 KyeU join:2003-12-31 Canada | reply to redxii
Re: Windows MetaFiles still vulnerable With the possibility of it being any image file, I doubt there is anything most people can do.
Crippling the DLL seems to be the most reasonable workaround, even if you can't see thumbnails and use Windows Fax and Picture Viewer. |
|
 gracie7Geek GoddessPremium join:2003-07-15 confusion | said by KyeU:Crippling the DLL seems to be the most reasonable workaround, even if you can't see thumbnails and use Windows Fax and Picture Viewer. except according to the post just before yours, it's NOT the picture viewer dll, but the windows gdi dll; if you can disable that (not sure), it means NO graphics at all, right? not even sure many programs would function.
why can't someone come up with a way to prevent .wmf and other metafiles from opening at all, without interfering with .jpg, etc.? -- graciella! "not tonight dear, I have DSL." Creating SuperOrganizations Worldwide Creating & Hosting SuperSites Worldwide |
|
 KyeU join:2003-12-31 Canada | quote: Update 23:19 UTC: Not that we didn't have enough "good" news already, but if you are relying on perimeter filters to block files with WMF extension from reaching your browser, you might have a surprise waiting for you. Windows XP will detect and process a WMF file based on its content ("magic bytes") and not rely on the extension alone, which means that a WMF sailing in disguise with a different extension might still be able to get you.
»isc.sans.org/diary.php
I'm not sure if this means that a WMF file renamed to TXT will be able to infect you. |
|
 | To those of us using Avast!
Enable URL-blocking in Web-shield, and add *.wmf.
Just read it on the Avast forum. |
|
 jbobReach Out and Touch SomeonePremium join:2004-04-26 Little Rock, AR | reply to redxii
After all this discussion about this being an IFRAME exploit I am wondering......I have seen it suggested elsewhere but would it mitigate things to just go to IE Security Settings and disable the IFRAME support under "Launching programs and files in an IFRAME?" Could it be that simple? I know how IE is so imnbedded into the OS that even though a different browser is being used parts of IE are still being accessed to facilitate internet activity. Sometimes it is hard to know where IE ends and the OS begins. Just fishing I guess. Can any MS gurus out there confirm or deny this? |
|
 KyeU join:2003-12-31 Canada 4 edits | reply to redxii Ok, I've just made a big discovery with Proxomitron.
Apparently it can match by Hex, which is significant, because I've written a filter that searches for the magic bytes for the .WMF file.
I am now certain Proxomitron can now act as a very strong workaround for this issue, by killing all .WMF files, by identifying them by their magic bytes.
If you've imported my Header filter, you can delete it. (And also delete the old Web Page filter.)
This filter now only kills infected .WMF (or any extension) files.
Here is the new Web Page filter:
[Patterns] Name = "Kill Infected .WMF Files [Kye-U]" Active = TRUE URL = "$TYPE(oth)" Limit = 5 Match = "[%01][%00][%09][%00][%00]" Replace = "\k$ALERT(Infected .WMF File Killed on:\n\n\u)" You must also import this Header filter to filter all file extensions:
[HTTP headers] In = FALSE Out = TRUE Key = "URL: All File Extensions Force Filter (Out)" URL = "*.*" Replace = "$FILTER(true)" |
|
 KyeU join:2003-12-31 Canada | reply to redxii Beehappyy.biz is now closed.
quote: Account closed due terms violation
|
|
 hpguruCurb Your DogmaPremium join:2002-04-12 | reply to KyeU
said by KyeU:Here is the new filter: [Patterns] Name = "Kill .WMF Files [Kye-U]" Active = TRUE URL = "$TYPE(oth)" Limit = 15 Match = "[%D7][%CD][%C6][%9A][%00]$SET(1=\k$ALERT(.WMF File Killed on:\n\n\u))" "|[%01][%00][%09][%00][%00]$SET(1=\k$ALERT(Infected .WMF File Killed on:\n\n\u))" Replace = "\1" Very nice! :) Reminds me of the old days at Arne's forum. :)
-- Get hpHOSTS! Member ASAP George Bush is lying to you. |
|
 KyeU join:2003-12-31 Canada | I've updated the filter 
Now only kills infected files. (Can be any file extension)
I miss those good old days 
Anyways, now, people using Proxomitron can be well protected.
This filter provides the user extra security when surfing on sites, which is the initial area where they get infected.
I've tested this filter against many infected WMF files, and it works just fine  |
|
 | Terrific work as always KyeU .  |
|
 KyeU join:2003-12-31 Canada | reply to redxii Filter was missing a ")".
Fixed now  |
|
 Link LoggerPremium,MVM join:2001-03-29 Calgary, AB kudos:3 Reviews:
·Shaw
| reply to KyeU A number of source sites have been cleaned up or otherwise shutdown, but of course others are springing up. It would also appear that most AV's have now picked up on the signature, so ensure your AV is up to date.
Blake -- Vendor: Firewall Logging Software »www.SonicLogger.com - SonicWall and 3Com »www.LinkLogger.com - Linksys, Netgear and Zyxel |
|
 HA NutPremium join:2004-05-13 USA | reply to redxii I'm not infected but have read of some who are. How can they repair the mess this leaves? I don't seem to be finding any approach to fixing the machines that are hosed... |
|
|
|
 trparkyApple... YUMPremium,MVM join:2000-05-24 Cleveland, OH kudos:1 Reviews:
·Time Warner Cable
·Time Warner VOIP
·AT&T U-Verse
| said by HA Nut:I'm not infected but have read of some who are. How can they repair the mess this leaves? I don't seem to be finding any approach to fixing the machines that are hosed... These are probably one of those times where you have to cut your losses and do the old 'wipe and reload' bit.
Besides, even if you did manage to get the junk out, knowing how much junk got into it, would you trust the machine again? If you ask me, no, I wouldn't trust it without it being wiped and reloaded. -- WedgeAntilles250
Tom's Rant |
|
 redxiiPremium,Mod join:2001-02-26 Sherwood, MI Reviews:
·Clear Wireless
·Suddenlink
·Sprint Mobile Br.. Host: Broadband Tweaks Suddenlink ISDN Fiber Optic AOL Broadband
| It installs 2 rootkits, and if you are slow to stop whatever has been executed from the WMF (about a few minutes) then it will install more stuff and probably more rootkits. I wouldn't bother cleaning it. -- Open Source -> Close Minded Microsoft Windows 2000/XP Security: Some Assembly Required. Excessive use of "$" as in "M$" may make you look like a fool. |
|
 mysecPremium join:2005-11-29 kudos:4 | said by redxii:It installs 2 rootkits,... Which site are you referring to, and where did you find out about the rootkit install?
thanks.
|
|
 redxiiPremium,Mod join:2001-02-26 Sherwood, MI Reviews:
·Clear Wireless
·Suddenlink
·Sprint Mobile Br.. Host: Broadband Tweaks Suddenlink ISDN Fiber Optic AOL Broadband
| xpladv470.wmf/xpl.wmf.. there is no "site" in particular they're the same. wmf_decode.wmf didn't seem to do anything even in the admin account.
I know by running Rootkitrevealer and seeing that the files it found aren't visible in Explorer (all files shown). Plus there are corresponding drivers shown in Device Manager. -- Open Source -> Close Minded Microsoft Windows 2000/XP Security: Some Assembly Required. Excessive use of "$" as in "M$" may make you look like a fool. |
|
 dantz join:2005-05-09 Honolulu, HI | reply to redxii Here we have a dangerous exploit spreading rapidly with no patch in sight and nobody has even mentioned the most reliable fallback defense you can construct: an image! Image your drive BEFORE you get clobbered and your recovery will be much, much faster, not to mention easier and more complete. |
|
 KyeU join:2003-12-31 Canada 1 edit | reply to redxii Thanks to JJoeBugg, I've discovered that I've forgotten that Proxomitron does not filter .WMF files by default. A separate filter had to be made to be able to filter all file extensions.
Web Page filter:
[Patterns] Name = "Kill Infected .WMF Files [Kye-U]" Active = TRUE URL = "$TYPE(oth)" Limit = 5 Match = "[%01][%00][%09][%00][%00]" Replace = "\k$ALERT(Infected .WMF File Killed on:\n\n\u)" You must also import this Header filter to filter all file extensions:
[HTTP headers] In = FALSE Out = TRUE Key = "URL: All File Extensions Force Filter (Out)" URL = "*.*" Replace = "$FILTER(true)" |
|
 grindy join:2000-10-26 La Conner, WA | reply to redxii Forgive this no doubt stupid question, but exactly how is IE vulnerable? It doesn't display *.wmf's that I know of...
 |
|