声明:JavaEye新闻文章的版权属于JavaEye网站所有,严禁任何网站转载本文,否则必将追究法律责任!
在最近的“黑帽子”(Black Hat)网上技术交流会上,有黑客宣称找到了能够在gif图片中隐藏可执行java文件的方法。
这种方法可以创建一个GIF图片文件,但同时也是也是一个JAR文件。当这样的文件被上传到网站,而该web服务器运行有JVM运行时,该恶意java Applet就会被执行。
黑客们没有提供具体细节,因为Sun正在准备相应的安全补丁。
引用
During a recent webinar to promote the upcoming Black Hat briefings in Las Vegas, a group of hackers announced the creation of a hybrid file that can potentially bypass a browser’s same origin policy. They created a GIF file that also happens to be a JAR file ( a “GIFAR” file). Once uploaded onto a web site, and assuming the web server runs a JVM, it allows one to run a malicious java applet on someone else’s web server.
Details were not provided, since the hackers claim that Sun is still working on a patch. For more on hybrid (image) files as attack vectors, go to minute 41:23 of the webinar.
Details were not provided, since the hackers claim that Sun is still working on a patch. For more on hybrid (image) files as attack vectors, go to minute 41:23 of the webinar.
这种方法可以创建一个GIF图片文件,但同时也是也是一个JAR文件。当这样的文件被上传到网站,而该web服务器运行有JVM运行时,该恶意java Applet就会被执行。
黑客们没有提供具体细节,因为Sun正在准备相应的安全补丁。
来自:http://ajaxian.com/archives/evil-gifs-hiding-java-in-your-image


评论 共 8 条 发表评论
Eastsun 2008-07-07 21:51
只要不用java操作该图片,又有什么问题呢
貌似没这么简单
xufei0110 2008-07-07 17:38
weishuwei 2008-07-07 13:32
tedeyang 2008-07-07 09:48
web client吧?
XMLDB 2008-07-07 09:17
icewubin 2008-07-07 09:16
星光闪烁 2008-07-06 21:55
都别装了 2008-07-06 21:29