Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - for those that think jpgs are "safe"

 
Thread Tools Search this Thread
Old 11-11-2003, 11:36 PM   #1
Default for those that think jpgs are "safe"


open this in IE:

http://www.nero-online.org/norway.jpg


--
Colonel Flagg
http://www.internetwarzone.org/

Privacy at a click:
http://www.cotse.net

Q: How many Bill Gates does it take to change a lightbulb?
A: None, he just defines Darkness? as the new industry standard..."

"...I see stupid people."


Colonel Flagg
  Reply With Quote
Old 11-11-2003, 11:59 PM   #2
Jim Watt
 
Posts: n/a
Default Re: for those that think jpgs are "safe"
On Tue, 11 Nov 2003 18:36:37 -0500, Colonel Flagg
<> wrote:

>open this in IE:
>
>http://www.nero-online.org/norway.jpg


Hmmm I'm glad its harmless.

well spotted.
--
Jim Watt http://www.gibnet.com


Jim Watt
  Reply With Quote
Old 11-12-2003, 12:05 AM   #3
John E. Carty
 
Posts: n/a
Default Re: for those that think jpgs are "safe"
I clicked the link and IE comes up with a page with which says Last Measure
of Last Measure. What did you think I would see???

"Colonel Flagg" <> wrote in
message news:.. .
> open this in IE:
>
> http://www.nero-online.org/norway.jpg
>
>
> --
> Colonel Flagg
> http://www.internetwarzone.org/
>
> Privacy at a click:
> http://www.cotse.net
>
> Q: How many Bill Gates does it take to change a lightbulb?
> A: None, he just defines Darkness? as the new industry standard..."
>
> "...I see stupid people."





John E. Carty
  Reply With Quote
Old 11-12-2003, 12:24 AM   #4
John E. Carty
 
Posts: n/a
Default Re: for those that think jpgs are "safe"
So what did it do? I opened it in IE and just got a page with Last Measure
of Last Measure!

"Jim Watt" <_way> wrote in message
news:...
> On Tue, 11 Nov 2003 18:36:37 -0500, Colonel Flagg
> <> wrote:
>
> >open this in IE:
> >
> >http://www.nero-online.org/norway.jpg

>
> Hmmm I'm glad its harmless.
>
> well spotted.
> --
> Jim Watt http://www.gibnet.com





John E. Carty
  Reply With Quote
Old 11-12-2003, 12:36 AM   #5
Colonel Flagg
 
Posts: n/a
Default Re: for those that think jpgs are "safe"
In article <1Pesb.37537$>,
says...
> I clicked the link and IE comes up with a page with which says Last Measure
> of Last Measure. What did you think I would see???
>
> "Colonel Flagg" <> wrote in
> message news:.. .
> > open this in IE:
> >
> > http://www.nero-online.org/norway.jpg
> >
> >
> > --
> > Colonel Flagg
> > http://www.internetwarzone.org/
> >
> > Privacy at a click:
> > http://www.cotse.net
> >
> > Q: How many Bill Gates does it take to change a lightbulb?
> > A: None, he just defines Darkness? as the new industry standard..."
> >
> > "...I see stupid people."

>
>
>



it's an iframe exploit with a trojan in it.... I do hope you're not
infected and that you're using a good anti-virus.





from F-Secure Event Log:

Malicious code found in file C:\Documents and Settings\xxxxxx\Local
Settings\Temporary Internet Files\Content.IE5\72CZNTWT\norway[1].jpe.

Infection: Trojan.VBS.IFrame
Action: The file was deleted.




--
Colonel Flagg
http://www.internetwarzone.org/

Privacy at a click:
http://www.cotse.net

Q: How many Bill Gates does it take to change a lightbulb?
A: None, he just defines Darkness? as the new industry standard..."

"...I see stupid people."


Colonel Flagg
  Reply With Quote
Old 11-12-2003, 02:10 AM   #6
dkg_ctc
 
Posts: n/a
Default Re: for those that think jpgs are "safe"
"John E. Carty" <> wrote in
news:05fsb.37542$:

[top-post corrected]
> "Jim Watt" <_way> wrote in message
> news:...
>> On Tue, 11 Nov 2003 18:36:37 -0500, Colonel Flagg
>> <> wrote:
>>
>> >open this in IE:
>> >
>> >http://www.nero-online.org/norway.jpg

>>
>> Hmmm I'm glad its harmless.
>>
>> well spotted.

>
> So what did it do? I opened it in IE and just got a page with Last
> Measure of Last Measure!


Looks like it's just meant to be an annoyance which recursively opens
a page inside some IFRAMEs. The IFRAMEs then loads up pictures from
goatse.cx. (Don't bother going to goatse.cx...just take my word for
it that it's unpleasant.) I wouldn't call this a trojan, or even
anything that could be harmful...just something someone could use to
be annoying.


dkg_ctc
  Reply With Quote
Old 11-12-2003, 02:53 AM   #7
Colonel Flagg
 
Posts: n/a
Default Re: for those that think jpgs are "safe"
In article <Xns9430CD392B3F2dkgctc@130.133.1.4>,
says...
> "John E. Carty" <> wrote in
> news:05fsb.37542$:
>
> [top-post corrected]
> > "Jim Watt" <_way> wrote in message
> > news:...
> >> On Tue, 11 Nov 2003 18:36:37 -0500, Colonel Flagg
> >> <> wrote:
> >>
> >> >open this in IE:
> >> >
> >> >http://www.nero-online.org/norway.jpg
> >>
> >> Hmmm I'm glad its harmless.
> >>
> >> well spotted.

> >
> > So what did it do? I opened it in IE and just got a page with Last
> > Measure of Last Measure!

>
> Looks like it's just meant to be an annoyance which recursively opens
> a page inside some IFRAMEs. The IFRAMEs then loads up pictures from
> goatse.cx. (Don't bother going to goatse.cx...just take my word for
> it that it's unpleasant.) I wouldn't call this a trojan, or even
> anything that could be harmful...just something someone could use to
> be annoying.
>




sorry. wrong again. that was an *example* of what *could* happen if you
actually load it with something more malicious. use a proper anti-virus
and it will find it.




--
Colonel Flagg
http://www.internetwarzone.org/

Privacy at a click:
http://www.cotse.net

Q: How many Bill Gates does it take to change a lightbulb?
A: None, he just defines Darkness? as the new industry standard..."

"...I see stupid people."


Colonel Flagg
  Reply With Quote
Old 11-12-2003, 03:12 AM   #8
donutbandit
 
Posts: n/a
Default Re: for those that think jpgs are "safe"
Colonel Flagg <> wrote in
news::

> open this in IE:
>
> http://www.nero-online.org/norway.jpg


And does this work if Install On Demand is not enabled?


donutbandit
  Reply With Quote
Old 11-12-2003, 03:14 AM   #9
Mimic
 
Posts: n/a
Default Re: for those that think jpgs are "safe"
"Colonel Flagg" <> wrote in
message news:.. .
> In article <1Pesb.37537$>,
> says...
> > I clicked the link and IE comes up with a page with which says Last

Measure
> > of Last Measure. What did you think I would see???
> >
> > "Colonel Flagg" <> wrote in
> > message news:.. .
> > > open this in IE:
> > >
> > > http://www.nero-online.org/norway.jpg
> > >
> > >
> > > --
> > > Colonel Flagg
> > > http://www.internetwarzone.org/
> > >
> > > Privacy at a click:
> > > http://www.cotse.net
> > >
> > > Q: How many Bill Gates does it take to change a lightbulb?
> > > A: None, he just defines Darkness? as the new industry standard..."
> > >
> > > "...I see stupid people."

> >
> >
> >

>
>
> it's an iframe exploit with a trojan in it.... I do hope you're not
> infected and that you're using a good anti-virus.
>



No and No ;D

Also, it did nuffin but b0rked my MSIE heh, isnt it just a modified version
ofm y :
http://alt26.go.ro/execute.jpg ?
That has been featured in the in millions of threads we;ve had on whether
jpgs are dangerous ?


--
Mimic

"Without Knowledge you have fear, With fear you create your own nightmares."
"There are 10 types of people in this world. Those that understand Binary,
and those that dont."
"C makes it easy to shoot yourself in the foot. C++ makes it harder, but
when you do, it blows away your whole leg"





Mimic
  Reply With Quote
Old 11-12-2003, 03:47 AM   #10
Colonel Flagg
 
Posts: n/a
Default Re: for those that think jpgs are "safe"
In article <bos8ee$95g$>, says...
> Colonel Flagg <> wrote in
> news::
>
> > open this in IE:
> >
> > http://www.nero-online.org/norway.jpg

>
> And does this work if Install On Demand is not enabled?
>



it works if you're not a guru and you haven't made a change to the
security of your IE... just like 90% or more end-users out there.

the people writing this stuff isn't targetting guru's, they're
targetting the millions of people out there that are wide open to
exploitation. quit thinking just about yourself and yours, start
considering the other folks out there that have no clue.



--
Colonel Flagg
http://www.internetwarzone.org/

Privacy at a click:
http://www.cotse.net

Q: How many Bill Gates does it take to change a lightbulb?
A: None, he just defines Darkness? as the new industry standard..."

"...I see stupid people."


Colonel Flagg
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
jpgs and jpegs dont show up in thumbnail view Kingalfonso General Help Related Topics 0 12-06-2007 12:30 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46