Brendan Tompkins [MVP]

Sponsors

The Lounge

News

Advertisement

Images in this post missing? We recently lost them in a site migration. We're working to restore these as you read this. Should you need an image in an emergency, please contact us at imagehelp@codebetter.com
IE JPEG Overrun Can Allow Creation of Local Admin Account.

Stefano has a problem with people publishing hacks on the net.  He congratulates them for being “stupid.”   I think he's talking about this story from this story from Netcraft:  Here's an excerpt:.

The critical security hole allows a remote attacker to create a JPEG image that, when viewed in Microsoft software programs, could allow the hacker to gain control of the computer. The flaw was revealed by Microsoft Sept. 14, along with a security update that addresses it. Code that partially exploits the flaw was published last week, and has been rapidly developed into code that could be used in an attack using a virus or worm.

The latest exploit, published this morning on the Full Disclosure mailing list, claims to be able to create an administrator-level account on Windows machines.

Not to pick on Stefano, but I don't think these hackers are at all stupid, in fact, the ones posting hacks on the net, and not using these exploits, are not only very smart, but doing us all a big service too!

-Brendan


Posted 09-23-2004 10:37 AM by Brendan Tompkins

[Advertisement]

Comments

Brendan Tompkins wrote re: IE JPEG Overrun Can Allow Creation of Local Admin Account.
on 09-23-2004 7:11 AM
I'd put it this way. A security hole that only a few people know about is a much bigger hole than one everyone knows.
Jean-Sebastien Carle wrote re: IE JPEG Overrun Can Allow Creation of Local Admin Account.
on 09-23-2004 12:32 PM
Btw, I think you mean "excerpt" not "expert". ;)
Brendan Tompkins wrote re: IE JPEG Overrun Can Allow Creation of Local Admin Account.
on 09-23-2004 2:23 PM
Damn spell checkers! ;)

Add a Comment

(required)  
(optional)
(required)  
Remember Me?