Likes Likes:  0
Resultaten 1 tot 4 van de 4
Geen

Onderwerp: WMF exploit

  1. #1
    Andreas Marx
    WMF exploit
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    WMF exploit

    Hi,

    I like what SANS is saying about the current MS announcement to deliver a patch by Jan 10, 2006, but not earlier:
    http://isc.sans.org/diary.php

    This is the interesting part:
    "Although the issue is serious and malicious attacks are being attempted, Microsoft's intelligence sources indicate that the scope of the attacks are not widespread."
    - Microsoft Security Advisory (912840)

    First, there are many websites which intentionally includes Iframes to malware WMF files (like some "crack", "XXX" or "patch" websites). Besides this, there were some mass hacks of usually more trustworthy web sites -- now, the websites will still render
    fine, but the included WMF file will be started automatically.

    We have analysed some 100 malware WMF files and they can do almost anything. We saw download trojans, adware and spyware apps, backdoors, lots of bots (zombie programs), as well as password-spying programs which are looking for PINs and TANs for online ba
    nking attacks. I expect that some 1,000 websites are already compromised.

    One of the malware apps we have discovered at 2005-12-29 (some days ago!) already had a build-in infection counter at a (hidden) website and we saw the number 233,000. This means, a few days back, some 100,000 PCs seems to be compromised already. Today, t
    he website is still working, and has delivered more than 1,000,000 malware installation files already. With 1+ million PCs under your control, you can do almost everything!

    This means, the issue is extremely critical, even if the current attack vector seems to be websites only. We already saw a few malware WMF files in e-mails, but not many. The chances are good, however, that we might see a worm in the next few days which s
    preads using WMF files and e-mail as infection vector. Well, I can't understand why Microsoft is considering some 1,000,000 infections as being "not widespread". And that's the counter for just ONE special malware file!

    Note: I've informed MS (secure@microsoft.com) about the malware links, the counter and I've send them the malware WMF files as well as the downloaded EXE files some days ago already.

    cheers,
    Andreas

    http://www.av-test.org

    __________________________________________________ ____________
    Verschicken Sie romantische, coole und witzige Bilder per SMS!
    Jetzt bei WEB.DE FreeMail: http://f.web.de/?mc=021193


  2. #2
    Paul Laudanski
    WMF exploit
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: WMF Exploit

    On Tue, 3 Jan 2006, Sam Munro wrote:

    > I haven't seen this mentioned yet so I thought I would give you guys a
    > heads-up a very good patch has been written by Ilfak
    > Guilfanov<http://www.hexblog.com/2005/12/wmf_vuln.html> as
    > a tempory solution until ms get their act together.
    >
    > Can be downloaded here:
    > http://www.hexblog.com/security/file..._hexblog14.exe


    Ilfak's hexblog.com is down. CastleCops is hosting the downloads now and
    there is a hexblog forum setup which Ilfak himself is moderating:

    http://castlecops.com/f212-Hexblog.html

    The downloads, etc can be found here:

    http://castlecops.com/postlite143213-.html

    --
    Paul Laudanski, Microsoft MVP Windows-Security
    [cal] http://events.castlecops.com
    [de] http://de.castlecops.com
    [en] http://castlecops.com
    [wiki] http://wiki.castlecops.com
    [family] http://cuddlesnkisses.com


  3. #3
    Discussion Lists
    WMF exploit
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: WMF Exploit

    All,
    I think I was able to get the SAFER mechanism to block this for IE, and
    any program covered under it. I know that there are other workarounds,
    but I have found the SAFER approach has stopped every one of these sorts
    of attacks. I have a vbscript that activates SAFER for IE, and various
    other client apps. Email me at this address if you want me to send it
    out to anyone.

    Thanks!

    > -----Original Message-----
    > From: Bill Busby [mailto:williambusby2001@yahoo.com]=20
    > Sent: Thursday, December 29, 2005 1:35 PM
    > To: Hayes, Bill; davidribyrne@yahoo.com
    > Cc: bugtraq@securityfocus.com
    > Subject: RE: WMF Exploit
    >=20
    >=20
    > It is not only *.wmf extensions it is all files that
    > have windows metafile headers that will open with the
    > Windows Picture and Fax Viewer. Any file that has the
    > header of a windows metafile can trigger this exploit.
    >=20
    > --- "Hayes, Bill" <Bill.Hayes@owh.com> wrote:
    >=20
    > > CERT now has posted Vulnerability Note VU#181038,
    > > "Microsoft Windows may
    > > be vulnerable to buffer overflow via specially
    > > crafted WMF file"
    > > (http://www.kb.cert.org/vuls/id/181038). The note
    > > provides additional
    > > details about the exploit and its effects. Very few workarounds have
    > > been proposed other than blocking at the perimeter
    > > and possibly
    > > remapping the .wmf extension to some application
    > > other than the
    > > vulnerable Windows Picture and Fax Viewer
    > > (SHIMGVU.DLL).
    > >=20
    > > Bill...
    > >=20
    > > -----Original Message-----
    > > From: davidribyrne@yahoo.com
    > > [mailto:davidribyrne@yahoo.com]
    > > Sent: Wednesday, December 28, 2005 4:18 PM
    > > To: bugtraq@securityfocus.com
    > > Subject: WMF Exploit
    > >=20
    > >=20
    > > Another quick observation, again, I apologize if
    > > this information has
    > > already been posted; I haven't been able to read all
    > > the posts today.
    > > The thumbnail view in Windows Explorer will parse
    > > the graphics files in
    > > a folder, even if the file is never explicitly
    > > opened. This is enough to
    > > trigger the exploit. Even more frightening is that
    > > you don't have to use
    > > the thumbnail view for a thumbnail to be generated.
    > > Under some
    > > circumstances, just single-clicking on the file will
    > > cause it to be
    > > parsed.
    > >=20
    > > David Byrne
    > >=20

    >=20
    >=20
    >=20
    > =09
    > =09
    > __________________________________=20
    > Yahoo! for Good - Make a difference this year.=20
    > http://brand.yahoo.com/cybergivingweek2005/
    >=20


  4. #4
    Joshua
    WMF exploit
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: WMF Exploit

    This is probably due to M$ thumbnail generation. You can disable that
    and see if it fixes the problem...

    grasshopa@securityfocus.com wrote:

    >I've tested the exploit on XP home and I've found that it does not even need a single click on my machine. Once the folder containing the file is open (this was in list view) the exploit will run.
    >
    >Scary sh*t!
    >
    >
    >



Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics