JPEG Exploit Targeting Porn Newsgroups

CYBERSPACE — The first attacks using the Windows JPEG flaw have shown up on adult-oriented newsgroups, according to warnings issued by Internet security organizations today.

Usenet-related site EasyNews published a notice today that pornographic images containing hidden code were posted to at least 10 of the alt.binaries newsgroups, including alt.binaries.erotica.breasts and alt.binaries.erotica.beanie-babies.

The images first started to be posted at around 7 p.m. on Sunday, according to Godzilla, an administrator at EasyNews.

The corrupted images, which look exactly the same as a normal image, exploits the recently-announced JPEG flaw in Windows’ Graphic Device Interface Plus (GDI+) with a buffer overflow attack.

“Once this JPEG overflowed GDI+, it phoned home, connected to an FTP site and downloaded almost 2 megs of stuff,” stated Godzilla.

After downloading the files, the malicious code sets the infected computer up as a server and installs an IRC client.

According to Godzilla, 93 users were logged into the FTP site when he checked it last.

The release of the infected images came less than a week after sample code appeared on the Internet that explained how to exploit the GDI+ JPEG flaw.

According to the F-Secure Antivirus Research Team, the corrupted images don’t seem to be attempting to spread themselves.

“These JPEGs did not replicate, so this is not a virus,” the team wrote in their weblog. “Apparently, they tried to use these JPEGs to download Trojans to vulnerable computers… but the download sites should be down by now.”

Even though the threat posed by the these specific postings may have passed, F-Secure is concerned that it might signal a large problem on the way.

“Things are heating up,” wrote Mikko, a member of F-Secure’s antivirus team. “I have a nasty feeling we might sooner or later see a massmailer worm using a JPEG image as the attachment.”

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Lauren Phillips, Derek Kage Cap AEBN's Top Stars for 3rd Quarter of 2025

AEBN has revealed its most popular performers in straight and gay theaters for the third quarter of 2025.

XBIZ 2026 Conference to Debut All-New Company Lounges, Community Track

The event website for XBIZ 2026 is now live, unveiling details for North America’s largest adult industry conference, including two all-new show features: Company Lounges and a Community Track.

Mymember.site Integrates VR Functionality

Mymember.site has added virtual reality playback capability to its website management platform.

Texas Patti to Launch Fetish Platform 'EmpireDom'

Performer and content creator Texas Patti is launching a new platform for doms and fetish creators, EmpireDom.com.

Ohio AG Threatens Action Against 'Major' Adult Sites Over AV Law

Ohio Attorney General Dave Yost announced today that his office is sending "notice of violation" letters to 19 adult websites for failure to comply with the state's recently enacted age verification law.

Chaturbate Announces 2025 Music Contest Winners

Chaturbate has revealed the winners of its 2025 music competition.

2026 XBIZ Exec Awards Pre-Noms Open With Debut of New 'Impact' Honors

XBIZ is pleased to announce that the pre-nomination period for the 2026 XBIZ Exec Awards, the adult industry’s premier career honor, begins today and runs through Oct. 14.

MYM Rolls Out New Traffic Features for German Creators

German platform MYM has launched a new traffic system for its creators.

Ukrainian Content Creators on Hook for Nearly $10M in Back Taxes

Content creators in Ukraine owe the equivalent of $9.3 million in back taxes, according to the country's State Tax Service.

Eroutique Relaunches Site Through YourPaysitePartner

Eroutique has relaunched its official website through YourPaysitePartner (YPP).

Show More