Thread
:
Security on Nits?
View Single Post
Benson
2008-04-14 , 15:40
Posts: 4,930 | Thanked: 2,272 times | Joined on Oct 2007
#
16
Installing packages is done as root; no matter what you set up (other than rejecting packages
before
installation), a malicious package can disable or circumvent the firewall. Same as on any UNIX system; if you don't trust the software, don't do a system-wide install.
After installing, you can check sudoers, as it's reasonably likely that malware would put itself in there to permit any malicious activities that require root. All depends on the payload, of course. A keylogger can get by quite fine by itself, as long as some usable process (ssh, mail, etc.) is able to access the outside world.
Things you can do to check software you're considering installing:
Check the file-list.
Check the install scripts.
That should make the scope of things it can do clear; but even with no SUID or sudoers entries, you can do a lot.
Quote & Reply
|
The Following 2 Users Say Thank You to Benson For This Useful Post:
meanwhile
,
TA-t3
Benson
View Public Profile
Send a private message to Benson
Find all posts by Benson