Security Flaw in Jpeg File handling
A new security flaw in the way Jpeg files are being handled has just been announced bout few days back. This flaw will cause a buffer overrun and allow code execution without the user knowing it. All this by just viewing a picture.
Imagine this scenario…
You get a forwarded email from your friends which contains lots of cute pictures. Thinking its just pictures, and nothing harmful, you continue to view it. While u are viewing the picture, the malicious codes within the picture file proceeds to download a trojan horse from a remote server and then executing it in your computer. All this are done in the background while you view the picture. You close the email and u think, “Hey, I didn’t download any exe files so my computer is still safe” Wrong…. Your computer has already been infected and anybody can now access your computer.
The above scenario is not only limited to just email. You can be viewing a picture from a website, or from a word document, or powerpoint slide etc.. and you’ll still be affected by it.
Cool huh…. I’ve already managed to get the software which allows me to do the above scenario. What the software does is to embedd a small piece of code into the jpeg file which will cause a buffer overrun and execute a file, downloaded from a remote server, locally on your computer. Now all I need right now it to find the source codes to this software so I can start experimenting with it.
Those who need this cool piece of software can email me for it and I’ll be glad to let you have it. If anyone can find the source code to exploit this vulnerability, can u let me know about it.

