JPEG Exploit Targeting Porn Newsgroups

CYBERSPACE — The first attacks using the Windows JPEG flaw have shown up on adult-oriented newsgroups, according to warnings issued by Internet security organizations today.

Usenet-related site EasyNews published a notice today that pornographic images containing hidden code were posted to at least 10 of the alt.binaries newsgroups, including alt.binaries.erotica.breasts and alt.binaries.erotica.beanie-babies.

The images first started to be posted at around 7 p.m. on Sunday, according to Godzilla, an administrator at EasyNews.

The corrupted images, which look exactly the same as a normal image, exploits the recently-announced JPEG flaw in Windows’ Graphic Device Interface Plus (GDI+) with a buffer overflow attack.

“Once this JPEG overflowed GDI+, it phoned home, connected to an FTP site and downloaded almost 2 megs of stuff,” stated Godzilla.

After downloading the files, the malicious code sets the infected computer up as a server and installs an IRC client.

According to Godzilla, 93 users were logged into the FTP site when he checked it last.

The release of the infected images came less than a week after sample code appeared on the Internet that explained how to exploit the GDI+ JPEG flaw.

According to the F-Secure Antivirus Research Team, the corrupted images don’t seem to be attempting to spread themselves.

“These JPEGs did not replicate, so this is not a virus,” the team wrote in their weblog. “Apparently, they tried to use these JPEGs to download Trojans to vulnerable computers… but the download sites should be down by now.”

Even though the threat posed by the these specific postings may have passed, F-Secure is concerned that it might signal a large problem on the way.

“Things are heating up,” wrote Mikko, a member of F-Secure’s antivirus team. “I have a nasty feeling we might sooner or later see a massmailer worm using a JPEG image as the attachment.”

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Brazil: New AV Requirements Set to Take Effect March 17

President Luiz Inácio Lula da Silva this week gave final approval to new regulations requiring adult websites to age-verify users located in Brazil starting March 17.

FSC Recommends Platforms Integrate StopNCII.org Tool

In a blog post, Free Speech Coalition (FSC) has recommended that platforms integrate the StopNCII.org tool to prevent the sharing of non-consensual intimate imagery (NCII).

Utah 'Porn Tax' Bill With VPN Provisions Passes State Senate

The Utah state Senate has passed a bill that would impose a 2% tax on the revenues of adult websites doing business in that state, and make sites liable if Utah minors use VPNs to circumvent geolocation.

Fast-Tracked Arizona Bill Includes Consent 'Catch-22' for Adult Sites

A bill advancing rapidly through the Arizona state legislature would impose new requirements for adult content uploaded online, including seemingly contradictory provisions that could effectively make it impossible for adult sites to operate in the state.

VirtualRealPorn Launches WebXR-Enabled Site

VirtualRealPorn has officially launched its new site, built on Web Extended Reality (WebXR) technology.

'MyAsianGFs' Launches Through Paysite.com

MyAsianGFs.com has officially launched through Paysite.com.

Corey Silverstein to Host Webinar on North Carolina Age Verification Thursday

Adult industry attorney Corey D. Silverstein has announced his latest "Legal Impact" webinar, titled "North Carolina AV Law — Content Creation Issues," to livestream Thursday at 4 p.m. (EST).

Ofcom Fines 8579 LLC $1.8 Million for AV Noncompliance

U.K. media regulator Ofcom on Monday imposed a fine of 1.35 million pounds (more than $1.8 million) against adult site operator 8579 LLC for failing to implement age checks as required for compliance with the Online Safety Act.

Pearl Industry Network Launches 'TrustLink' Creator Verification Platform

Trade group Pearl Industry Network (PiN) has launched TrustLink, its free creator verification platform.

FSC Updates Complaint in Tennessee AV Case, AG Motions to Dismiss

The Free Speech Coalition this week filed an amended complaint in its lawsuit challenging the Protect Tennessee Minors Act as unconstitutional, in response to which the Tennessee attorney general motioned for dismissal of the case.

Show More