Windows XP Community - XPHeads



Registry Mechanic - Free Scan Now

Threat HTTP TIF Folder

microsoft.public.windowsxp.help_and_support


Reply
  #1 (permalink)  
Old 02-16-2008, 01:40 AM
artysan
 
Posts: n/a
Threat HTTP TIF Folder
I uploaded a picture to a forum and the recipients replied that a virus was
embedded in it .I have carried out full scans of my computer with three
different systems .Also I have tried sending the picure to myself and then
scanning it and still cannot reproduce the complaints
They have not informed me of the virus/trojan name but sent the following

HTTP TIF Folder Info. Disclosure
Severity: Medium
This attack could pose a moderate security threat. It does not require
immediate action.

Description
This signature detects attempts to exploit an information disclosure
vulnerability exists in Internet Explorer in the way that drag and drop
operations are handled in certain situations.

Additional Information
An information disclosure vulnerability exists in Internet Explorer in the
way that drag and drop operations are handled in certain situations. An
attacker could exploit the vulnerability by constructing a specially crafted
Web page that could allow for information disclosure if a user viewed and
interacted with the Web page. An attacker who successfully exploited this
vulnerability would be able to retrieve files from the Temporary Information
Files (TIF) folder on a user?s system.

Affected:
Windows.

Response
Download and install the Microsoft patch applicable to this vulnerability.

Patch KB 92545 was installed months ago
Thank you artysan
--
artysan
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 02-16-2008, 02:43 AM
VanguardLH
 
Posts: n/a
Re: Threat HTTP TIF Folder
"artysan" <artysan@discussions.microsoft.com> wrote in message
news:E879293D-CE51-4882-BB5D-1424FF447D70@microsoft.com...
>I uploaded a picture to a forum and the recipients replied that a
>virus was
> embedded in it ...


Submit the file to VirusTotal (http://www.virustotal.com/).

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 02-16-2008, 02:53 AM
David H. Lipman
 
Posts: n/a
Re: Threat HTTP TIF Folder
From: "artysan" <artysan@discussions.microsoft.com>

| I uploaded a picture to a forum and the recipients replied that a virus was
| embedded in it .I have carried out full scans of my computer with three
| different systems .Also I have tried sending the picure to myself and then
| scanning it and still cannot reproduce the complaints
| They have not informed me of the virus/trojan name but sent the following
|

< snip >

| Thank you artysan

The Tibs Trojan has used steganographic techiques. However a peer utility is needed to
extract the executable Trojan from the JPEG.

Graphics in themselves can NOT be viruses.

Sending the graphic back to yourself is NOT a good test.

Please submit a sample of this suspect graphic to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against many different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.

You can also submit a suspect, one at a time, via the following email URL...
mailto:scan@virustotal.com?subject=SCAN

When you get the report, please post back the exact results.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 02-16-2008, 05:11 AM
artysan
 
Posts: n/a
RE: Threat HTTP TIF Folder
E-mail with file sent to address as shown ,email returned quote"DNS Hard
error lookin up", address.
Went to website and sent file from there. Report showed nothing no virus's
or Trojans discovered Result 0/32 from scan. Regards and thanks for your
input,artysan.
--
artysan


"artysan" wrote:

> I uploaded a picture to a forum and the recipients replied that a virus was
> embedded in it .I have carried out full scans of my computer with three
> different systems .Also I have tried sending the picure to myself and then
> scanning it and still cannot reproduce the complaints
> They have not informed me of the virus/trojan name but sent the following
>
> HTTP TIF Folder Info. Disclosure
> Severity: Medium
> This attack could pose a moderate security threat. It does not require
> immediate action.
>
> Description
> This signature detects attempts to exploit an information disclosure
> vulnerability exists in Internet Explorer in the way that drag and drop
> operations are handled in certain situations.
>
> Additional Information
> An information disclosure vulnerability exists in Internet Explorer in the
> way that drag and drop operations are handled in certain situations. An
> attacker could exploit the vulnerability by constructing a specially crafted
> Web page that could allow for information disclosure if a user viewed and
> interacted with the Web page. An attacker who successfully exploited this
> vulnerability would be able to retrieve files from the Temporary Information
> Files (TIF) folder on a user?s system.
>
> Affected:
> Windows.
>
> Response
> Download and install the Microsoft patch applicable to this vulnerability.
>
> Patch KB 92545 was installed months ago
> Thank you artysan
> --
> artysan

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 02-16-2008, 05:16 AM
artysan
 
Posts: n/a
RE: Threat HTTP TIF Folder
attached file to email and sent to address you advised .Email returned "Bad
destination host DNS Hard error......
Went to website address and put file on there .Results was 0/32 scans.
Thanks for your input ,artysan
--
artysan


"artysan" wrote:

> I uploaded a picture to a forum and the recipients replied that a virus was
> embedded in it .I have carried out full scans of my computer with three
> different systems .Also I have tried sending the picure to myself and then
> scanning it and still cannot reproduce the complaints
> They have not informed me of the virus/trojan name but sent the following
>
> HTTP TIF Folder Info. Disclosure
> Severity: Medium
> This attack could pose a moderate security threat. It does not require
> immediate action.
>
> Description
> This signature detects attempts to exploit an information disclosure
> vulnerability exists in Internet Explorer in the way that drag and drop
> operations are handled in certain situations.
>
> Additional Information
> An information disclosure vulnerability exists in Internet Explorer in the
> way that drag and drop operations are handled in certain situations. An
> attacker could exploit the vulnerability by constructing a specially crafted
> Web page that could allow for information disclosure if a user viewed and
> interacted with the Web page. An attacker who successfully exploited this
> vulnerability would be able to retrieve files from the Temporary Information
> Files (TIF) folder on a user?s system.
>
> Affected:
> Windows.
>
> Response
> Download and install the Microsoft patch applicable to this vulnerability.
>
> Patch KB 92545 was installed months ago
> Thank you artysan
> --
> artysan

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 02-16-2008, 05:25 AM
David H. Lipman
 
Posts: n/a
Re: Threat HTTP TIF Folder
From: "artysan" <artysan@discussions.microsoft.com>

| attached file to email and sent to address you advised .Email returned "Bad
| destination host DNS Hard error......
| Went to website address and put file on there .Results was 0/32 scans.
| Thanks for your input ,artysan

There 'ya go.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 01:52 AM.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74