ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

IM photos could turn nasty

Dan Ilet ZDNet.co.uk

Published: 19 Oct 2004 16:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts are warning users that hackers can use JPEG profile photos on instant messenger to attack networks.

According to security company WhiteHat UK, hackers can use an exploit in JPEGs, which enables them to embed malicious code into profile photos on instant messenger. When a recipient sees the photo on their instant messenger (IM) client, it can cause an exploit code, such as a Trojan or worm, to automatically execute.

"Potentially, the photos that are sent with instant messenger could be used with the Microsoft JPEG exploits already out there," said Jason Hart, security director for WhiteHat UK. "Essentially you can say it's the same as any JPEG using the IM protocol as a portal to come through."

IM travels on port 80, which is often regarded as a trusted channel because Internet traffic also uses it. Hart said that any company using IM that allows JPEGs was open to attck: "The majority of times, desktop computers are the last to be secured by big corporations. So a company with instant messenger enabled could be penetrated. A computer could be exploited, and that would bypass all controls within a corporation."

The JPEG exploit can work on a variety of image related files, such as .gif or .icon, said Mikko Hypponen of F-Secure. He added that it would be hard to detect viruses in JPEGs because antivirus software mainly searches for .exe files.

Hart advised companies should secure their IM environment: "The message is to disable instant messenger unless you have the added security controls."

Last week, Hart warned that hackers could also use an nmap bot over IM to carry out denial-of-service attacks on companies.

In September, two reports of a worm that downloaded from Web sites linked to AOL's Instant Messenger were reported to US security body SANS.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
37 out of 83 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

SAP Consultant - Senior Manager - M & A Strategy - London

Services (FS); Technology, Media & Telecommunications (TMT); FMCG, Consumer Business, or Energy & Utilities Services; Ability to exploit an ...

Planning & Controls Analyst

Planning & Controls Analyst IT Services Bradford, West Yorkshire Excellent plus benefits This is the role for someone who wants to become a ...

Quality Lead - Unilever - Level C-00055185

In depth exposure to a high profile global venture. Support implementation coordination for agreed QPI, SOX and Security controls Manage one quality ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment