Date: 27-04-24  Time: 22:17 pm

Author Topic: One for the Admins  (Read 2262 times)

tweetytek

  • Club Racer
  • ****
  • Posts: 467
    • Main bike:
      FZS600 00-01
    • - RR900, SV650
    • View Profile
One for the Admins
« on: 07 October 2014, 09:28:47 pm »
Was reading this today
http://foc-u.co.uk/index.php/topic,13239.0.html

Not true that images are not harmful... I work for an MoD contractor working in Defence Information and Intelligence (cyber security).
 PC based images are complex formats and contain meta data and other parts that are not directly visible when painted onto the display  — it is possible to conceal "stuff" within without affecting how the image is displayed on the screen , even when hyperlinked. Venomous  data can reside within the image that exploits "back doors" in poor quality image rendering programs - including doors like stacks, buffers, data segment larger than the stated image format type and exception handlers and alike. With skill, a virus writer  :b can utilise these flaws to infect your machine when you open the image with a certain program. Granted this wont work just displaying the image as Mickvp said, but if one were to click on the image and open it in a certain app, then Bang!! you're infected.
Just thought I'd clear that up for the Admins
« Last Edit: 07 October 2014, 09:30:07 pm by tweetytek »
Three lefts make a right

mickvp

  • Global Moderator
  • GP Hero
  • *****
  • Posts: 2,246
    • Main bike:
      FZS 1000 Gen1
    • View Profile
Re: One for the Admins
« Reply #1 on: 07 October 2014, 10:29:18 pm »
so in short - not harmful in the format it is being displayed in.

I appreciate what you are saying, and you are right of course - someone could insert malicious information if they were that way motivated. The image in question on that thread had no malicious data on it though (and I know, because I checked the meta data and also the HTML code in which it is embedded).

The truth is, some guys one here have a hard enough time figuring out how to login and post anything (im looking at you Red98 :lol ) so rathen than explain anything technical with regards to the interwebz, its best to use small words and just say everything will be OK :rollin


The site which had been marked as malicious (memegenerator) has since been moved into the clear list, so that warning does not come up for the very same image now.

Thanks for the heads up though, we will as ever continue to check out these reports as they come in :D
« Last Edit: 07 October 2014, 10:30:48 pm by mickvp »

red98

  • GP Hero
  • ******
  • Posts: 6,567
    • Main bike:
      FZS 1000 Gen1
    • - FZS600,CB400/4,X7,CB250
    • View Profile
Re: One for the Admins
« Reply #2 on: 08 October 2014, 06:54:09 am »
so in short - not harmful in the format it is being displayed in.

I appreciate what you are saying, and you are right of course - someone could insert malicious information if they were that way motivated. The image in question on that thread had no malicious data on it though (and I know, because I checked the meta data and also the HTML code in which it is embedded).

The truth is, some guys one here have a hard enough time figuring out how to login and post anything (im looking at you Red98 :lol ) so rathen than explain anything technical with regards to the interwebz, its best to use small words and just say everything will be OK :rollin


The site which had been marked as malicious (memegenerator) has since been moved into the clear list, so that warning does not come up for the very same image now.

Thanks for the heads up though, we will as ever continue to check out these reports as they come in :D












mmmmmmmmmmmm  :( :( ...and there was silly old me thinking this was a motorcycle forum   :rolleyes ... :lol
One, is never going to be enough.....

tweetytek

  • Club Racer
  • ****
  • Posts: 467
    • Main bike:
      FZS600 00-01
    • - RR900, SV650
    • View Profile
Re: One for the Admins
« Reply #3 on: 08 October 2014, 06:56:22 am »
Oh the internet is a place of skulldugerry and cutlesses  :lol
Three lefts make a right

ChristoT

  • Alleged Foc-u Daphnis & Chloe expert
  • GP Hero
  • ******
  • Posts: 5,207
  • Fluent in English, French and bullshit!
    • Main bike:
      FZS600 98-99
    • - Saab 9-3, caravan, hang glider
    • View Profile
Re: One for the Admins
« Reply #4 on: 08 October 2014, 12:47:16 pm »
mmmmmmmmmmmm  :( :( ...and there was silly old me thinking this was a motorcycle forum   :rolleyes ... :lol

You mean this ISN'T flower arranging? Aww shit!  :lol :lol
The Deef's apprentice

darrsi

  • GP Hero
  • ******
  • Posts: 10,651
    • Main bike:
      FZS600 00-01
    • View Profile
Re: One for the Admins
« Reply #5 on: 30 November 2014, 10:21:59 am »
Was reading this today
http://foc-u.co.uk/index.php/topic,13239.0.html

Not true that images are not harmful... I work for an MoD contractor working in Defence Information and Intelligence (cyber security).
 PC based images are complex formats and contain meta data and other parts that are not directly visible when painted onto the display  — it is possible to conceal "stuff" within without affecting how the image is displayed on the screen , even when hyperlinked. Venomous  data can reside within the image that exploits "back doors" in poor quality image rendering programs - including doors like stacks, buffers, data segment larger than the stated image format type and exception handlers and alike. With skill, a virus writer  :b can utilise these flaws to infect your machine when you open the image with a certain program. Granted this wont work just displaying the image as Mickvp said, but if one were to click on the image and open it in a certain app, then Bang!! you're infected.
Just thought I'd clear that up for the Admins



I lost the way after "Not true....."  :z
More people are born because of alcohol than will ever die from it.

tweetytek

  • Club Racer
  • ****
  • Posts: 467
    • Main bike:
      FZS600 00-01
    • - RR900, SV650
    • View Profile
Re: One for the Admins
« Reply #6 on: 30 November 2014, 01:24:14 pm »
Why bother posting then? Suppose your post count is +1 up and another for the doubtless response to this.

Jeeeez  :z
Three lefts make a right