Entry: Malware using the JPEG security Hole Sep 30, 2004



Both PCWorld and SANS are reporting two separate cases of malware that attempts to use the recent Microsoft-announced JPEG security hole. In the first article, the malware targets AOL Instant Messaging, trying to lure people to a website that will download malicious code to your PC and open a backdoor to the malware author.  In the SANS report, the hacker used porn images to attract attention. These images use the JPEG hole to gain access to the computer.

If you haven't done it yet, run the JPEG toolkit on your system to detect vulnerable code. This exploit exists on multiple non-Microsoft products.  See the SANs report for more information on this toolkit.

   0 comments

Leave a Comment:

Name


Homepage (optional)


Comments