NODE 03dab17dRe: Virus attacks on PGP
frantz@netcom.com (Bill Frantz)Tue, 21 Nov 1995 16:00:58 +0800
At 14:52 11/20/95 -0800, Thomas E Zerucha wrote:
>... The code can also be cross compiled
>and burned onto a CDROM which would make it difficult to infect.
Certainly having PGP run from a CDROM or other read-only device would be a
big help. Even better would be to have all the privileged code also run
from a read-only device.
Bill Frantz
NODE c2c3dacaRe: Virus attacks on PGP
SINCLAIR DOUGLAS N <sinclai@ecf.toronto.edu>Tue, 21 Nov 1995 21:51:32 +0800
> Certainly having PGP run from a CDROM or other read-only device would be a
> big help. Even better would be to have all the privileged code also run
> from a read-only device.
Seeing as PGP is quite small the simplest and cheapest read-only device
would be a write-protected floppy disk.
Could a virus write to a write-protected disk? I'm not sure if the
protection is done in the BIOS or the drive hardware.
NODE f54ebba6Re: Virus attacks on PGP
John Lull <lull@acm.org>Wed, 22 Nov 1995 02:17:43 +0800
On Tue, 21 Nov 1995 08:34:46 -0500, you wrote:
> Seeing as PGP is quite small the simplest and cheapest read-only device
> would be a write-protected floppy disk.
>
> Could a virus write to a write-protected disk? I'm not sure if the
> protection is done in the BIOS or the drive hardware.
In the drive hardware.
NODE 216919a3Re: Virus attacks on PGP
Ian Whalley <ian@virusbtn.com>Wed, 22 Nov 1995 03:07:56 +0800
>>Could a virus write to a write-protected disk? I'm not sure if the
>>protection is done in the BIOS or the drive hardware.
>In the drive hardware.
In certain rare cases, drive hardware fails in such a way to allow
write access to write-protected diskettes - I have one such machine
here. This appears to happen more often in 5.25" drives - perhaps
this is simply because most of the ones I come in contact with are
older than the 3.5" ones.
This is not a suitable viral attack, however, least of all against
a specific target like PGP. However, viruses attacking specific
programs are well-known, both in concept and actuality - take
AntiEXE, which will corrupt certain sector reads if the sector
starts with a given byte pattern. In a similar way it would be possible
to attack PGP, at least on DOS platforms. However, it would be
dependent upon compiler used/version of PGP/etc etc, and only
work in a few cases.
More likely is something which waits to see when a certain program
is run (let's say PGP :-)), and records keystrokes (keyphrase,
anyone?). Then it takes a copy of the secret key file along with
the keyphrase, and is able to do whatever it likes with them.
Slightly off-topic, for which I apologise, but there we go.
I.
---------------------------------------------------------------------
| Ian Whalley, Editor, | Phone/Fax : +44-1235-555139/531889 |
| Virus Bulletin, | DDI : +44-1235-544039 |
| 21 The Quadrant, |------------------------------------------|
| Abingdon Science Park, | PGP key : 2A 02 96 E5 5D 77 4C 8D |
| Oxon, OX14 3YS, UK. | fingerprint : EB 22 14 6F E0 3B A0 D3 |
---------------------------------------------------------------------