Rocksolid Light

News from da outaworlds

mail  files  register  groups  login

Message-ID:  

BOFH excuse #133: It's not plugged in.


comp / comp.os.linux.misc / ISO of a linux animalware / antivirus scanner

SubjectAuthor
* ISO of a linux animalware / antivirus scannerThe Doctor
+* Re: ISO of a linux animalware / antivirus scannerBobbie Sellers
|`* Re: ISO of a linux animalware / antivirus scannerComputer Nerd Kev
| `* Re: ISO of a linux animalware / antivirus scannerCarlos E.R.
|  `* Re: ISO of a linux animalware / antivirus scannerComputer Nerd Kev
|   `* Re: ISO of a linux animalware / antivirus scannerCarlos E.R.
|    `* Re: ISO of a linux animalware / antivirus scannerComputer Nerd Kev
|     `* Re: ISO of a linux animalware / antivirus scannerCarlos E.R.
|      `* Re: ISO of a linux animalware / antivirus scannerComputer Nerd Kev
|       `- Re: ISO of a linux animalware / antivirus scannerComputer Nerd Kev
+* Re: ISO of a linux animalware / antivirus scannerCarlos E.R.
|`* Re: ISO of a linux animalware / antivirus scannerMarioCCCP
| `- Re: ISO of a linux animalware / antivirus scannerCarlos E.R.
+* Re: ISO of a linux animalware / antivirus scannerShadow
|`* Re: ISO of a linux animalware / antivirus scannerThe Doctor
| `- Re: ISO of a linux animalware / antivirus scannerShadow
+* Re: ISO of a linux animalware / antivirus scannerJulius Bernotas
|`- Re: ISO of a linux animalware / antivirus scannerThe Doctor
`* Re: ISO of a linux animalware / antivirus scannervallor
 `* Re: ISO of a linux animalware / antivirus scannerThe Doctor
  `- Re: ISO of a linux animalware / antivirus scanner186282@ud0s4.net

1
Subject: ISO of a linux animalware / antivirus scanner
From: The Doctor
Newsgroups: comp.os.linux.misc,
Organization: NetKnow News
Date: Mon, 26 Aug 2024 23:50 UTC
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!news.quux.org!news.nk.ca!.POSTED.doctor.nl2k.ab.ca!not-for-mail
From: doctor@doctor.nl2k.ab.ca (The Doctor)
Newsgroups: comp.os.linux.misc,
Subject: ISO of a linux animalware / antivirus scanner
Date: Mon, 26 Aug 2024 23:50:34 -0000 (UTC)
Organization: NetKnow News
Message-ID: <vaj4ca$157e$1@gallifrey.nk.ca>
Injection-Date: Mon, 26 Aug 2024 23:50:34 -0000 (UTC)
Injection-Info: gallifrey.nk.ca; posting-host="doctor.nl2k.ab.ca:204.209.81.1";
logging-data="38126"; mail-complaints-to="usenet@gallifrey.nk.ca"
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: doctor@doctor.nl2k.ab.ca (The Doctor)
View all headers

I suspect a Windows OS with an Intel MB
have malware embedded in them.

Are there are Linux ISOs I can use to test my theory?
--
Member - Liberal International This is doctor@nk.ca Ici doctor@nk.ca
Yahweh, King & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism ;

Subject: Re: ISO of a linux animalware / antivirus scanner
From: vallor
Newsgroups: comp.os.linux.misc,
Date: Tue, 27 Aug 2024 00:36 UTC
References: 1
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: vallor@cultnix.org (vallor)
Newsgroups: comp.os.linux.misc,
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: 27 Aug 2024 00:36:58 GMT
Lines: 24
Message-ID: <lj4ldaFasmaU8@mid.individual.net>
References: <vaj4ca$157e$1@gallifrey.nk.ca>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net DpNjWJV9L7rIcZDg79iuKQ55DFmhlQ/rCj6A31Fhaww00ydmFp
Cancel-Lock: sha1:6PZfgenGGQvbLOwLQFHsFsFprp0= sha256:2qDkgpehDW/d4/0wnu5Ogeo4WFBhsyNwgcLlxrWQFp0=
X-Face: +McU)#<-H?9lTb(Th!zR`EpVrp<0)1p5CmPu.kOscy8LRp_\u`:tW;dxPo./(fCl
CaKku`)]}.V/"6rISCIDP`
User-Agent: Pan/0.160 (Toresk; 7830f38; Linux-6.11.0-rc5)
View all headers

On Mon, 26 Aug 2024 23:50:34 -0000 (UTC), doctor@doctor.nl2k.ab.ca (The
Doctor) wrote in <vaj4ca$157e$1@gallifrey.nk.ca>:

> I suspect a Windows OS with an Intel MB
> have malware embedded in them.
>
> Are there are Linux ISOs I can use to test my theory?

If only there were a worldwide database where one could ask
about this... /s

Seriously though, are you cool with clamav? Boot an ubuntu
live distro, sudo apt install clamtk, then run clamtk.

You might have to pull up the file manager to get your windows
partition mounted, then scan the mount directory recursively.

But if you suspect the virus is in the SMI for the processor, not
sure if there's anything you can do about that.

--
-v System76 Thelio Mega v1.1 x86_64 NVIDIA RTX 3090 Ti
OS: Linux 6.11.0-rc5 Release: Mint 21.3 Mem: 258G
"Never eat anything bigger than your head."

Subject: Re: ISO of a linux animalware / antivirus scanner
From: The Doctor
Newsgroups: comp.os.linux.misc,
Organization: NetKnow News
Date: Tue, 27 Aug 2024 02:50 UTC
References: 1 2
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!news.quux.org!news.nk.ca!.POSTED.doctor.nl2k.ab.ca!not-for-mail
From: doctor@doctor.nl2k.ab.ca (The Doctor)
Newsgroups: comp.os.linux.misc,
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: Tue, 27 Aug 2024 02:50:56 -0000 (UTC)
Organization: NetKnow News
Message-ID: <vajeug$19mo$1@gallifrey.nk.ca>
References: <vaj4ca$157e$1@gallifrey.nk.ca> <lj4ldaFasmaU8@mid.individual.net>
Injection-Date: Tue, 27 Aug 2024 02:50:56 -0000 (UTC)
Injection-Info: gallifrey.nk.ca; posting-host="doctor.nl2k.ab.ca:204.209.81.1";
logging-data="42712"; mail-complaints-to="usenet@gallifrey.nk.ca"
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: doctor@doctor.nl2k.ab.ca (The Doctor)
View all headers

In article <lj4ldaFasmaU8@mid.individual.net>,
vallor <vallor@cultnix.org> wrote:
>On Mon, 26 Aug 2024 23:50:34 -0000 (UTC), doctor@doctor.nl2k.ab.ca (The
>Doctor) wrote in <vaj4ca$157e$1@gallifrey.nk.ca>:
>
>> I suspect a Windows OS with an Intel MB
>> have malware embedded in them.
>>
>> Are there are Linux ISOs I can use to test my theory?
>
>If only there were a worldwide database where one could ask
>about this... /s
>
>Seriously though, are you cool with clamav? Boot an ubuntu
>live distro, sudo apt install clamtk, then run clamtk.
>
>You might have to pull up the file manager to get your windows
>partition mounted, then scan the mount directory recursively.
>
>But if you suspect the virus is in the SMI for the processor, not
>sure if there's anything you can do about that.
>

What about a debian or kali live distro?

>--
>-v System76 Thelio Mega v1.1 x86_64 NVIDIA RTX 3090 Ti
> OS: Linux 6.11.0-rc5 Release: Mint 21.3 Mem: 258G
> "Never eat anything bigger than your head."

--
Member - Liberal International This is doctor@nk.ca Ici doctor@nk.ca
Yahweh, King & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism ;

Subject: Re: ISO of a linux animalware / antivirus scanner
From: 186282@ud0s4.net
Newsgroups: comp.os.linux.misc
Organization: wokiesux
Date: Tue, 27 Aug 2024 08:49 UTC
References: 1 2 3
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!border-2.nntp.ord.giganews.com!nntp.giganews.com!Xl.tags.giganews.com!local-4.nntp.ord.giganews.com!nntp.earthlink.com!news.earthlink.com.POSTED!not-for-mail
NNTP-Posting-Date: Tue, 27 Aug 2024 08:49:15 +0000
Subject: Re: ISO of a linux animalware / antivirus scanner
Newsgroups: comp.os.linux.misc
References: <vaj4ca$157e$1@gallifrey.nk.ca> <lj4ldaFasmaU8@mid.individual.net>
<vajeug$19mo$1@gallifrey.nk.ca>
From: 186283@ud0s4.net (186282@ud0s4.net)
Organization: wokiesux
Date: Tue, 27 Aug 2024 04:49:13 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101
Thunderbird/78.13.0
MIME-Version: 1.0
In-Reply-To: <vajeug$19mo$1@gallifrey.nk.ca>
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Message-ID: <B3CdnTlYPLWWDlD7nZ2dnZfqnPidnZ2d@earthlink.com>
Lines: 39
X-Usenet-Provider: http://www.giganews.com
NNTP-Posting-Host: 99.101.150.97
X-Trace: sv3-3Xl/S3oKAVm/GJJ6f4VQgC9ck3S7UCPg10ZSVEXRIGQ6hxAlKF7ltyfBn2wtk1squMl+eMlI3Nr65fc!yv2nw7IT1MQhHqRXLAmJpEyDMDtDXwPN7CFmE3c/j/BfQtSklqqA5fhtaFXmiDe/+bli+W6OcW+b!DCapIAsAEZqdsJ5mFzzF
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
View all headers

On 8/26/24 10:50 PM, The Doctor wrote:
> In article <lj4ldaFasmaU8@mid.individual.net>,
> vallor <vallor@cultnix.org> wrote:
>> On Mon, 26 Aug 2024 23:50:34 -0000 (UTC), doctor@doctor.nl2k.ab.ca (The
>> Doctor) wrote in <vaj4ca$157e$1@gallifrey.nk.ca>:
>>
>>> I suspect a Windows OS with an Intel MB
>>> have malware embedded in them.
>>>
>>> Are there are Linux ISOs I can use to test my theory?
>>
>> If only there were a worldwide database where one could ask
>> about this... /s
>>
>> Seriously though, are you cool with clamav? Boot an ubuntu
>> live distro, sudo apt install clamtk, then run clamtk.
>>
>> You might have to pull up the file manager to get your windows
>> partition mounted, then scan the mount directory recursively.
>>
>> But if you suspect the virus is in the SMI for the processor, not
>> sure if there's anything you can do about that.
>>
>
> What about a debian or kali live distro?

I *think* he's worried about BUILT-IN spyware - actually
part of the BIOS or On-Chip ........

Clam isn't gonna find that.

I wouldn't put it PAST Intel or some PC maker to
do such. User-mining PAYS BIG apparently. Some
big-name PCs you buy came with whole suites of
"helpful" utilities added which, really, are
naught but spyware. Hell, there was a whole
series of Samsung TVs ... if you enabled net
access it kept phoning home ....

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Carlos E.R.
Newsgroups: comp.os.linux.misc
Date: Tue, 27 Aug 2024 10:11 UTC
References: 1
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: comp.os.linux.misc
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: Tue, 27 Aug 2024 12:11:09 +0200
Lines: 14
Message-ID: <tal0qkx3nv.ln2@Telcontar.valinor>
References: <vaj4ca$157e$1@gallifrey.nk.ca>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net 6R8VixMqpcvB2jbh2/b7HwT0EhryYvrrj7V+OTPJ4l/F7+YA3I
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:+Ov2q/z5suV/VfqBFXXpSlyH8y0= sha256:B0NDuDy5vy174Ql6NWrDm12D08uzRrwdsjLqjnkOzDw=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <vaj4ca$157e$1@gallifrey.nk.ca>
View all headers

On 2024-08-27 01:50, The Doctor wrote:
> I suspect a Windows OS with an Intel MB
> have malware embedded in them.
>
> Are there are Linux ISOs I can use to test my theory?

You need to ask in a Windows group.

If you want to use clamav, you can do that with any linux distro of your
liking in which you install clamav.

--
Cheers, Carlos.

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Shadow
Newsgroups: comp.os.linux.misc
Organization: A noiseless patient Shadow
Date: Tue, 27 Aug 2024 14:59 UTC
References: 1
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: Sh@dow.br (Shadow)
Newsgroups: comp.os.linux.misc
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: Tue, 27 Aug 2024 11:59:07 -0300
Organization: A noiseless patient Shadow
Lines: 20
Message-ID: <40qrcjll8ifi3souqnukq23j939u869lvq@4ax.com>
References: <vaj4ca$157e$1@gallifrey.nk.ca>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 27 Aug 2024 16:59:11 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="1a7067cbb73739936bf031a258f08766";
logging-data="3191295"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18kB5YnZrPxLJm/S4xCRWw+vEdmQQvph6A="
Cancel-Lock: sha1:25dks5uklr37n20h6tZrRkzvM0Y=
X-Newsreader: Forte Agent 3.3/32.846
View all headers

On Mon, 26 Aug 2024 23:50:34 -0000 (UTC), doctor@doctor.nl2k.ab.ca
(The Doctor) wrote:

>I suspect a Windows OS with an Intel MB
>have malware embedded in them.
>
>Are there are Linux ISOs I can use to test my theory?

Kaspersky Rescue Disk. Unplug your network card before booting
with it, it connects to "search for updates".
Scans Windows and Linux.
I don't think it does hardware-embedded malware though.
[]'s

PS a full scan will take all night....

--
Don't be evil - Google 2004
We have a new policy - Google 2012
Google Fuchsia - 2021

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Julius Bernotas
Newsgroups: comp.os.linux.misc,
Date: Tue, 27 Aug 2024 15:05 UTC
References: 1
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!news.dfncis.de!not-for-mail
From: gaussianblue@tilde.pink (Julius Bernotas)
Newsgroups: comp.os.linux.misc,
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: 27 Aug 2024 15:05:20 GMT
Lines: 24
Message-ID: <lj689gFkevjU1@mid.dfncis.de>
References: <vaj4ca$157e$1@gallifrey.nk.ca>
X-Trace: news.dfncis.de wRxFOKa7/aZq6OIxA+wIvgYhF3mVmcJwVxDCUgGiKtOoiR6lN2UGOmqzsE
Cancel-Lock: sha1:mlwOdRs8UpzmfYaAPEOmBv+LoYA= sha256:jWbwmiGKgq03eFtF8cUu52q7PZlKQOpnnuEm1HTFdAU=
User-Agent: nn/6.7.3
View all headers

doctor@doctor.nl2k.ab.ca (The Doctor) writes:

>I suspect a Windows OS with an Intel MB
>have malware embedded in them.

>Are there are Linux ISOs I can use to test my theory?

Could you clarify what problem you are facing? You have a machine
that you suspect being infected by malware. And you are uncomfortable
with using it. Do I understand it correctly? Why are you feeling
uncomfortable using an infected machine? Or is the problem
another one: You are trying check your machine for malware
to have the assurance to use a machine that is not infected
by any malware. This problem has an easy solution:
Don't use your own machine. Use your employer's machine.
Your employer's IT department will take care that your
machine is being checked for malware regularly and will
do so by following best practice in IT. And you don't have to worry.

>--
>Member - Liberal International This is doctor@nk.ca Ici doctor@nk.ca
>Yahweh, King & country!Never Satan President Republic!Beware AntiChrist rising!
>Look at Psalms 14 and 53 on Atheism ;

Subject: Re: ISO of a linux animalware / antivirus scanner
From: The Doctor
Newsgroups: comp.os.linux.misc
Organization: NetKnow News
Date: Tue, 27 Aug 2024 22:02 UTC
References: 1 2
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!panix!weretis.net!feeder9.news.weretis.net!news.nk.ca!.POSTED.doctor.nl2k.ab.ca!not-for-mail
From: doctor@doctor.nl2k.ab.ca (The Doctor)
Newsgroups: comp.os.linux.misc
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: Tue, 27 Aug 2024 22:02:17 -0000 (UTC)
Organization: NetKnow News
Message-ID: <valid9$kp$3@gallifrey.nk.ca>
References: <vaj4ca$157e$1@gallifrey.nk.ca> <40qrcjll8ifi3souqnukq23j939u869lvq@4ax.com>
Injection-Date: Tue, 27 Aug 2024 22:02:17 -0000 (UTC)
Injection-Info: gallifrey.nk.ca; posting-host="doctor.nl2k.ab.ca:204.209.81.1";
logging-data="665"; mail-complaints-to="usenet@gallifrey.nk.ca"
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: doctor@doctor.nl2k.ab.ca (The Doctor)
View all headers

In article <40qrcjll8ifi3souqnukq23j939u869lvq@4ax.com>,
Shadow <Sh@dow.br> wrote:
>On Mon, 26 Aug 2024 23:50:34 -0000 (UTC), doctor@doctor.nl2k.ab.ca
>(The Doctor) wrote:
>
>>I suspect a Windows OS with an Intel MB
>>have malware embedded in them.
>>
>>Are there are Linux ISOs I can use to test my theory?
>
> Kaspersky Rescue Disk. Unplug your network card before booting
>with it, it connects to "search for updates".
> Scans Windows and Linux.
> I don't think it does hardware-embedded malware though.
> []'s
>
> PS a full scan will take all night....
>

Kaspersky banned in NA!

>--
>Don't be evil - Google 2004
>We have a new policy - Google 2012
>Google Fuchsia - 2021

--
Member - Liberal International This is doctor@nk.ca Ici doctor@nk.ca
Yahweh, King & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism ;

Subject: Re: ISO of a linux animalware / antivirus scanner
From: The Doctor
Newsgroups: comp.os.linux.misc,
Organization: NetKnow News
Date: Tue, 27 Aug 2024 22:03 UTC
References: 1 2
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!news.quux.org!news.nk.ca!.POSTED.doctor.nl2k.ab.ca!not-for-mail
From: doctor@doctor.nl2k.ab.ca (The Doctor)
Newsgroups: comp.os.linux.misc,
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: Tue, 27 Aug 2024 22:03:09 -0000 (UTC)
Organization: NetKnow News
Message-ID: <valiet$kp$4@gallifrey.nk.ca>
References: <vaj4ca$157e$1@gallifrey.nk.ca> <lj689gFkevjU1@mid.dfncis.de>
Injection-Date: Tue, 27 Aug 2024 22:03:09 -0000 (UTC)
Injection-Info: gallifrey.nk.ca; posting-host="doctor.nl2k.ab.ca:204.209.81.1";
logging-data="665"; mail-complaints-to="usenet@gallifrey.nk.ca"
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: doctor@doctor.nl2k.ab.ca (The Doctor)
View all headers

In article <lj689gFkevjU1@mid.dfncis.de>,
Julius Bernotas <gaussianblue@tilde.pink> wrote:
>doctor@doctor.nl2k.ab.ca (The Doctor) writes:
>
>>I suspect a Windows OS with an Intel MB
>>have malware embedded in them.
>
>>Are there are Linux ISOs I can use to test my theory?
>
>Could you clarify what problem you are facing? You have a machine
>that you suspect being infected by malware. And you are uncomfortable
>with using it. Do I understand it correctly? Why are you feeling
>uncomfortable using an infected machine? Or is the problem
>another one: You are trying check your machine for malware
>to have the assurance to use a machine that is not infected
>by any malware. This problem has an easy solution:
>Don't use your own machine. Use your employer's machine.
>Your employer's IT department will take care that your
>machine is being checked for malware regularly and will
>do so by following best practice in IT. And you don't have to worry.
>

Firmware upgrade does not go through.

Drive not expand to use full capacity .

>>--
>>Member - Liberal International This is doctor@nk.ca Ici doctor@nk.ca
>>Yahweh, King & country!Never Satan President Republic!Beware AntiChrist rising!
>>Look at Psalms 14 and 53 on Atheism ;
>

--
Member - Liberal International This is doctor@nk.ca Ici doctor@nk.ca
Yahweh, King & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism ;

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Bobbie Sellers
Newsgroups: comp.os.linux.misc
Organization: none at all
Date: Tue, 27 Aug 2024 22:40 UTC
References: 1
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: blissInSanFrancisco@mouse-potato.com (Bobbie Sellers)
Newsgroups: comp.os.linux.misc
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: Tue, 27 Aug 2024 15:40:21 -0700
Organization: none at all
Lines: 31
Message-ID: <valkkl$352e9$1@dont-email.me>
References: <vaj4ca$157e$1@gallifrey.nk.ca>
Reply-To: blissInSanFrancisco@mouse-potato.com
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 28 Aug 2024 00:40:22 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="a37d359fd7dde28897fd3db559c09b3f";
logging-data="3312073"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/d3OwPBpYuzZTLn81jILn2"
User-Agent: Betterbird (Linux)
Cancel-Lock: sha1:n88oxRd8a7bZmHqtt2sU7Dakcdk=
In-Reply-To: <vaj4ca$157e$1@gallifrey.nk.ca>
Content-Language: en-US
View all headers

On 8/26/24 16:50, The Doctor wrote:
> I suspect a Windows OS with an Intel MB
> have malware embedded in them.
>
> Are there are Linux ISOs I can use to test my theory?

Well it is known that the Intels have a Minix fork
embedded to send data back to the factory. I think that
the data with which they are concerned relates to CPU
functions not with your Personal data. Windows and MS
use Windows for personal data collection.
Only thing I can suggest to excape these matters
is to go to an AMD Ryzen motherboard.
I see that you are worried about the full use
of your hard drive and that must be enabled in the BIOS
or not. I suggest that that you remove Windows as soon
as you find a Linux Distribution with which you are
satisfied, in that it run from a Live Iso file aand
detects all your hardware.

If you did not think it was embedded I would
say to download Knoppix ISO file and use its Clam AntiVirus
software.

Good luck.

bliss- Dell Precision 7730- PCLOS 2024.06- Linux 6.6.47-Plasma 5.27.11

--
b l i s s - S F 4 e v e r at D S L E x t r e m e dot com

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Shadow
Newsgroups: comp.os.linux.misc
Organization: A noiseless patient Shadow
Date: Wed, 28 Aug 2024 00:11 UTC
References: 1 2 3
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: Sh@dow.br (Shadow)
Newsgroups: comp.os.linux.misc
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: Tue, 27 Aug 2024 21:11:44 -0300
Organization: A noiseless patient Shadow
Lines: 34
Message-ID: <drpscj5rd45maocb49rtnnv2s5kn40426c@4ax.com>
References: <vaj4ca$157e$1@gallifrey.nk.ca> <40qrcjll8ifi3souqnukq23j939u869lvq@4ax.com> <valid9$kp$3@gallifrey.nk.ca>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 28 Aug 2024 02:11:49 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="46198b810425611cf07c9f67db0e2bab";
logging-data="3348724"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19RBQZ5uuElG5Tn1s4ghex3uD0U8BgOa4M="
Cancel-Lock: sha1:oQWTDJkpkinJxKcxuTfo2JWN4is=
X-Newsreader: Forte Agent 3.3/32.846
View all headers

On Tue, 27 Aug 2024 22:02:17 -0000 (UTC), doctor@doctor.nl2k.ab.ca
(The Doctor) wrote:

>In article <40qrcjll8ifi3souqnukq23j939u869lvq@4ax.com>,
>Shadow <Sh@dow.br> wrote:
>>On Mon, 26 Aug 2024 23:50:34 -0000 (UTC), doctor@doctor.nl2k.ab.ca
>>(The Doctor) wrote:
>>
>>>I suspect a Windows OS with an Intel MB
>>>have malware embedded in them.
>>>
>>>Are there are Linux ISOs I can use to test my theory?
>>
>> Kaspersky Rescue Disk. Unplug your network card before booting
>>with it, it connects to "search for updates".
>> Scans Windows and Linux.
>> I don't think it does hardware-embedded malware though.
>> []'s
>>
>> PS a full scan will take all night....
>>
>
>Kaspersky banned in NA!

Only if you are the government.
Can't stop civilians from downloading and using it.
It's a free country, right?

Maybe not.... all download links are being blocked. LOL.
[]'s
--
Don't be evil - Google 2004
We have a new policy - Google 2012
Google Fuchsia - 2021

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Computer Nerd Kev
Newsgroups: comp.os.linux.misc
Organization: Ausics - https://newsgroups.ausics.net
Date: Wed, 28 Aug 2024 22:49 UTC
References: 1 2
Message-ID: <66cfa97c@news.ausics.net>
From: not@telling.you.invalid (Computer Nerd Kev)
Subject: Re: ISO of a linux animalware / antivirus scanner
Newsgroups: comp.os.linux.misc
References: <vaj4ca$157e$1@gallifrey.nk.ca> <valkkl$352e9$1@dont-email.me>
User-Agent: tin/2.0.1-20111224 ("Achenvoir") (UNIX) (Linux/2.4.31 (i586))
NNTP-Posting-Host: news.ausics.net
Date: 29 Aug 2024 08:49:32 +1000
Organization: Ausics - https://newsgroups.ausics.net
Lines: 35
X-Complaints: abuse@ausics.net
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!news.bbs.nz!news.ausics.net!not-for-mail
View all headers

Bobbie Sellers <blissInSanFrancisco@mouse-potato.com> wrote:
> Well it is known that the Intels have a Minix fork
> embedded to send data back to the factory. I think that
> the data with which they are concerned relates to CPU
> functions not with your Personal data.

Yes, the general functions of these processors in modern CPUs are
described in detail here:

https://www.devever.net/~hl/backstage-cast

The privacy issue is that they can have the capacity to access data
in RAM, then since their firmware is closed-source one can't be
sure it doesn't collect personal data and send it back somehow. Or
it's been shown they can be hacked to do that and then snoop out
passwords etc. from RAM, which perhaps is what the OP's concerned
about.

> Only thing I can suggest to excape these matters
> is to go to an AMD Ryzen motherboard.

No, AMD Ryzen has it's own equivalent commonly called PSP, and it's
had documented security vulnerabilities too:

https://en.wikipedia.org/wiki/AMD_Secure_Technology#Reported_vulnerabilities

Your only real escape would be to run a CPU that's so old or
low-spec that you wouldn't have the performance to run a modern
web browser with Javascript support. Of course those web browsers
are where people generally enter information worth snooping on now,
so there's no real escape anymore.

--
__ __
#_ < |\| |< _#

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Carlos E.R.
Newsgroups: comp.os.linux.misc
Date: Sat, 31 Aug 2024 01:45 UTC
References: 1 2 3
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: comp.os.linux.misc
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: Sat, 31 Aug 2024 03:45:08 +0200
Lines: 45
Message-ID: <469aqkxivn.ln2@Telcontar.valinor>
References: <vaj4ca$157e$1@gallifrey.nk.ca> <valkkl$352e9$1@dont-email.me>
<66cfa97c@news.ausics.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net IiDwoZcWlcLChYia/BvBtQrDcXjAcfpxem5uS+NOwF7ygqSklt
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:Oka2ZLSKUqZ2HCaVoU/m91fNcRA= sha256:0EjrNA1OpS1fPHIQTCiGRLYyByP7mWEHZ+ehrRS144o=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <66cfa97c@news.ausics.net>
View all headers

On 2024-08-29 00:49, Computer Nerd Kev wrote:
> Bobbie Sellers <blissInSanFrancisco@mouse-potato.com> wrote:
>> Well it is known that the Intels have a Minix fork
>> embedded to send data back to the factory. I think that
>> the data with which they are concerned relates to CPU
>> functions not with your Personal data.
>
> Yes, the general functions of these processors in modern CPUs are
> described in detail here:
>
> https://www.devever.net/~hl/backstage-cast
>
> The privacy issue is that they can have the capacity to access data
> in RAM, then since their firmware is closed-source one can't be
> sure it doesn't collect personal data and send it back somehow. Or
> it's been shown they can be hacked to do that and then snoop out
> passwords etc. from RAM, which perhaps is what the OP's concerned
> about.
>
>> Only thing I can suggest to excape these matters
>> is to go to an AMD Ryzen motherboard.
>
> No, AMD Ryzen has it's own equivalent commonly called PSP, and it's
> had documented security vulnerabilities too:
>
> https://en.wikipedia.org/wiki/AMD_Secure_Technology#Reported_vulnerabilities
>
> Your only real escape would be to run a CPU that's so old or
> low-spec that you wouldn't have the performance to run a modern
> web browser with Javascript support. Of course those web browsers
> are where people generally enter information worth snooping on now,
> so there's no real escape anymore.
>

You simply need a non enterprise CPU that doesn't have the mini minix.
That feature costs money. And has to be enabled in the BIOS. The BIOS
may not have support for it, and then the feature is dead, useless.

Its purpose is not to send data back to factory. Its purpose is to be
used by the IT department for remote maintenance. And using this feature
is expensive.

--
Cheers, Carlos.

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Computer Nerd Kev
Newsgroups: comp.os.linux.misc
Organization: Ausics - https://newsgroups.ausics.net
Date: Sat, 31 Aug 2024 22:15 UTC
References: 1 2 3 4
Message-ID: <66d39612@news.ausics.net>
From: not@telling.you.invalid (Computer Nerd Kev)
Subject: Re: ISO of a linux animalware / antivirus scanner
Newsgroups: comp.os.linux.misc
References: <vaj4ca$157e$1@gallifrey.nk.ca> <valkkl$352e9$1@dont-email.me> <66cfa97c@news.ausics.net> <469aqkxivn.ln2@Telcontar.valinor>
User-Agent: tin/2.0.1-20111224 ("Achenvoir") (UNIX) (Linux/2.4.31 (i586))
NNTP-Posting-Host: news.ausics.net
Date: 1 Sep 2024 08:15:47 +1000
Organization: Ausics - https://newsgroups.ausics.net
Lines: 51
X-Complaints: abuse@ausics.net
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!news.bbs.nz!news.ausics.net!not-for-mail
View all headers

Carlos E.R. <robin_listas@es.invalid> wrote:
> On 2024-08-29 00:49, Computer Nerd Kev wrote:
>> No, AMD Ryzen has it's own equivalent commonly called PSP, and it's
>> had documented security vulnerabilities too:
>>
>> https://en.wikipedia.org/wiki/AMD_Secure_Technology#Reported_vulnerabilities
>>
>> Your only real escape would be to run a CPU that's so old or
>> low-spec that you wouldn't have the performance to run a modern
>> web browser with Javascript support. Of course those web browsers
>> are where people generally enter information worth snooping on now,
>> so there's no real escape anymore.
>>
>
> You simply need a non enterprise CPU that doesn't have the mini minix.
> That feature costs money. And has to be enabled in the BIOS. The BIOS
> may not have support for it, and then the feature is dead, useless.

It seems that you're talking about a specific documented exploit like
this one:

"PLATINUM
In June 2017, the PLATINUM cybercrime group became notable for
exploiting the serial over LAN (SOL) capabilities of AMT to perform
data exfiltration of stolen documents. SOL is disabled by default
and must be enabled to exploit this vulnerability."
https://en.wikipedia.org/wiki/Intel_Management_Engine#PLATINUM

But a look around that page shows that there have been many others
without the limitation of requiring enterprise-only features of
the IME to be enabled. And those are only the vulnerabilites that
have been made public.

> Its purpose is not to send data back to factory. Its purpose is to be
> used by the IT department for remote maintenance. And using this feature
> is expensive.

It's also for booting, thermal management, and other things besides.
Since it's closed-source and the binary is obfuscated, one can't be
sure there aren't secret backdoors put inside on the request of the
US government either.

But with the existance of rootkits, the intended purpose is
actually irrelevant because a malicious firmware could be installed
that does something completely different. I think that's part of
what the OP was concerned about, though I don't know if any
software can check whether it's happened.

--
__ __
#_ < |\| |< _#

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Carlos E.R.
Newsgroups: comp.os.linux.misc
Date: Sun, 1 Sep 2024 01:53 UTC
References: 1 2 3 4 5
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: comp.os.linux.misc
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: Sun, 1 Sep 2024 03:53:55 +0200
Lines: 35
Message-ID: <j2ucqkxs9k.ln2@Telcontar.valinor>
References: <vaj4ca$157e$1@gallifrey.nk.ca> <valkkl$352e9$1@dont-email.me>
<66cfa97c@news.ausics.net> <469aqkxivn.ln2@Telcontar.valinor>
<66d39612@news.ausics.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net r1veXkUMQ20u9cu6D/RRGA+o52udzZphQGGvPqDDf4l7tPHcF/
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:nxvwK5vja8XQWITvLIfxEVCqz0E= sha256:FBnGtdKPl6LKl78yHtQGBLdXXnUsxh62s8ApkyOMtws=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <66d39612@news.ausics.net>
View all headers

On 2024-09-01 00:15, Computer Nerd Kev wrote:
> Carlos E.R. <robin_listas@es.invalid> wrote:
>> On 2024-08-29 00:49, Computer Nerd Kev wrote:
>>> No, AMD Ryzen has it's own equivalent commonly called PSP, and it's
>>> had documented security vulnerabilities too:
>>>
>>> https://en.wikipedia.org/wiki/AMD_Secure_Technology#Reported_vulnerabilities
>>>
>>> Your only real escape would be to run a CPU that's so old or
>>> low-spec that you wouldn't have the performance to run a modern
>>> web browser with Javascript support. Of course those web browsers
>>> are where people generally enter information worth snooping on now,
>>> so there's no real escape anymore.
>>>
>>
>> You simply need a non enterprise CPU that doesn't have the mini minix.
>> That feature costs money. And has to be enabled in the BIOS. The BIOS
>> may not have support for it, and then the feature is dead, useless.
>
> It seems that you're talking about a specific documented exploit like
> this one:

No, I am not talking about a exploit, but a computer department feature
that you can buy or not.

You simply have to buy processors or motherboards without the feature.

It costs money to have this feature. Just don't buy it.

If your computer is a work computer that has been provided by the
company, it is their choice and their problem, not yours.

--
Cheers, Carlos.

Subject: Re: ISO of a linux animalware / antivirus scanner
From: MarioCCCP
Newsgroups: comp.os.linux.misc
Organization: A noiseless patient Spider
Date: Sun, 1 Sep 2024 02:02 UTC
References: 1 2
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: NoliMihiFrangereMentulam@libero.it (MarioCCCP)
Newsgroups: comp.os.linux.misc
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: Sun, 1 Sep 2024 04:02:41 +0200
Organization: A noiseless patient Spider
Lines: 49
Message-ID: <vb0i02$17qin$1@dont-email.me>
References: <vaj4ca$157e$1@gallifrey.nk.ca> <tal0qkx3nv.ln2@Telcontar.valinor>
Reply-To: MarioCCCP@CCCP.MIR
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Sun, 01 Sep 2024 04:02:42 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="9c7beb24d6523d11bf9c6a2ec1e43151";
logging-data="1305175"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18XQD/jbnnmYH9YFlXSgfFd"
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:J5iQEfRR+AOHcOl4A39+QPUTek4=
In-Reply-To: <tal0qkx3nv.ln2@Telcontar.valinor>
Content-Language: en-GB, it-IT
View all headers

On 27/08/24 12:11, Carlos E.R. wrote:
> On 2024-08-27 01:50, The Doctor wrote:
>> I suspect a Windows OS with an Intel MB
>> have malware embedded in them.
>>
>> Are there are Linux ISOs I can use to test my theory?
>
> You need to ask in a Windows group.
>
> If you want to use clamav, you can do that with any linux
> distro of your liking in which you install clamav.
>

I have it (and possibly, I have forgot !, running it), but I
ignore how valuable this antivirus is, since it is since
2017 that I have give up following benchmarks of AVs,
detections ratings and so.
So I ask : how good is it this clamav ?

I have a win11 install in vwmare (but I dont' even use it to
web browse, just pilot the scanner whose linux version is
buggy) but I just use its internal "defender".

This clamav is effective enough (and frequently enough
updated) for, i.g., cleanup suspect USB keys before exposing
them to the W11 guest ? I am not aware if this sharing is
sort of a direct tunnelling to the disk or some actions of
the hypervisor happens in a transparent layer (possibly
relevant for rootkits and so).

how it works inside ? Based on a database signatures or
"heuristic" / intercepting suspect behaviours ?
Is it equally / less / more safe to use an AV in a
virtualized environmente ? I'd say : no (since this one is
at the host level and act before the USB key is unmounted
from host and connected in the guest, but just mere
suppositions).

And windows defender inside a VM is known to be effective as
in a real machine ?

my knowledge of AV is really outdated now !

--
1) Resistere, resistere, resistere.
2) Se tutti pagano le tasse, le tasse le pagano tutti
MarioCPPP

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Computer Nerd Kev
Newsgroups: comp.os.linux.misc
Organization: Ausics - https://newsgroups.ausics.net
Date: Sun, 1 Sep 2024 04:56 UTC
References: 1 2 3 4 5 6
Message-ID: <66d3f402@news.ausics.net>
From: not@telling.you.invalid (Computer Nerd Kev)
Subject: Re: ISO of a linux animalware / antivirus scanner
Newsgroups: comp.os.linux.misc
References: <vaj4ca$157e$1@gallifrey.nk.ca> <valkkl$352e9$1@dont-email.me> <66cfa97c@news.ausics.net> <469aqkxivn.ln2@Telcontar.valinor> <66d39612@news.ausics.net> <j2ucqkxs9k.ln2@Telcontar.valinor>
User-Agent: tin/2.0.1-20111224 ("Achenvoir") (UNIX) (Linux/2.4.31 (i686))
NNTP-Posting-Host: news.ausics.net
Date: 1 Sep 2024 14:56:35 +1000
Organization: Ausics - https://newsgroups.ausics.net
Lines: 39
X-Complaints: abuse@ausics.net
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!news.bbs.nz!news.ausics.net!not-for-mail
View all headers

Carlos E.R. <robin_listas@es.invalid> wrote:
> On 2024-09-01 00:15, Computer Nerd Kev wrote:
>> Carlos E.R. <robin_listas@es.invalid> wrote:
>>> You simply need a non enterprise CPU that doesn't have the mini minix.
>>> That feature costs money. And has to be enabled in the BIOS. The BIOS
>>> may not have support for it, and then the feature is dead, useless.
>>
>> It seems that you're talking about a specific documented exploit like
>> this one:
>
> No, I am not talking about a exploit, but a computer department feature
> that you can buy or not.

The thing that runs the Minix fork is the Intel Management Engine.
It's part of the boot process so never completely optional. It can
load optional modules listed here though:
https://en.wikipedia.org/wiki/Intel_Management_Engine#Modules

Some security vulerabilities are in the optional modules, but
others still exist even if they're disabled, and either route has
allowed code to be installed which snoops on the user.

See this:
"Difference from Intel AMT
The Management Engine is often confused with Intel AMT (Intel
Active Management Technology). AMT runs on the ME, but is only
available on processors with vPro. AMT gives device owners
remote administration of their computer,[5] such as powering
it on or off, and reinstalling the operating system.

However, the ME itself has been built into all Intel chipsets
since 2008, not only those with AMT. While AMT can be
unprovisioned by the owner, there is no official, documented
way to disable the ME."
https://en.wikipedia.org/wiki/Intel_Management_Engine#Difference_from_Intel_AMT

--
__ __
#_ < |\| |< _#

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Carlos E.R.
Newsgroups: comp.os.linux.misc
Date: Sun, 1 Sep 2024 12:23 UTC
References: 1 2 3 4 5 6 7
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: comp.os.linux.misc
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: Sun, 1 Sep 2024 14:23:19 +0200
Lines: 23
Message-ID: <nu2eqkx49p.ln2@Telcontar.valinor>
References: <vaj4ca$157e$1@gallifrey.nk.ca> <valkkl$352e9$1@dont-email.me>
<66cfa97c@news.ausics.net> <469aqkxivn.ln2@Telcontar.valinor>
<66d39612@news.ausics.net> <j2ucqkxs9k.ln2@Telcontar.valinor>
<66d3f402@news.ausics.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net zu/CRMAZdSslirmjT2z6hA5xDe3QBXW7k0uaSn0ECdxW7Vvovl
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:gWSb0syIvO9EEkgT1SPAoxgvQgw= sha256:Od82fimbaiFMew0djUdxAJjSxUDeSsuO6kLT2icsVPY=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <66d3f402@news.ausics.net>
View all headers

On 2024-09-01 06:56, Computer Nerd Kev wrote:
> Carlos E.R. <robin_listas@es.invalid> wrote:
>> On 2024-09-01 00:15, Computer Nerd Kev wrote:
>>> Carlos E.R. <robin_listas@es.invalid> wrote:
>>>> You simply need a non enterprise CPU that doesn't have the mini minix.
>>>> That feature costs money. And has to be enabled in the BIOS. The BIOS
>>>> may not have support for it, and then the feature is dead, useless.
>>>
>>> It seems that you're talking about a specific documented exploit like
>>> this one:
>>
>> No, I am not talking about a exploit, but a computer department feature
>> that you can buy or not.
>
> The thing that runs the Minix fork is the Intel Management Engine.
> It's part of the boot process so never completely optional.

It is optional to choose a processor that doesn't have it, or a
motherboard that doesn't support it.

--
Cheers, Carlos.

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Computer Nerd Kev
Newsgroups: comp.os.linux.misc
Organization: Ausics - https://newsgroups.ausics.net
Date: Sun, 1 Sep 2024 13:10 UTC
References: 1 2 3 4 5 6 7 8
Message-ID: <66d467dd@news.ausics.net>
From: not@telling.you.invalid (Computer Nerd Kev)
Subject: Re: ISO of a linux animalware / antivirus scanner
Newsgroups: comp.os.linux.misc
References: <vaj4ca$157e$1@gallifrey.nk.ca> <valkkl$352e9$1@dont-email.me> <66cfa97c@news.ausics.net> <469aqkxivn.ln2@Telcontar.valinor> <66d39612@news.ausics.net> <j2ucqkxs9k.ln2@Telcontar.valinor> <66d3f402@news.ausics.net> <nu2eqkx49p.ln2@Telcontar.valinor>
User-Agent: tin/2.0.1-20111224 ("Achenvoir") (UNIX) (Linux/2.4.31 (i686))
NNTP-Posting-Host: news.ausics.net
Date: 1 Sep 2024 23:10:54 +1000
Organization: Ausics - https://newsgroups.ausics.net
Lines: 27
X-Complaints: abuse@ausics.net
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!news.bbs.nz!news.ausics.net!not-for-mail
View all headers

Carlos E.R. <robin_listas@es.invalid> wrote:
> On 2024-09-01 06:56, Computer Nerd Kev wrote:
>> Carlos E.R. <robin_listas@es.invalid> wrote:
>>> No, I am not talking about a exploit, but a computer department feature
>>> that you can buy or not.
>>
>> The thing that runs the Minix fork is the Intel Management Engine.
>> It's part of the boot process so never completely optional.
>
> It is optional to choose a processor that doesn't have it, or a
> motherboard that doesn't support it.

Certainly. I'm posting this from a laptop with a Pentium III CPU
and it doesn't have an Intel Management Engine. However I gave up
running Firefox on this years ago. Instead for that I use a PC with
a faster newer processor and that does have an Intel Management
Engine, and there's no updated BIOS available to fix some of the
known IME vulerabilities found since it was made either.

But the Talos workstations might be one solution if money and x86
compatability isn't a concern, since they use the open IBM POWER9
processor and firmware. So it is a choice, but hardly a trivial
one.

--
__ __
#_ < |\| |< _#

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Computer Nerd Kev
Newsgroups: comp.os.linux.misc
Organization: Ausics - https://newsgroups.ausics.net
Date: Sun, 1 Sep 2024 22:22 UTC
References: 1 2 3 4 5 6 7 8 9 10
Message-ID: <66d4e929@news.ausics.net>
From: not@telling.you.invalid (Computer Nerd Kev)
Subject: Re: ISO of a linux animalware / antivirus scanner
Newsgroups: comp.os.linux.misc
References: <vaj4ca$157e$1@gallifrey.nk.ca> <valkkl$352e9$1@dont-email.me> <66cfa97c@news.ausics.net> <469aqkxivn.ln2@Telcontar.valinor> <66d39612@news.ausics.net> <j2ucqkxs9k.ln2@Telcontar.valinor> <66d3f402@news.ausics.net> <nu2eqkx49p.ln2@Telcontar.valinor> <66d467dd@news.ausics.net> <g5oeqkx36r.ln2@Telcontar.valinor>
User-Agent: tin/2.0.1-20111224 ("Achenvoir") (UNIX) (Linux/2.4.31 (i586))
NNTP-Posting-Host: news.ausics.net
Date: 2 Sep 2024 08:22:34 +1000
Organization: Ausics - https://newsgroups.ausics.net
Lines: 38
X-Complaints: abuse@ausics.net
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!news.bbs.nz!news.ausics.net!not-for-mail
View all headers

Carlos E.R. <robin_listas@es.invalid> wrote:
> On 2024-09-01 15:10, Computer Nerd Kev wrote:
>> Carlos E.R. <robin_listas@es.invalid> wrote:
>>> On 2024-09-01 06:56, Computer Nerd Kev wrote:
>>>> Carlos E.R. <robin_listas@es.invalid> wrote:
>>>>> No, I am not talking about a exploit, but a computer department feature
>>>>> that you can buy or not.
>>>>
>>>> The thing that runs the Minix fork is the Intel Management Engine.
>>>> It's part of the boot process so never completely optional.
>>>
>>> It is optional to choose a processor that doesn't have it, or a
>>> motherboard that doesn't support it.
>>
>> Certainly. I'm posting this from a laptop with a Pentium III CPU
>> and it doesn't have an Intel Management Engine. However I gave up
>> running Firefox on this years ago. Instead for that I use a PC with
>> a faster newer processor and that does have an Intel Management
>> Engine, and there's no updated BIOS available to fix some of the
>> known IME vulerabilities found since it was made either.
>
> Does the motherboard support the feature?

Booting? Um, yes. That's all it needs to support in order to be
vulnerable to some of the documented attacks. Provided malicious
software is running on the CPU, or has run before and installed
something on the IME like the OP's question was about.

> It will not work without MB support. And they need access to your
> LAN.

Only if 'they' are similarly laser-focused on whatever specific IME
hack you've heard about and won't hear of any other ones. I give
up.

--
__ __
#_ < |\| |< _#

Subject: Re: ISO of a linux animalware / antivirus scanner
From: Carlos E.R.
Newsgroups: comp.os.linux.misc
Date: Tue, 3 Sep 2024 11:25 UTC
References: 1 2 3
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: comp.os.linux.misc
Subject: Re: ISO of a linux animalware / antivirus scanner
Date: Tue, 3 Sep 2024 13:25:11 +0200
Lines: 26
Message-ID: <o98jqkxj2e.ln2@Telcontar.valinor>
References: <vaj4ca$157e$1@gallifrey.nk.ca> <tal0qkx3nv.ln2@Telcontar.valinor>
<vb0i02$17qin$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net bnWJTCPLKj51UUScZKqnzgyoaRmfJ+UEXzNLZQRboPxXlkom7q
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:QkfTPbEU45AZU0pHT1heZLWE+Uk= sha256:5qP5NNWITmqMfZFQDSROFcsfytONH1xK3tVGDdvzpwg=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <vb0i02$17qin$1@dont-email.me>
View all headers

On 2024-09-01 04:02, MarioCCCP wrote:
> On 27/08/24 12:11, Carlos E.R. wrote:
>> On 2024-08-27 01:50, The Doctor wrote:
>>> I suspect a Windows OS with an Intel MB
>>> have malware embedded in them.
>>>
>>> Are there are Linux ISOs I can use to test my theory?
>>
>> You need to ask in a Windows group.
>>
>> If you want to use clamav, you can do that with any linux distro of
>> your liking in which you install clamav.
>>
>
> I have it (and possibly, I have forgot !, running it), but I ignore how
> valuable this antivirus is, since it is since 2017 that I have give up
> following benchmarks of AVs, detections ratings and so.
> So I ask : how good is it this clamav ?

Better read here:

https://en.wikipedia.org/wiki/ClamAV

--
Cheers, Carlos.

1

rocksolid light 0.9.8
clearnet tor