|
|
This topic comprises 2 pages: 1 2
|
|
Author
|
Topic: Viruses in JPEG images
|
|
|
Daryl C. W. O'Shea
Film God

Posts: 3977
From: Midland Ontario Canada (where Panavision & IMAX lenses come from)
Registered: Jun 2002
|
posted 09-28-2004 01:09 AM
The server itself is secure, as long as you don't login interactively. Or more specifically, don't go directory browsing for JPEGs.
It's the shell, and thus IE also, that uses GDI+ package. Code that was written years ago and has been assumed to be good since nobody has noticed a problem with it until earlier this year. Reviewing all of the pre-existing packages used in such a large piece of software is pretty unrealistic. Having someone that can spot such problems isn't cheap. Your average entry level idiot programmer won't see it.
The root problem is that, until fairly recently, Microsoft, like most software companies, didn't properly engineer their software. A good design was rare, and a well engineered design and design process was mostly non-existent. People just hacking out solutions to problems in code was way too common, and to some extent is still too common today.
If you want to see something sad, look for the near zero announcements of other products that are affected by the flaw. There's probably hundreds of them since the GDI+ package is included in Microsoft's Development Studio code packages. Those companies are truely the sad ones. The ones blindly using code they don't understand and then forgetting they ever used it.
| IP: Logged
|
|
Randy Stankey
Film God

Posts: 6539
From: Erie, Pennsylvania
Registered: Jun 99
|
posted 09-28-2004 11:22 PM
quote: Daryl C. W. O'Shea
The root problem is that, until fairly recently, Microsoft, like most software companies, didn't properly engineer their software.
I agree with that about 90%. There was a day when properly engineered code was a necessity. You may have had only 64 KB of memory to work with. Processors ran in the tens of MHz. at most. Floppies held 400 KB. You HAD to write code that fit within those limits and you HAD to make it run fast. Then, one day, systems started getting Bigger-Better-Faster-Cheaper. Over a period of years, people stopped worrying about whether or not their code would run in the "space" allotted on a given machine. To put it mildly; People got sloppy!
Now, we're starting to come around full circle. We have lots of "computes" to work with. Nobody has to worry about running out of memory, processor power or disk storage. (In most cases.) However, people have to worry about getting lost in the "forrest" of their own code!
It seems to me that few companies/people take the time to map out their plans/wants/needs for their software before they start. Without a map it's easy to get lost in the woods, so to speak. Once they start writing code, I see little evidence of "unit testing" like was done years ago. Once they get close to making a finished product, I see little evidence of proper alpha/beta testing anymore. Because of all this I see less and less evidence that people even know what to do with applications and/or system software that have bugs.
Back in the day... Way back in the 80's... I used to help a lot of friends of mine who were commercial software developers. I wasn't very good at writing software but I KNEW how to break it! They would give me software and my job was to beat on it as hard as I could then send it back broken. (Repeat until problems found approaches zero.)
I see little evidence of this kind of care in software development today. Cripes! The malware developers have better testing procedures than the "good guys"!
| IP: Logged
|
|
Bobby Henderson
"Ask me about Trajan."

Posts: 10973
From: Lawton, OK, USA
Registered: Apr 2001
|
posted 09-29-2004 12:09 AM
I wonder how much of this problem stems from the habit of many software companies "frankensteining" together apps from a lots of pre-existing chunks of code. I've heard that stuff sometimes described as "public domain code" or something similar to that. I'm not a computer programmer. But I have the strong impression little, if any, modern application software is developed entirely from the ground up.
I see strange similarities in some graphics applications for instance. A $4,000 trade-specific sign design program will have some of the same functions, toolbars & menu designs as apps like Canvas or Illustrator --and even have the same damned bugs occuring! Every time a new version of Freehand, Illustrator or Corel has been released over the last few years, each version seems to have gotten slower and more buggy. About the only modern vector-drawing app any professional graphics person is upgrading to is IllustratorCS, but many always keep their 5 to 8 year old versions handy in case they have to jump back to something actually stable (in this category, that means Freehand 8, CorelDRAW 9 and Illustrator 7).
As sloooooooow as some of the graphics companies are to react (Macromedia in particular), I would not be surprised if this GDI+ thing showed up as a real threat across many graphics applications. Adobe Photoshop would be the only one I would expect to see patched on a fast basis. And the Mac version would probably get patched first (if need be). Very few PC users actually paid for their copies of Photoshop (which is also why only the PC version of PhotoshopCS has that software activation thingie).
| IP: Logged
|
|
|
|
All times are Central (GMT -6:00)
|
This topic comprises 2 pages: 1 2
|
Powered by Infopop Corporation
UBB.classicTM
6.3.1.2
The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion
and agrees to release the authors from any and all liability.
|