Cc: <david@...>, Eric Paris <eparis@...>, Theodore Tso <tytso@...>, <davecb@...>, <linux-security-module@...>, Adrian Bunk <bunk@...>, Mihai Don??u <mdontu@...>, <linux-kernel@...>, <malware-list@...>, Arjan van de Ven <arjan@...>
Don't mix exploits with viruses -- they are different.
Exploit is where application does something very unexpected due to a
bug.
Virus is where machine works correctly, but user does something
stupid.
For exploits, randomization + patching + compartments seem like a
solution. We should be working on "how to confine openoffice.org so
that it can't do much damage" instead of "how to detect .doc documents
that makes openoffice.org do something unexpected".
Pavel
--
(english) http://www.livejournal.com/~pavelmachek
(cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html
--