[comp.virus] viruses that reprogram ANSI keys

V2002A@TEMPLEVM.BITNET (08/02/89)

Hi, Just a quick note about viruses that reprogram keys to do
nasty things.  Several good terminal emulation packages have a
feature that allows you to 'lock out' any host generated key
redefinitions.  With Persofts Smarterm 220/240 series of programs
you can set the 'User Features Locked' and the program will ignore
all attempts to reprogram the keys with escape sequences.

Andy Wing     V2002A@TEMPLEVM.BITNET

[Ed. Not bad, but does MS-DOS's ANSI.SYS allow to lock out these
sequences?  I don't believe that it does.  If not, escape codes
imbedded in documentation, for example, can do a lot...]

hutto@attctc.Dallas.TX.US (Jon Hutto) (08/04/89)

They don't usually harm people using communications softwares as much as
it does BBS's, because the sequences are set for only certain directories,
and files.

IBM's ANSI.SYS doesn't let you filter them out eithere. There are some
ANSI substitutes that do. Such as NANSI, and PC-Mag had one in an issue
called ANSI.COM.


- --
- --
  Jon Hutto     PC-Tech BBS  (214)271-8899     2400 baud
USENET:    {ames, texbell, rutgers, portal}!attctc!hutto
INTERNET:  hutto@attctc.dallas.tx.us  or  attctc!hutto@ames.arc.nasa.gov

kelly@uts.amdahl.com (Kelly Goen) (08/05/89)

In article <0004.8908041206.AA09232@ge.sei.cmu.edu>, hutto@attctc.Dallas.TX.US
(Jon Hutto) writes:
> They don't usually harm people using communications softwares as much as
> it does BBS's, because the sequences are set for only certain directories,
> and files.
The trick of defining a command sequence to create sushi on a unix system would
 compromise root integrity... most comm software that is capable of either emul
atining programmable terminal sequences or ansi.sys and programs that implement
 those sequences are capable of accepting a command line into a buffer or windo
w with the view attribute set to non-visible and then retransmitting that comma
nd to the host unix system all under remote control.... I could hardly call tha
t harmless... furthermore most users including a surprising number of systems a
dministration types are unaware that their terminal or programmable termulator/
file transfer package can be tricked in this fashion..>
>   Jon Hutto     PC-Tech BBS  (214)271-8899     2400 baud
> USENET:    {ames, texbell, rutgers, portal}!attctc!hutto
> INTERNET:  hutto@attctc.dallas.tx.us  or  attctc!hutto@ames.arc.nasa.gov
Kelly Goen   Cybernetic Systems Specialists Inc.
Disclaimer: My Thoughts are my own. Neither Amdahl Corp nor Onsite Consulting m
ake any warranty and/or have anything to do with the information contained abov
e!


p.s. sushi --> SuperUser SHell Interactive the trick above is known as a boomer
ang also!!