Scott,

If possible, please have the JPG vulnerability detection work independently of the SKIPEXT setting (not sure if it does already). I'm not looking forward to having to scan every JPG for this vulnerability.

Another thing that might not be known or not discussed to a great extent is what other extensions might this also affect. JPG and JPEG are fairly obvious, but does the same exploitable code handle other things such as GIF's, PNG's, BMP's, etc.? I'm not sure that this matters with the vulnerability detection, but it is definitely something to look out for. Could it be possible that even something as simple as changing the Content-Type: for a txt attachment could cause that file to be executed by the affected code?

This thing could be very, very bad. This has got to be the most convoluted patch that Microsoft has ever sent out for such a thing (it even confused me), and this thing seems absolutely ripe for viruses that source the files off of other sites, so merely linking to an image could cause harm to computers that receive them. Given server side redirection, any URL extension could come back as a JPG with the proper MIME encoding. How about a worm that spreads across Web servers similar to Code Red which then modifies images so that they contain the virus? Bad, bad, bad, bad. I don't think there are any legitimate contingency plans for something like this if it is what I think it is. Infected JPG's are one of the few worst-case scenarios.

Fingers crossed, hoping that the high school kids are all busy with school for now.

Matt



R. Scott Perry wrote:


> Without blocking all .JPG files, nothing. The problem is that there is a
> lack of information on how to detect such .JPG's.


You can find details about the exploit at
http://www.microsoft.com/technet/security/bulletin/MS04-028.mspx


Thanks for the URL -- although good 'ole Microsoft does specify how to detect them there, a Google search on the E-mail address of the person they thanked for discovering the vulnerability led me to the details.

I expect we'll have a new version on Monday to take care of this (unless some start spreading before then, in which case we would have a new version ready ASAP).

-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Ultra reliable virus detection and the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.



-- ===================================================== MailPure custom filters for Declude JunkMail Pro. http://www.mailpure.com/software/ =====================================================

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to