Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 09-15-2004, 03:28 PM   #1
bluff
Too lazy to set a custom title
 
Join Date: Jan 2004
Location: Bluffville
Posts: 6,253
JPEG files can contain viruses

Software bug raises spectre of 'JPEG of death'

16:14 15 September 04

NewScientist.com news service


Flawed software code used by numerous Microsoft applications to render images mean that a specially constructed image file could hijack a computer or spread a virus.

Ten years ago the idea of an image infecting a computer was the subject of a hoax email. But what was once a myth is now a genuine threat after Microsoft disclosed a flaw in the image processing code used in a range of its software programs on Tuesday.

Some experts blame the new threat on shoddy programming. "In a properly coded world, a graphic should not be able to infect your computer," says Graham Cluley, senior researcher with the UK-based anti-virus firm Sophos. "It should be impossible."

So far, no one is known to have exploited the flaw and Cluley says it is far from certain anyone will develop a computer virus based on it. But code designed to exploit the bug could appear on the internet soon, and this is often the first step towards the creation of a hacking tool or virus based on the flaw.

Crafty programmer

A number of Microsoft operating systems and applications contain the relevant bug, including Windows XP, Windows Server 2003 and Office XP, as well as many smaller applications. Microsoft has released downloadable fixes for affected software, available from the Microsoft TechNet site here.

The affected code has a so-called "buffer overrun" flaw. The buffer is a protected part of the computer memory, but flaws can mean that excessive input data can overrun into unprotected parts of a memory. A crafty programmer can use such a flaw to execute unauthorised code on a computer, potentially providing themselves with a point of entry in order to take complete control.

The hoax email message released in 1994 warned of a JPEG virus that could have severe consequences for the unlucky recipient.

"If you use a 386/486/Pentium machine to display your JPEG pictures, then you are at risk of catching the JPEG virus," the message read. "Although the JPEG virus is nominally benign, it can cause some multisync monitors to malfunction, effectively destroying the monitor."

A virus based on the new software flaw should not be able to damage a victim's monitor, but Rob Rosenberg, editor of the debunking site Vmyths.com, notes that the hoax could come back to haunt people.

"In '94 it was a myth, but in '04 it's the real thing," he told the computer security web site SecurityFocus. "We've got the JPEG of death now."


Will Knight

http://www.newscientist.com/news/news.jsp?id=ns99996408
bluff is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 03:29 PM   #2
bluff
Too lazy to set a custom title
 
Join Date: Jan 2004
Location: Bluffville
Posts: 6,253
shit
bluff is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 03:30 PM   #3
GatorB
The Demon & 12clicks
 
Industry Role:
Join Date: Oct 2001
Location: SallyRand is a FAGGOT
Posts: 18,208
Just get SP2 and you don't have to worry about it. It doesn't apply to SP2.
GatorB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 03:30 PM   #4
FilthyRob
Confirmed User
 
Join Date: Feb 2004
Location: Anaheim - CA
Posts: 6,741
Great more exploits coming
__________________
AKA - Clubsexy
FilthyRob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 03:31 PM   #5
Dirty F
Too lazy to set a custom title
 
Dirty F's Avatar
 
Industry Role:
Join Date: Jul 2001
Posts: 59,204
Repost of a repost of repost and we can expect MANY reposts in the coming days
Dirty F is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 03:33 PM   #6
bluff
Too lazy to set a custom title
 
Join Date: Jan 2004
Location: Bluffville
Posts: 6,253
Quote:
Originally posted by Battuss
Repost of a repost of repost and we can expect MANY reposts in the coming days
didn't read this here before
bluff is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 03:34 PM   #7
Dirty F
Too lazy to set a custom title
 
Dirty F's Avatar
 
Industry Role:
Join Date: Jul 2001
Posts: 59,204
Quote:
Originally posted by bluff
didn't read this here before
But you can expect news like that to be posted on gfy before
Dirty F is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 03:42 PM   #8
Trent Edison
Too lazy to set a custom title
 
Join Date: Jun 2003
Location: Freeport 7
Posts: 6,132
Quote:
Originally posted by GatorB
Just get SP2 and you don't have to worry about it. It doesn't apply to SP2.
No, id better let jpeg viruses eat my machine than install this shit...
__________________

Trent Edison is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 03:44 PM   #9
GatorB
The Demon & 12clicks
 
Industry Role:
Join Date: Oct 2001
Location: SallyRand is a FAGGOT
Posts: 18,208
Quote:
Originally posted by Trent Edison
No, id better let jpeg viruses eat my machine than install this shit...
Nothing wrong with SP2. installed it on 2 computers with zero problems. One is an AMD 600 Mhz running on PC100 SDRAM
GatorB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 03:47 PM   #10
BlueFly
Confirmed User
 
Join Date: Nov 2003
Location: NC, USA
Posts: 716
it won't fuck with my mac...
__________________
Now Taking Hard Link Trades
BTW - NEVER use thexxxhost.com
BlueFly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 03:48 PM   #11
Trent Edison
Too lazy to set a custom title
 
Join Date: Jun 2003
Location: Freeport 7
Posts: 6,132
So far you are the only one ive seen who says something different than "SP2 SUCKS MONKEY BALLS!"...
__________________

Trent Edison is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 03:52 PM   #12
block
Confirmed User
 
Join Date: Jan 2004
Location: Winnipeg, Canada - *cough* check sig *cough*
Posts: 1,258
Well I have sp2 so I'm good to go then...
__________________

ICQ - 19961769
block is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 03:53 PM   #13
GatorB
The Demon & 12clicks
 
Industry Role:
Join Date: Oct 2001
Location: SallyRand is a FAGGOT
Posts: 18,208
Quote:
Originally posted by Trent Edison
So far you are the only one ive seen who says something different than "SP2 SUCKS MONKEY BALLS!"...
Who me? Well I'm not an idiot. I know how to install something.
GatorB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 04:24 PM   #14
nastyking
 
Join Date: Nov 2002
Posts: 2,174
Quote:
Originally posted by BlueFly
it won't fuck with my mac...
myth: mac is buffer overflow proof
__________________
nastyking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 04:27 PM   #15
riosluts
Confirmed User
 
Join Date: Sep 2003
Posts: 5,250
yeah i got a email explaing this. All ya gotta do is run the windows update
__________________

riosluts is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2004, 05:08 PM   #16
Dirty Dane
Sick Fuck
 
Dirty Dane's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: www
Posts: 9,491
http://www.microsoft.com/technet/sec.../MS04-028.mspx
Dirty Dane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.