Snort mailing list archives

Re: iFrame's in gifs


From: waldo kitty <wkitty42 () windstream net>
Date: Fri, 24 Jun 2011 21:03:20 -0400

On 6/24/2011 18:24, rmkml wrote:
Hi James,
Maybe: http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?name=Trojan:Win32/Jpgiframe.A

this is not directed at the URL above but more to the thread and what it depicts...

as an old time (35+ years) coder, i really have to ask, W!T!F!?! why would ANY 
graphic processing library or engine ever switch modes in midstream when drawing 
specifically graphic images?? this particular injection should introduce garbage 
into the drawn image or cause an error resulting in the image drawing 
terminating at that point... further processing should abort back to the html 
processing stuff which should not even care or begin to process possible 
residual graphical data in a (shared?) buffer... i'm completely flabbergasted 
and dumbfounded at this :? :(

------------------------------------------------------------------------------
All the data continuously generated in your IT infrastructure contains a 
definitive record of customers, application performance, security 
threats, fraudulent activity and more. Splunk takes this data and makes 
sense of it. Business sense. IT sense. Common sense.. 
http://p.sf.net/sfu/splunk-d2d-c1
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please see http://www.snort.org/docs for documentation


Current thread: