> I expect we'll have a new version on Monday to take care of 
> this (unless some start spreading before then, in which case 
> we would have a new version ready ASAP).

Well after reading http://www.heise.de/newsticker/meldung/51459 (german) I
think it's time to release something!

In short:
There is available a small _public_ tool allowing to anyone who can move a
mouse 

1.) to select an image
2.) enter a external URL for the EXE that should be loaded
3.) save the malicous exe (whatever you want) on a webspace

And voil�: There is a new JPEG-Exploit image for your personal use.


In the mid of the article there is a list of AV-Engines able to identify
this exploit. But there is also a note that many Desktop-AV-Engines has set
to skip GIF/JPEG images for scanning. So enable this if you want be
protected.
Keep also in mind that there are engines like F-Prot having auto-updaters
but not auto-upgrades. An engine prior to 3.15b installed on a desktop with
enabled and working updater will not catch this images as exploit.


As I can understand there are many situations where we can't scan for jpeg
images. For example if the JPEG is not part of the message but simply linked
as an external image. (<img src= http://www.jpeg-exploit.com/image.jpg >)

Or also if there is a simply link in the body beside a short text: "Cool
picture... :-)"

If we would realy prepared we should think about some settings allowing us
to filter for certain suspicious content.

SKIPEXT JPEG is one.

Another one maybe in junkmail if it should become realy necessary:
HOLD messages containing links to external images? 
SPAMCHK is able to add extra points for external linked images:
"ImageLinks=25" will add 25 points for external linked image tags.
I know not realy usable but what if there comes up a wave of
jpeg-exploit-messages?
We all know that virus and spam has become an unit last months. It's
unbelievable that thus people can resist using this tecnique to distribute
their malware.

Maybe an external test able to identify all external linked images,
downloading and scaning them on the mailserver?
Probably this will cause a big load on mid and high traffic servers but if
the tool is smart enough it will keep a whitelist of already scanned image
URLs. (most external images should be linked in automaticaly gernerated
bulk-mailings)

In any case it would be very usefull to have the ability to MOVE  or COPY
messages describbed above in separate folders for further investigation or
also for temporary holding them until we're sure that it will not cause
problems on client side. (and I will not stop asking for as long as I have
to use this filter software!)

Markus




---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to