[prev in list] [next in list] [prev in thread] [next in thread] 

List:       dshield
Subject:    [Dshield] JPEG Downloader Toolkit
From:       "Johannes B. Ullrich" <jullrich () sans ! org>
Date:       2004-09-24 20:35:29
Message-ID: 1096058129.14773.12.camel () mrburns ! lan
[Download RAW message or body]

[Attachment #2 (multipart/signed)]


Ok. This was released last night. But in order to claim our
imaginary office pool, I declare the game over as of now
with the release of this tool. The 'JPEG Downloader Toolkit'
is a simple GUI driven tool. You provide it with a JPEG and 
a URL. The tool will add code to the jpeg to download and
execute a binary found at that specific URL.

Recommendations:
- update virus scanners (most AVs will recognize images 
  generated by the tool. And will tag the tool itself as well)
- double check that you are patched.

If anybody finds a suspect image, please drop it here:
http://isc.sans.org/contact.php




-- 
----------------------------------------------------------------
CTO SANS Internet Storm Center               http://isc.sans.org
phone: (617) 639 5000                          jullrich@sans.org 

["signature.asc" (application/pgp-signature)]

_______________________________________________
DShield and the Internet Storm Center are sponsored by the SANS Institute.
To learn more about current SANS training, see http://www.sans.org .

_______________________________________________
send all posts to list@lists.dshield.org
To change your subscription options (or unsubscribe), see: http://www.dshield.org/mailman/listinfo/list


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic