ANTenna Blog -- Hardware & Software
Could Linux Fall Prey To Windows Malware?
Posted by Matthew McKenzie Wednesday, Nov 18, 2009, 05:20 PM ET
Can software that allows you to run Windows software on a Linux system also expose your system to Windows malware? In practice, the answer appears to be no.
And in theory? Let's face it: When common sense goes missing, anything is possible.
For about a month now, I have been following the response to one user's attempt to answer a simple question: Can a Windows virus actually damage a Linux system?
This experiment involved an application called Wine that makes it possible to run many (but not all) Windows applications on a Linux desktop system. Wine is free and open-source software; a company called CodeWeavers also sells a commercial open-source version called CrossOver.
I won't delve into the technical details here, but Wine is a very different product than virtualization tools like VirtualBox or VMware. I personally prefer to use virtualization rather than Wine when I need to run a Windows app on a Linux system, but Wine certainly has its uses (and its supporters).
In this case, disregarding all of the warnings and installing a shifty-looking piece of software via Wine, did, indeed, result in all sorts of strange and disagreeable consequences. Unlike a real Windows system, however, once the malware got loose, it couldn't wander very far.
Here is how another reader described the results on a subsequent Slashdot post:
"Wine has advanced enough to make Linux not immune to Windows viruses. However, just like many Wine applications, it takes a bit of effort to get the program off the ground. Also, just like some Windows programs running via Wine, not all features may work — in this case, the crippling of the system, immunity to the task manager, identity theft, etc."
Some of the most interesting perspectives on this story, however, surfaced in comments posted both on he original site and in response to the Slashdot story. Reading through these makes two things very clear about the security risks associated with running Wine-enabled Windows apps on a Linux system:
- There are, in theory, situations in which Windows malware running on Wine could cause serious damage to a Linux system.
- All of these scenarios are extremely unlikely unless a Linux user displays a stunning lack of common sense, such as running Wine under a root account.
In fact, according to a 2008 CodeWeavers white paper that addresses exactly this topic, nobody has actually seen this happen in a real-world setting:
Not surprisingly, a question we sometimes hear is whether or not Wine exposes users to the same level of risk. The short answer is: in theory, perhaps; in practice, no. That is, a virus could theoretically infect a Unix-based system (either Mac OS X or Linux) running a Windows program, but it would require an extremely unlikely scenario for that to happen. To our knowledge, it has never happened.
Risk assessment is always a matter of context: When one compares the risk of a piece of Windows malware escaping Wine and damaging a Linux system versus the risk that a typical Windows system will fall prey to a malware attack, it is only possible to draw one conclusion.
Still, if you're a Wine user and want to cover all of your bases, CrossOver adds some additional security features, along with the technical support to ensure that you use them effectively.
If Linux ever gains ground as a mass-market desktop OS, we might have to revisit this question; clueless users who will click on anything can always find ways to get themselves into trouble. For now, however, most Linux users can definitely find more important things to worry about than whether running Wine will expose them to unnecessary security risks.
Hardware & Software
Company Size: 1-49
| Open Source
| Security
| Windows
This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.
Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.
Important Note: This comment area is NOT intended for commercial messages or solicitations of business.
- Phone Systems Guide - What kind of phone system is right for your business
- Web Design Guide - What to look for in a Web designer
- Merchant Services Guide - Credit card processing and more
- Online Marketing Guide - Leverage the Net to market your business
- Alternative Financing Guide - How to find the cash your business needs
- View all guides
Explore ANTenna Blog
Most Recent Posts
- Nasuni Offers Cloud-Based Primary Storage
- Automobiles: The Next Network Security Challenge?
- Cachengo Rolls Out Appliance + Cloud Storage Option
- For SMBs, PayPal Could Mean Risky Business
- Internet Access Options Grow
ANTenna Blog Topics
- Apple
- Backup
- bMighty
- Business & E-Business
- Business Continuity
- Cloud Computing
- Company Size: 1,100-1,500
- Company Size: 250-999
- Company Size: 50-249
- Company Size: 1-49
- Disaster Recovery
- Economics
- Education
- Entrepreneurs
- Finance/Accounting
- Finance/Banking/Insurance
- Government
- Green Business
- Hardware & Software
- Healthcare
- Hospitality
- How-To
- HR
- Imaging How-To
- International
- Internet/Web
- iPhone
- IT
- Linux
- Management
- Manufacturing/Mining
- Messaging
- Mobile
- Networking & Communications
- Non-Profit
- Open Source
- Operations
- Piracy
- Printers/Printing
- Professional/Creative Services
- Retail
- Unified Communications
- Sales/Marketing
- Start-Ups
- Security
- Server How-To
- Services
- Social Networking
- Software-as-a-Service
- Storage
- Strategy/Analysis/Biz Dev
- Technology/Telecom
- The rANT
- Transportation
- Travel
- Windows
- Web 2.0
- Women in Business
ANTenna Bloggers
ANTenna Blog Roll
- ANTenna Archive
- Ars Technica
- Business Know-How
- ChannelWeb Hot Topics
- ChannelWeb The Chart
- Datamation
- Duct Tape Marketing
- The Entrepreneurial Mind
- Freakonomics
- GigaOmNet
- Guy Kawasaki
- Inc.com
- IT Organization Management
- IT Manager's Journal
- IT Toolbox
- LifeHacker
- Mashable
- MonkeyBrains
- Network Computing Blog
- Scott Berkun
- Search Engine Land
- Search Engine Watch
- SmallBizResource
- SmallBizTechnology.com
- SmallBusinessHub
- Small Business Trends
- TechCrunch
- Technologizer
- Tech Republic
- The Secret Diary of Steve Jobs
- USA Today Small Biz Connection
- Valleywag
- Walt Mossberg Feed - All Things Digital
- Web Worker Daily
- WorkHappy.net
- WSJ's Business Technology
InformationWeek SMB email newsletter!
Browse by Category
IW SMB Tech
Term Of Day:
Boost your tech
vocabulary!
InformationWeek SMB's
TechEncyclopedia
defines more than
20,000 IT terms.
FREE Technology Services Locator!
Search our database of 200,000 solution- provider locations by business activity, technology, vertical market, and customer size. Find a technology partner NOW.
go




