Aircraft of World War II - Warbird Forums
 



Go Back   Aircraft of World War II - Warbird Forums > News & Announcements :: READ > Announcements

Announcements Please Read!

Reply
 
LinkBack Thread Tools Display Modes
Old 12-30-2005, 01:14 PM   #1
Administrator
 
horseUSA's Avatar
 
Join Date: Mar 2003
Location: Florida, USA
Posts: 587
Windows Exploit - WMF

There is a new exploit out which affects all windows versions, and only requires viewing of an image to become infected. Please read up on this exploit and be very careful in vewing images. The F-Secure blog has some good info ( http://www.f-secure.com/weblog/ ), and windows currently has no patch released but they do have a workaround available at http://www.microsoft.com/technet/sec...ry/912840.mspx located in General Info > Suggested Actions.

Quote:
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to an error in the handling of Windows Metafile files (".wmf") containing specially crafted SETABORTPROC "Escape" records. Such records allow arbitrary user-defined function to be executed when the rendering of a WMF file fails. This can be exploited to execute arbitrary code by tricking a user into opening a malicious ".wmf" file in "Windows Picture and Fax Viewer" or previewing a malicious ".wmf" file in explorer (i.e. opening a folder containing a malicious image file).

The vulnerability can also be exploited automatically when a user visits a malicious web site using Microsoft Internet Explorer.

NOTE: Exploit code is publicly available. This is being exploited in the wild. The vulnerability can also be triggered from explorer if the malicious file has been saved to a folder and renamed to other image file extensions like ".jpg", ".gif, ".tif", and ".png" etc.

The vulnerability has been confirmed on a fully patched system running Microsoft Windows XP SP2. Microsoft Windows XP SP1 and Microsoft Windows Server 2003 SP0 / SP1 are reportedly also affected. Other platforms may also be affected.
Description From http://secunia.com/advisories/18255/



Info Sites:
http://www.f-secure.com/weblog/
http://www.securityfocus.com/bid/16074
http://secunia.com/advisories/18255/
__________________

Aircraft of WW2 :: Site Admin
horseUSA is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Old 12-30-2005, 01:16 PM   #2
Senior Member
 
syscom3's Avatar
 
Join Date: Jun 2005
Location: Orange County, CA
Posts: 10,277
Funny you posted this message as I was just reading about it on yahoo.

http://news.yahoo.com/s/nf/20051229/tc_nf/40530
__________________
"Pilot to copilot..... what are those mountain goats doing up here in the clouds?"
syscom3 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Old 12-30-2005, 01:29 PM   #3
Senior Member
 
the lancaster kicks ass's Avatar
 
Join Date: Dec 2003
Posts: 19,945
Send a message via MSN to the lancaster kicks ass
thanks for the heads up............
__________________

"Reminds me of the time I sank the Tirpitz" comments a Spitfire pilot, "One pass of course, old boy."
the lancaster kicks ass is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Old 12-30-2005, 03:12 PM   #4
Senior Member
 
Pisis's Avatar
 
Join Date: Nov 2004
Location: Praga Mater Urbium
Posts: 5,859
thanks for the warning horse.
__________________
"He's a menace to himself and everything else in the air... yes, birds too." - Airplane!

Memory of Nation

Why Did Hitler Want Czechoslovakia

WW2 Was A War That Had To Be Fought!

What Really Happened in Israel?

Children of Hamas

Pisis is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Old 01-07-2006, 01:39 PM   #5
Senior Member
 
the lancaster kicks ass's Avatar
 
Join Date: Dec 2003
Posts: 19,945
Send a message via MSN to the lancaster kicks ass
just checked out that site again, a patch has been released by microsoft..........

http://www.f-secure.com/weblog/archi...ve-012006.html

go down one entry to jan. 5th...........
__________________

"Reminds me of the time I sank the Tirpitz" comments a Spitfire pilot, "One pass of course, old boy."
the lancaster kicks ass is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 02:38 AM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.0
Ad Management plugin by RedTyger
Design by HTWoRKS


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118