JPEG Exploit Targeting Porn Newsgroups

CYBERSPACE — The first attacks using the Windows JPEG flaw have shown up on adult-oriented newsgroups, according to warnings issued by Internet security organizations today.

Usenet-related site EasyNews published a notice today that pornographic images containing hidden code were posted to at least 10 of the alt.binaries newsgroups, including alt.binaries.erotica.breasts and alt.binaries.erotica.beanie-babies.

The images first started to be posted at around 7 p.m. on Sunday, according to Godzilla, an administrator at EasyNews.

The corrupted images, which look exactly the same as a normal image, exploits the recently-announced JPEG flaw in Windows’ Graphic Device Interface Plus (GDI+) with a buffer overflow attack.

“Once this JPEG overflowed GDI+, it phoned home, connected to an FTP site and downloaded almost 2 megs of stuff,” stated Godzilla.

After downloading the files, the malicious code sets the infected computer up as a server and installs an IRC client.

According to Godzilla, 93 users were logged into the FTP site when he checked it last.

The release of the infected images came less than a week after sample code appeared on the Internet that explained how to exploit the GDI+ JPEG flaw.

According to the F-Secure Antivirus Research Team, the corrupted images don’t seem to be attempting to spread themselves.

“These JPEGs did not replicate, so this is not a virus,” the team wrote in their weblog. “Apparently, they tried to use these JPEGs to download Trojans to vulnerable computers… but the download sites should be down by now.”

Even though the threat posed by the these specific postings may have passed, F-Secure is concerned that it might signal a large problem on the way.

“Things are heating up,” wrote Mikko, a member of F-Secure’s antivirus team. “I have a nasty feeling we might sooner or later see a massmailer worm using a JPEG image as the attachment.”

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Strike 3 Rejects Meta 'Personal Use' Defense in AI Suit

Vixen Media Group owner Strike 3 Holdings this week responded to Facebook parent company Meta’s motion to dismiss Strike 3’s suit accusing Meta of pirating VMG content to train its artificial intelligence models.

Pornhub, Stripchat: VLOP Designation Based on Flawed Data

In separate cases, attorneys for Pornhub and Stripchat this week told the EU’s General Court that the European Commission relied on unreliable data when it classified the sites as “very large online platforms” (VLOPs) under the EU’s Digital Services Act, news organization MLex reports.

New Age Verification Service 'AgeWallet' Launches

Tech company Brady Mills Agency has officially launched its subscription-based age verification solution, AgeWallet.

AEBN Publishes Popular Searches for September, October

AEBN has published the top search terms for the months of September and October from its straight and gay theaters in all 50 states and the District of Columbia.

Creator, Influencer YesKingzTV Passes Away at 47

Adult content creator and social media personality YesKingzTV, aka Micheal Willis Heard, has passed away at the age of 47.

Pre-Nominations Now Open for 2026 TEAs

The pre-nomination period for the 2026 Trans Erotica Awards (TEAs) is now open.

FSC Releases Updated Age Verification Toolkit

The Free Speech Coalition (FSC) has announced the release of its updated age verification toolkit.

Duke Tax Joins Pineapple Support as Supporter-Level Sponsor

Duke Tax has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

UK Moving Ahead with Plan to Outlaw 'Choking' Content

The U.K. government has announced its intent to follow through on criminalizing “choking” content, a plan that was announced earlier this year.

Italy to Require Age Verification for Adult Sites

Italian media regulator AGCOM has announced that all sites and platforms hosting adult content will be required to implement age verification systems to prevent access by users under 18.

Show More