In theory we could block links to JPGs in HTML based email but that doesn't
help us with people just browsing the Internet.



> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] On Behalf Of Markus Gufler
> Sent: Saturday, September 25, 2004 2:59 AM
> To: [EMAIL PROTECTED]
> Subject: RE: [Declude.Virus] F-Prot/GDI+ FYI
> Importance: High
>
>
> > I expect we'll have a new version on Monday to take care of this
> > (unless some start spreading before then, in which case we
> would have
> > a new version ready ASAP).
>
> Well after reading
> http://www.heise.de/newsticker/meldung/51459 (german) I think
> it's time to release something!
>
> In short:
> There is available a small _public_ tool allowing to anyone
> who can move a mouse
>
> 1.) to select an image
> 2.) enter a external URL for the EXE that should be loaded
> 3.) save the malicous exe (whatever you want) on a webspace
>
> And voil�: There is a new JPEG-Exploit image for your personal use.
>
>
> In the mid of the article there is a list of AV-Engines able
> to identify this exploit. But there is also a note that many
> Desktop-AV-Engines has set to skip GIF/JPEG images for
> scanning. So enable this if you want be protected.
> Keep also in mind that there are engines like F-Prot having
> auto-updaters but not auto-upgrades. An engine prior to 3.15b
> installed on a desktop with enabled and working updater will
> not catch this images as exploit.
>
>
> As I can understand there are many situations where we can't
> scan for jpeg images. For example if the JPEG is not part of
> the message but simply linked as an external image. (<img
> src= http://www.jpeg-exploit.com/image.jpg >)
>
> Or also if there is a simply link in the body beside a short
> text: "Cool picture... :-)"
>
> If we would realy prepared we should think about some
> settings allowing us to filter for certain suspicious content.
>
> SKIPEXT JPEG is one.
>
> Another one maybe in junkmail if it should become realy necessary:
> HOLD messages containing links to external images?
> SPAMCHK is able to add extra points for external linked images:
> "ImageLinks=25" will add 25 points for external linked image tags.
> I know not realy usable but what if there comes up a wave of
> jpeg-exploit-messages?
> We all know that virus and spam has become an unit last
> months. It's unbelievable that thus people can resist using
> this tecnique to distribute their malware.
>
> Maybe an external test able to identify all external linked
> images, downloading and scaning them on the mailserver?
> Probably this will cause a big load on mid and high traffic
> servers but if the tool is smart enough it will keep a
> whitelist of already scanned image URLs. (most external
> images should be linked in automaticaly gernerated
> bulk-mailings)
>
> In any case it would be very usefull to have the ability to
> MOVE  or COPY messages describbed above in separate folders
> for further investigation or also for temporary holding them
> until we're sure that it will not cause problems on client
> side. (and I will not stop asking for as long as I have to
> use this filter software!)
>
> Markus
>
>
>
>
> ---
> [This E-mail was scanned for viruses by Declude Virus
> (http://www.declude.com)]
>
> ---
> This E-mail came from the Declude.Virus mailing list.  To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".    The archives can be found
> at http://www.mail-archive.com.
>


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to