Author Topic: Windows WMF-vulnerability  (Read 1413 times)

0 Members and 1 Guest are viewing this topic.

Offline Fury

  • The Curmudgeon
  • 213
Windows WMF-vulnerability
http://www.neowin.net/index.php?act=view&id=31931

The long story short:
- There is no security patch from Microsoft yet.
- Internet Explorer runs WMF-files without asking.
- Firefox and Opera won't save you from this exploit, but they ask before running WMF-files.
- Anti-Spyware and Anti-Virus softwares do not reliably detect any of the variations of this exploit.
- Once your system is infected, you probably have to reinstall Windows.

See a video about the first exploit in action: (note that the file extension is wmv, not wmf)
http://www.websensesecuritylabs.com/images/alerts/wmf-movie.wmv
« Last Edit: January 02, 2006, 01:05:55 am by Mr. Fury »

  

Offline Janos

  • A *really* weird sheep
  • 28
Re: Windows WMF-vulnerability
- Disabling WMFs doesn't help because they can be renamed to pretty much anything. If you somehow manage to block them then clearing your cache can install the exploit (it checks the cache files). Lovely.
- Mozilla and other Indie Alternative Cool Browsers decrease but don't remove the threat. You CAN stop the WMFs from loading in IE, but there's some technobabble explanation as to why it doesn't work.
- Yeah, you're ****ed, better stay away from eBay and Wiki and forums and uhhh whatever. Someone might have posted a picture here - in SomethingAwful it was a transparent 1x1px .gif which contained the exploit. Good luck finding that one.
- NOD32 helps, get it
- the exploit itself is useless, but it can piggybank a nice amount of trojans, spies and **** into your precious hard drives.

Remember - if you drive alone, you drive with Hitler.
lol wtf

 

Offline Kamikaze

  • A Complacent Wind
  • 29
    • http://www.nodewar.com
Re: Windows WMF-vulnerability
I hear you can get exploited just by browsing inside a directory that has an infected file.

Here're a couple methods to avoid being hit:

Run "regsvr32 -u %windir%\system32\shimgvw.dll" in the command prompt. This unregisters the Windows picture and fax viewer.

http://www.hexblog.com/2005/12/wmf_vuln.html <-- Unofficial patch

More info about the exploit/bug itself:

http://www.f-secure.com/weblog/
http://isc.sans.org/diary.php?storyid=994
Science alone of all the subjects contains within itself the lesson of the danger of belief in the infallibility of the greatest teachers in the preceding generation . . .Learn from science that you must doubt the experts. As a matter of fact, I can also define science another way: Science is the belief in the ignorance of experts. - Richard Feynman

 

Offline achtung

  • Friendly Neighborhood Mirror Guy
  • 210
  • ****in' Ace
    • Freespacemods.net
Re: Windows WMF-vulnerability
Heard about it already.

regsvr32 -u shimgvw.dll
Unregister

regsvr32 shimgvw.dll
Reregister

Yours is too long Kamikaze :p
FreeSpaceMods.net | FatHax | ??????
In the wise words of Charles de Gaulle, "China is a big country, inhabited by many Chinese."

Formerly known as Swantz

 

Offline Fury

  • The Curmudgeon
  • 213
Re: Windows WMF-vulnerability
Swantz, unregistering shimgvw.dll only prevents IE and Windows from viewing wmf-files automatically, it does not prevent your system from being infected if you open a wmf-file regardless.

 

Offline achtung

  • Friendly Neighborhood Mirror Guy
  • 210
  • ****in' Ace
    • Freespacemods.net
Re: Windows WMF-vulnerability
I know it doesnt fix it, it's just a preventitive measure.
FreeSpaceMods.net | FatHax | ??????
In the wise words of Charles de Gaulle, "China is a big country, inhabited by many Chinese."

Formerly known as Swantz

 

Offline Sandwich

  • Got Screen?
  • 213
    • Skype
    • Steam
    • Twitter
    • Brainzipper
Re: Windows WMF-vulnerability
SERIOUSLY...! | {The Sandvich Bar} - Rhino-FS2 Tutorial | CapShip Turret Upgrade | The Complete FS2 Ship List | System Background Package

"...The quintessential quality of our age is that of dreams coming true. Just think of it. For centuries we have dreamt of flying; recently we made that come true: we have always hankered for speed; now we have speeds greater than we can stand: we wanted to speak to far parts of the Earth; we can: we wanted to explore the sea bottom; we have: and so  on, and so on: and, too, we wanted the power to smash our enemies utterly; we have it. If we had truly wanted peace, we should have had that as well. But true peace has never been one of the genuine dreams - we have got little further than preaching against war in order to appease our consciences. The truly wishful dreams, the many-minded dreams are now irresistible - they become facts." - 'The Outward Urge' by John Wyndham

"The very essence of tolerance rests on the fact that we have to be intolerant of intolerance. Stretching right back to Kant, through the Frankfurt School and up to today, liberalism means that we can do anything we like as long as we don't hurt others. This means that if we are tolerant of others' intolerance - especially when that intolerance is a call for genocide - then all we are doing is allowing that intolerance to flourish, and allowing the violence that will spring from that intolerance to continue unabated." - Bren Carlill

 

Offline Taristin

  • Snipes
  • 213
  • BlueScalie
    • Skelkwank Shipyards
Freelance Modeler | Amateur Artist

 

Offline Flipside

  • əp!sd!l£
  • 212
Re: Windows WMF-vulnerability
Probably being overloaded atm, I suspect theres a lot of people trying to access that site.

 

Offline Kosh

  • A year behind what's funny
  • 210
Re: Windows WMF-vulnerability
Looks like this isn't a bug, but just a leftover from the 1980's.

http://www.f-secure.com/weblog/#00000761

Scroll down a bit and you'll see it.
"The reason for this is that the original Fortran got so convoluted and extensive (10's of millions of lines of code) that no-one can actually figure out how it works, there's a massive project going on to decode the original Fortran and write a more modern system, but until then, the UK communication network is actually relying heavily on 35 year old Fortran that nobody understands." - Flipside

Brain I/O error
Replace and press any key

 

Offline knn

  • 28
Re: Windows WMF-vulnerability
Since hexblog is unavailable, you can dl the patch from http://handlers.sans.org/tliston/wmffix_hexblog14.exe

Edit: changed to version 1.4 and [url]-d
« Last Edit: January 03, 2006, 05:44:49 pm by knn »
"Don't try to be a great man, just be a man and let history make its own judgments." -- Zefram Cochrane

 

Offline karajorma

  • King Louie - Jungle VIP
  • Administrator
  • 214
    • Karajorma's Freespace FAQ
Re: Windows WMF-vulnerability
Anyone notice the comment that states that this is unlikely to be the only WMF flaw? :rolleyes:
Karajorma's Freespace FAQ. It's almost like asking me yourself.

[ Diaspora ] - [ Seeds Of Rebellion ] - [ Mind Games ]

 

Offline Kamikaze

  • A Complacent Wind
  • 29
    • http://www.nodewar.com
Re: Windows WMF-vulnerability
Ironically, this "feature" from the 80's is only easily exploitable on Windows XP and 2003.

From the F-secure blog:

Quote
...in a practical sense, only Windows XP and Windows Server 2003 (in all their service pack levels) are vulnerable to the WMF flaw.
...all versions of Windows back to 3.0 have the vulnerability in GDI32. Except for Windows XP and Windows Server 2003, no Windows versions, in their default configuration, have a default association for WMF files, and none of their Paint programs or any other standard programs installed with them can read WMF files...
Science alone of all the subjects contains within itself the lesson of the danger of belief in the infallibility of the greatest teachers in the preceding generation . . .Learn from science that you must doubt the experts. As a matter of fact, I can also define science another way: Science is the belief in the ignorance of experts. - Richard Feynman

 
Re: Windows WMF-vulnerability
I'm using Linux for the next two weeks. I won't have time for gaming anyway.
'And anyway, I agree - no sig images means more post, less pictures. It's annoying to sit through 40 different sigs telling about how cool, deadly, or assassin like a person is.' --Unknown Target

"You know what they say about the simplest solution."
"Bill Gates avoids it at every possible opportunity?"
-- Nuke and Colonol Drekker

 

Offline Kamikaze

  • A Complacent Wind
  • 29
    • http://www.nodewar.com
Science alone of all the subjects contains within itself the lesson of the danger of belief in the infallibility of the greatest teachers in the preceding generation . . .Learn from science that you must doubt the experts. As a matter of fact, I can also define science another way: Science is the belief in the ignorance of experts. - Richard Feynman