[10510] in Public-Access_Computer_Systems_Forum

home help back first fref pref prev next nref lref last post

Re: CD-ROMs in Libraries, and viruses

daemon@ATHENA.MIT.EDU (Public-Access Computer Systems For)
Fri Aug 9 20:05:58 1996

Date: Fri, 09 Aug 1996 15:17:09 -0500 (CDT)
From: Public-Access Computer Systems Forum <LIBPACS@UHUPVM1.UH.EDU>
To: Multiple recipients of list PACS-L <PACS-L@UHUPVM1.UH.EDU>
Reply-To: Public-Access Computer Systems Forum <PACS-L@UHUPVM1.UH.EDU>

2 Messages; 79 Lines

From: nomm1@office.nsh.library.ns.ca (Mclaughlin Michael)
One the following point....
: viruses are another consideration - as there is not currently a =
: virus-checking utility for CD-ROM drives.

Please consider the following....
  The bove statement was a bit confusing to me.  Our library scans all
CD's prior to installation with any of these four utilities:  F-Prot,
McCafee, Central Point AntiVirus, and Nortons AntiVirus.  I realize that
you can't disinfect a CD (due to the read only nature), but these
utilities will at least prevent you from infecting your micro from the
outset.  And since the CD can't be infected after the manufacturing
process, then I'd say you are safe.

  One thing to note, is that sometimes a manufacturer slips up and a
virus infected diskette is used as a master disc in the manufacturing of
the final product.  Never let them get away with this.  If you find it,
report it, and demand a virus free replacement or a full refund.  It is
very embarrassing for the software companies to goof up on virus
checking, but it has happened to us before.

The company shipped first the French version, and then two different
disks, both of them infected.  The killer was that they denied the
possiblity of a virus, claiming that all software is scanned (as it
should be) prior to production.  HOWEVER, after I forced the issue, it
was discovered that there virus checker (which was one of the above four)
was grossly out of date.  The moral of this story, REMEMBER THAT YOUR
VIRUS CHECKER IS ONLY AS GOOD AS IT'S LAST UPDATE.

I'll let other's address the other issues, but I just wanted to clarify
this part with you.


Michael J. McLaughlin
Halifax, NS
mclaugh@cast.navnet.net
*-----

From: "Gary M Klein (bear-at-heart)" <gklein@willamette.edu>
Subject: Viruses coming into a system, from a CDROM?
     Today's question about security & integrity of CDROM drives in a
public environment to me raises a similar question.

     HAS ANYONE HEARD OF any cases of "viruses" infecting a computer or
network, that were transmitted by a CDROM?

     We have all heard of some software product that had so many
glitches, that it was removed, since it may have caused a system to
crash, or because it was causing unexplained lock-ups.  But has there ever
been a bona fide virus infection, that came from a CDROM?

     Of course it is technically feasible for it to happen, but I
am curious if it has ever been documented.  I would be more concerned
about the firms that manufactured, assembled, distributed such a disk,
and the other clients who might be relying on the services of such a
CDROM production firm, rather than the odd chance that some nefarious
individual might want to insert a virus laden disk into my CDROM unit.

     Since it takes only one weak link to ruin something moving through
an assembly line, it is near impossible for a software user to know where
along the system did a virus get imbedded into the data.  And software
customers cannot readily ascertain what firm assembled what portion of
the final product.  Just like the outsourcing of jet engine maintenance
by major airlines, is usually to regional machine shops.  So that the jet
landing in Boston is typically serviced by a nearby specialist, even if that
airline's central repair facility is in Seattle.  So if we get a bad
disk, it is easier for us to blame the firm whose brand name stands
behind the software label, rather than the disk production firm (which
might be in Indiana or India).

     But if no one has actually documented a viral attack coming from a
CDROM, then this may be more of worrying over what might go wrong, as
opposed to the reasonable steps to assure security & integrity of your
network that are already in place.

GARY KLEIN "not your average business librarian"
gklein@willamette.edu     http://www.willamette.edu/~gklein

home help back first fref pref prev next nref lref last post