Warning

 

Close

Confirm Action

Are you sure you wish to do this?

Confirm Cancel
BCM
User Panel

Page / 2
Next Page Arrow Left
Link Posted: 1/3/2006 10:44:50 PM EDT
[#1]

Quoted:
It has to be a .WMF file thu all u have to do it tell your browser to not load WMF files.


That is not correct, as bastiat has already pointed out.  From Microsoft's own security bulletin:



If I block .wmf files by extension, can this protect me against attempts to exploit this vulnerability?
No. Because the Graphics Rendering Engine determines file type by means other than just looking at the file extensions, it is possible for WMF files with changed extensions to still be rendered in a way that could exploit the vulnerability.

<snip>

It is important to remember that this malicious attachment may not be a .wmf. It could also be a .jpg, .gif, or other format



If you want to take more effective preventative action, GRC reports that the official patch has already been leaked:

www.grc.com/sn/notes-020.htm

You can also get the unofficial patch there.  Apply according to your own judgement and use at your own risk.
Link Posted: 1/4/2006 11:12:01 AM EDT
[#2]

umm who the hell uses WMF anyway


Microsoft uses them.  Office installs a huge number of them.  I just looked through the tape logs from the 24 Windows computers here, and there are 149,764 .wmf files.  That's an average of 6,240 per Windows system.  .WMF files are going to be around for a long time.


almost every image online is either jpg, gif, or png.


So?  All you have to do is view a web page, or even a forum page like here, that contains an image that exploits this backdoor, and you're screwed.z
Link Posted: 1/5/2006 9:21:20 PM EDT
[#3]
Microsoft has released the official patch. Mine just came in through autoupdate.
Link Posted: 1/5/2006 11:22:11 PM EDT
[#4]
I love seeing those mal adjusted, livin in moms basement, never been laid, punks when the PO-PO gets em... Your virus isnt so funny now is it?
Link Posted: 1/5/2006 11:55:07 PM EDT
[#5]

Quoted:
Microsoft has released the official patch. Mine just came in through autoupdate.


+1

Leastwise, I guess that’s what happened.  (Paused surfing to start taping a stupid anime cartoon on TNT, got engrossed in it, came back 2 1/2 hours later to find my machine rebooted with a note that Windows had been updated!! )
Link Posted: 1/5/2006 11:56:50 PM EDT
[#6]

Quoted:
Microsoft has released the official patch. Mine just came in through autoupdate.



I guess that must be the same update I just got. Hopefully I haven't already been infected. Damn hackers! They should all hang!
Link Posted: 1/6/2006 7:56:05 AM EDT
[#7]
http://www.microsoft.com/downloads/details.aspx?familyid=0C1B4C96-57AE-499E-B89B-215B7BB4D8E9&displaylang=en
Page / 2
Next Page Arrow Left
Close Join Our Mail List to Stay Up To Date! Win a FREE Membership!

Sign up for the ARFCOM weekly newsletter and be entered to win a free ARFCOM membership. One new winner* is announced every week!

You will receive an email every Friday morning featuring the latest chatter from the hottest topics, breaking news surrounding legislation, as well as exclusive deals only available to ARFCOM email subscribers.


By signing up you agree to our User Agreement. *Must have a registered ARFCOM account to win.
Top Top