CodeBetter.Com
CodeBetter.Com
RSS 2.0 via Feedburner
           Do you Twitter? Follow us @CodeBetter

Brendan Tompkins [MVP]

Blog First. Ask Questions Later.

IE JPEG Overrun Can Allow Creation of Local Admin Account.

Stefano has a problem with people publishing hacks on the net.  He congratulates them for being “stupid.”   I think he's talking about this story from this story from Netcraft:  Here's an excerpt:.

The critical security hole allows a remote attacker to create a JPEG image that, when viewed in Microsoft software programs, could allow the hacker to gain control of the computer. The flaw was revealed by Microsoft Sept. 14, along with a security update that addresses it. Code that partially exploits the flaw was published last week, and has been rapidly developed into code that could be used in an attack using a virus or worm.

The latest exploit, published this morning on the Full Disclosure mailing list, claims to be able to create an administrator-level account on Windows machines.

Not to pick on Stefano, but I don't think these hackers are at all stupid, in fact, the ones posting hacks on the net, and not using these exploits, are not only very smart, but doing us all a big service too!

-Brendan



Comments

Jean-Sebastien Carle said:

Btw, I think you mean "excerpt" not "expert". ;)
# September 23, 2004 12:32 PM

Brendan Tompkins said:

Damn spell checkers! ;)
# September 23, 2004 2:23 PM

Leave a Comment

(required)  
(optional)
(required)  

Enter the numbers above:
Add

About Brendan Tompkins

Brendan has been programming with .NET since the first public beta and is owner and operator of Port Technology Services, a consultancy company providing .NET application development services to the Maritime industry. In July, 2007, he was awarded the Microsoft MVP award for ASP.NET. He's also a proud co-founder of failed .COM startup Intrinsigo, and has had a hand in the failure of numerous other businesses. He currently runs CodeBetter.Com and Devlicio.us, and lives in Norfolk, Virgina with his wife Tiara and son Ian.

View Brendan's profile on LinkedIn

Check out Devlicio.us!

Our Sponsors

Free Tech Publications