<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title><![CDATA[.desktop files can run malware]]></title>
    <link>http://brainstorm.ubuntu.com/item/18132/</link>
    <description><![CDATA[A blogger recently described a method to use .desktop files to run malware on unsuspecting users. Whereas executables have popup instructions that alert the user, .desktop launchers run on click and can appear exactly like regular files. This is not a bug; developers describe it as "expected behavior".<br /><br />http://www.geekzone.co.nz/foobar/6229<br />
<br />


<b>[-22 votes] Solution #2: Add an overlay icon</b>
<br />

<br />
<br />



]]></description>

    <language>en-us</language>
    <pubDate>Thu, 19 Feb 2009 01:31:09 +0000</pubDate>
    <lastBuildDate>Sat, 21 Feb 2009 04:15:07 +0000</lastBuildDate>
    <generator>QAPoll module</generator>
    <guid isPermaLink="true">http://brainstorm.ubuntu.com/idea/18132/</guid>
        <item>
  <title>Comment from andruk</title>
  <description><![CDATA[I voted for this, and I wish you all the luck in the world getting this voted up.  But, I must point out that as far as I've read, both Gnome and KDE have marked this bug as "Won't Fix".  Perhaps this idea getting lots of votes will be enough to change their minds.  I hope it does.<br /><br />This flaw isn't as bad as the WMF flaw in Windows, but it is close.  The WMF flaw was a flaw *by design*, as is this.<br /><br />To me, it should be very apparent if an icon (that's what the user understands it to be) is going to run anything.  We are just as vulnerable to malware delivered via social-engineering as Windows and any other operating system out there.  This decreases that attack surface, and should be implemented.]]></description>
  <pubDate>Fri, 20 Feb 2009 09:51:10 +0000</pubDate>
</item>
        <item>
  <title>Comment from viraptor</title>
  <description><![CDATA['+x' means something is executable by kernel. .desktop files are not "executable". They are data files.<br />Putting an executable flag on a .desktop file is simply wrong.<br /><br />.desktop files could simply get a new miniicon overlayed - something like the windows shortcut arrow.]]></description>
  <pubDate>Fri, 20 Feb 2009 17:39:13 +0000</pubDate>
</item>
        <item>
  <title>Comment from aysiu</title>
  <description><![CDATA[The steps required for this theoretical malware are still too much, and once you bring social engineering into the picture (i.e., user ignorance or stupidity), then the machine is basically going to be compromised anyway.<br /><br />Why don't we just get rid of GDebi, then, too?]]></description>
  <pubDate>Fri, 20 Feb 2009 19:17:21 +0000</pubDate>
</item>
        <item>
  <title>Comment from AndrewLuecke</title>
  <description><![CDATA[aysiu.. Why aren't perl and other scripts easier to run..]]></description>
  <pubDate>Fri, 20 Feb 2009 23:40:38 +0000</pubDate>
</item>
        <item>
  <title>Comment from firexq</title>
  <description><![CDATA[Aysiu, I agree that patching up "trick" malware isn't a task to dwell on. However, at present Ubuntu hides the .desktop ending of a file, meaning that it will appear indistinguishable from a normal file until clicked on. Stupid users will always go off running random code and the like, but even a non-stupid user could fall for this. Ubuntu does not provide him suffient information to make an informed decision.]]></description>
  <pubDate>Sat, 21 Feb 2009 04:15:07 +0000</pubDate>
</item>
      </channel>
</rss>
