Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    InfoSecBOFH
    Re: [Full-disclosure] WMF round-up, updates and de-mystification
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: [Full-disclosure] WMF round-up, updates and de-mystification

    So this patch is trusted because you said so?

    I have tested and confirmed that this patch only works in specific
    scnenarios and does not mitigate the entire issue. Variations still
    work.

    On 1/3/06, Gadi Evron <ge@linuxbox.org> wrote:
    > Quite a bit of confusing and a vast amount of information coming from
    > all directions about the WMF 0day. Here are some URL's and generic facts
    > to set us straight.
    >
    > The "patch" by Ilfak Guilfanov works, but by disabling a DLL in Windows.
    > So far no problems have been observed by anyone using this patch. You
    > should naturally check it out for yourselves but I and many others
    > recommend it until Microsoft bothers to show up with their own patch.
    >
    > Ilfak is trusted and is in no way a Bad Guy.
    >
    > You can find more information about it at his blog:
    > http://www.hexblog.com/2005/12/wmf_vuln.html
    >
    > If you are still not sure about the patch by Ilfak, check out the
    > discussion of it going on in the funsec list about the patch, with Ilfak
    > participating:
    > https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
    > Occasional information of new WMF problems keep coming in over there.
    >
    > In this URL you can find the best summary I have seen of the WMF issue:
    > http://isc.sans.org/diary.php?storyid=3D994
    > by the "SANS ISC diary" team.
    >
    > In this URL you can find the best write-up I have seen on the WMF issue:
    > http://blogs.securiteam.com/index.php/archives/167
    > By Matthew Murphy at the "Securiteam Blogs".
    >
    > Also, it should be noted at this time that since the first public
    > discovery of this "problem", a new one has been coming in - every day.
    > All the ones seen so far are variants of the original and in all ways
    > the SAME problem. So, it would be best to acknowledge them as the
    > same... or we will keep having a NEW 0day which really isn't for about 2
    > months when all these few dozen variations are exhausted.
    >
    > A small BUT IMPORTANT correction for future generations:
    > The 0day was originally found and reported by Hubbard Dan from Websense
    > on a closed vetted security mailing list, and later on at the Websense
    > public page. All those who took credit for it took it wrongly.
    >
    > Thanks, and a better new year to us all,
    >
    > Gadi.
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    > Hosted and sponsored by Secunia - http://secunia.com/
    >


  2. #2
    Larry Seltzer
    Re: [Full-disclosure] WMF round-up, updates and de-mystification
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: [Full-disclosure] WMF round-up, updates and de-mystification

    >>I have tested and confirmed that this patch only works in specific
    scnenarios and does not mitigate the entire issue. Variations still work.I
    have tested and confirmed that this patch only works in specific scnenarios
    and does not mitigate the entire issue. Variations still work.

    Oh really? Do you have any more information on this or do you just like to
    throw bricks? I have a hard time believing you're right, because it would
    mean that there are variations of the attack that don't use its fundamental
    mechanism.

    All that said, it's clear to me that the rush to adopt this patch is
    precipitous. For instance, it's largely unnecessary on Windows 9x, NT, and
    2K, unless you rely on a specifically vulnerable app, like Notes.

    Larry Seltzer
    eWEEK.com Security Center Editor
    http://security.eweek.com/
    http://blog.ziffdavis.com/seltzer
    Contributing Editor, PC Magazine
    larryseltzer@ziffdavis.com



  3. #3
    Gadi Evron
    Re: [Full-disclosure] WMF round-up, updates and de-mystification
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: WMF round-up, updates and de-mystification

    Hey Pierre!
    I stand corrected although beyond my simplification, the URL's do a good jo=
    b.

    Gadi.

    On 1/3/06, Pierre Vandevenne <pierre@datarescue.com> wrote:
    > Good Afternoon,
    >
    > Tuesday, January 3, 2006, 9:28:40 AM, you wrote:
    >
    > GE> The "patch" by Ilfak Guilfanov works, but by disabling a DLL in Windo=

    ws.
    >
    > I wouldn't say it does that. If you really want to simplify it in the
    > extreme, it hides the vulnerable function. The patch was, imho done
    > precisely to avoid disabling the dll, and because disabling the dll
    > wasn't necessarily successful in all cases.
    >
    > --
    > Best regards,
    > Pierre mailtoierre@datarescue.com
    >
    >
    > _______________________________________________
    > Fun and Misc security discussion for OT posts.
    > https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
    > Note: funsec is a public and open mailing list.
    >


Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics