ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

iDefense launches format testing kit

Joris Evers CNET News.com

Published: 29 Jul 2005 16:50 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

New tools could help bug hunters find vulnerabilities in popular file formats, such as the JPEG and GIF image formats.

Flaws in how applications handle those file formats are drawing interest among security researchers, according to speakers at the Black Hat security conference in Las Vegas.

Some of those bugs can be serious: a victim's PC could be hijacked by simply viewing an image on a Web site or in an email. Microsoft issued three "critical" security bulletins earlier this month, two related to file format flaws.

There could be a significant increase in the discovery of such flaws. iDefense, a security intelligence company, is making available tools that let researchers automate the discovery of file format vulnerabilities. The company released the tools Thursday in conjunction with Black Hat.

"I really do think this is a low-hanging-fruit area for vulnerabilities," Michael Sutton, a lab director at iDefense, said in a presentation at Black Hat. iDefense itself has found several file format flaws. "We really did not work hard to find the vulnerabilities. We did work hard on the tools."

The tools, for Windows and Linux, can automatically tweak files bit-for-bit and then open the malformed file in any application. If an error is found in the opening of the file, the tool will capture the error data. The researcher can then investigate that data, which may point to a vulnerability, according to iDefense.

"These are not tools where you just push a button and the vulnerability shows up," Sutton said. "It pinpoints an exception and then you as a researcher have to investigate."

The tools, called FileFuzz for Windows and SpikeFile and NotSpikeFile for Linux, could be used with malicious intent, but iDefense hopes they will be used to help protect users. "These don't have to be used for evil purposes. They can be used for good, and I hope they will be," Sutton said.

One Black Hat attendee said he expects only well-intended security researchers to use the tools. "These tools only discover whether an application and a format could have a vulnerability," said Joshua Feldman, a security engineer at Science Applications International. "This is definitely for the white hats."

The tools are open source, which means others can expand and improve upon them. They tools available for download from the iDefense site.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
54 out of 84 people found this useful


Full Talkback thread

0 comments

Related Jobs

Linux/Unix/ Red- Hat/ Networking/ TCP/IP/ Oracle/West London/40k

Linux/Unix/ Red- Hat/ Are you a Linux Systems Administrator/ NOC Engineer looking for a new challenge ? Do you want to work for the world leading ...

Linux Engineer - Red Hat Enterprise Linux / RHEL4 - Bristol

We are looking for solid support engineering experience with Linux / Red Hat Enterprise Linux / RHEL4 Additional skills will be: 1) Clustering/HPC ...

Systems Administrator

Payroll users service requirements - Assist in the provision of a user Support facility - Monitor receipt of data against predetermined timescales ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation