r/linuxmint Powered by Cinnamon šŸ”‹ 1d ago

Fluff Task Failed Successfully šŸ§ļø

Post image

You're welcome to general reposti this OC for the cause šŸ¤ļø

712 Upvotes

88 comments sorted by

262

u/gotshanghaied 1d ago

Every OS is vulnerable. The real trick is not opening the pdf in the first place.

66

u/AussieBirb 1d ago

... or any dodgy link and/or suspect file in general.

16

u/the_reluctance 1d ago

or opening it on a old laptop with nothing on it but a antivirus and whatever os your main computer uses to see what it does

12

u/ParachutingPiglets 1d ago

Looks at old Acer laptop sitting in the closet

3

u/Progressbar95 21h ago

Reinstall windows after lol

2

u/LicenseToPost Powered by Cinnamon šŸ”‹ 15h ago

XP or earlier for best results

1

u/ParachutingPiglets 9h ago

I loved Win XP

1

u/LicenseToPost Powered by Cinnamon šŸ”‹ 2h ago

You and me both šŸ„¹ļø

Carried my school teacher's broken computer 1.1 miles home in 9th grade to escape Mac.

1

u/ParachutingPiglets 9h ago

The old laptop either has outdated Arch or Debian on it. I have an old Win10 CD that is hopefully not scratched too bad. I’m curious how to go about getting boot installation media for Win XP.

12

u/krs1426 1d ago

The real trick is the PDFs we clicked along the way...

1

u/dumbasPL 1d ago

Cubes joins the chat.

It might be vulnerable, but the exploit will only have access to the pdf and nothing else on the system, and will soon be destroyed when the VM shuts down.

210

u/taosecurity Mint | Bazzite | PikaOS | CachyOS | Debian | FreeBSD | Windows 1d ago

If you think Linux is not vulnerable to malware, or even PDF malware, I have a link I'd like you to click.

Also, stop the attempts to flex. Just focus on Linux.

5

u/30porn87 1d ago

I mean, almost all attacks are broad, general attacks.

I've never seen a Linux payload in such an attack, even through http which exposes your OS.
So you'd need to get spear fished, in which case the target should be aware that it is a potential target (of trolls, the state etc.)

4

u/taosecurity Mint | Bazzite | PikaOS | CachyOS | Debian | FreeBSD | Windows 1d ago

Watch this. Just one example of a Linux RAT.

https://youtu.be/m-frPZtSBwA?is=WrmDUa4iNCyWHRWP

-42

u/CautiousLength6423 1d ago

Stop the attemps to flex says the person with a flair with all the mainstream distros. Nvm u do u

-24

u/LicenseToPost Powered by Cinnamon šŸ”‹ 1d ago

šŸ‘‰ā¤ļø

130

u/brickyboy124 1d ago

Linux isn’t inherently protected, the only reason less viruses work is because of lack of user base. Aka it’s not worth a virus bothering to attack Linux. As soon as Linux has a big enough user base (year of the Linux desktop fr) it will be just as vulnerable as Mac or Windows.Ā 

Also you shouldn’t rely on a virus not bothering to hack you, you should not risk running a virus in the first place.Ā 

30

u/LVL90DRU1D :sloth: Ubuntu 18.04 LTS 1d ago

remember that MacOS had no viruses before some period of time as well

1

u/toffuuu3050101 18h ago

Not true even the way older classics ones did have Viruses and Malware, but yes, not as many like Windows, Linux which has had ever since it was in general the first release of. Time is all it needs for one to be made by someone. I come from at first with use of Mac OS 7.6, 8 and 9 as well as Mac OS X until i switched and my own build away from OSX 10.5 and ridiculous Apple Prices even back then. And thats even worse now. lol

26

u/kudlitan 1d ago edited 1d ago

The meme says the payload is an .exe, which doesn't work in Linux.

Linux does have additional levels of protection:

  • the virus cannot harm the system-level files without your password; and

  • the executable bit must be turned on to actually run.

32

u/brickyboy124 1d ago

the payload is an exe

Yeah and if Linux gets more popular… virus’s will start having .sh or .deb or whatever. My point is that Linux’s security through ā€œnot worth itā€ is a temporary state of existence.Ā 

the virus cannot harm system-level files without the password

Same for windows? Yet people still get hacked on windows. Also most targets of viruses, such as chrome logged in cookies, are not system level files.Ā 

6

u/SnowyRVulpix 1d ago

Windows users typically run as admin. Linux users don't

7

u/brickyboy124 1d ago

You don’t need sudo to hack someone’s chrome cookies for their discord account. Or their crypto wallet.Ā 

3

u/taosecurity Mint | Bazzite | PikaOS | CachyOS | Debian | FreeBSD | Windows 1d ago

This 1000%.

1

u/LicenseToPost Powered by Cinnamon šŸ”‹ 1h ago

Just Chrome.

šŸ¦Šļø

3

u/Llandu-gor 1d ago

yeah but on windows almost anything you do will ask admin, launch a game it ask admin for deps, launch adobe it ask for admin to update. so opening a pdf seing adobe icon and people are like "again an update ? here your admin"

on linux you need to run for admin and the only time it's needed is for installing system app or driver / update them

19

u/LXC37 1d ago

The meme says the payload is an .exe, which doesn't work in Linux.

Unless it has wine, which is good enough to run some malware, which will then be able to harm linux even without being aware it exists. If not the OS itself then at least user data, which is what most malware targets this days anyway.

the virus cannot harm the system-level files without your password;

Unless it exploits one of thousands software or hardware vulnerabilities.

the executable bit must be turned on to actually run.

Which is trivially easy to bypass as you can set it on your own files.

1

u/kudlitan 1d ago edited 1d ago

but then these still reduce the probability of being infected, since the premise of the post I replied to was popularity is the only variable that affects probability of being infected. see the context.

0

u/Bernsteinn 1d ago

Vulnerabilities aren't really an issue on Linux particularly not on Debian/Ubuntu based distros with their extremely fast release circles. And if something does get through, there's always Linux Defender watching your back (no, Clam isn't even in the same league).

3

u/SilverCutePony 1d ago
  1. Same for windows, it can't modify system files without admin rights. Even if any user have them, apps still runs without them by default, unless the user agrees to give access
  2. Lots of ways to bypass. Not all formats needs additional steps. Plus, even if they do, you can just pack it with an already enabled attribute into an archive format that saves them

3

u/Zatujit 1d ago

But the second protection is laughable when you just need to put the executable in a tar gz and then when you decompress you get a file with the executable not turned on

1

u/Francois-C 1d ago

This may be the first time I've come to Apple's defense, but this meme doesn't make much sense: an .exe—so presumably a Windows PE executable beginning with 'MZ'—wouldn't run on macOS either. They use ELF files too, I assume.

2

u/sabledrakon 1d ago

Linux does have an advantage though. The base security model isn't anywhere near as permissive as Windows is. One of my old teachers summed it up like this:

On Windows, you can do anything, unless you can't. On Linux, you can't do anything, unless you can.

Most of the 'trick' is not blindly allowing escalations of privilege. For Windows, it's trivial, as it's usually one click away and most people aren't fully paying attention to UAC. Meanwhile, on Linux, you need to give it your password. It's meant to make you sit up and pay attention, so you're a little more vigilant about anything asking for password confirmation.

5

u/brickyboy124 1d ago

I’ve seen windows UAC ask my grandma for her password, yet it didn’t stop her running a malicious file.Ā 

0

u/Hettyc_Tracyn Cachyos | Hyprland | rolling release 1d ago

Which is why you don’t let people who don’t do the research and install random nonsense have admin access…

2

u/brickyboy124 1d ago

Windows makes you an admin by default when you set it up… 

almost no one who uses windows is going to bother demoting themselves, or has someone to do it for them.

0

u/Hettyc_Tracyn Cachyos | Hyprland | rolling release 1d ago

Well, if an old person, who doesn’t know how to stay safe online, has a computer, it’s the duty of their children/grandchildren to prevent stuff like ransomware, etc as they (the old person) are more likely to fall for it…

2

u/brickyboy124 1d ago

Sure but that’s besides my point: people (not just dumb people) run malicious files and accept UAC all the time. They just have to think the file is installing something legit.Ā 

1

u/Hettyc_Tracyn Cachyos | Hyprland | rolling release 1d ago

Yup

-1

u/Cent_Quatre 1d ago

Aside from the different design and smaller userbase, linux has the avantage of having a much more savvy userbase as well.

5

u/JaKrispy72 Linux Mint 22.3 Zena | Cinnamon 1d ago

Not anymore.

-1

u/screwdriverfan 1d ago

Yeah. Security through obscurity.

57

u/Goldman7911 1d ago

Also, wine currently is so good that even some windows malware has a chance of causing problems

6

u/khunset127 1d ago

another W for non-gamers who don't use or need wine

1

u/nekogasuki143 1d ago

We still have snapshot (the recovery thing) which restores the PC to last snapshot if it gets corrupted.

2

u/TomOnABudget 16h ago

That shit never helped me. I hope it'll finally become usable for normal users.

1

u/nekogasuki143 16h ago

well Linux has a learning curve......

2

u/TomOnABudget 16h ago

It's more like a mountain ridge. It's got ups, downs and the occasional sheer drop.

And a fanbase of mountaineers that'll tell you it's so easy their grandma and children climb (in the Linux community, use Linux). Meanwhile they all know someone who disappeared in an avalanche.

1

u/nekogasuki143 16h ago

so trueee, I wanted to try arch and other popular distros after a few weeks with my Mint. But when mint started giving me the L with wifi and speaker drivers.... I pretend linux mint is the only linux distro and enjoy my life.

4

u/khunset127 1d ago

snapshots can do nothing if it went unnoticed

3

u/CautiousLength6423 1d ago

Hmm like the snapshot was taken AFTER the trijan infiltration. That makes sense.

2

u/nekogasuki143 1d ago

Well the age old saying goes "prevention is better than cure."

16

u/TabascoTaco 1d ago

What is an exe gonna do on macOS

9

u/redguard128 1d ago

.dmg

2

u/Zaprit 1d ago

.dmg is not an executable, it’s a disk image. A lot of the Mac malware I’ve seen recently is mostly social engineering involving getting idiots to paste random crap into a terminal, so that’ll probably make its way over to Linux as time goes by as well.

5

u/Abducted_Llama 1d ago

Idk if it was intended as a joke , but I took it as ā€œdamageā€. Like dmg is an abbreviation of damage.

10

u/[deleted] 1d ago

[removed] — view removed comment

29

u/taosecurity Mint | Bazzite | PikaOS | CachyOS | Debian | FreeBSD | Windows 1d ago

Because when you make dumb memes, anything is possible.

0

u/LicenseToPost Powered by Cinnamon šŸ”‹ 1h ago

sudo apt install Love

sudo apt remove fear

3

u/articulatedstupidity 1d ago

Cosmopolitan libc would beg to differ

2

u/Strassi007 1d ago

The cause to spread misinformation? Why would we do that? We arenā€˜t all idiots.

1

u/LicenseToPost Powered by Cinnamon šŸ”‹ 1h ago
sudo apt install humor

2

u/SnowyRVulpix 1d ago

It can't destroy the system. It can destroy your user account.

2

u/leRealKraut 1d ago

Does macOS realy do .exe files just because?

Linux Mint does likely do something.

2

u/vaquishaProdigy 1d ago

If it compromises MacOs then it could compromise Linux too, if it is coded the right way

1

u/Bernsteinn 1d ago

Or the other way around. On Virustotal is a file with the same hash a a (supposed?) AppArmor script that changes Windows registry values.

2

u/w00dy1105 19h ago

This guy's got a future in security!

2

u/LicenseToPost Powered by Cinnamon šŸ”‹ 15h ago

šŸ‘‰ļøšŸ’—ļø

2

u/artistpanda5 Linux Mint 22.3 Zena | Cinnamon 17h ago

What happens if you run a .exe virus payload under Wine?

1

u/LicenseToPost Powered by Cinnamon šŸ”‹ 15h ago

whiskey I imagine

3

u/Digi-Device_File 1d ago

plot twist: the idiot uses wine...

1

u/pissrockious 1d ago

i got wine so m screwed either way if i fall for it i think lols

1

u/LicenseToPost Powered by Cinnamon šŸ”‹ 1h ago

Put your wine in a barrel and it won't infect the winery.

1

u/vswey 1d ago

Just use wine

1

u/SniperSnake18000 1d ago

Me laughing maniacally at the Trojans failure till I watch as wine boots up

1

u/Pkemr7 1d ago

i think a linux targeting virus would deal alot more damage than one targeted at windows

1

u/zerotaboo 22h ago

*Runs Wine

1

u/NoNandChips9090 13h ago

[Wine joins the chat]
exe you say...

1

u/tapedficus 1d ago

So it's a pdf that's also an exe?

0

u/Beginning-Pace-1426 1d ago

Oh my poor darling.

When people who switch to Linux think that they are somehow now invulnerable as an actual target I cringe.

I bet I could take a newbie Linux Mint user's system in less time than an average Windows user's.

2

u/Hettyc_Tracyn Cachyos | Hyprland | rolling release 1d ago

That’s what having an external backup is for, in case you, or a program, break something…

2

u/No-Froyo-9310 1d ago

Happy Cake Day!

2

u/Hettyc_Tracyn Cachyos | Hyprland | rolling release 1d ago

Thanks!

1

u/Hettyc_Tracyn Cachyos | Hyprland | rolling release 1d ago

That’s what having an external backup is for, in case you, or a program, break something…