> I expect we'll have a new version on Monday to take care of > this (unless some start spreading before then, in which case > we would have a new version ready ASAP).
Well after reading http://www.heise.de/newsticker/meldung/51459 (german) I think it's time to release something! In short: There is available a small _public_ tool allowing to anyone who can move a mouse 1.) to select an image 2.) enter a external URL for the EXE that should be loaded 3.) save the malicous exe (whatever you want) on a webspace And voil�: There is a new JPEG-Exploit image for your personal use. In the mid of the article there is a list of AV-Engines able to identify this exploit. But there is also a note that many Desktop-AV-Engines has set to skip GIF/JPEG images for scanning. So enable this if you want be protected. Keep also in mind that there are engines like F-Prot having auto-updaters but not auto-upgrades. An engine prior to 3.15b installed on a desktop with enabled and working updater will not catch this images as exploit. As I can understand there are many situations where we can't scan for jpeg images. For example if the JPEG is not part of the message but simply linked as an external image. (<img src= http://www.jpeg-exploit.com/image.jpg >) Or also if there is a simply link in the body beside a short text: "Cool picture... :-)" If we would realy prepared we should think about some settings allowing us to filter for certain suspicious content. SKIPEXT JPEG is one. Another one maybe in junkmail if it should become realy necessary: HOLD messages containing links to external images? SPAMCHK is able to add extra points for external linked images: "ImageLinks=25" will add 25 points for external linked image tags. I know not realy usable but what if there comes up a wave of jpeg-exploit-messages? We all know that virus and spam has become an unit last months. It's unbelievable that thus people can resist using this tecnique to distribute their malware. Maybe an external test able to identify all external linked images, downloading and scaning them on the mailserver? Probably this will cause a big load on mid and high traffic servers but if the tool is smart enough it will keep a whitelist of already scanned image URLs. (most external images should be linked in automaticaly gernerated bulk-mailings) In any case it would be very usefull to have the ability to MOVE or COPY messages describbed above in separate folders for further investigation or also for temporary holding them until we're sure that it will not cause problems on client side. (and I will not stop asking for as long as I have to use this filter software!) Markus --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
