Security from what? By default, there are no services listening. And what malware runs on Linux?
Security from what? By default, there are no services listening. And what malware runs on Linux?
Desktop linux, not "the Linux kernel". The kernel isn't amazing, but on the desktop side you regularly see downright absurd stuff like this https://scarybeastsecurity.blogspot.com/2016/11/0day-exploit...
and less surprising bugs like this https://donncha.is/2016/12/compromising-ubuntu-desktop/
The quality of software outside of some widely deployed server software tends to be quite poor, exploit mitigations are not being implemented.
>And what malware runs on Linux?
Far too many to list. You can easily find hundreds of public examples. This terrible wikipedia page provides a decent starting point with a list of names to google https://en.wikipedia.org/wiki/Linux_malware
That's a bug which only occurs on five year old distributions and which was fixed years before any exploit was ever found. Honestly if that's being brought up as a bad example Linux is looking pretty good compared to other operating systems.
shellrc and profile as well as almost all core unix tools allow running arbitrary code.
You can even bend the paths of bashrc and friends so the user can't trivially inspect them without dropping to root first (at which point, arbitrary code can trivially obtain root access too)
I don't think we're reading the same post unless you got confused by the part where he discusses the exploit not the bug.
> Honestly if that's being brought up as a bad example Linux is looking pretty good compared to other operating systems.
Compared to what? FreeBSD? Certainly not any modern desktop OS.
MSFT is investing heavily in exploit mitigations while Linux distros are probably still struggling with ASLR. https://www.blackhat.com/docs/us-16/materials/us-16-Weston-W...