CPSC 527 or: How I Learned to Start Worrying and Write a Virus
danieru.com
danieru.com
The real horrifying part though is the fact that the people who want to solve the problem are being discouraged from doing so by the thread of blacklisting. On one level it's immoral, on another it's self destructive. More schools should be offering classes like this.
Even before I switched away from Windows I never used them.
If we fear people start developing malware and virus, think about all those web design classes out there where students don't realize how vulnerable their implementations are. Think about all the free sec tools out there.
> Most anti-virus companies (including ours) have a policy against hiring former virus writers for anti-virus work
What? Who do they hire then? I supposed I am qualified because I never written a serious virus/trojan. Would I call rm -rf a joke? There was a guy discovered a way to create botnet by XSS a Gmail chrome extension two days ago. Would anyone call that some form of trojan?
My friend did this prank in a computer lab. He knows the local IP to each computer and they are sequential. He wrote a shell script which (1) screen capture the current screen on each computer, send that image to the adjacent computer, and then change the background.
I think your enemy can also be your friends. If people are curious, they will find a way to beat their curiosity. If they are technically smart, they can write virus that bypass AV scanner. Hey, those are the guys you want to hire. Are they suggesting that none of the researchers working for these AV labs have never written some form of virus or malware or Trojan prior to employment?
I also would have loved to have had a course like this when I was at uni. I might have paid more attention in the systems course :(
Keep it up !
It brought the whole computer lab down after I manually "installed" it on each of the 5 machines one day.
This was in middle school, and yeah, my middle school was a joke. They ended up formatting all of the machines and the lab was down for half of the semester.
If, as you suggested, someone released a virus designed to fix a person's computer, it would still be harmful in principle because you are making the assumption that people want strangers executing code on their machines.
Except that's pretty much what happens every time you visit a website with JS enabled...
Clearly there is a difference between a benign website and a site that hosts code that knowingly takes control of the user's computer (regardless of the programmer's intentions).
Nowadays we have some techiniques for restraining a virus, so that might work better... But then, we took the good parts of that virus and packaged on software that we deploy in a controled matter - we call that software anti-virus. There is no need to even test it anymore.
Used the same exploit as the blaster virus, patching the exploit on the host computer and self-propagating from it.
So I am expected to believe that the makers of anti virus programs have an interest in solving the virus problem, AND that they are actually capable of doing this, AND that they are the only way this can be done? Not buying it.
> Due to the inherent danger of this software, you may only work on these assignments in the designated lab room for the course.
> You will be required to sign a form stating that you have read and understood the lab protocols, and that you understand that misuse of the information in this course can result in civil and criminal penalties under the laws of Canada and of other countries.
Also, the link to the course's contents on John Aycock's page[2] says:
> (course access only, sorry)
So I guess they don't want to make the contents of the course public