Hacker News new | ask | show | jobs
by Evbn 4816 days ago
Re the conclusion: to protect yourself, don't run an OS that will silently install software just because you clicked on a blue link in a program published by the OS vendor.

Steve Ballmer should be jailed as an accessory for allowing this.

1 comments

With a malware name like "Trojan.Win32.Jorik.IRCbot.xkt" - implying a Windows vector - I can't see why someone would downvote you for that comment.

I've got Skype on my *nix box, so do the downvoters assume that my system is also vulnerable to this malware?

There's no indication anywhere in the descriptions of this malware - on Kaspersky's blog or elsewhere - that it is exploiting any new or unique Windows-specific vulnerabilities. It could easily just be a downloadable executable that people are stupid enough to run. Social engineering works great. If your goal is simply to get a malicious executable onto as many machines as possible, Win32 is the obvious target to choose.

You've got Skype on your *nix box: Are you certain it's NOT vulnerable to malware? Obviously a Win32 executable isn't going to run on Linux, but if there's a hole in Skype what's stopping the bug responsible for that hole from causing a similar problem on Linux or OS X?

At this point no facts have been published to describe the nature of the malware in depth, so it's stupid to assume that it's dependent on some platform-specific exploit. On the other hand, it relies on clicking a link, so hopefully you're smart enough not to click shortened URLs sent by friends on Skype, no matter what OS you're running!