Re: Avi or mpeg virus possible ?



From: "Todd H." <comphelp@xxxxxxxxx>


|
| That's what I'm talking about.
|
| An embedded netcat listener, for example, is surely an example of
| malware, and these can be made extremely tiny in size, and embedded
| right into a media file crafted against a specific media viewer's
| vulnerability. View the media file, get owned by by malware. No
| external moving parts required.
|

Viewing will not extract a binary. You need a helper application to extract a binary from a
graphic or moving graphic file.

The Tibs Trojan is well known to do this with the well known FroggerEXE.

The EXE files are stored in JPEGs and all you see is a simple Frog in a picture.
Viewing the Frog in the JPEG will not extract the EXE. An external program has to do it.

The same holds true for; AVI, MOV, MPEG, etc.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


.



Relevant Pages

  • Re: Avi or mpeg virus possible ?
    ... View the media file, get owned by by malware. ... Viewing will not extract a binary. ...
    (alt.computer.security)
  • Re: Avi or mpeg virus possible ?
    ... | That is certainly the easiest and most common way to get owned by such downloads. ... Quicktime and Flash vulnerabilities seem to ... the question was embedded malware in the ... View the media file, ...
    (alt.computer.security)