Hackers Smell Blood In Common Windows Interface

rik

OSNN Addict
Joined
22 Mar 2004
Messages
115
Article in it's original form and vulnerability scanner can be found here.


By Dan Neel, CRN
11:46 AM EDT Fri. Sep. 24, 2004
Since Wednesday, a rising tide of attacks which could precede the arrival of a new worm have been attempting to exploit the Windows GDI (graphic device interface) for JPEG files, according to the Internet Storm Center, Bethesda, Md.

GDIs handle and transmit graphics to output devices like monitors and printers. Hackers are attempting to bombard the JPEG GDIs to achieve a buffer overrun that could allow for the execution of malicious code.

Microsoft made the vulnerability public last week with the issuance of a Microsoft Security Bulletin MS04-028.

Microsoft rates the severity of the threat as critical and advises users to apply an update immediately. Updates and their related Windows operating-system versions can be found here.

Officials at the Internet Storm Center warned "We expect a rapid development of additional exploits over the next few days."

The Storm Center also cautioned that many non-Microsoft programs are also vulnerable to the JPEG GDI exploits, and has issued a link to a free scanner download to detect vulnerable GDIs. That scanner can be found here.
 
IIRC, the Athlon64 CPU provides protections against buffer overruns on the hardware level. Would this be enough to negate this threat?
 

Members online

No members online now.

Latest profile posts

Also Hi EP and people. I found this place again while looking through a oooollllllldddd backup. I have filled over 10TB and was looking at my collection of antiques. Any bids on the 500Mhz Win 95 fix?
Any of the SP crew still out there?
Xie wrote on Electronic Punk's profile.
Impressed you have kept this alive this long EP! So many sites have come and gone. :(

Just did some crude math and I apparently joined almost 18yrs ago, how is that possible???
hello peeps... is been some time since i last came here.
Electronic Punk wrote on Sazar's profile.
Rest in peace my friend, been trying to find you and finally did in the worst way imaginable.

Forum statistics

Threads
62,015
Messages
673,494
Members
5,623
Latest member
AndersonLo
Back