ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

JPEG exploit could beat antivirus, says expert

Dan Ilet ZDNet.co.uk

Published: 29 Sep 2004 14:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Anti-virus software looks as if it will struggle to protect corporate networks from the latest Windows vulnerability - innocent looking JPEG files that contain security attacks.

According to director of antivirus research for F-Secure Mikko Hypponen, antivirus software will strain to find JPEG malware because by default it only searches for .exe files.

"Normal antivirus software by default will not detect JPEGs," said Hypponen. "You can set your antivirus scanner to look for JPEG, but the trouble is that you can change the file extension on a JPEG to so many things."

There are around 11 similar file extensions that JPEGs can be changed to, such as .icon or .jpg2. Hypponen said that this would make searching for malicious JPEGs even more difficult because it could take up a significant amount of valuable processor power.

Internet Explorer processes JPEGs before it caches them. That could also mean that desktops would become infected before antivirus software had a chance to work.

"This means that it is not enough to scan at the desktop," said Hypponen. "You have to scan at the gateway, but this will put a huge load on your bandwidth."

Hypponen said that he expected a virus attack using the exploit to occur soon: "There has been so much interest in this vulnerability that someone is bound to do this. But saying that, there was a similar vulnerability found two months ago in Bitmaps, and no one has exploited that yet."

Yesterday code that exploits the way Microsoft Windows processes Jpegs was posted to U.S. newsgroup Easynews. Hypponen wrote on the F-Secure weblog that this was not a virus because it had no way of spreading. In order for the code to infect a machine, a user must download the image it purports to be and view it in Windows Explorer.

Yesterday Microsoft hit back at critics over its handling of the vulnerability. In a prepared press statement, it said: "Microsoft does not consider this a high risk to customers given the amount of user action required to execute the attack and is not currently aware of any significant customer impact. We will continue to investigate the situation and provide customers with additional resources and guidance as necessary."

Additional reporting by Rob Lemos of ZDNet UK sister site CNET News.com

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
81 out of 170 people found this useful



Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

PC Build Engineer

My client requires 3 PC build engineers with excellent Microsoft Windows experience for a migration project. The ideal candidate should be available ...

Systems Administrator / 2nd Line Support, Deeside, 20,000

The successful candidate will support Windows Server 2003, Backup Exec, Exchange, Firewall, VPN, Antivirus/Antispam, Active Directory & Group Policy. ...

Helpdesk Manager - Technologies client - London City 40,000

Excellent opportunity for an experienced Helpdesk Manager to join my technologies client based in the City London, to manage a Helpdesk of 4 support ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment