Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753290AbYHRBRc (ORCPT ); Sun, 17 Aug 2008 21:17:32 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1750947AbYHRBRY (ORCPT ); Sun, 17 Aug 2008 21:17:24 -0400 Received: from brmea-mail-2.Sun.COM ([192.18.98.43]:46026 "EHLO brmea-mail-2.sun.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750858AbYHRBRX (ORCPT ); Sun, 17 Aug 2008 21:17:23 -0400 Date: Sun, 17 Aug 2008 17:17:05 -0400 From: David Collier-Brown Subject: Re: [malware-list] [RFC 0/5] [TALPA] Intro to alinuxinterfaceforon access scanning In-reply-to: To: Peter Dolding Cc: david@lang.hm, rmeijer@xs4all.nl, Alan Cox , capibara@xs4all.nl, Eric Paris , Theodore Tso , Rik van Riel , linux-security-module@vger.kernel.org, Adrian Bunk , Mihai Don??u , linux-kernel@vger.kernel.org, malware-list@lists.printk.net, Pavel Machek , Arjan van de Ven Reply-to: davecb@sun.com Message-id: <48A89551.9050107@sun.com> MIME-version: 1.0 Content-type: text/plain; format=flowed; charset=us-ascii Content-transfer-encoding: 7BIT X-Accept-Language: en-us, en References: <18129.82.95.100.23.1218802937.squirrel@webmail.xs4all.nl> User-Agent: Mozilla/5.0 (X11; U; SunOS sun4u; en-US; rv:1.7) Gecko/20041221 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1135 Lines: 23 Peter Dolding wrote: > Currently if we have a unknown infection on a windows partition that > is been shared by linux the scanner on Linux cannot see that the > windows permissions has been screwed with. OS with badly damaged > permissions is a sign of 1 of three things. ... It's more likely that the files will reside on Linux/Unix under Samba, and so the permissions that Samba implements will be the ones that the virus is trying to mess up. These are implemented in terms of the usual permission bits, plus extended attributes/ACLs. Linux systems mounting Windows filesystems are somewhat unusual (;-)) --dave -- David Collier-Brown | Always do right. This will gratify Sun Microsystems, Toronto | some people and astonish the rest davecb@sun.com | -- Mark Twain cell: (647) 833-9377, bridge: (877) 385-4099 code: 506 9191# -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/