Re: A Puzzle! JPEG-JPG inclussions, vulnerabilities
Re: A Puzzle! JPEG-JPG inclussions, vulnerabilities
Posted this in the wrong discussion, my bad..
I should have added: The formats defined as JPEG/JPG [among a few other
formats] also allow the creator/author and other {identifying} information
to be included within the formats.
Web based images generally contain these types of information as well what I
previously indicated could POSSIBLY be included.
*Image search/indexing spiders* will/could access this information
increasing presence and other for the originators, and for tracking of their
usage.
--
MEB
a Peoples' counsel
--
"MEB" <meb@not
here@hotmail.com> wrote in message
news:eY%239CheEJHA.2292@TK2MSFTNGP04.phx.gbl...
|
|
| "~BD~" <BoaterDave@nospam.invalid> wrote in message
| news:OIAUF$cEJHA.5732@TK2MSFTNGP04.phx.gbl...
| |
| | > "~BD~" <BoaterDave@nospam.invalid> wrote in message
| | > news:uXgWA0ZEJHA.3476@TK2MSFTNGP02.phx.gbl...
| | >>
| | >> "Dan" <Dan@discussions.microsoft.com> wrote in message
| | >> news:10E9AABE-ED76-4C6E-9CC9-905450792A00@microsoft.com...
| | >>> Thanks Dave for the correction.
| | >>
| | >>
This was meant to be light-hearted, albeit with serious
undertones
| (for 98 Guy anyway!)
| | >>
| | >> Maybe you can help me. I posted a message in the Microsoft security
| group earlier this morning in
| | >> 'your' Source Code thread. When I checked just now (using Outlook
| Express) the message header had
| | >> a line scored through it and in the message box it said the message
is
| no longer available on the
| | >> server.
| | >>
| | >> Have you ever seen this happen before? Any idea why it might happen?
| | >>
| | >> It is, however, still showing on Google Groups. I repeat it here:-
| | >>
| | >> (It was in response to FromTheRafters who said ....... )
| | >>
| | >> "The transmission is textual - the protocol has no issues I am
| | >> aware of. Any security risk would probably be in the extensions
| | >> that allow this textual data to 'contain' malware - similar to the
| | >> e-mail protocols".
| | >>
| | >> *
| | >>
| | >> *
| | >>
| | >>
| | >> Hmmm! <stroking chin!>
| | >>
| | >> What about when 'pictures' or photographs are included (including
| screenshots) - there's a term
| | >> for
| | >> that which escapes me right now! In other words, not in 'plain text'.
| | >>
| | >>
| | >> I once received a 'screenshot' as an email attachment (I'd asked for
it
| to be sent to me). I
| | >> opened
| | >> the 'picture' (jpeg I think) and all seemed fine.
| | >>
| | >>
| | >> I then opened the file with Notepad (I do crazy things like that!).
| Wow! Inside that file, above
| | >> all the 'gobbledegook' one might expect, were *live* links to all
| manner of web pages ,,,,,,,, of
| | >> course I went and looked! <grin>
| | >>
| | >>
| | >> During my experimentation over the years, I've seen lots of SPAM
| (advertising the likes of Viagra
| | >> and Jewelry) - every one of those links shown in Notepad was, I'm
| certain, taking me to a SPAM
| | >> site!
| | >>
| | >>
| | >> I''ve been told that is impossible ........... yet I saw it with my
own
| eyes! So there!
| | >>
| | >>
| | >> Any thoughts?
| | >>
| | >>
| | >> Dave
| | >>
| | >>
| | >> --
| |
| |
| | "Gary S. Terhune" <none> wrote in message
| news:%23IGr4ocEJHA.1272@TK2MSFTNGP05.phx.gbl...
| | > All kinds of stuff gets immediately rejected or filtered out soon
after
| it gets posts to the MS
| | > server. There is generally no rhyme no reason for it. Fact is, nobody
is
| in charge of the MS news
| | > servers. What there *is* is an ad hoc group of people with differing
and
| sometimes ridiculous
| | > ideas about how to block SPAM and "objectionable" material, whatever
| they decide that is.
| | > --
| | > Gary S. Terhune
| | > MS-MVP Shell/User
| | >
http://grystmill.com
| |
| |
| | Gary - thanks for taking the time and trouble to respond. I've come to
| respect your expertise and
| | attitude. Thanks.
| |
| | It took me a fair while to appreciate that the MS news servers were
| divorced from Microsoft itself
| | and that there is no moderation here, in general terms anyway. I'm quite
| certain that a very high
| | percentage of folk visiting the groups do so out of desperation - I know
I
| did! I must have been
| | using Outlook Express for about 8 years before I became aware that it
| could be used for
| | participating in newsgroups in addition to use for email! Doh!
| |
| | I have, though, always assumed that Microsoft funds the cost of running
| the servers. Can you confirm
| | that that is so? I did once question why there are two active servers -
| news.microsoft.com AND
| | msnews.microsoft.com. A historical 'quirk' I believe I was told.
| |
| | I'm uncertain if you read right through my post. Have you any
| understanding of *how* live links to
| | web sites could be 'hidden' within a jpeg file? I'm happy for you to
email
| me if you would prefer so
| | to do. Just let me know here and I'll give you my address. TIA
| |
| | In the meantime, I'll try posting my message to FTR again and see what
| happens this time!
| |
| | Dave
| |
| | Dave
| |
| | --
|
| The JPEG/JGP issue was a matter of concern [and still is] several years
ago
| with numerous sites related and discussions in the forums. One could
| reasonably state that the/those format(s) has(have) been used successfully
| to do exactly as you indicate.
|
|
http://www.google.com/search?hl=en&q=JPEG+used+to+hack&btnG=Search
|
http://www.google.com/search?hl=en&q=JPEG+vulnerability&btnG=Search
|
|
| --
| MEB
| a Peoples' counsel
| --
| _________
|
|
|