site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
120745
Share Topic
Posting?
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
page: 1 · 2 · 3 · 4 · 5 · 6 · 7 · 8 ... 43 · 44 · 45
AuthorAll Replies

KyeU

join:2003-12-31
Canada

reply to redxii

Re: Windows MetaFiles still vulnerable

With the possibility of it being any image file, I doubt there is anything most people can do.

Crippling the DLL seems to be the most reasonable workaround, even if you can't see thumbnails and use Windows Fax and Picture Viewer.


gracie7
Geek Goddess
Premium
join:2003-07-15
confusion

said by KyeU:

Crippling the DLL seems to be the most reasonable workaround, even if you can't see thumbnails and use Windows Fax and Picture Viewer.
except according to the post just before yours, it's NOT the picture viewer dll, but the windows gdi dll; if you can disable that (not sure), it means NO graphics at all, right? not even sure many programs would function.

why can't someone come up with a way to prevent .wmf and other metafiles from opening at all, without interfering with .jpg, etc.?
--
graciella! "not tonight dear, I have DSL."
Creating SuperOrganizations Worldwide
Creating & Hosting SuperSites Worldwide

KyeU

join:2003-12-31
Canada

quote:
Update 23:19 UTC: Not that we didn't have enough "good" news already, but if you are relying on perimeter filters to block files with WMF extension from reaching your browser, you might have a surprise waiting for you. Windows XP will detect and process a WMF file based on its content ("magic bytes") and not rely on the extension alone, which means that a WMF sailing in disguise with a different extension might still be able to get you.
»isc.sans.org/diary.php

I'm not sure if this means that a WMF file renamed to TXT will be able to infect you.


confused5
Super Member

join:2005-03-28

To those of us using Avast!

Enable URL-blocking in Web-shield,
and add *.wmf.

Just read it on the Avast forum.



jbob
Reach Out and Touch Someone
Premium
join:2004-04-26
Little Rock, AR

reply to redxii

After all this discussion about this being an IFRAME exploit I am wondering......I have seen it suggested elsewhere but would it mitigate things to just go to IE Security Settings and disable the IFRAME support under "Launching programs and files in an IFRAME?" Could it be that simple? I know how IE is so imnbedded into the OS that even though a different browser is being used parts of IE are still being accessed to facilitate internet activity. Sometimes it is hard to know where IE ends and the OS begins.
Just fishing I guess. Can any MS gurus out there confirm or deny this?

KyeU

join:2003-12-31
Canada

4 edits

reply to redxii
Ok, I've just made a big discovery with Proxomitron.

Apparently it can match by Hex, which is significant, because I've written a filter that searches for the magic bytes for the .WMF file.

I am now certain Proxomitron can now act as a very strong workaround for this issue, by killing all .WMF files, by identifying them by their magic bytes.

If you've imported my Header filter, you can delete it. (And also delete the old Web Page filter.)

This filter now only kills infected .WMF (or any extension) files.

Here is the new Web Page filter:

[Patterns]
Name = "Kill Infected .WMF Files [Kye-U]"
Active = TRUE
URL = "$TYPE(oth)"
Limit = 5
Match = "[%01][%00][%09][%00][%00]"
Replace = "\k$ALERT(Infected .WMF File Killed on:\n\n\u)"

You must also import this Header filter to filter all file extensions:

[HTTP headers]
In = FALSE
Out = TRUE
Key = "URL: All File Extensions Force Filter (Out)"
URL = "*.*"
Replace = "$FILTER(true)"

KyeU

join:2003-12-31
Canada

reply to redxii
Beehappyy.biz is now closed.

quote:
Account closed due terms violation


hpguru
Curb Your Dogma
Premium
join:2002-04-12

reply to KyeU

said by KyeU:

Here is the new filter:

[Patterns]
Name = "Kill .WMF Files [Kye-U]"
Active = TRUE
URL = "$TYPE(oth)"
Limit = 15
Match = "[%D7][%CD][%C6][%9A][%00]$SET(1=\k$ALERT(.WMF File Killed on:\n\n\u))"
"|[%01][%00][%09][%00][%00]$SET(1=\k$ALERT(Infected .WMF File Killed on:\n\n\u))"
Replace = "\1"
Very nice! :) Reminds me of the old days at Arne's forum. :)

--
Get hpHOSTS! Member ASAP
George Bush is lying to you.

KyeU

join:2003-12-31
Canada

I've updated the filter

Now only kills infected files. (Can be any file extension)

I miss those good old days

Anyways, now, people using Proxomitron can be well protected.

This filter provides the user extra security when surfing on sites, which is the initial area where they get infected.

I've tested this filter against many infected WMF files, and it works just fine



no__1__here
Premium
join:2003-10-13
Tomball, TX

Terrific work as always KyeU See Profile.


KyeU

join:2003-12-31
Canada

reply to redxii
Filter was missing a ")".

Fixed now



Link Logger
Premium,MVM
join:2001-03-29
Calgary, AB
kudos:3
Reviews:
·Shaw

reply to KyeU
A number of source sites have been cleaned up or otherwise shutdown, but of course others are springing up. It would also appear that most AV's have now picked up on the signature, so ensure your AV is up to date.

Blake
--
Vendor: Firewall Logging Software »www.SonicLogger.com - SonicWall and 3Com »www.LinkLogger.com - Linksys, Netgear and Zyxel



HA Nut
Premium
join:2004-05-13
USA

reply to redxii
I'm not infected but have read of some who are. How can they repair the mess this leaves? I don't seem to be finding any approach to fixing the machines that are hosed...



trparky
Apple... YUM
Premium,MVM
join:2000-05-24
Cleveland, OH
kudos:1
Reviews:
·Time Warner Cable
·Time Warner VOIP
·AT&T U-Verse

said by HA Nut:

I'm not infected but have read of some who are. How can they repair the mess this leaves? I don't seem to be finding any approach to fixing the machines that are hosed...
These are probably one of those times where you have to cut your losses and do the old 'wipe and reload' bit.

Besides, even if you did manage to get the junk out, knowing how much junk got into it, would you trust the machine again? If you ask me, no, I wouldn't trust it without it being wiped and reloaded.
--
WedgeAntilles250

Tom's Rant


redxii
Premium,Mod
join:2001-02-26
Sherwood, MI
Reviews:
·Clear Wireless
·Suddenlink
·Sprint Mobile Br..
Host:
Broadband Tweaks
Suddenlink
ISDN
Fiber Optic
AOL Broadband

It installs 2 rootkits, and if you are slow to stop whatever has been executed from the WMF (about a few minutes) then it will install more stuff and probably more rootkits. I wouldn't bother cleaning it.
--
Open Source -> Close Minded
Microsoft Windows 2000/XP Security: Some Assembly Required.
Excessive use of "$" as in "M$" may make you look like a fool.


mysec
Premium
join:2005-11-29
kudos:4

said by redxii:

It installs 2 rootkits,...
Which site are you referring to, and where did you find out about the rootkit install?

thanks.



redxii
Premium,Mod
join:2001-02-26
Sherwood, MI
Reviews:
·Clear Wireless
·Suddenlink
·Sprint Mobile Br..
Host:
Broadband Tweaks
Suddenlink
ISDN
Fiber Optic
AOL Broadband

xpladv470.wmf/xpl.wmf.. there is no "site" in particular they're the same. wmf_decode.wmf didn't seem to do anything even in the admin account.

I know by running Rootkitrevealer and seeing that the files it found aren't visible in Explorer (all files shown). Plus there are corresponding drivers shown in Device Manager.
--
Open Source -> Close Minded
Microsoft Windows 2000/XP Security: Some Assembly Required.
Excessive use of "$" as in "M$" may make you look like a fool.


dantz

join:2005-05-09
Honolulu, HI

reply to redxii
Here we have a dangerous exploit spreading rapidly with no patch in sight and nobody has even mentioned the most reliable fallback defense you can construct: an image! Image your drive BEFORE you get clobbered and your recovery will be much, much faster, not to mention easier and more complete.


KyeU

join:2003-12-31
Canada

1 edit

reply to redxii
Thanks to JJoeBugg, I've discovered that I've forgotten that Proxomitron does not filter .WMF files by default. A separate filter had to be made to be able to filter all file extensions.

Web Page filter:

[Patterns]
Name = "Kill Infected .WMF Files [Kye-U]"
Active = TRUE
URL = "$TYPE(oth)"
Limit = 5
Match = "[%01][%00][%09][%00][%00]"
Replace = "\k$ALERT(Infected .WMF File Killed on:\n\n\u)"

You must also import this Header filter to filter all file extensions:

[HTTP headers]
In = FALSE
Out = TRUE
Key = "URL: All File Extensions Force Filter (Out)"
URL = "*.*"
Replace = "$FILTER(true)"

grindy

join:2000-10-26
La Conner, WA

reply to redxii
Forgive this no doubt stupid question, but exactly how is IE vulnerable?
It doesn't display *.wmf's that I know of...

page: 1 · 2 · 3 · 4 · 5 · 6 · 7 · 8 ... 43 · 44 · 45

Sunday, 27-May 21:35:24 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics