Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen

Onderwerp: WMF exploit

  1. #1
    ninjapicook@gmail.com
    WMF exploit
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    WMF exploit

    use c:\regsvr32.exe /u shimgvw.dll
    to disable wmf execution

  2. #2
    Derick Anderson
    WMF exploit
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: WMF Exploit

    =20

    > -----Original Message-----
    > From: Hayes, Bill [mailto:Bill.Hayes@owh.com]=20
    > Sent: Wednesday, December 28, 2005 6:02 PM
    > To: davidribyrne@yahoo.com
    > Cc: bugtraq@securityfocus.com
    > Subject: RE: WMF Exploit
    >=20
    > CERT now has posted Vulnerability Note VU#181038, "Microsoft=20
    > Windows may be vulnerable to buffer overflow via specially=20
    > crafted WMF file"
    > (http://www.kb.cert.org/vuls/id/181038). The note provides=20
    > additional details about the exploit and its effects. Very=20
    > few workarounds have been proposed other than blocking at the=20
    > perimeter and possibly remapping the .wmf extension to some=20
    > application other than the vulnerable Windows Picture and Fax=20
    > Viewer (SHIMGVU.DLL).
    >=20
    > Bill...


    F-Secure
    (http://www.f-secure.com/weblog/archi....html#00000752)
    mentioned a Microsoft workaround (which I actually did not see in the MS
    TechNet bulliten they linked to):

    ----

    Un-register the Windows Picture and Fax Viewer (Shimgvw.dll)

    1. Click Start, click Run, type "regsvr32 -u
    %windir%\system32\shimgvw.dll"
    (without the quotation marks), and then click OK.

    2. A dialog box appears to confirm that the un-registration process has
    succeeded.
    Click OK to close the dialog box.

    Impact of Workaround: The Windows Picture and Fax Viewer will no longer
    be started
    when users click on a link to an image type that is associated with the
    Windows Picture and Fax Viewer.

    To undo this change, re-register Shimgvw.dll by following the above
    steps.
    Replace the text in Step 1 with "regsvr32 %windir%\system32\shimgvw.dll"
    (without the quotation marks).

    ----

    It's highly dumbed down but suitable for bulk distribution to the
    average user =3D). Additionally F-Secure mentions sites related to the
    attack, blocking them is an interim solution.

    Derick Anderson

  3. #3
    Bill Busby
    WMF exploit
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: WMF Exploit

    It is not only *.wmf extensions it is all files that
    have windows metafile headers that will open with the
    Windows Picture and Fax Viewer. Any file that has the
    header of a windows metafile can trigger this exploit.

    --- "Hayes, Bill" <Bill.Hayes@owh.com> wrote:

    > CERT now has posted Vulnerability Note VU#181038,
    > "Microsoft Windows may
    > be vulnerable to buffer overflow via specially
    > crafted WMF file"
    > (http://www.kb.cert.org/vuls/id/181038). The note
    > provides additional
    > details about the exploit and its effects. Very few
    > workarounds have
    > been proposed other than blocking at the perimeter
    > and possibly
    > remapping the .wmf extension to some application
    > other than the
    > vulnerable Windows Picture and Fax Viewer
    > (SHIMGVU.DLL).
    >
    > Bill...
    >
    > -----Original Message-----
    > From: davidribyrne@yahoo.com
    > [mailto:davidribyrne@yahoo.com]
    > Sent: Wednesday, December 28, 2005 4:18 PM
    > To: bugtraq@securityfocus.com
    > Subject: WMF Exploit
    >
    >
    > Another quick observation, again, I apologize if
    > this information has
    > already been posted; I haven't been able to read all
    > the posts today.
    > The thumbnail view in Windows Explorer will parse
    > the graphics files in
    > a folder, even if the file is never explicitly
    > opened. This is enough to
    > trigger the exploit. Even more frightening is that
    > you don't have to use
    > the thumbnail view for a thumbnail to be generated.
    > Under some
    > circumstances, just single-clicking on the file will
    > cause it to be
    > parsed.
    >
    > David Byrne
    >






    __________________________________
    Yahoo! for Good - Make a difference this year.
    http://brand.yahoo.com/cybergivingweek2005/

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics