Re: GIFs Good, Flash Executable Bad [Was: Plain text files in internet explorer]

From: FX (fx@phenoelit.de)
Date: 09/03/02


Date: Tue, 3 Sep 2002 09:55:05 +0200
From: FX <fx@phenoelit.de>
To: vuln-dev@securityfocus.com


> Or a vulnerability in IE's jpeg module that
> allows jpegs to carry viruses. It's not 'just like any executable', but
> it's not automatically safe either.

Attacks using malformed .ICO files are quite simple. Actually, IE on Windows
9x (or everything else using Win9x icon rendering functions) is vulnerable.
Some image viewers could be exploited by something like this (tested on
InfraView).
Details: http://www.darklab.org/archive/msg00100.html

yours truly,
FX

-- 
         FX           <fx@phenoelit.de>
      Phenoelit   (http://www.phenoelit.de)
672D 64B2 DE42 FCF7 8A5E E43B C0C1 A242 6D63 B564



Relevant Pages

  • Re: anti-abuse privacy??
    ... programs for viruses all in one bite. ... > the vulnerability which allows your machine to be infected just by ... > cleaner. ... >> and then download the tool to fix it. ...
    (microsoft.public.security)
  • ZoneEdit Account Hijack Vulnerability
    ... Topic: ZoneEdit Account Hijack Vulnerability ... transmission of viruses and will not accept ANY excuse for the ... digitally signed using our public PGP keys. ...
    (Bugtraq)
  • Re: Anti Virus: Improving the defense strategy through proactiveness...
    ... >>> Better software that's not vulnerable to viruses. ... >> 'leet Linux system should remember that hackers love Ramen Noodles. ... > there are huge differences in the degree of vulnerability between even ... someone claiming that there was such a thing as invulnerable software and I ...
    (comp.os.linux.security)
  • Re: Anti Virus: Improving the defense strategy through proactiveness...
    ... >>> Better software that's not vulnerable to viruses. ... >> 'leet Linux system should remember that hackers love Ramen Noodles. ... > there are huge differences in the degree of vulnerability between even ... someone claiming that there was such a thing as invulnerable software and I ...
    (comp.security.unix)
  • Re: Anti Virus: Improving the defense strategy through proactiveness...
    ... >>> Better software that's not vulnerable to viruses. ... >> 'leet Linux system should remember that hackers love Ramen Noodles. ... > there are huge differences in the degree of vulnerability between even ... someone claiming that there was such a thing as invulnerable software and I ...
    (comp.security.misc)