In theory we could block links to JPGs in HTML based email but that doesn't help us with people just browsing the Internet.
> -----Original Message----- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of Markus Gufler > Sent: Saturday, September 25, 2004 2:59 AM > To: [EMAIL PROTECTED] > Subject: RE: [Declude.Virus] F-Prot/GDI+ FYI > Importance: High > > > > I expect we'll have a new version on Monday to take care of this > > (unless some start spreading before then, in which case we > would have > > a new version ready ASAP). > > Well after reading > http://www.heise.de/newsticker/meldung/51459 (german) I think > it's time to release something! > > In short: > There is available a small _public_ tool allowing to anyone > who can move a mouse > > 1.) to select an image > 2.) enter a external URL for the EXE that should be loaded > 3.) save the malicous exe (whatever you want) on a webspace > > And voil�: There is a new JPEG-Exploit image for your personal use. > > > In the mid of the article there is a list of AV-Engines able > to identify this exploit. But there is also a note that many > Desktop-AV-Engines has set to skip GIF/JPEG images for > scanning. So enable this if you want be protected. > Keep also in mind that there are engines like F-Prot having > auto-updaters but not auto-upgrades. An engine prior to 3.15b > installed on a desktop with enabled and working updater will > not catch this images as exploit. > > > As I can understand there are many situations where we can't > scan for jpeg images. For example if the JPEG is not part of > the message but simply linked as an external image. (<img > src= http://www.jpeg-exploit.com/image.jpg >) > > Or also if there is a simply link in the body beside a short > text: "Cool picture... :-)" > > If we would realy prepared we should think about some > settings allowing us to filter for certain suspicious content. > > SKIPEXT JPEG is one. > > Another one maybe in junkmail if it should become realy necessary: > HOLD messages containing links to external images? > SPAMCHK is able to add extra points for external linked images: > "ImageLinks=25" will add 25 points for external linked image tags. > I know not realy usable but what if there comes up a wave of > jpeg-exploit-messages? > We all know that virus and spam has become an unit last > months. It's unbelievable that thus people can resist using > this tecnique to distribute their malware. > > Maybe an external test able to identify all external linked > images, downloading and scaning them on the mailserver? > Probably this will cause a big load on mid and high traffic > servers but if the tool is smart enough it will keep a > whitelist of already scanned image URLs. (most external > images should be linked in automaticaly gernerated > bulk-mailings) > > In any case it would be very usefull to have the ability to > MOVE or COPY messages describbed above in separate folders > for further investigation or also for temporary holding them > until we're sure that it will not cause problems on client > side. (and I will not stop asking for as long as I have to > use this filter software!) > > Markus > > > > > --- > [This E-mail was scanned for viruses by Declude Virus > (http://www.declude.com)] > > --- > This E-mail came from the Declude.Virus mailing list. To > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and > type "unsubscribe Declude.Virus". The archives can be found > at http://www.mail-archive.com. > --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
