top_left top_right
bottom_left
Next Event: Unknown | Forum Rules | QGL Website | Event Registration
openFolder AusForums.com
iconwatfolderLineopenFolder LANs
iconwatfolderLineopenFolder QGL
iconwatfolderLineopenFolder QGL Forum
Author
Topic: JPEG Virus in the Wild
natslovR
Posts: 825
Location: Canberra, Australian Capital Territory
Easynews has caught the first case of a jpeg virus in the wild. You can read about it here. It's nasty, downloading some remote access tools, running them as a service, and connecting you to an IRC channel.

There's more about it on slashdot.

Guess this is just a reminder to be wary of jpeg's now as well and to keep your anti-virus software up to date (AVG for free virus checker)

The first jpeg to contain the virus was a image posted to a transexual image group, the second was to hetro porn groups.

There was another article earlier in the day on slashdot claiming the Microsoft scanning tool isn't up to scratch, as it only checks for Microsoft supplied problem files, not any files with the bug that may have been put there by 3rd party software. The tool mentioned in that article as more complete than the Microsoft one is this one, GDIScan

If the scan shows you have vulnerable files, it means you haven't patched for MS04-028 (or you have but have since installed software that overwrote it?). So go install MS04-028. promoted forum item
system
--
Superform
Posts: 2548
Location: Cairns, Queensland
GAWD DAMN
trog
Posts: 15405
Location: Brisbane, Queensland
How do you re-rerun the tool that checks for vulnerable software?
natslovR
Posts: 826
Location: Canberra, Australian Capital Territory
trog,

since you news'd it, i added the final paragraph about the scanner and fixed up a typo.
CaPt0
Posts: 5534
Location: Brisbane, Queensland
trog use the mbsa tool.

microsoft basle security alalyser.
Superform
Posts: 2551
Location: Cairns, Queensland
ok... i scaned and found i have vulnerable versions...

wtf do i do now??
natslovR
Posts: 827
Location: Canberra, Australian Capital Territory
Get the MS04-028 security fix. i'll include link in original post
Irhabi
Posts: 1387
Location: Brisbane, Queensland
the Microsoft Security Bulletin MS04-028 doesnt have a patch for WinXp pro SP2..
trog
Posts: 15406
Location: Brisbane, Queensland
I don't think XP SP2 is vulnerable

edit: props to natslovr for the comprehensive edit

last edited by trog at 15:39:11 28/Sep/04
Irhabi
Posts: 1392
Location: Brisbane, Queensland
there were a few dll's that are but turns out they belong to office
trog
Posts: 15407
Location: Brisbane, Queensland
Yeh, I get a few DLLs reported belonging to office (by that non-MS tool), which is sad because OfficeUpdate supposedly fixed me the other day).

I've been confused by everything about this 'fix', MS seem to have handled it completely lamely. I can see lots of pwned computers in the very near future.
natslovR
Posts: 3901
Location: Sydney, New South Wales
The tool i linked to found quite a few things on one of my boxes, which i thought i'd ms04-028'd to do with Visual Studio and Beta versions of MS Server software. Also, stuff in the uninstall area.
trog
Posts: 15409
Location: Brisbane, Queensland
Well, that tool still reports active DLLs in my windows install that look like office files. I have Works 2000 installed. OfficeUpdate supposedly brought me up to date, but not according to this GDI tool!

Edit: oh, actually, I just RTFMed and now know vulnerable DLLs show in red. What a newb I am.

last edited by trog at 16:09:03 28/Sep/04
Superform
Posts: 2558
Location: Cairns, Queensland
well it says i have them in dreamweaver...

so i'm f***ed i guess
möoby
Posts: 2236
Location: UK
didnt these patches come out a few weeks ago?
Opec
Posts: 2274
Location: Brisbane, Queensland
This vulnerabitiy is an absolute pain in arse. Basically any 3rd party apps that parse the JPEG file will in someway be vulnerable.

If not handled properly it's going cause mayhem. I'm having a pretty hard time trying to find all the patches for some of the DLLs that GDIscan has found to be vulnerable.

For example:

C:\I386\ASMS\1000\MSFT\WINDOWS\GDIPLUS\GDIPLUS.DLL

I've patched my system with the MS patch etc but I have no idea what/which app uses this DLL :( Tried google without much luck...

NOT HAPPY JAN.
[Q]
Posts: 7720
Location: Brisbane, Queensland
So according to the MS page as long as you have XP SP2 windows itself is no longer vulnerable? ie. Opening the jpg in windows explorer wont execute the vrus?
Opec
Posts: 2275
Location: Brisbane, Queensland

So according to the MS page as long as you have XP SP2 windows itself is no longer vulnerable? ie. Opening the jpg in windows explorer wont execute the vrus?


Yes if you patched your Windows, any "MS" Windows related software the relies on the JPEG parser is not vulnerable. However, unpatched 3rd party software that rely on thier on JPEG parser might still be. That's why this suck so bad :(

last edited by Opec at 18:00:35 28/Sep/04
z0r
Posts: 925
Location: Brisbane, Queensland
but doesn't that mean that because windows itself is patched, the third party software woulnd't be able to "do anything" about it?
sorry if this is too much of a noob question.
Skitza
Posts: 5695
Location: Brisbane, Queensland
No because different apps use their own different gdi blah. Something like that.
trog
Posts: 15412
Location: Brisbane, Queensland
The way I understand it is, Microsoft released a library of graphics functions that they distributed, I assume as a DLL. Other software writers used this DLL when distributing their software, so by default, that DLL is vulnerable to this exploit.
natslovR
Posts: 3902
Location: Sydney, New South Wales
From what the open letter said, the library people are distributing isn't freely distributable, i.e. you had to have permission to distribute it with your application, so microsoft KNOW which applications were licensed to distribute it, and they should just release a list of applications so that we can see if we are affected and go and harass the application distributor about a patch.
Malthius
Posts: 798
Location: Brisbane, Queensland
I found 1 vulnerable dll in a program's folder, installed only the other day. Windows / Office update seems to have done the business on the rest of it.

I just deleted the offending dll, and it seemed to my non programmer mind that the program ran fine - I'm assuming it just hooked the safe version of the DLL from the system32 directory?
lmnt
Posts: 1312
Location: Brisbane, Queensland
great, another bulls*** waste of time cause some fat nerd cant get laid.
[Q]
Posts: 7722
Location: Brisbane, Queensland
I just re-installed symantec virus maker again and then tried to download the dirty viral jpg in question. Uni licenses are cool.
http://www.q.ausanime.com/upload-files/sav.jpg

Picked it up right away and deleted it before it could even finish.

GG DOCTOR
http://www.q.ausanime.com/upload-files/Norton-jpb.jpg
Rukh
Posts: 530
Location: Brisbane, Queensland
natslovR:

gdiplus.dll is freely downloadable from here.

The library interface for it comes with the freely downloadable Platform SDK.
Superform
Posts: 2620
Location: Cairns, Queensland
madmax... u rock... who would have thought there was so much brains on this forum
system
--
Not a new post since your last visit.
New Post Since your last visit
Back To Forum
Advertise with Us | Privacy Policy | Contact Us
© Copyright 2001-2026 AusGamers Pty Ltd. ACN 093 772 242.
Hosted by Mammoth Networks - Australian VPS Hosting
Web development by Mammoth Media.