[36850] in bugtraq

home help back first fref pref prev next nref lref last post

GDI+ JPEG exploit

daemon@ATHENA.MIT.EDU (albatross@tim.it)
Wed Oct 6 13:02:08 2004

Date: 6 Oct 2004 08:00:06 -0000
Message-ID: <20041006080006.29512.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: <albatross@tim.it>
To: bugtraq@securityfocus.com



The SANS is warning to a JPEG image with MS04-028 overflow that downloads and executes a jpeg.exe file. The program modifies the registry and installs in autorun. It notifies the compromise to an IRC server and waits for commands. 

http://isc.sans.org/diary.php?date=2004-10-05

albatross

home help back first fref pref prev next nref lref last post