site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies

KyeU

join:2003-12-31
Canada

reply to redxii

Re: Windows MetaFiles still vulnerable

I've created two Proxomitron filters to help protect the user against downloading/loading .WMF images.

Web Filter:

[Patterns]
Name = "Kill .WMF [Kye-U]"
Active = TRUE
Bounds = "<*>"
Limit = 256
Match = "*.wmf*"
Replace = "$ALERT(.WMF Extension Killed on:\n\n\u)"

Header Filter:

[HTTP headers]
In = FALSE
Out = TRUE
Key = "URL-Killer: Kill WMF Connection [Kye-U] (Out)"
URL = "(^*=(^http://*.(^([a-z]+{2,4})(^/))))*.wmf(*)\1$TST(\1=(^/))"
Match = "*&($CONFIRM(.WMF FILE EXTENSION FOUND\n\nAllow connection to the URL below?\n\n\u\n\1)|$SET(1=URL with .WMF Extension Killed\k))"
Replace = "\1"

jp10558
Premium
join:2005-06-24
Willseyville, NY

Thanks Kye-U. With this, do I still need to disable Windows Picture Viewer?


KyeU

join:2003-12-31
Canada

1 edit

It would catch most .WMF files I would think. The Web Page Filter kills most standard images with .WMF extension, and the Header Filter catches the connections to *.WMF, this is because heavily encrypted JS files are difficult to match, but their connection requests are out in the open

I would think it is still safe to disable Windows Picture Viewer, or perhaps even associating the .WMF file extension to Notepad (or another file).



Chip
Premium
join:2001-12-23
Connecticut
Reviews:
·Comcast Formerl..

said by KyeU:

I would think it is still safe to disable Windows Picture Viewer, or perhaps even associating the .WMF file extension to Notepad (or another file).
Here's what I tried. I changed the association for WMF/EMF from the viewer to the Foxit pdf reader.I then went to crackz and got the warning box shown above. So far I haven't got the same symptoms that RedXII1234 got when he initially went to the site.

I'm going to take some time and go through the machine and see if I find anything suspicious.
--
The three great strategies for obscuring an issue are to introduce irrelevancies, to arouse prejudice, and to excite ridicule--Bergen Evans

pier5

join:2002-03-27
34312

bestserials had this wmf exploit but maxthon/IE opened a dialog asking if I wanted to view the WMF file with its associated viewer. I said "No" and the infection was prevented.


Sunday, 27-May 21:40:38 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics