GDI+ JPEG exploit worse than first thought
Finjan Software has exposed a new dangerous exploit that significantly increases the damage potential of the so-called "JPEG vulnerability" which was published by Microsoft on September 16, 2004 (Microsoft’s security bulletin MS04-028).
An attacker can remotely take over a user’s PC by simply having the user browse a web page that contains a malformed image file using Internet Explorer. The previous vulnerability did not expose Internet Explorer to this attack.
As previously reported, Microsoft’s GDI+ JPEG decoder DLL file (gdiplus.dll) contains a vulnerability that allows an attacker to execute arbitrary code remotely on Windows operating systems. In order to be attacked though the user had to obtain the contaminated image file by means of Email, or to otherwise save it to the local disk, and then view the image by one of the vulnerable Microsoft software products.
In other words, the previous vulnerability required some degree of "social engineering" to make the user perform an operation which triggers the attack. Conversely, this new vulnerability affects any Internet Explorer user who merely browses a malicious page.
Note that this same vulnerability affects JPEG image files even if they have been renamed with the following file extensions: - .bmp
.dib
.emf
.gif
.ico
.jfif
.jpe
.jpeg
.jpg
.png
.rle
.tif
.tiff
.wmf
More info:
jpeg exploit vicious and lethal
I cant believe the damage that this vulnerability has caused me. At the point now where a complete reformat and clean installation is looking like my only option for regaining control of my system. Soooo dont want to do it as I study online and have everything including family pics etc on here.
Is there any hope of getting my pc back??? I cant even reinstall my nortons so I currently i have no antivirus protection.
Re: jpeg exploit vicious and lethal
Quote:
Originally posted by rogue_red
At the point now where a complete reformat and clean installation is looking like my only option for regaining control of my system. ...
Recommend trying this first:- Create a new folder named C:\HijackThis
- Download HijackThis version 1.98.2 from http://www.majorgeeks.com/download3155.html and download it into your C:\HijackThis folder
- Extract the downloaded C:\HijackThis\hijackthis.zip file into C:\HijackThis
- Launch the C:\HijackThis\hijackthis.exe program and click "Scan"
- When it's done, click "Save Log" and save it as C:\HijackThis\hijackthis.log
- The saved log file will automatically come up in Notepad. Click "Edit|Select All" then "Edit|Copy"
- Start a new thread in our HijackThis Logfile forum: http://discussions.virtualdr.com/for...php?forumid=71
- Click once inside the Message box, then press [Ctrl-V] (or click Edit|Paste) to paste the contents of your hijackthis.log file into the message
- Add a Subject and any comments to your message and click "Submit New Thread"
- Hopefully one of our HijackThis Logfile experts will be along shortly to analyze your logfile and help you rid your PC of any malware