GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   JPEG files can contain viruses (https://gfy.com/showthread.php?t=357125)

bluff 09-15-2004 03:28 PM

JPEG files can contain viruses
 
Software bug raises spectre of 'JPEG of death'

16:14 15 September 04

NewScientist.com news service


Flawed software code used by numerous Microsoft applications to render images mean that a specially constructed image file could hijack a computer or spread a virus.

Ten years ago the idea of an image infecting a computer was the subject of a hoax email. But what was once a myth is now a genuine threat after Microsoft disclosed a flaw in the image processing code used in a range of its software programs on Tuesday.

Some experts blame the new threat on shoddy programming. "In a properly coded world, a graphic should not be able to infect your computer," says Graham Cluley, senior researcher with the UK-based anti-virus firm Sophos. "It should be impossible."

So far, no one is known to have exploited the flaw and Cluley says it is far from certain anyone will develop a computer virus based on it. But code designed to exploit the bug could appear on the internet soon, and this is often the first step towards the creation of a hacking tool or virus based on the flaw.

Crafty programmer

A number of Microsoft operating systems and applications contain the relevant bug, including Windows XP, Windows Server 2003 and Office XP, as well as many smaller applications. Microsoft has released downloadable fixes for affected software, available from the Microsoft TechNet site here.

The affected code has a so-called "buffer overrun" flaw. The buffer is a protected part of the computer memory, but flaws can mean that excessive input data can overrun into unprotected parts of a memory. A crafty programmer can use such a flaw to execute unauthorised code on a computer, potentially providing themselves with a point of entry in order to take complete control.

The hoax email message released in 1994 warned of a JPEG virus that could have severe consequences for the unlucky recipient.

"If you use a 386/486/Pentium machine to display your JPEG pictures, then you are at risk of catching the JPEG virus," the message read. "Although the JPEG virus is nominally benign, it can cause some multisync monitors to malfunction, effectively destroying the monitor."

A virus based on the new software flaw should not be able to damage a victim's monitor, but Rob Rosenberg, editor of the debunking site Vmyths.com, notes that the hoax could come back to haunt people.

"In '94 it was a myth, but in '04 it's the real thing," he told the computer security web site SecurityFocus. "We've got the JPEG of death now."


Will Knight

http://www.newscientist.com/news/news.jsp?id=ns99996408

bluff 09-15-2004 03:29 PM

shit

GatorB 09-15-2004 03:30 PM

Just get SP2 and you don't have to worry about it. It doesn't apply to SP2.

FilthyRob 09-15-2004 03:30 PM

Great more exploits coming

Dirty F 09-15-2004 03:31 PM

Repost of a repost of repost and we can expect MANY reposts in the coming days :)

bluff 09-15-2004 03:33 PM

Quote:

Originally posted by Battuss
Repost of a repost of repost and we can expect MANY reposts in the coming days :)
didn't read this here before

Dirty F 09-15-2004 03:34 PM

Quote:

Originally posted by bluff
didn't read this here before
But you can expect news like that to be posted on gfy before :)

Trent Edison 09-15-2004 03:42 PM

Quote:

Originally posted by GatorB
Just get SP2 and you don't have to worry about it. It doesn't apply to SP2.
No, id better let jpeg viruses eat my machine than install this shit...

GatorB 09-15-2004 03:44 PM

Quote:

Originally posted by Trent Edison
No, id better let jpeg viruses eat my machine than install this shit...
Nothing wrong with SP2. installed it on 2 computers with zero problems. One is an AMD 600 Mhz running on PC100 SDRAM

BlueFly 09-15-2004 03:47 PM

it won't fuck with my mac... :)

Trent Edison 09-15-2004 03:48 PM

So far you are the only one ive seen who says something different than "SP2 SUCKS MONKEY BALLS!"...

block 09-15-2004 03:52 PM

Well I have sp2 so I'm good to go then...

GatorB 09-15-2004 03:53 PM

Quote:

Originally posted by Trent Edison
So far you are the only one ive seen who says something different than "SP2 SUCKS MONKEY BALLS!"...
Who me? Well I'm not an idiot. I know how to install something.

nastyking 09-15-2004 04:24 PM

Quote:

Originally posted by BlueFly
it won't fuck with my mac... :)
myth: mac is buffer overflow proof :1orglaugh

riosluts 09-15-2004 04:27 PM

yeah i got a email explaing this. All ya gotta do is run the windows update

Dirty Dane 09-15-2004 05:08 PM

http://www.microsoft.com/technet/sec.../MS04-028.mspx :)


All times are GMT -7. The time now is 04:13 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123