[NF] Strange File Behavior

2007-04-04 Thread Hal Kaplan
Someone brought in a machine that hangs every time a particular file is referenced. I am not sure exactly what referenced means. It definitely includes reading the file and it appears to include even listing it in Windows Explorer Details view and also deleting it. It is an 8K file that wound

Re: [NF] Strange File Behavior

2007-04-04 Thread Malcolm Greene
Hal, Sounds like a corrupt JPG file that Windows is trying to render. Corruption could be unintentional or an intentional way to exploit known security flaws in GDIPLUS.DLL. You can google GDIPLUS.DLL exploits for more info. Malcolm ___ Post

Re: [NF] Strange File Behavior

2007-04-04 Thread Ted Roche
On 4/4/07, Hal Kaplan [EMAIL PROTECTED] wrote: It is an 8K file that wound up in Temporary Internet Files (yes, IE 6) and has a .jpg extension. There's a number of well-documented jpg exploits out in the wild. Best thing to do would be to boot with another OS off disk (Knoppix is good for this)