Re: [Full-Disclosure] 2 vulnerabilities combine to auto execute received files in Nokia series 60 OS

From: Thierry Zoller (Thierry_at_sniff-em.com)
Date: 01/24/05

  • Next message: Anders Langworthy: "Re: [Full-Disclosure] 2 vulnerabilities combine to auto execute received files in Nokia series 60 OS"
    Date: Mon, 24 Jan 2005 21:11:16 +0100
    To: "Paul Kurczaba" <seclists@securinews.com>
    
    

    Dear Paul Kurczaba,

    PK> Wouldn't the phone try to open the jpg file as a picture, and not execute
    PK> it. Just like on desktop PCs: if you rename a .exe (application/program) to
    PK> a jpg (picture file), and try to open the file, your image program will open
    PK> the file, thinking it is a image file. The application code will not be
    PK> executed.

    Well there is a twist, Nokia says it identifies files NOT by the
    filename but by the extension, even when shelling them, so there won't
    be an image view but code being run. (Note I have no access to said
    devices, I am solely interpreting).

    -- 
    Regards,
    Thierry Zoller
    http://www.sniff-em.com [Yes]
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Anders Langworthy: "Re: [Full-Disclosure] 2 vulnerabilities combine to auto execute received files in Nokia series 60 OS"

    Relevant Pages

    • Re: Display stored JPGs on a form
      ... I create a form with a Bound Object Frame control that has as its control ... the JPG file type and change it from Internet Exploer to MS Office Picture ...
      (microsoft.public.access.forms)
    • Re: Can we view a picture from its memory data?
      ... we save all data into a .jpg file and use an Image ... > Is there a way that we can pass those memory .jpg data into Image ... ' Load a picture from a byte array ... ' The function loads the array in a memory stream and then uses the ...
      (microsoft.public.vb.general.discussion)
    • Re: Creating a Logo with PowerPoint (or Publisher)
      ... the picture as a .jpg file. ... opt to save as PNG. ... be less expensive in the long run to send someone a PNG or even the PPT ... provide you with EPS, PNG, GIF, and probably also a JPG file. ...
      (microsoft.public.powerpoint)
    • AW: [Full-Disclosure] 9/11 virus
      ... "I want to see this picture." ... The user never wanted to execute a file, he wanted to see a picture. ... miscommunication issue, not stupidity of users. ... A better interface would ...
      (Full-Disclosure)
    • Re: Conversing "Jpg" file into "doc" document
      ... Do you mean that the jpg file contains an image of text, ... then load the file into Office Picture ... open Microsoft Document Imaging and ... if you'd simply like to have the jpg file in a Word document as a ...
      (microsoft.public.word.conversions)