Go to Unsolved Mystery Publications Main Index Go to Free account page
Go to frequently asked mystery questions Go to Unsolved Mystery Publications Main Index
Welcome: to Unsolved Mysteries 1 2 3
 
 New Mystery StoryNew Unsolved Mystery UserLogon to Unsolved MysteriesRead Random Mystery StoryChat on Unsolved MysteriesMystery Coffee housePsychic Advice on Unsolved MysteriesGeneral Mysterious AdviceSerious Mysterious AdviceReplies Wanted on these mystery stories
 




Show Stories by
Newest
Recently Updated
Wanting Replies
Recently Replied to
Discussions&Questions
Site Suggestions
Highest Rated
Most Rated
General Advice
Ancient Beliefs
Angels, God, Spiritual
Conspiracy Theories
Debates
Dreams
Dream Interpretation
Embarrassing Moments
ESP
General Interest
Ghosts/Apparitions
Hauntings
History
Horror
Household tips
Human Interest
Humor / Jokes
In Recognition of
Lost Friends/Family
Missing Persons
Mysterious Happenings
Mysterious Sounds
Near Death Experience
Ouija Mysteries
Out of Body Experience
Party Line
Philosophy
Prayers
Predictions
Psychic Advice
Quotes
Religious / Religions
Reviews
Riddles
Sci-fi
Serious Advice
Strictly Fiction
Unsolved Crimes
UFOs
Urban Legends
USM Events and People
USM Games
In Memory of
Search Stories:


Stories By AuthorId:


Google
Web Site   

~Security researchers say JPEG virus imminent~~*Phe*~

  Author:  609  Category:(Interesting) Created:(9/29/2004 11:42:00 AM)
This post has been Viewed (595 times)

By Robert Lemos CNET News.com September 28, 2004, 1:02 PM

A Trojan horse that exploits a recent critical flaw in Microsoft Windows' handling of JPEG images has been posted to several newsgroups, but it has no way to spread, security experts said Tuesday.

Though the code only threatens visitors to the newsgroups where the malicious programs--hidden in images--are posted, antivirus experts continue to warn that it's a short step from such code to an effective computer virus.

"We are getting closer and closer to an exploit that could be turned into a worm," said Oliver Friedrichs, senior manager with security-software maker Symantec's incident response group.

The posting of the code hidden in a JPEG graphic is the latest in a series of events that security experts have widely predicted: A serious flaw in the widespread Microsoft Windows operating system and software was found; code that showed how to take advantage of the flaw has been published; and a tool to automatically create malicious JPEG images is continually being refined, Friedrichs said.

The latest code, found Tuesday by online newsgroup access provider Easynews, actually requires the victim to download the false image and view it in Windows Explorer in order for his or her system to be infected, Friedrichs said. That should severely limit the number of computers that are compromised by the program.

Microsoft also pooh-poohed any danger represented by the program.

"Microsoft does not consider this a high risk to customers given the amount of user action required to execute the attack and is not currently aware of any significant customer impact," the software giant said in a statement. "We will continue to investigate the situation and provide customers with additional resources and guidance as necessary."

Easynews announced that a program that scans images posted to Internet newsgroups had registered several hits, finding false JPEG images embedded with malicious code.

Mike Minor, Easynews' chief technology officer, said he had been monitoring the Usenet feed for 36 hours before discovering an infected image. "We couldn't find any other trace of any other posts from that IP address," Minor said. Easynews has not spotted any infected JPEGs since the two it identified late Sunday.

The code, which Easynews called a virus, does not have any mechanism to spread, antivirus-software company F-Secure said in its Weblog.

"These JPEGs did not replicate, so this is not a virus," the company said. "Apparently they tried to use these JPEGs to download Trojan (horse programs) to vulnerable computers, but the download sites should be down by now."

The code posted to Easynews, which Symantec has dubbed Trojan.Moo, was apparently created with the automated tool released by several hackers. The tool, known as the JPEG of Death creation kit, is constantly being updated by its creators and will likely be able to generate viruses soon, said antivirus experts.

"I think because the source code for the kit was released, we will see people that take that source code and create new versions," said Craig Schmugar, virus research manager for security software maker McAfee.

Both McAfee and Symantec have generic detection in their antivirus software for images that contain malicious code.

The JPEG flaw affects various versions of at least a dozen Microsoft software applications and operating systems, including Windows XP, Windows Server 2003, Office XP, Office 2003, Internet Explorer 6 Service Pack 1, Project, Visio, Picture It and Digital Image Pro. The software giant has a full list of affected applications in the advisory on its Web site. Windows XP Service Pack 2, which is still being distributed to many customers' computers, is not vulnerable to the flaw.

CNET News.com's Declan McCullagh contributed to this report.

How it changed my life:

I got this story from zdnet.com

You can join Unsolved Mysteries and post your own mysteries or
interesting stories for the world to read and respond to Click here

Scroll all the way down to read replies.

Show all stories by   Author:  609 ( Click here )

Spring is coming

Replies:      
Date: 9/29/2004 6:45:00 PM  From Authorid: 44960    Thank you Phe, for sharing this information with us. (((PrissieHuggzz)))  

Find great Easter stories on Angels Feather
Information Privacy policy and Copyrights

Renasoft is the proud sponsor of the Unsolved Mystery Publications website.
See: www.rensoft.com Personal Site server, Power to build Personal Web Sites and Personal Web Pages
All stories are copyright protected and may not be reproduced in any form, except by specific written authorization
Other Cool Sites:
demo.quickebay.com 
demo.webjetengine.com 
demo.netjetengine.com 
demo.totallyon.com 
demo.usmpg.com 
demo.personalebay.com 
demo.encyclopedia-of-knowledge.com 
demo.mysterieschannel.com 
demo.creativeanger.com 
demo.businessmoneybusiness.com 
Awesome Free Web Graphics 
Favorite Grapic Quotes 
Greetings in Glittery Text 
Your name in Glittery Text 
www.thehomebusinessindex.com 
www.diet-food-weightloss-health.com 
www.investingandinvestments.com 
www.cancerinformationworld.com 
www.datinglovematchmaking.com 
www.creditinformationworld.com 
www.insurancelinksdirect.com 
www.ilovemysteries.com 
www.casinopokergambleing.com 
www.make-money-while-sleeping.com 
www.vacation-travel-cruse-deals-information.com 


.

Pages:512 397 1023 1406 175 18 334 1346 732 812 560 1249 1283 379 198 1322 1305 1590 1134 1206 375 611 1369 999 1499 931 943 1083 431 580 258 747 1005 561 409 414 454 872 701 1061 739 131 1380 853 1072 402 357 160 443 1217 1529 585 541 407 1111 1189 1083 120 1554 1516 338 451 274 217 850 1464 1176 477 1167 822 981 1438 762 1402 1545 1226 559 133 191 373 659 1209 1231 845 65 923 691 665 8 86