Chris Posted September 28, 2004 Report Share Posted September 28, 2004 Malicious hackers are seeding Internet news groups that traffic in pornography with JPEG images that take advantage of a recently disclosed security hole in Microsoft (Profile, Products, Articles) Corp.'s software, according to warnings from antivirus software companies and Internet security groups.The reports are the first evidence of public attacks using the critical flaw, which Microsoft identified and patched on Sept. 14. Users who unwittingly download the poison images could have remote control software installed on their computers that gives remote attackers total control over the machine, experts warned. The images were posted in a variety of Internet news groups where visitors post and share pornographic images or "binaries." The altered JPEG images were posted to groups such as "alt.binaries.erotica.breasts" on Monday by someone using the e-mail address "[email protected]," according to information published on the online security discussion group Bugtraq and on Easynews.com, a Web portal for Usenet, the global network of news servers.More | Here Quote Link to comment Share on other sites More sharing options...
moon Posted September 29, 2004 Report Share Posted September 29, 2004 Apparently, simply viewing an infected JPEG can infect your machine ? Quote Link to comment Share on other sites More sharing options...
Chris Posted September 29, 2004 Author Report Share Posted September 29, 2004 seems so. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted September 29, 2004 Report Share Posted September 29, 2004 Remember, viewing an image means it's already in your computer, whether it be in RAM or a temp folder on the hard drive. Quote Link to comment Share on other sites More sharing options...
moon Posted September 30, 2004 Report Share Posted September 30, 2004 Well that's back to square one for me. So this exploit can infect RAM. Is there a third -party app. to protect against it ? Can AVG be configured ? Quote Link to comment Share on other sites More sharing options...
-pops- Posted September 30, 2004 Report Share Posted September 30, 2004 As it states in the original article:- Microsoft identified and patched on Sept. 14.There should not, therefore, be any problem. It's only Windows users that don't keep their systems up to date and malware-fre that are at risk and people of that ilk will have plenty of other problems plaguing them anyway. Quote Link to comment Share on other sites More sharing options...
andsome Posted September 30, 2004 Report Share Posted September 30, 2004 I downloaded that patch, and received a message to the effect that my computer was not at risk. Quote Link to comment Share on other sites More sharing options...
moon Posted September 30, 2004 Report Share Posted September 30, 2004 That patch does not fix all applications, pops, that's why I'm so keen on a third party app. Online graphics is part of my business, like yours.In addition to GDI+ being a standard component of Windows, different Windows applications frequently distribute their own versions of GDI+. Those versions might reside in folders used by the applications and be out of reach of the Windows patch, or could be installed after the Microsoft patch was applied, undoing that patch, Ullrich said. Quote Link to comment Share on other sites More sharing options...
-pops- Posted September 30, 2004 Report Share Posted September 30, 2004 Hmm... I don't download JPEG images though - and certainly not porn from newsgroups :) The graphics work I do with, and for, my son's business is normally in our own generated TIFF format or, for the stuff I'm mainly involved with in this line, in one of the video formats but, still created by us.Thinking back on this, I remember reading several years ago in the Daily Telegraph computer pages about hiding malicious code inside a JPEG image so, this isn't as recent as it appears. Quote Link to comment Share on other sites More sharing options...
moon Posted September 30, 2004 Report Share Posted September 30, 2004 Yes, well this one can activate in RAM, so it's not necessary to download to get infected. Just viewing a site can doom one's machine ( quote dave Pitstop) JPEg is the format of choice for uploaded graphics . Quote Link to comment Share on other sites More sharing options...
expertec Posted September 30, 2004 Report Share Posted September 30, 2004 But if you view an image on a web page it has been downloaded! Quote Link to comment Share on other sites More sharing options...
moon Posted September 30, 2004 Report Share Posted September 30, 2004 Yes, but it's only held in RAM. The previous exploits have required saving. Quote Link to comment Share on other sites More sharing options...
expertec Posted September 30, 2004 Report Share Posted September 30, 2004 No, it's in your temporary internet files. Quote Link to comment Share on other sites More sharing options...
moon Posted September 30, 2004 Report Share Posted September 30, 2004 Really ? All that's saved to my Temp. Internet Files folder are cookies. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted September 30, 2004 Report Share Posted September 30, 2004 Everything goes to RAM before it goes to the Hard drive. Quote Link to comment Share on other sites More sharing options...
expertec Posted September 30, 2004 Report Share Posted September 30, 2004 Yes, but go to hard drive it does. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.