Whether this is serious or not I do not know. But according to Symantec it is. I was unable to use my back button as when I did I was informed that it was directing me to the attacking IP address. I had to completely shut down windows and re-boot my computer. I am also told that I have a malicious script in my temporary internet files.Time: 10:26AM CDT
Date: 10/27/2005
Intrusion: ICC Profile TagData Overflow
Intruder: eupedia.jref.com(67.19.168.133)(http(80))
Risk Level: HIGH!
Attacked IP: localhost
Attacked Port: 2132
When I clicked on more info about the ip address I was informed of the following:
IP address: 67.19.168.133
Network: theplanet.com
Location: Dallas, Texas, USA
Node Name: 133.67-19-168,reverse.theplanet.com
Here is additional info I was given by my security software:
OrgID: TPCM
CustName: ThePlanet.com Internet Services, Inc.
Street: 1333 North Stemmons Freeway
Street: Suite 110
City: Dallas
StateProv: TX
Country: US
PostalCode: 75207
RegDate: 1999-08-31
Updated: 2004-05-07
ReferralServer: rwhois://rwhois.theplanet.com:4321
OrgAbuseHandle: ABUSE271-ARIN
OrgAdminHandle: CROSB-ARIN
OrgNOCHandle: TECHN33-ARIN
OrgTechHandle: TECHN33-ARIN
NetHandle: NET-67-18-0-0-1
OrgID: TPCM
Parent: NET-67-0-0-0-0
NetName: NETBLK-THEPLANET-BLK-11
NetRange: 67.18.0.0 - 67.19.255.255
NetType: allocation
RegDate: 2004-03-15
Updated: 2004-07-29
NameServer: NS1.THEPLANET.COM
NameServer: NS2.THEPLANET.COM
TechHandle: PP46-ARIN
TechHandle: PP46-ARIN
TechName: Pathos, Peter
TechPhone: +1-214-782-7800
TechEmail: adimns@theplanet.com
OrgAbuseHandle: ABUSE271-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-214-782-7802
OrgAbuseEmail: abuse@theplanet.com
OrgTechHandle: TECHN33-ARIN
OrgTechName: Technical Support
OrgTechPhone: +1-214-782-7800
OrgTechEmail: admins@theplanet.com
OrgAdminHandle: CROSB-ARIN
OrgAdminName: Crosby, Lance
OrgAdminPhone: +1-214-800-6008
OrgAdminEmail: lcrosby@theplanet.com
OrgNOCHandle: TECHN33-ARIN
OrgNOCName: Technical Support
OrgNOCPhone: +1-214-782-7800
OrgNOCEmail: admins@theplanet.com
Here is additional info concerning the attack:
ICC Profile TagData Overflow
Severity: High
This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.
Description
This signature detects a buffer overflow condition in icm32.dll, exploited by rendering a malicious image file.
Additional Information
A buffer overflow has been reported in the icm32.dll. If the image contains International Color Consortium (ICC) data, icm32.dll will be loaded to process it.
A buffer overrun vulnerability exists in the processing images that contains a large ICC tag data size for any of the following tag entry signatures:
1)rXYZ
2)bXYZ
3)gXYZ
The purpose of the International Color Consortium® (ICC) format is to provide a cross-platform device profile format. Such device profiles can be used to translate color data created on one device into another device's native color space. The acceptance of this format by operating system vendors allows end users to transparently move profiles and images with embedded profiles between different operating systems. For example, this allows a printer manufacturer to create a single profile for multiple operating systems.
Affected:
All Windows.
Response
Visit the Microsoft Security Bulletin Page for patches.
Possible False Positives
There are no known false positives associated with this signature.
MS IE is filled with bugs etc..Why do you think they almost have an update every 5 minutesKinsao said:I use FireFox - so is my machine likely to be at risk also, or is it only IE that was made at risk? :?
Index said:By looking at that picture in your sig. Kinsao, it looks like you are already at risk
Pararousia said:I have my entire computer wrapped in latex.
Pachipro said:Luckily I was not affected by this intruder as my Symantec security software stopped it. The "malicious script" message I got was because of the Symantec Security software preventing my providers "desktop doctor" from accessing my computer. I ran a virus scan and am clean and was not affected.
thomas said:This problem seems to be related to unpatched versions of Internet Explorer and the way it reacts to certain JPG files.
Silverpoint said:However, given that many users are not well versed in securing their PCs, I would suggest that as a responsible site, JREF should isolate and remove any files that may exploit this vulnerability as quickly as possible.
Kinsao said:You don't think Kouji-san is manly?I don't think he'd be best pleased..... :box:
Maciamo said:What do you mean by removing those files ? Removing all the pictures from the Japan Gallery and Europe Gallery ? That won't happen.
RockLee said:MS IE is filled with bugs etc..Why do you think they almost have an update every 5 minutes
Kinsao said:You don't think Kouji-san is manly?I don't think he'd be best pleased..... :box:
mikecash said:To be perfectly honest, I thought it was a girl.
Sensuikan San said:Q]And what is the lesson to be learned here, class?
A]Use any browser other than IE!
(Sorry, Mr. Gates! .... but you're gonna have to do something soon .......!)
ニ淡ニ停?。ニ停?彈/QUOTE]
Completely agree! I hate IE (and most microsoft products except Word, Excel, etc) with a passion
Anyway, I think there's a thread about other browsers people use. Seems people tend to like Firefox and Opera. Me, I'm on a mac, so I use Camino
Kinsao said:You don't think Kouji-san is manly?I don't think he'd be best pleased..... :box:
I always thought the VK artists intentionally tried to dress androgynously as part of their art, and maybe as a means to remove conventional concepts of masculinity/femininity.
lastmagi said:I always thought the VK artists intentionally tried to dress androgynously as part of their art, and maybe as a means to remove conventional concepts of masculinity/femininity.
Norton claims there are no false positives for this signature. I think they are wrong. If you compare the known ICC exploit code to the sRGB IEC61966-2.1 Color Space Profile you will find that the resulting binary data are nearly identical.Pachipro said:Can anyone explain this to me?
Silverpoint said:There was a security vulnerability reported last year (CAN-2004-0200), for which a security update was released. The earlier issue explicity dealt with JPEG files and shouldn't be confused with this similar sounding exploit.
The vulnerability Maciamo is talking about is related to the Color Management Module in Microsoft Windows (all versions from '98 onwards), which loads when it is required to process certain profile data of both image and non-image files. It is a Windows vulnerability which affects a wide range of files (not just JPEG) and is not limited to Internet Explorer. Downloading the patch mentioned earlier in the thread will fix this problem.
However, given that many users are not well versed in securing their PCs, I would suggest that as a responsible site, JREF should isolate and remove any files that may exploit this vulnerability as quickly as possible.