Oh come on, guys! That ultrahax image I posted is merely a hoax I had hoped some of you would have noticed it. It's just a screenshot of a GUI that I made in 10 minutes in VB6 to scare you off a bit. None of those buttons actually work. I guessed somebody was trying to get attention by posting an image of a tool that is supposed to be able to crash jj2+. So I decided to make one myself to show how easy it is to fool people. Personally, I believe that the other tool is also a hoax and cannot crash jj2+.
However, it is theoretically possible to remotely inject an arbitrary DLL into a jj2 process and both, jj2 and jj2+ are currently vulnerable to this attack. While I am not willing to discuss it in public, I will have to file a security report on this vulnerability sometime and include a fix.
~Ol
__________________
<a href="http://nmap.org/"><img border="0" alt="Nmap Security Scanner" src="http://images.insecure.org/nmap/images/prop/nmap_bnr_matrix_pfos.gif"/></a>
|