JPEG Exploit Targeting Porn Newsgroups

CYBERSPACE — The first attacks using the Windows JPEG flaw have shown up on adult-oriented newsgroups, according to warnings issued by Internet security organizations today.

Usenet-related site EasyNews published a notice today that pornographic images containing hidden code were posted to at least 10 of the alt.binaries newsgroups, including alt.binaries.erotica.breasts and alt.binaries.erotica.beanie-babies.

The images first started to be posted at around 7 p.m. on Sunday, according to Godzilla, an administrator at EasyNews.

The corrupted images, which look exactly the same as a normal image, exploits the recently-announced JPEG flaw in Windows’ Graphic Device Interface Plus (GDI+) with a buffer overflow attack.

“Once this JPEG overflowed GDI+, it phoned home, connected to an FTP site and downloaded almost 2 megs of stuff,” stated Godzilla.

After downloading the files, the malicious code sets the infected computer up as a server and installs an IRC client.

According to Godzilla, 93 users were logged into the FTP site when he checked it last.

The release of the infected images came less than a week after sample code appeared on the Internet that explained how to exploit the GDI+ JPEG flaw.

According to the F-Secure Antivirus Research Team, the corrupted images don’t seem to be attempting to spread themselves.

“These JPEGs did not replicate, so this is not a virus,” the team wrote in their weblog. “Apparently, they tried to use these JPEGs to download Trojans to vulnerable computers… but the download sites should be down by now.”

Even though the threat posed by the these specific postings may have passed, F-Secure is concerned that it might signal a large problem on the way.

“Things are heating up,” wrote Mikko, a member of F-Secure’s antivirus team. “I have a nasty feeling we might sooner or later see a massmailer worm using a JPEG image as the attachment.”

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

New Fansly Analytics Platform 'SlyKiwi' Launches

SlyKiwi, a new analytics platform exclusively designed for Fansly content, has officially launched.

FPNCash Appoints Kimi Evans Head of Business Development

FPNCash has appointed Kimi Evans as its new head of business development.

CamModelDirectory Launches Platform Upgrade

CamModelDirectory has launched its CMD 3.0 platform upgrade.

AEBN Publishes Popular Searches by Country for June, July

AEBN has released the list of popular searches from its straight and gay theaters by country in June and July.

Playboy to Move Global HQ to Miami Beach

Playboy announced today that it will be moving its global corporate headquarters from Los Angeles to Miami Beach.

Bellesa Plus Names Magalie Rheaut as Chief Growth Officer

Bellesa Plus has named Magalie Rheaut as its Chief Growth Officer.

PASS to Relaunch Performer Subsidy Fund

PASS has announced that it will relaunch the Performer Subsidy Fund (PSF) to cover sexually transmitted infection (STI) test panel costs for up to 10 people each month.

Pineapple Support Taps Austin Ponce as Brand Ambassador

Pineapple Support has named Austin Ponce as its newest brand ambassador.

Taylor Vixxen Stars in New DezyRed Interactive VR Game

Taylor Vixxen stars in an interactive VR game from DezyRed.

XBIZ Amsterdam's Jakarta Hotel Sold Out, Additional Hotels Announced

Guest rooms at XBIZ Amsterdam’s host conference venue, Jakarta Hotel, are now completely sold out.

Show More