Assume that there will be JPEG exploits for Mozilla 1.7.2 . Thus, by running the browser and inavertently looking at an infected site, you will get rooted, and the remote zombie the exploit talks to can read all necessary configuration information. exec( uname -a ) > mail > zombie , for example. The zombie can then select the appropriate rootkit for that version of Linux, and load quite a lot of executable scripts into whatever is writeable - ramdisk, mountable hard disk, operating kernel, whatever. Your hard disk can be scribbled on, your machine can be zombied, passwords and credit cards sent out, all sorts of mischief can be done.

Yes, you can return to status quo with a flick of the power switch - but how does the typical windoze user know when to do that? And it is not quite status quo; your information is on the zombie, and the zombie has put information on your hard disk. If it ever gets control again, it has a running start.

All this can be automated, and there is no protection beyond the read-only nature of the CD, since there is no root password. After the rooting, the CD can be ignored until the next reboot.

The typical Knoppix user is a Linux newbie, straight from windoze. I am giving them a Knoppix CD so they have an alternative to windoze, and most of them will actually use it a long time from now, when their windoze has become unusable, probably by enemy action. I don't want to compound their problems with something that can allow as much damage as windoze itself.