Sunday, January 1st, 2006
I’ve spent some more effort on trying to infect Windows 98 SE in a virtual machine with some of the exploit samples I can find. The first attempt was at a website with the .wmf download. No luck infecting the system there. Then, I’ve loaded up the image and visited kyeu dot info/WMF/ and tried […]
Posted in Computers, Security, Spyware, Tech Support, Viruses, Windows | 2 Comments »
Sunday, January 1st, 2006
Most of the talk on the WMF zero-day has centered on Windows XP, 2000 and 2003. The unofficial patch is available for those three platforms. Microsoft’s (eventual) patch will likely be for those as well. Incidents.org had a comment in one of their posts that this would be a “watershed moment” for Windows 98/ME and […]
Posted in Computers, Security, Tech Support, Windows | No Comments »
Sunday, January 1st, 2006
The same person that has given the New Year’s gift of an unofficial patch for the WMF exploit circulating has also provided a WMF vulnerability checker, download and install, it will tell if you’re vulnerable. Post is available here. According to the first comment it seems as though the vulnerability checker is triggering Norton’s auto-protect. […]
Posted in Computers, Security | 1 Comment »
Sunday, January 1st, 2006
Since there’s been quite a bit of flux the last couple of days I thought I’d try to “reset” the situation and give a general overview of where we stand now with regards to the recent WMF zero-day exploit. 1st there is a vulnerability in the way Windows renders WMF (Windows MetaFile) image files that […]
Posted in Computers, Security, Spyware, Tech Support, Viruses, Windows | 1 Comment »
Sunday, January 1st, 2006
This is going to be a rough start to the new year for IT staff and computer users…. There’s coverage at Incidents.org, the sunbeltblog and f-secure of the latest twist in what will likely be a BIG mess to clean up. It looks like there’s a someone spamming emails to tons of addresses with a […]
Posted in Computers, Security, Spyware, Viruses | No Comments »
Saturday, December 31st, 2005
Sans is talking about the unofficial patch for the WMF vulnerability. One of their handlers has helped with it to extend it to work on XP SP 1 and Windows 2000. They’ve also looked at the patch thoroughly and it sounds as though it’s very well done. Send article as PDF
Posted in Computers, Security | No Comments »
Saturday, December 31st, 2005
Just when you thought we had a good understanding of the recent zero-day WMF (Windows metafile exploit) it’s worse. Sans is reporting on a new variation on the exploit released today. They have gone to yellow (again) to warn people. Here are some details. This exploit was “made by the folks at metasploit and xfocus, […]
Posted in Computers, Security, Spyware, Viruses | No Comments »
Saturday, December 31st, 2005
One of the vectors that has been mentioned early on is the infection of a system through the WMF exploit even when the exploited file was downloaded through a dos command shell. At first this seemed absurd, but it appeared that Google Desktop search was indexing files dynamically and once the file was downloaded it […]
Posted in Computers, Security | No Comments »
Saturday, December 31st, 2005
There is news this morning of a new twist in the WMF vulnerability (it was only a matter of time.) There are reports of an instant messenger worm using the vulnerability to spread. Currently incidents.org is reporting that the worm is spreading through the MSN messenger IM network and contains a malformed WMF file called […]
Posted in Computers, Security, Viruses | No Comments »
Saturday, December 31st, 2005
The F-secure blog is reporting on a third party patch for the WMF exploit. I have not tested it, it seems to come from a knowledgable source though. As I’m writing this though, the thought strikes me that a really nasty trick would be a claimed fix that actually exploited the vulnerability. It pays to […]
Posted in Computers, Security | No Comments »