Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 09-18-2004, 02:01
zdensys
 
Posts: n/a
Visit the link below for the list of affected program.
It's advisable to run both WU and OU to patch this.

Code:
http://www.microsoft.com/security/bulletins/200409_jpeg_tool.mspx
Reply With Quote
  #2  
Old 09-18-2004, 02:53
�XC�PTiON™
 
Posts: n/a
This has to one of the worst Windows Update "experiences". Unlike other updates, which clearly confirm that you are updated or not.

This one requires you to first install an ActiveX control under the premise that it will scan your system for affected graphics programs.

After installing the control, all you get is a message to go back to windows update.

I'm a little puzzled, does this control do anything about the other programs that may be affected by the vulnerability or not?
Reply With Quote
  #3  
Old 09-18-2004, 05:29
tbone
 
Posts: n/a
I went in circles for a while with this one, too. Apparently, this bug is present in multiple Microsoft products. The GDI+ library has it, but only for Windows XP and server 2003, as well the version that comes with the SDK. However, most newer versions of Office as well as IE6 and the .NET framework contain the bug, too. So pretty much any Windows system will have this *somewhere*.

The only place I could actually find downloadable updates to patch this was from the corresponding technet article:

http://www.microsoft.com/technet/security/bulletin/MS04-028.mspx

The detection tool on WU doesn't appear to damn thing except point you to their web site without so much as telling you which components it found on your system, so you'll just have to figure that part out yourself. I'm assuming that each one needs to be updated.
Reply With Quote
  #4  
Old 09-27-2004, 00:38
Seventh
 
Posts: n/a
Quote:
hxxp://packetstormsecurity.org/0409-exploits/jpegcompoc.zip
Proof of concept exploit for the recent JPEG buffer overrun vulnerability that crashes any Windows XP system that has not been patched for this flaw.
The JPEG file above crashed my "Windows Picture and Fax Viewer" on my XP box w/o SPx and explorer restarted. but it didnt crashed my IE6.

Quote:
hxxp://packetstormsecurity.org/0409-exploits/ms04-028.sh
Proof of concept local exploit that creates a JPEG image to test for the buffer overrun vulnerability discovered under Microsoft Windows. Shellcode and valid addresses have been removed.
Reply With Quote
  #5  
Old 09-28-2004, 17:07
archaios
 
Posts: n/a
JPEG buffer overflow?

This is a prime example of why the whole development methodology in use by Microsoft must be questioned. The existence of an (extremely simplistic) buffer overflow due to a patent lack of bounds checking is an appalling reflection on this software monolith. The aptitude of their QA team resounds hollowly in my mind...

-archaios
Reply With Quote
  #6  
Old 09-28-2004, 22:52
amnesia
 
Posts: n/a
hxxp://www.easynews.com/virus.html

Might be interesting to work on the jpeg specimen. POC included in the link as well.
Reply With Quote
  #7  
Old 10-01-2004, 17:59
pll823
 
Posts: n/a
my computer has infected with this virus,all Documents has been gone
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Beware of Fake Exetools Site chessgod101 General Discussion 0 06-23-2014 06:25


All times are GMT +8. The time now is 18:17.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )