Originally posted by: nweaver
Originally posted by: Seeruk
I think what is being alluded to in this post is something a little more basic...
Here is a fact...for free... no charge.... I'll give this to you as I am a nice guy.....
AN IDIOT ON WINDOWS IS STILL AN IDIOT ON LINUX
Now what does that pearl of wisdom mean? It means someone who can't read in windows still won't read in linux! The newspapers, the interweb, jeezuz even my grandparents are screaming with scare stories about don't click this, don't visit these sites, and whatever you do - DON'T PRESSS THAT RED BUTTON!
But what do the idiots do? Nothing that is advised to them thats for sure. They still scavenge for free porn (ooo all I have to do is install this free program for porn?? CoOool), they still open attachments called freecar.exe and they still haven't the faintest idea of what the hell they are doing.
You would think linux would make them safer but it doesnt! A browser hijacker was installed on my friends machine just last week. The only difference was instead of a pop-up OK button, he gave root password instead!
Wow, where did he get this browser hijack that asked for the root password? I would wonder what person would be targeting linux machines.
Even with my root password, there is a very very very limited amount of things you can do, as root has NO remote access, you have to get in remotely on my nonstandard SSH port with one of the few user accounts that has ssh access. Those all have very complex passwords, and I use keys to connect.
Back on point, it's much harder for a standard user to fubar their linux box then it is for a windows user. They can, at best, hose their account, but not the full box. My brother in law doesn't have the root password
I don't of course know where he got the browser hijacker because I arrived several days after the event.
But needless to say he frequently visits sites of questionable morales
Anyway... it was really very simple ... a shellscript downloaded and ran attempting to modify lots of userspace information, which in turn of course popped up the root password dialog.
Like I say... at the end of the day if a person is desperate or stupid enough for something... it doesnt matter whether its an OK button or the vital details they have to give... they just keep on giving it up like a $2 wh0re