Re: Can Exploit-ANIfile.c infect JPG files?



On Tue, 24 Apr 2007 18:47:26 -0400, "David H. Lipman"
From: "cquirke (MVP Windows shell/user)"

| You can put an exploit into any type of file.
| Whether it will "get traction" depends on whether the OS is smart
| enough to refuse to pass it to the exploitable surface.

| I know ANI exploits sprawl over to .CUR and perhaps .ICO, but I dunno
| about .JPG; I know that a previous WMF exploit did spread to .JPG

Attached is a perfect example.

It is a screen capture of an Avira submission report based upon files I submitted Yesterday.

"The file '0day.jpg' has been determined to be 'MALWARE'. Our analysts named the threat
EXP/Ani.Gen"

Hmm... in this XP SP2 PC, I tried renaming an .ANI as .JPG, and it
"opened" in the MS viewer that usually shows .JPG, which stated the
file wasn't displayable. I then tried the same in IView, which said
"this is an .ANI named as a .JPG; rename?"

The trouble with this sort of testing is that this PC has no default
action for .ANI files, so I can't tell whether the content within the
renamed .JPG was ever being handled as .ANI



-------------------- ----- ---- --- -- - - - -
Tip Of The Day:
To disable the 'Tip of the Day' feature...
-------------------- ----- ---- --- -- - - - -
.



Relevant Pages

  • Re: Can Exploit-ANIfile.c infect JPG files?
    ... | "opened" in the MS viewer that usually shows .JPG, ... I then tried the same in IView, ... | action for .ANI files, so I can't tell whether the content within the ... I think it is how the web page loads the JPG as content on a miscreant web ...
    (microsoft.public.security.virus)
  • RE: [Full-Disclosure] 2 vulnerabilities combine to auto execute received files in Nokia series 60 OS
    ... Wouldn't the phone try to open the jpg file as a picture, and not execute ... if you rename a .exe to ... extension such as jpg or an unknown extension, ...
    (Full-Disclosure)
  • Re: Renaming pics?
    ... You do not need to add it depending on how you rename. ... click on the Views icon and select Details to display file ... Scroll down and remove the check in the box "Hide Extension ...." ... You will now see the .jpg added to your file name. ...
    (microsoft.public.windowsxp.photos)
  • Re: jpgs
    ... You are simply forgetting to add the extension .jpg after the new name. ... If you need to batch rename and number, you can do this easily with XP. ... Copy the photos you want to place in a particular order into this new ... You can copy photos to this new folder from any photo folder you ...
    (microsoft.public.windowsxp.photos)
  • Re: help photos have vanished
    ... unknown file format i have no idea why or how this has happened the ... summary info is blank, i dont know much about computers can please ... Were these JPG files or raw camera files? ... So, what you do, you rename the ...
    (rec.photo.digital)