Likes Likes:  0
Resultaten 1 tot 4 van de 4
Geen
  1. #1
    Pierre Vandevenne
    Re: [funsec] WMF round-up, updates and de-mystification
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: [funsec] WMF round-up, updates and de-mystification

    Good Afternoon,

    Tuesday, January 3, 2006, 9:28:40 AM, you wrote:

    GE> The "patch" by Ilfak Guilfanov works, but by disabling a DLL in Windows.

    I wouldn't say it does that. If you really want to simplify it in the
    extreme, it hides the vulnerable function. The patch was, imho done
    precisely to avoid disabling the dll, and because disabling the dll
    wasn't necessarily successful in all cases.

    --
    Best regards,
    Pierre mailtoierre@datarescue.com



  2. #2
    Larry Seltzer
    Re: [funsec] WMF round-up, updates and de-mystification
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: [funsec] WMF round-up, updates and de-mystification

    GE> The "patch" by Ilfak Guilfanov works, but by disabling a DLL in Windows.
    PV> I wouldn't say it does that. If you really want to simplify it in the
    extreme, it hides the vulnerable function.

    Think of it as a "White Hat Rootkit"

    Larry Seltzer
    eWEEK.com Security Center Editor
    http://security.eweek.com/
    http://blog.ziffdavis.com/seltzer
    Contributing Editor, PC Magazine
    larryseltzer@ziffdavis.com



  3. #3
    Krpata, Tyler
    Re: [funsec] WMF round-up, updates and de-mystification
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: WMF round-up, updates and de-mystification

    It looks like MS has backed off on "viewing mail" as a possible attack
    vector. As of today, the advisory
    (http://www.microsoft.com/technet/sec...ry/912840.mspx) reads:

    "In an E-mail based attack involving the current exploit, customers
    would have to be persuaded to click on a link within a malicious e-mail
    or open an attachment that exploited the vulnerability. At this point,
    no attachment has been identified in which a user can be attacked simply
    by reading mail."

    However, the advisory now includes this (incorrect) piece of
    information:

    "Windows Metafile (WMF) images can be embedded in other files such as
    Word documents. Am I vulnerable to an attack from this vector?"
    "No. While we are investigating the public postings which seek to
    utilize specially crafted WMF files through IE, we are looking
    thoroughly at all instances of WMF handling as part of our
    investigation. While we're not aware of any attempts to embed specially
    crafted WMF files in, for example Microsoft Word documents, our advice
    is to accept files only from trusted source would apply to any such
    attempts."


    -----Original Message-----
    From: Gadi Evron [mailto:ge@linuxbox.org]=20
    Sent: Tuesday, January 03, 2006 3:29 AM
    To: bugtraq@securityfocus.com
    Cc: full-disclosure@lists.grok.org.uk; FunSec [List]
    Subject: WMF round-up, updates and de-mystification

    Quite a bit of confusing and a vast amount of information coming from=20
    all directions about the WMF 0day. Here are some URL's and generic facts

    to set us straight.

    The "patch" by Ilfak Guilfanov works, but by disabling a DLL in Windows.

    So far no problems have been observed by anyone using this patch. You=20
    should naturally check it out for yourselves but I and many others=20
    recommend it until Microsoft bothers to show up with their own patch.

    Ilfak is trusted and is in no way a Bad Guy.

    You can find more information about it at his blog:
    http://www.hexblog.com/2005/12/wmf_vuln.html

    If you are still not sure about the patch by Ilfak, check out the=20
    discussion of it going on in the funsec list about the patch, with Ilfak

    participating:
    https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
    Occasional information of new WMF problems keep coming in over there.

    In this URL you can find the best summary I have seen of the WMF issue:
    http://isc.sans.org/diary.php?storyid=3D994
    by the "SANS ISC diary" team.

    In this URL you can find the best write-up I have seen on the WMF issue:
    http://blogs.securiteam.com/index.php/archives/167
    By Matthew Murphy at the "Securiteam Blogs".

    Also, it should be noted at this time that since the first public=20
    discovery of this "problem", a new one has been coming in - every day.=20
    All the ones seen so far are variants of the original and in all ways=20
    the SAME problem. So, it would be best to acknowledge them as the=20
    same... or we will keep having a NEW 0day which really isn't for about 2

    months when all these few dozen variations are exhausted.

    A small BUT IMPORTANT correction for future generations:
    The 0day was originally found and reported by Hubbard Dan from Websense=20
    on a closed vetted security mailing list, and later on at the Websense=20
    public page. All those who took credit for it took it wrongly.

    Thanks, and a better new year to us all,

    Gadi.


  4. #4
    Adam Shostack
    Re: [funsec] WMF round-up, updates and de-mystification
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: WMF round-up, updates and de-mystification

    On Tue, Jan 03, 2006 at 10:28:40AM +0200, Gadi Evron wrote:
    | The "patch" by Ilfak Guilfanov works, but by disabling a DLL in Windows.
    | So far no problems have been observed by anyone using this patch. You

    This is incorrect. Michael Hennessy has reported problems on
    the patch-management mailing list:

    > I took the SANS advice and de-registered the dll, and also installed
    > Ilfak Guilfanov's "temporary patch" on 1 win2k machine and 6 XP
    > machines today.
    >
    > All fine except for one of the XP machines - wouldn't run IE without
    > gpf'ing until I uninstalled the patch - but leaving the dll
    > de-registered didn't seem to cause any grief anywhere, so far.
    >
    > FWIW, the iexplore crashes left this in the event log:
    >
    > Event ID 4097, source : drwatson The application, C:\Program
    > Files\Internet Explorer\iexplore.exe, generated an application
    > error The error occurred on 01/02/2006 @ 14:49:49.709 The exception
    > generated was c0000005 at address 0068E3BA (<nosymbols>)
    >
    > I suspect that the patch conflicts with an application that is
    > specific to this machine.


    http://marc.theaimsgroup.com/?l=patc...4877814460&w=2


Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics