Author Topic: MIME types exceptions in Web-shield  (Read 5284 times)

0 Members and 1 Guest are viewing this topic.

Offline Lars-Erik

  • Avast Evangelist
  • Sr. Member
  • ***
  • Posts: 394
    • Lars-Erik Østerud
MIME types exceptions in Web-shield
« on: March 21, 2011, 12:36:04 AM »
I see in the exceptions section for the Web-shield that there are exceptions for video/* and audio/*, but for image there are only exceptions for image/gif and image/png, and not for image/jpg.

I guess this is because code could be hidden inside a JPG-image that would execute on Windows.

But wasn't this threat fixed in a Windows-update some time ago?

Is there danger adding image/* to the exception list now?

A majority of web-page images are JPG, and not having an exception for that causes many file to be scanned, slowing down display of web-pages (especially on older computers).

What are your thoughts?
www.osterud.name - ICQ: 7297605 - AIM/Yahoo/Facebook/Skype/Astra: LarsErikOsterud

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89109
  • No support PMs thanks
Re: MIME types exceptions in Web-shield
« Reply #1 on: March 21, 2011, 01:26:39 AM »
Because .jpg files are targets of malware and need to be scanned to prevent exploits/malware.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lars-Erik

  • Avast Evangelist
  • Sr. Member
  • ***
  • Posts: 394
    • Lars-Erik Østerud
Re: MIME types exceptions in Web-shield
« Reply #2 on: March 21, 2011, 02:51:01 AM »
So when Microsoft says they have "plugged" that hole in Windows, they are not telling us all?
I thought that error had to do with something overflowing and then triggering something inside the file.
Normal web-browser and image-programs don't execute anything inside a file.
Can you say a bit more about how a JPG file causes a threat still now?
(please be technical if you need to, I am a programmer, so Iæll try to understand :-)
www.osterud.name - ICQ: 7297605 - AIM/Yahoo/Facebook/Skype/Astra: LarsErikOsterud

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89109
  • No support PMs thanks
Re: MIME types exceptions in Web-shield
« Reply #3 on: March 21, 2011, 03:04:17 AM »
There are still exploit attempts regardless of what MS tells you. Code can be placed at the end of a jpg file which can be executed, try to redirect you to a malicious site, etc.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

doktornotor

  • Guest
Re: MIME types exceptions in Web-shield
« Reply #4 on: March 21, 2011, 03:07:09 AM »
Also assuming that users regularly patch their Windows does not exactly match reality. See all the people with XP SP2 here.  >:(

Offline Lars-Erik

  • Avast Evangelist
  • Sr. Member
  • ***
  • Posts: 394
    • Lars-Erik Østerud
Re: MIME types exceptions in Web-shield
« Reply #5 on: March 21, 2011, 03:18:36 AM »
Also assuming that users regularly patch their Windows does not exactly match reality. See all the people with XP SP2 here.  >:(
Know that :-)
But for those who DO update their systems.
Is JPG still a risk for those today?
www.osterud.name - ICQ: 7297605 - AIM/Yahoo/Facebook/Skype/Astra: LarsErikOsterud

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89109
  • No support PMs thanks
Re: MIME types exceptions in Web-shield
« Reply #6 on: March 21, 2011, 03:20:37 AM »
Read my last post again, there are examples of such redirection in the viruses and worms forum if you search.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

doktornotor

  • Guest
Re: MIME types exceptions in Web-shield
« Reply #7 on: March 21, 2011, 03:27:26 AM »
But for those who DO update their systems.
Is JPG still a risk for those today?

GDI+ is notoriously buggy. E.g., looking at the "impressive" list of affected SW at http://www.sophos.com/support/knowledgebase/article/64693.html I seriously doubt that MS will ever learn. Also note that MS09-062 covers  WMF, PNG, TIFF, BMP...  ::) MS has been fixing this thing over and over again.

Offline Lars-Erik

  • Avast Evangelist
  • Sr. Member
  • ***
  • Posts: 394
    • Lars-Erik Østerud
Re: MIME types exceptions in Web-shield
« Reply #8 on: March 21, 2011, 10:16:46 PM »
But avast! had exceptions for PNG and GIF as standard.
Should they be removed as well (can PNG and GIF also contain code)?
www.osterud.name - ICQ: 7297605 - AIM/Yahoo/Facebook/Skype/Astra: LarsErikOsterud

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89109
  • No support PMs thanks
Re: MIME types exceptions in Web-shield
« Reply #9 on: March 21, 2011, 11:13:54 PM »
I bow to avast's greater knowledge of these matters and would tend to leave the default settings. If they became a target which could be exploited no doubt they would be removed.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security