distro and enjoy my life.
4
u/khunset127 1d ago
snapshots can do nothing if it went unnoticed
3
u/CautiousLength6423 1d ago
Hmm like the snapshot was taken AFTER the trijan infiltration. That makes sense.
2
16
u/TabascoTaco 1d ago
What is an exe gonna do on macOS
9
u/redguard128 1d ago
.dmg
2
u/Zaprit 1d ago
.dmg is not an executable, itās a disk image. A lot of the Mac malware Iāve seen recently is mostly social engineering involving getting idiots to paste random crap into a terminal, so thatāll probably make its way over to Linux as time goes by as well.
5
u/Abducted_Llama 1d ago
Idk if it was intended as a joke , but I took it as ādamageā. Like dmg is an abbreviation of damage.
10
1d ago
[removed] ā view removed comment
29
u/taosecurity Mint | Bazzite | PikaOS | CachyOS | Debian | FreeBSD | Windows 1d ago
Because when you make dumb memes, anything is possible.
0
3
2
u/Strassi007 1d ago
The cause to spread misinformation? Why would we do that? We arenāt all idiots.
1
2
2
u/leRealKraut 1d ago
Does macOS realy do .exe files just because?
Linux Mint does likely do something.
2
u/vaquishaProdigy 1d ago
If it compromises MacOs then it could compromise Linux too, if it is coded the right way
1
u/Bernsteinn 1d ago
Or the other way around. On Virustotal is a file with the same hash a a (supposed?) AppArmor script that changes Windows registry values.
2
2
u/artistpanda5 Linux Mint 22.3 Zena | Cinnamon 17h ago
What happens if you run a .exe virus payload under Wine?
1
3
1
u/pissrockious 1d ago
i got wine so m screwed either way if i fall for it i think lols
1
u/LicenseToPost Powered by Cinnamon š 1h ago
Put your wine in a barrel and it won't infect the winery.
1
u/SniperSnake18000 1d ago
Me laughing maniacally at the Trojans failure till I watch as wine boots up
1
1
1
0
u/Beginning-Pace-1426 1d ago
Oh my poor darling.
When people who switch to Linux think that they are somehow now invulnerable as an actual target I cringe.
I bet I could take a newbie Linux Mint user's system in less time than an average Windows user's.
2
u/Hettyc_Tracyn Cachyos | Hyprland | rolling release 1d ago
Thatās what having an external backup is for, in case you, or a program, break somethingā¦
2
1
u/Hettyc_Tracyn Cachyos | Hyprland | rolling release 1d ago
Thatās what having an external backup is for, in case you, or a program, break somethingā¦
262
u/gotshanghaied 1d ago
Every OS is vulnerable. The real trick is not opening the pdf in the first place.