Jump to content

Hackers use porn to target Microsoft JPEG hole


Chris
 Share

Recommended Posts

Malicious hackers are seeding Internet news groups that traffic in pornography with JPEG images that take advantage of a recently disclosed security hole in Microsoft (Profile, Products, Articles) Corp.'s software, according to warnings from antivirus software companies and Internet security groups.

The reports are the first evidence of public attacks using the critical flaw, which Microsoft identified and patched on Sept. 14. Users who unwittingly download the poison images could have remote control software installed on their computers that gives remote attackers total control over the machine, experts warned.

The images were posted in a variety of Internet news groups where visitors post and share pornographic images or "binaries." The altered JPEG images were posted to groups such as "alt.binaries.erotica.breasts" on Monday by someone using the e-mail address "[email protected]," according to information published on the online security discussion group Bugtraq and on Easynews.com, a Web portal for Usenet, the global network of news servers.

More | Here

Link to comment
Share on other sites

As it states in the original article:-

Microsoft identified and patched on Sept. 14.

There should not, therefore, be any problem. It's only Windows users that don't keep their systems up to date and malware-fre that are at risk and people of that ilk will have plenty of other problems plaguing them anyway.

Link to comment
Share on other sites

That patch does not fix all applications, pops, that's why I'm so keen on a third party app. Online graphics is part of my business, like yours.

In addition to GDI+ being a standard component of Windows, different Windows applications frequently distribute their own versions of GDI+. Those versions might reside in folders used by the applications and be out of reach of the Windows patch, or could be installed after the Microsoft patch was applied, undoing that patch, Ullrich said.
Link to comment
Share on other sites

Hmm... I don't download JPEG images though - and certainly not porn from newsgroups :)

The graphics work I do with, and for, my son's business is normally in our own generated TIFF format or, for the stuff I'm mainly involved with in this line, in one of the video formats but, still created by us.

Thinking back on this, I remember reading several years ago in the Daily Telegraph computer pages about hiding malicious code inside a JPEG image so, this isn't as recent as it appears.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy