Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.misc > #33235 > unrolled thread

Linux Executables Deployed as Stealth Windows Loaders

Started by"Andrei Z." <no-email@invalid.invalid>
First post2021-09-19 17:47 +0300
Last post2021-09-21 23:59 -0400
Articles 5 — 4 participants

Back to article view | Back to comp.os.linux.misc


Contents

  Linux Executables Deployed as Stealth Windows Loaders "Andrei Z." <no-email@invalid.invalid> - 2021-09-19 17:47 +0300
    Re: Linux Executables Deployed as Stealth Windows Loaders SolutionsViaDIY <NoSpamJunkMailAtAll@NoSpam.com> - 2021-09-19 13:08 -0400
      Re: Linux Executables Deployed as Stealth Windows Loaders "David W. Hodgins" <dwhodgins@nomail.afraid.org> - 2021-09-19 13:24 -0400
      Re: Linux Executables Deployed as Stealth Windows Loaders "Andrei Z." <no-email@invalid.invalid> - 2021-09-19 20:41 +0300
        Re: Linux Executables Deployed as Stealth Windows Loaders SevenOverSix <hae274c.net> - 2021-09-21 23:59 -0400

#33235 — Linux Executables Deployed as Stealth Windows Loaders

From"Andrei Z." <no-email@invalid.invalid>
Date2021-09-19 17:47 +0300
SubjectLinux Executables Deployed as Stealth Windows Loaders
Message-ID<si7iim$1pb2$1@gioia.aioe.org>
No Longer Just Theory: Black Lotus Labs Uncovers Linux Executables 
Deployed as Stealth Windows Loaders

https://blog.lumen.com/no-longer-just-theory-black-lotus-labs-uncovers-linux-executables-deployed-as-stealth-windows-loaders/

[toc] | [next] | [standalone]


#33236

FromSolutionsViaDIY <NoSpamJunkMailAtAll@NoSpam.com>
Date2021-09-19 13:08 -0400
Message-ID<2jrekg9thekhkrmo72uol4q9q34ld88u4v@4ax.com>
In reply to#33235
On Sun, 19 Sep 2021 17:47:50 +0300, "Andrei Z."
<no-email@invalid.invalid> wrote:

>No Longer Just Theory: Black Lotus Labs Uncovers Linux Executables 
>Deployed as Stealth Windows Loaders
>
>https://blog.lumen.com/no-longer-just-theory-black-lotus-labs-uncovers-linux-executables-deployed-as-stealth-windows-loaders/


For those of us who are not techies, what does this mean, exactly?  I
read the article but not sure I understand completely.  Does it mean
we think we're installing Linux but we're getting nasty Windows,
instead???  Unless it's specifically this Windows Subsystem for Linux
(WSL) which can't be accidentally installed as Linux by mistake?

Sorry, I'm really not a techie ...  (And in case of yes to the above
[???], how can a layperson know the difference?)


-- 
This email has been checked for viruses by Avast antivirus software.
https://www.avast.com/antivirus

[toc] | [prev] | [next] | [standalone]


#33237

From"David W. Hodgins" <dwhodgins@nomail.afraid.org>
Date2021-09-19 13:24 -0400
Message-ID<op.09y9a6jka3w0dxdave@hodgins.homeip.net>
In reply to#33236
On Sun, 19 Sep 2021 13:08:01 -0400, SolutionsViaDIY <NoSpamJunkMailAtAll@nospam.com> wrote:

> On Sun, 19 Sep 2021 17:47:50 +0300, "Andrei Z."
> <no-email@invalid.invalid> wrote:
>
>> No Longer Just Theory: Black Lotus Labs Uncovers Linux Executables
>> Deployed as Stealth Windows Loaders
>>
>> https://blog.lumen.com/no-longer-just-theory-black-lotus-labs-uncovers-linux-executables-deployed-as-stealth-windows-loaders/
>
>
> For those of us who are not techies, what does this mean, exactly?  I
> read the article but not sure I understand completely.  Does it mean
> we think we're installing Linux but we're getting nasty Windows,
> instead???  Unless it's specifically this Windows Subsystem for Linux
> (WSL) which can't be accidentally installed as Linux by mistake?
>
> Sorry, I'm really not a techie ...  (And in case of yes to the above
> [???], how can a layperson know the difference?)

It's strictly the windows subsystem for linux. As usual, m$ puts out something
that sort of works on the market, with no concern for security.

Regards, Dave Hodgins

-- 
Change dwhodgins@nomail.afraid.org to davidwhodgins@teksavvy.com for
email replies.

[toc] | [prev] | [next] | [standalone]


#33238

From"Andrei Z." <no-email@invalid.invalid>
Date2021-09-19 20:41 +0300
Message-ID<si7soh$u28$1@gioia.aioe.org>
In reply to#33236
SolutionsViaDIY wrote:
> On Sun, 19 Sep 2021 17:47:50 +0300, "Andrei Z."
> <no-email@invalid.invalid> wrote:
> 
>> No Longer Just Theory: Black Lotus Labs Uncovers Linux Executables
>> Deployed as Stealth Windows Loaders
>>
>> https://blog.lumen.com/no-longer-just-theory-black-lotus-labs-uncovers-linux-executables-deployed-as-stealth-windows-loaders/
> 
> 
> For those of us who are not techies, what does this mean, exactly?  I
> read the article but not sure I understand completely.  Does it mean
> we think we're installing Linux but we're getting nasty Windows,
> instead???  Unless it's specifically this Windows Subsystem for Linux
> (WSL) which can't be accidentally installed as Linux by mistake?
> 
> Sorry, I'm really not a techie ...  (And in case of yes to the above
> [???], how can a layperson know the difference?)
> 
> 
Researchers have recorded a new way to compromise computers running 
Windows that uses malicious Linux binary files created for Windows 
Subsystem for Linux (WSL).

[toc] | [prev] | [next] | [standalone]


#33240

FromSevenOverSix <hae274c.net>
Date2021-09-21 23:59 -0400
Message-ID<VeydnQBIVoiEN9f8nZ2dnUU7-S3NnZ2d@earthlink.com>
In reply to#33238
On 9/19/21 1:41 PM, Andrei Z. wrote:
> SolutionsViaDIY wrote:
>> On Sun, 19 Sep 2021 17:47:50 +0300, "Andrei Z."
>> <no-email@invalid.invalid> wrote:
>>
>>> No Longer Just Theory: Black Lotus Labs Uncovers Linux Executables
>>> Deployed as Stealth Windows Loaders
>>>
>>> https://blog.lumen.com/no-longer-just-theory-black-lotus-labs-uncovers-linux-executables-deployed-as-stealth-windows-loaders/ 
>>>
>>
>>
>> For those of us who are not techies, what does this mean, exactly?  I
>> read the article but not sure I understand completely.  Does it mean
>> we think we're installing Linux but we're getting nasty Windows,
>> instead???  Unless it's specifically this Windows Subsystem for Linux
>> (WSL) which can't be accidentally installed as Linux by mistake?
>>
>> Sorry, I'm really not a techie ...  (And in case of yes to the above
>> [???], how can a layperson know the difference?)
>>
>>
> Researchers have recorded a new way to compromise computers running 
> Windows that uses malicious Linux binary files created for Windows 
> Subsystem for Linux (WSL).


   I was looking into WSL/WSL2 just last week. Went with a Virtualbox
   solution instead. Click icon, REAL Linux VM (mx19) starts. MUCH
   better. Fine control.

   Anything MS has touched since W98 should be considered "contaminated".

   Oh, for fun, search the W2k registry for "NSA"  :-)

[toc] | [prev] | [standalone]


Back to top | Article view | comp.os.linux.misc


csiph-web