[PLUG] anti virus

David C. Hansen dave@sr71.net
Thu, 20 Sep 2001 08:56:21 -0700


Leon wrote:
> 
> Is there anti virus software for mandrake linux?  does it come
> preinstalled with it?  I don't want to get hte nimda virus
As the other posters said, there very little danger from virii in a UNIX
environment.  The biggest threat is from people.  One of the best tools
to detect the success of these attacks is Tripwire, which I believe
originated right here at Purdue.
http://www.tripwire.org/
Tripwire records signatures of all kinds of files, from "ls" to
"/etc/hosts" to your kernel image.  If one of these files changes
without reason, it is a good sign of an attack. 

Anybody else have anything to add?  Tripwire is the second best reason
that I can come up with when people ask why UNIX doesn't have anti-virus
programs.  
-- 
David C. Hansen
dave@sr71.net
ICQ: 7785546
AIM: HansenDC79