PDA

View Full Version : TBF2 Hack attempt?


« RČ» HKS
01-04-2006, 01:14 AM
I was on here yesterday and all of a sudden NIS 2006 popped up with a hack attempt. I checked it out only to find it came from TBF2. Not sure what's going on here?

Hmm I thought I had a screenshot of it, but here is what the log says:

3/01/06 7:46:31 PM Instrusion detected and blocked. All communication with TotalBF2.com (64.34.200.249)
Intrusion: ICC TagData Overflow

Same thing happened on 31/12/05 same attack.

Any ideas as to why would be appreciated. It sounds like there is an image file which contains malicious code somewhere on TBF2.

Thanks

Explanation of this attack from Symantec:

ICC Profile TagData Overflow
Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects a buffer overflow condition in icm32.dll, exploited by rendering a malicious image file.

Additional Information

A buffer overflow has been reported in the icm32.dll. If the image contains International Color Consortium (ICC) data, icm32.dll will be loaded to process it.

A buffer overrun vulnerability exists in the processing images that contains a large ICC tag data size for any of the following tag entry signatures:

1)rXYZ
2)bXYZ
3)gXYZ

The purpose of the International Color Consortium® (ICC) format is to provide a cross-platform device profile format. Such device profiles can be used to translate color data created on one device into another device's native color space. The acceptance of this format by operating system vendors allows end users to transparently move profiles and images with embedded profiles between different operating systems. For example, this allows a printer manufacturer to create a single profile for multiple operating systems.

Affected:

All Windows.

Response

Visit the Microsoft Security Bulletin Page for patches.

Possible False Positives

There are no known false positives associated with this signature.

SaladFork
01-04-2006, 02:01 AM
Norton Internet Security (NIS) is known for having many false positives. I recommend switching to a different program (Kaspersky, Avast), or just check "Don't create a security alert for this threat again."

~Salad

Sir. Shpox
01-04-2006, 02:03 AM
Seconded, I tested many Anti-viri F-secure, Panda Bitdefender.., including paid and free ones, best one on my list was Kaspersky. Please look it into it.

« RČ» HKS
01-04-2006, 02:12 AM
Possible False Positives

There are no known false positives associated with this signature.

I have never had any probs with NIS I have used it for many years. I know they like to get bagged like EA does but it works for me.

SaladFork
01-04-2006, 02:51 AM
Alright, so just chose the option so it no longer alerts you, =)

~Salad

« RČ» HKS
01-04-2006, 03:13 AM
Alright, so just chose the option so it no longer alerts you, =)

~Salad

Thanks yeah I did that last time when it came up. The post was meant more so to warn tbf2 that an image may contain malicious code somewhere on the tbf2 site.

Sir. Shpox
01-04-2006, 03:27 AM
Pfft, there's malicous code in Salads Avatar :p

« RČ» HKS
01-04-2006, 04:18 AM
Pfft, there's malicous code in Salads Avatar :p

:laugh:

Keyelite
01-04-2006, 04:24 AM
Seconded, I tested many Anti-viri F-secure, Panda Bitdefender.., including paid and free ones, best one on my list was Kaspersky. Please look it into it.

Thirded, Kaspersky is the possibly the best ever, no problems whatsoever, and its 100% right every time.. atleast for me

Xicer
01-04-2006, 05:29 AM
If only it were free...

Sir. Shpox
01-04-2006, 05:37 AM
Oh but it can be but I won't get into such things ;)

Xicer
01-04-2006, 04:18 PM
Oh believe me, Ive probably done it more than you =D