Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Poison porn pics show up online
BBC ^ | 30 September, 2004 | N/A

Posted on 10/01/2004 2:38:34 PM PDT by swilhelm73

Security experts have been expecting such images to turn up after Microsoft revealed a weakness in the way Windows handles the popular Jpeg format.

Soon after this discovery, a program started circulating online that was written to exploit this bug.

The poisoned images were posted to a porn newsgroup at the weekend and were found by Usenet provider Easynews.

Early warning

Poisoned pictures containing the bug have been widely predicted following the discovery of the Jpeg bug that afflicts more than a dozen Microsoft programs.

To fall victim to the poisoned pictures, users must view it using Windows Explorer.

VULNERABLE PROGRAMS Windows XP Windows XP Service Pack 1 Windows Server 2003 Internet Explorer 6 SP1 Office XP SP3 Office 2003 Digital Image Pro 7.0 Digital Image Pro 9 Digital Image Suite 9 Greetings 2002 Picture It! 2002 Picture It! 7.0 Picture It! 9 Producer for PowerPoint Project 2002 SP1 Project 2003 Visio 2002 SP2 Visio 2003 Visual Studio .NET 2002 Visual Studio .NET 2003 Once in place, the code then tells an infected machine to contact a server on the web to download another program that lets it be taken over remotely by an attacker.

The partner server that held the remote control code has now been shut down.

Oliver Friedrichs, senior manager with Symantec Security Response, said that he expected future versions of the bug to strike when images are viewed with the Internet Explorer browser and Outlook.

Microsoft played down the threat from the images. In a statement it said few people were likely to fall victim because of the series of steps they had to go through to get infected.

The net watchdog, the Internet Storm Center, said the poisoned images only crashed computers in tests, but added that working versions were probably close to being finished.

It also said that poisoned images were starting to circulate on AOL Instant Messenger.

Security firm F-Secure said that, so far, the few poisoned pictures posted on Usenet were not a virus because they do not replicate.

"Unfortunately I have a nasty feeling we might sooner or later see a mass-mailer worm using a Jpeg image as the attachment," wrote Mikko Hypponen in the company's online journal.

Users who have updated their Windows XP machines with the SP2 update could still be at risk from this bug if they are running unpatched programs, such as Microsoft Office, that are vulnerable.

Microsoft is urging people to update their version of Windows and download patches to close the loophole.

Some security firms have also produced tools that let users scan computers to see which machines are vulnerable to the exploit.

Anti-virus firms have updated their software to recognise the signature of the virus-bearing images.


TOPICS: Miscellaneous; News/Current Events; Technical
KEYWORDS: computersecurity; jpeg; lowquality; microsoft; nosecurity; virus
Navigation: use the links below to view more comments.
first 1-2021-4041-51 next last

1 posted on 10/01/2004 2:38:35 PM PDT by swilhelm73
[ Post Reply | Private Reply | View Replies]

To: swilhelm73

Ordinarily, I'd ask for pictures, but in this case...


2 posted on 10/01/2004 2:41:13 PM PDT by talleyman (The Kerry Sutra - 1001 positions, every one scr*wed...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: swilhelm73

I wonder how many of them thought they were just going blind...


3 posted on 10/01/2004 2:41:24 PM PDT by BigDaddyTX
[ Post Reply | Private Reply | To 1 | View Replies]

To: All

Dump IE, switch to Firefox.


4 posted on 10/01/2004 2:47:33 PM PDT by Reagan is King (The modern definition of 'racist' is someone who is winning an argument with a liberal.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: talleyman; NYC GOP Chick

Pinging the picture diva...


5 posted on 10/01/2004 2:48:38 PM PDT by sauropod (Hitlary: "We're going to take things away from you on behalf of the common good.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: swilhelm73

 

Sadly, it's true.

 

6 posted on 10/01/2004 2:50:15 PM PDT by Fintan (Oh...am I supposed to read the article???)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Reagan is King
Dump IE, switch to Firefox.

right-o! and while we're at it, let's all dump our cars for one of those two-wheeled gyroscopic people mover things.

7 posted on 10/01/2004 2:51:58 PM PDT by the invisib1e hand (do not remove this tag under penalty of law.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: swilhelm73

Downloading pr0n is dumb and can cause your computer to suddenly freeze u


8 posted on 10/01/2004 2:53:07 PM PDT by Billthedrill
[ Post Reply | Private Reply | To 1 | View Replies]

To: Reagan is King
Dump IE, switch to Firefox.

The problem is not with IE itself:

The vulnerability in caused due to a boundary error within the GDI+ JPEG Parsing component (Gdiplus.dll). This can be exploited to cause a buffer overflow by tricking a user into viewing a specially crafted JPEG image with any application using the vulnerable component for JPEG image processing.

I don't know if Firefox or Mozilla use that dll.

9 posted on 10/01/2004 2:53:55 PM PDT by RogueIsland
[ Post Reply | Private Reply | To 4 | View Replies]

To: Fintan

AAAG! now, I'm blind.


10 posted on 10/01/2004 2:57:53 PM PDT by bourbon (Works best when angry.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Fintan

A post like yours is surely worth a 1-week ban from FR!

You're an evil, evil person.


11 posted on 10/01/2004 2:59:38 PM PDT by MplsSteve
[ Post Reply | Private Reply | To 6 | View Replies]

To: swilhelm73

This says it isn't just porn pictures:

http://reviews.cnet.com/4520-3513_7-5515107-1.html

Can you imagine the Internet without pictures? A new flaw in the way Windows, and therefore Internet Explorer, renders JPEG images--one of the most common image formats on the Web--should make you think twice about whether you should display them. At the very least, it should nudge you into considering an alternative Internet browser, such as Firefox.

The code to exploit this flaw is now public. Usually, exploit code release is the first step toward a new virus or worm, and as we have seen before, the time from exploit to virus is generally about two to three weeks. In other words, the clock is ticking.

(snip)


12 posted on 10/01/2004 3:05:21 PM PDT by Calpernia (Breederville.com)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Calpernia

Yep, that's true.

This kind of code can be inserted into any kind of image.

Hopefully Microsoft is working 24/7 to fix this.


13 posted on 10/01/2004 3:32:00 PM PDT by swilhelm73 ("I think you can be an honest person and lie about any number of things" -- Dan Rather)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Fintan
Oh...good lord!!!!............I'm thinking we're going to have to institute a "rule" re: posting of Helen Thomas photos i.e. no posting between 7 a.m./9 a.m. - 12 p.m./2 p.m. - 5 p.m./7 p.m............whew Fintan, you just made this one................maybe, for us old farts, ban posting around evening "snack" times too, say 9 p.m. I know it will sink the Prevacid(sp) stock, but good god man, I don't own that many shoes where I can afford to wretch on every pair!!! hahaha!!!
14 posted on 10/01/2004 3:33:16 PM PDT by soozla ("I used to think I was indecisive, but now I'm not too sure............"-John Kerry)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Fintan

THAT'S the reason Photoshop should be regulated more closely than handguns.


15 posted on 10/01/2004 3:35:11 PM PDT by Richard Kimball (Kerry Campaign: An army of pompous phrases moving across the landscape in search of an idea)
[ Post Reply | Private Reply | To 6 | View Replies]

To: sauropod

Nope, not since the Dolly Parton Fiasco!


16 posted on 10/01/2004 4:24:22 PM PDT by NYC GOP Chick (Terry McAuliffe -- The Gift that Keeps on Giving)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Fintan

Now that's just NASTY! Ecch! Phtt!


17 posted on 10/01/2004 4:27:42 PM PDT by TADSLOS (Right Wing Infidel since 1954)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Fintan
OH! Man!
Good Lord!

Have A Heart!

I could've gone the whole rest of my life without seeing that!
(You have become a sadist)

18 posted on 10/01/2004 4:30:59 PM PDT by Fiddlstix (This Tagline for sale. (Presented by TagLines R US))
[ Post Reply | Private Reply | To 6 | View Replies]

To: swilhelm73

Speaking of porn, I understand there's another Paris Hilton porn tape floating around.


19 posted on 10/01/2004 4:39:31 PM PDT by Lizavetta
[ Post Reply | Private Reply | To 1 | View Replies]

To: Calpernia

It isn't just IE, and it isn't restricted to MS products. I posted an article from SANS earlier today that says they're getting reports of the exploit being used by AOL Instant Messenger.


20 posted on 10/01/2004 4:42:40 PM PDT by tacticalogic ("Oh bother!" said Pooh, as he chambered his last round.)
[ Post Reply | Private Reply | To 12 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-51 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson