Yorkshire Divers

London Diving Chamber - Emergency Recompression Facility
Go Back   YD Scuba Diving Forums > General Diving Forums > Surface Interval
User Name
Password

Welcome to the YD Scuba forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact support.

Surface Interval: Discuss FYI: Windows JPEG exploit found in the wild in the General Diving Forums forums: Tuesday September 28, 12:28 PM Windows JPEG exploit found in the wild By Ciaran Buckley Less than two weeks after ...

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 30-09-04, 04:10 AM
Mr T.'s Avatar
Senior Member
 

Join Date: May 2002
Location: Depends on the week in question
Posts: 12,240
Mr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the sea
Exclamation FYI: Windows JPEG exploit found in the wild

Tuesday September 28, 12:28 PM

Windows JPEG exploit found in the wild
By Ciaran Buckley

Less than two weeks after it was announced, hackers have exploited a Windows XP JPEG vulnerability and are spreading a virus through adult content newsgroups (which can mean everything from interest group forums, to financial updates to porn sites).

On 14 September, Microsoft (NASDAQ: MSFT - news) released Security Bulletin MS04-028, which warned that because of a problem with the way that Windows handles JPEG image files, malicious code could be executed on a user's machine if they simply viewed an ordinary image file. Because Microsoft's Internet Explorer browser is vulnerable, users could be attacked just by visiting a website that has affected images.

Within a week, malicious hackers had developed a proof of concept and software development kit (SDK) for others who wished to write a virus to exploit the vulnerability. A virus is now loose on the internet, having been posted to an adult content newsgroup with a JPEG extension.

"What's important for people to understand is how quickly after the bulletin is published that viruses are out in the wild," said Conor Flynn, technical director of Dublin-based Rits, speaking to ElectricNews.Net. "This is a difficult virus to stop, because not many people have web-based scanning at the perimeter and it can go straight from your browser to your PC."

The virus is a Trojan, which makes the computer available to the hacker as a drone or "zombie," which means that it could be used to forward spam onto other users, or to bombard websites in a distributed denial of service (DDoS).

The virus is also able to access information on the user's computer, including software license keys, credit card details or other confidential information. If the computer is on a network, then the virus will have access to all of the shared drives and could spread throughout the LAN.

Flynn advises users to install the patch for the flaw, which can be downloaded from Microsoft's site.

"People are patching the vulnerability, but they're doing it very slowly," said Conor Flynn. "People should download patches before they open Internet Explorer, people need to get into a new routine."

As a general rule, internet users should install anti-virus software and keep it updated and should configure a firewall to stop intrusions from the web, Flynn added. "The top three or four anti-virus programmes do a very good job if you keep them up to date," he said. "The Windows firewall is average, but there are firewalls like Symantec (NASDAQ: SYMC - news) , Tiny and ZoneAlarm which are very good and some of them are free for home users."
__________________
All divers are created equal(ised) - it's just that some of us handle the pressure better.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 30-09-04, 09:17 AM
Senior Member
 

Join Date: Feb 2003
Location: Buckinghamshire
Posts: 1,426
abucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkeller
Bren,
What was the source of this article?

Thanks
Andrew
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 30-09-04, 10:04 AM
PeteM's Avatar
New Member
 

Join Date: Apr 2003
Location: Essex
Posts: 95
PeteM can find the seaside on a mapPeteM can find the seaside on a mapPeteM can find the seaside on a map
Quote:
Originally Posted by abucksdiver
Bren,
What was the source of this article?

Thanks
Andrew
http://www.f-secure.com/v-descs/ms04-028.shtml
http://antivirus.about.com/od/securi.../a/jpgflaw.htm
http://www.infoworld.com/article/04/...exploit_1.html
http://www.techimo.com/newsapp/i12028.html
__________________
PeteM
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 30-09-04, 06:41 PM
Mr T.'s Avatar
Senior Member
 

Join Date: May 2002
Location: Depends on the week in question
Posts: 12,240
Mr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the seaMr T. paddles in the sea
Smile

Quote:
Originally Posted by abucksdiver
Bren,
What was the source of this article?

Thanks
Andrew

Sorry for the delay in coming back Andrew - here ya go:

http://www.enn.ie/frontpage/news-9555765.html
__________________
All divers are created equal(ised) - it's just that some of us handle the pressure better.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 30-09-04, 06:48 PM
JohnK's Avatar
The Artist formerly known as 'Kirky'
 

Join Date: May 2002
Location: Cheshire
Posts: 2,183
JohnK paddles in the seaJohnK paddles in the seaJohnK paddles in the seaJohnK paddles in the seaJohnK paddles in the seaJohnK paddles in the seaJohnK paddles in the seaJohnK paddles in the seaJohnK paddles in the seaJohnK paddles in the seaJohnK paddles in the sea
If I understand it right, anyone with XP and SP2 should be OK ????
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 30-09-04, 06:58 PM
Andrew H's Avatar
Member
 

Join Date: Jul 2004
Location: Bradford
Posts: 380
Andrew H dips toes in sea annuallyAndrew H dips toes in sea annuallyAndrew H dips toes in sea annuallyAndrew H dips toes in sea annuallyAndrew H dips toes in sea annuallyAndrew H dips toes in sea annuallyAndrew H dips toes in sea annuallyAndrew H dips toes in sea annually
JPEG exploit? For heavens sake how many holes are there in this OS? Of course if you apply SP2 then that will break.....

Andrew
__________________
I wish I had one of those clever signatures
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 01-10-04, 09:57 AM
Senior Member
 

Join Date: Feb 2003
Location: Buckinghamshire
Posts: 1,426
abucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkellerabucksdiver is a snorkeller
Thanks Bren,
Being "in the industry" I need to quote the source before discussing issues like this!

Regards
Andrew
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Sponsored Links

Yorkshire Divers - RSS Feed
All times are GMT +1. The time now is 01:18 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
Trademark and all rights reserved : © YD.com Ltd (2006)
YD.com Ltd (Registered in England - 05886696)
Other sites : Golf Clubs | New Premiership Football Kits | MP3 Portable Players | MP3 Players For Sale | Replica Football Kits | Cheap Football Boots

Forums Directory