Page 1 of 1

Windows WMF exploit

Posted: Tue Jan 03, 2006 12:47 am
by corncobman
All you have to do to get infected is to visit a website with an infected file on it.


WHAT IS IT?
There is a new exploit out that uses WMF (windows metafile format) files to infect a computer. All you have to do to get infected is view a webpage that has the image on it, or access an infected image that is on your computer. That means the forums can be a vector for infection too. (In fact, user Blue Reptile has already been permabanned for putting the exploit in his signature.)


WHO IS VULNERABLE?
The exploit affects Firefox, Internet Explorer, and any other browser that displayes or downloads the file into the cache on the local machine. The file could also be a WMF renamed to any other image type, or possible other filetypes. Anything that puts the image exploit onto your computer or opens it up in windows fax viewer or the part of windows that generates thumbnails of WMF files is a vulnerability. This means any vector that puts the image onto your computer (wget, browser, email, IM, etc) can potentially cause the problem.

This affects anyone on Windows (98, 98SE, ME, 2000, XP, 2003). USING FIREFOX DOES NOT ELIMINATE THE RISK as the file is still downloaded to your cache in most cases, but it does reduce your chances somewhat since the image is often not displayed in the browser. But if you then interact with the file in any way (thumbnail it, Google Desktop, hover over with the mouse) that causes it to be handled by the windows subsystem responsible for WMF then you will have problems. Once again, YOU CAN BE CAUGHT BY THIS EXPLOIT EVEN IF THE IMAGE DOES NOT SHOW IN THE BROWSER. If you use Windows, your system is vulnerable.




WHAT DOES IT DO?
The exploit can be used to drop viruses, trojans, installers etc onto your computer when the exploit is activated (when the file is parsed by the part of windows with the problem). It does not do anything by itself until it is activated. There have been several reports of trojans being downloaded, which then download other things, other spyware, etc. Some of these are "SpyAxe", "AYL" trojan downloader, "ASC" trojan, and other stuff.



Here's a video of what this version is doing:

http://www.websensesecuritylabs.com/ima ... -movie.wmv



More information here:

http://forums.somethingawful.com/showth ... id=1759903

Posted: Tue Jan 03, 2006 12:48 am
by primaltheory
old...like last month old.

Posted: Tue Jan 03, 2006 12:57 am
by corncobman
Okey dokey. Wasn't sure if anyone hadn't seen it before.

Posted: Tue Jan 03, 2006 1:05 am
by primaltheory
It's being hyped up pretty bad...

How to prevent it: Don't cache images, Turn off images completely...etc

Posted: Tue Jan 03, 2006 1:10 am
by Canis
Looks like an advertisement for WinHound software....

Posted: Tue Jan 03, 2006 1:16 am
by seremtan
thanks for reminding me to uninstall google desktop. what a useless POS

Posted: Tue Jan 03, 2006 1:17 am
by eepberries
primaltheory wrote:Turn off images completely...etc
lol no

Posted: Tue Jan 03, 2006 1:22 am
by BlueGene
Is there any other ways to fix this? I've heard about this a few days ago, I'm just waiting on microsoft. But it will take a while.

Posted: Tue Jan 03, 2006 1:23 am
by eepberries
BlueGene wrote:Is there any other ways to fix this? I've heard about this a few days ago, I'm just waiting on microsoft. But it will take a while.
Get virusscan nub

Posted: Tue Jan 03, 2006 1:31 am
by corncobman
BlueGene wrote:Is there any other ways to fix this? I've heard about this a few days ago, I'm just waiting on microsoft. But it will take a while.
Get an antivirus program and up to date virus definitions
Get some spyware removal tools, such as Spybot Search and Destroy and update them
Disconnect your computer from the internet
Go into safe mode and scan your computer

Posted: Tue Jan 03, 2006 1:35 am
by primaltheory
BlueGene wrote:Is there any other ways to fix this? I've heard about this a few days ago, I'm just waiting on microsoft. But it will take a while.
Oh so you're waiting for duke nukem forever to come out?

Posted: Tue Jan 03, 2006 1:39 am
by corncobman
http://www.hexblog.com/

has a program which patches your computer to be invulnerable to the exploit. Adds an add/remove program entry so you can remove it later when the patch actually comes out.

http://www.hexblog.com/security/files/w ... blog14.exe

and also a file to check whether you are vulnerable

http://www.hexblog.com/security/files/w ... exblog.exe

Posted: Tue Jan 03, 2006 2:48 am
by BlueGene
corncobman wrote:
Get an antivirus program and up to date virus definitions
Get some spyware removal tools, such as Spybot Search and Destroy and update them
Disconnect your computer from the internet
Go into safe mode and scan your computer
Already have Nod32, Spybot, Microsoft AntiSpyware & Ad-Aware.
primaltheory wrote: Oh so you're waiting for duke nukem forever to come out?
Yes, but I'm also waiting for you to post some videos of your dad and you street racing.
corncobman wrote:http://www.hexblog.com/

has a program which patches your computer to be invulnerable to the exploit. Adds an add/remove program entry so you can remove it later when the patch actually comes out.

http://www.hexblog.com/security/files/w ... blog14.exe

and also a file to check whether you are vulnerable

http://www.hexblog.com/security/files/w ... exblog.exe
That should do, thanks.