[comp.virus] Gatekeeper and Gatekeeper Aid

YOOPER@MSU.BITNET (Carl_A.Fassbender) (12/20/89)

In Michigan State University's public laboratory, we have run into
many viruses including the WDEF virus.  We decided to put Gatekeeper
and Gatekeeper aid on our system disks.  To protect these files from
being erased, they were made invisible using MacTools.  Now in the
control panel, the Gatekeeper icon does not show up.  Question: Does
this mean that Gatekeeper is not active?  What about Gatekeeper Aid?

dmg%retina.mitre.org@IBM1.CC.Lehigh.Edu (David Gursky) (12/21/89)

In VIRUS-L Digest V2 #265, "Carl_A.Fassbender" <YOOPER@MSU.BITNET> was
asking why the Gatekeeper & Gatekeeper Aid icon did not show up after
he made the files invisible.

The Mac OS does not load INITs that are part of files with the
Invisible bit set.  [Editorial comment: Hey Apple!  Why?????]  If you
want to have Gatekeeper active, you must have the file visible on the
desktop.

dplatt@ames.arc.nasa.gov (Dave Platt) (12/21/89)

YOOPER@MSU.BITNET (Carl_A.Fassbender) writes:
> In Michigan State University's public laboratory, we have run into
> many viruses including the WDEF virus.  We decided to put Gatekeeper
> and Gatekeeper aid on our system disks.  To protect these files from
> being erased, they were made invisible using MacTools.  Now in the
> control panel, the Gatekeeper icon does not show up.  Question: Does
> this mean that Gatekeeper is not active?  What about Gatekeeper Aid?

Apple's System 6.0 and later will not execute INIT resources which reside
in invisible files.  This was done to prevent viruses (e.g. SCORES)
from dropping invisible INIT files into the System folder.  By making
the Gatekeeper and Gatekeeper Aid files invisible, you've rendered them
inoperative.

You can, if you wish, make the whole System folder invisible;  this won't
prevent the system from booting and won't prevent Gatekeeper etc. from
installing themselves.  For lab machines, this is often a reasonable
approach.
- --
Dave Platt                                             VOICE: (415) 493-8805
  UUCP: ...!{ames,apple,uunet}!coherent!dplatt   DOMAIN: dplatt@coherent.com
  INTERNET:       coherent!dplatt@ames.arpa,  ...@uunet.uu.net
  USNAIL: Coherent Thought Inc.  3350 West Bayshore #205  Palo Alto CA 94303

denbeste@cis.ohio-state.edu (William C. DenBesten) (12/22/89)

dmg@retina.mitre.org (David Gursky) writes:
> In VIRUS-L Digest V2 #265, "Carl_A.Fassbender" <YOOPER@MSU.BITNET> was
> asking why the Gatekeeper & Gatekeeper Aid icon did not show up after
> he made the files invisible.
>
> The Mac OS does not load INITs that are part of files with the
> Invisible bit set.  [Editorial comment: Hey Apple!  Why?????]  If you
> want to have Gatekeeper active, you must have the file visible on the
> desktop.

Older versions of the system did not do this.  Apple started this
practice shortly after scores hit the mac.  The reasoning is that
there were if all inits had to be visible, then viruses would have a
harder time hiding from the user.  I believe this to be a good
decision.

On lab disks, I set the entire system folder invisible, but leave the
files visible.

N.B. this is my interpretation and recollection of timeframes.

- --
William C. DenBesten   is   denbeste@bgsu.edu  or   denbesten@bgsuopie.bitnet