<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Taking off the gloves, help me get punched out in Security</title>
<link>http://www.dslreports.com/forum/r15165697</link>
<description></description>
<language>en</language>
<pubDate>Sun, 06 Dec 2009 06:15:20 EDT</pubDate>
<lastBuildDate>Sun, 06 Dec 2009 06:15:20 EDT</lastBuildDate>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15174515</link>
<description><![CDATA[<A HREF="/useremail/u/793928"><b>Iridium</b></A> : If I have a VMWare image running XP Pro can I get in on it? ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15174515</guid>
<pubDate>Thu, 05 Jan 2006 06:17:40 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15173701</link>
<description><![CDATA[<A HREF="/useremail/u/341476"><b>jferello</b></A> : Well I downloaded the test files and tried to view the directory they were in and my system locks up for about 30 seconds and the I get a message from DEP stating it has stopped the program.  Then I get an error from Explorer.exe saying it needs to close, I close out and then it restarts explorer.exe and I come back to the desktop.  Also, not once did my AV program ask me anything, also I scanned the ZIP file and it said all clean.<br><br>What does this mean?  I never saw any processes for notepad at anytime, so does this mean I am safe?<br><br>System:<br>Windows XP Pro SP2 with all updates<br>Symantec Antivirus Corporate Edition v10.0.2.2000 with latest defs from today and set to scan all files.<br><SMALL>--<br>I never thought something so simple would be so hard to find.......</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15173701</guid>
<pubDate>Thu, 05 Jan 2006 00:46:56 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15172488</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : <div class="bquote"><SMALL>said by  norwegian <A HREF="/useremail/u/1159554"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Link Logger, you don't have an OEM copy sitting around do you ? psloss asked a question about %allusers%/startup, and the ability to add shortcuts from a limited user <br><br>--&raquo;<A HREF="/forum/remark,15135074">Who else is having fun with OEM security defaults?</A><br><br>I was wondering, if you created a shortcut there that linked so that when the exploit came in, it could have access to this, and see if it made any difference, being that you are still limited.<br> </DIV>It should be possible to reason that out: if a process running with limited user credentials was exploited via this vulnerability AND all limited users (or all users -- "Everyone") have write access to the "%ALLUSERSPROFILE%\Start Menu\Programs\Startup" directory, then an exploit with the logic that ZOverLord noted earlier could add itself there and would be escalated to admin the next time an admin logged into the system interactively.  Although copying an "infected" WMF there would probably also work, it wouldn't be necessary to drop another WMF file in the startup folder.<br><br>The opportunity to do that kind of privilege escalation is not unique to the problems with WMF, but they present a big opportunity right now...<br><br>Philip Sloss<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15172488</guid>
<pubDate>Wed, 04 Jan 2006 22:14:20 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15171771</link>
<description><![CDATA[<A HREF="/useremail/u/996768"><b>jbob</b></A> : In testing ZOverLord's updated files My AV fails at this time.  Using Symantec Client Security(Symantec Corp AV v10.0.2.2001) with todays defs set to scan All Files, none of the files are detected as hostile.<br>I have to deduct that either Symantec is behind on detection or smart enough to see this files are not a threat. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15171771</guid>
<pubDate>Wed, 04 Jan 2006 20:54:30 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15171197</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : <div class="bquote"><SMALL>said by  pog <A HREF="/useremail/u/1018019"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Say... here's a question for everyone:<br><br>What happens with infected WMF's that are embedded in Word files (or other document types)?  Is the code preserved?  Does anything get launched in preview or on open of the .doc?</DIV>I would very much suspect that if scanning is set to all files that they would be detected.  I'll see if I can whip up a test case later tonight.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15171197</guid>
<pubDate>Wed, 04 Jan 2006 19:42:25 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15170063</link>
<description><![CDATA[<A HREF="/useremail/u/1018019"><b>pog</b></A> : <div class="bquote"><SMALL>said by  Tuulilapsi <A HREF="/useremail/u/665380"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>So the most desirable solution remains to keep evil (tm) wmf files off your system in the first place, ...<br> </DIV>Gack!  I create a lot of vector-based graphics that end up as WMF's... it was a very nice format!  So sad to see it fall to the dark side. :o<br><br>Say... here's a question for everyone:<br><br>What happens with infected WMF's that are embedded in Word files (or other document types)?  Is the code preserved?  Does anything get launched in preview or on open of the .doc?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15170063</guid>
<pubDate>Wed, 04 Jan 2006 17:13:07 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15169852</link>
<description><![CDATA[<A HREF="/useremail/u/1159554"><b>norwegian</b></A> : Link Logger, you don't have an OEM copy sitting around do you ? psloss asked a question about %allusers%/startup, and the ability to add shortcuts from a limited user <br><br>--&raquo;<A HREF="/forum/remark,15135074">Who else is having fun with OEM security defaults?</A><br><br>I was wondering, if you created a shortcut there that linked so that when the exploit came in, it could have access to this, and see if it made any difference, being that you are still limited.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15169852</guid>
<pubDate>Wed, 04 Jan 2006 16:47:24 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15168741</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : <div class="bquote"><SMALL>said by  ZOverLord <A HREF="/useremail/u/889138"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Blake I just renamed a copy to .emf, do you catch that?<br><br>Just curious, for testing, my A/V is off so I can't tell if it would be caught or not. I just took notepad.wmf made a copy and called it notepad.emf<br> </DIV>If I have F-Secure on 'High' it kills it and deletes the file, if I have it on 'Normal' it runs the exploit.  Its the problem of what files are scanned, so ensure the AV is scanning ALL files and the system will be protected.<br><br>Well since my systems are fully protected from this most recent security menace (F-Secure is on the HIGH setting such that it scans all files, check your AV to ensure that it is also scanning all files), my users can surf to their heart's content, and I can go to bed.  Hopefully this thread had helped some people realize how their systems might have been vulnerable and how to ensure they are now protected.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15168741</guid>
<pubDate>Wed, 04 Jan 2006 14:18:49 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15168449</link>
<description><![CDATA[<A HREF="/useremail/u/889138"><b>ZOverLord</b></A> : <div class="bquote"><SMALL>said by  Link Logger <A HREF="/useremail/u/356416"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>I agree in an undefended system this exploit could be nasty as there are different execution criteria for it then say just a normal exe, but thankfully the file has a required format so there isn't many ways to hide the exploit within the file (otherwise it would execute as a metafile), so an AV has a good shot at killing it before it can execute if your AV is up to the task.<br><br>Blake<br> </DIV>Blake I just renamed a copy to .emf, do you catch that?<br><br>Just curious, for testing, my A/V is off so I can't tell if it would be caught or not. I just took notepad.wmf made a copy and called it notepad.emf<br><SMALL>--<br>Black, Grey and White Hats Unite here -> &raquo;<A HREF="http://testing.OnlyTheRightAnswers.com" >testing.OnlyTheRightAnswers.com</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15168449</guid>
<pubDate>Wed, 04 Jan 2006 13:40:40 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15168377</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : I agree in an undefended system this exploit could be nasty as there are different execution criteria for it then say just a normal exe, but thankfully the file has a required format so there isn't many ways to hide the exploit within the file (otherwise it would execute as a metafile), so an AV has a good shot at killing it before it can execute if your AV is up to the task.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15168377</guid>
<pubDate>Wed, 04 Jan 2006 13:31:06 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15168365</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : So the most desirable solution remains to keep evil (tm) wmf files off your system in the first place, or at the very least avoid ever browsing the folders that could possibly contain such files (browser & mail software cache directories, I'm looking at you). This in mind, isn't using a browser like Opera that does not automagically open wmf files and a mail client in text only mode the simplest way to entirely avoid this exploit? I haven't paid this thing that much attention, so it may be that I'm entirely mistaken, so correct me if I'm wrong. <br><SMALL>--<br><A HREF="http://nonadmin.editme.com/">Want security? Run as limited user.</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15168365</guid>
<pubDate>Wed, 04 Jan 2006 13:29:39 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15168305</link>
<description><![CDATA[<A HREF="/useremail/u/889138"><b>ZOverLord</b></A> : <div class="bquote"><SMALL>said by  Link Logger <A HREF="/useremail/u/356416"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>I'm doing some of that testing now.  I've turned off F-Secure otherwise it nails the exploit, but the problem is Windows wants to help you out and show you what is in the file if possible, so the file explorer 'executes' the metafile for example in order to build a small view into the file, hence infection.  In  ZOverLord <A HREF="/useremail/u/889138"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> test cases even a non-admin can execute the exploit as notepad isn't a 'restricted' application.  If the started application tried to say insert a startup into HKLM then it would fail as non-admin users don't have that privilege (to write there).<br><br>Blake<br> </DIV>Blake, Please be aware, I could have created a version that CHECKS for user rights, and not done anything until the user who opened the folder or clicked on the file was ADMIN.<br><br>So, it's very very dangerous to view a folder with a .wmf file in it, and there is no view, detail or otherwise that would stop the launch.<br><br>Worse, imagine that each time it launched it checked to see if it already did this or that and if so do something else, it could contain many things and every time viewed in a folder or clicked on check to see what it has already done and do something it has not yet.<br><br>Not sure if your with me, there are SO MANY machinations you could do, and every time someone viewed a folder with one of these in it, it could test for what it already did, and then do something else it has not done yet :-(<br><SMALL>--<br>Black, Grey and White Hats Unite here -> &raquo;<A HREF="http://testing.OnlyTheRightAnswers.com" >testing.OnlyTheRightAnswers.com</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15168305</guid>
<pubDate>Wed, 04 Jan 2006 13:20:56 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15168245</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : I'm doing some of that testing now.  I've turned off F-Secure otherwise it nails the exploit, but the problem is Windows wants to help you out and show you what is in the file if possible, so the file explorer 'executes' the metafile for example in order to build a small view into the file, hence infection.  In  ZOverLord <A HREF="/useremail/u/889138"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> test cases even a non-admin can execute the exploit as notepad isn't a 'restricted' application.  If the started application tried to say insert a startup into HKLM then it would fail as non-admin users don't have that privilege (to write there).<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15168245</guid>
<pubDate>Wed, 04 Jan 2006 13:12:45 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15168191</link>
<description><![CDATA[<A HREF="/useremail/u/889138"><b>ZOverLord</b></A> : YES, an ADMIN could trigger this just by viewing the contents of a folder where one of these .wmf file is located.<br><br>So, even if a limited user actually was the one that placed it on the system, ANYONE who views the file in a folder, will cause it to execute. Which means if it was an ADMIN that time, it would do it with ADMIN privileges.<br><br>AND......you do NOT need to have that folder being displayed as THUMBNAILS, if can be in detail view and it will STILL happen :-(<br><SMALL>--<br>Black, Grey and White Hats Unite here -> &raquo;<A HREF="http://testing.OnlyTheRightAnswers.com" >testing.OnlyTheRightAnswers.com</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15168191</guid>
<pubDate>Wed, 04 Jan 2006 13:05:16 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15168153</link>
<description><![CDATA[<A HREF="/useremail/u/269961"><b>astirusty</b></A> : <div class="bquote"><SMALL>said by  Link Logger <A HREF="/useremail/u/356416"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><BR><BR> In round two I made one simple adjustment and won the fight.</DIV>Blake, maybe after the testing/work you have done on the WMF exploit, you can clarify something I read on possible injection methods.<br><br>If a user is running as limited and manages to get a WMF image file exploit on to the system (past the AV apps) and the actual exploit is unable to run (as you have reported) -- Is it possible the administrator of the system could trigger the exploit while looking around the users directory?  <I>I am basing this off of  ZOverLord <A HREF="/useremail/u/889138"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> discussion of just going to the folder the WMF file is located in.</I><br><br>PS: Thanks for all your efforts! :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15168153</guid>
<pubDate>Wed, 04 Jan 2006 13:01:09 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15168099</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : I copied these from the other thread so they are current.<br><br>Blake]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15168099</guid>
<pubDate>Wed, 04 Jan 2006 12:54:57 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15167876</link>
<description><![CDATA[<A HREF="/useremail/u/889138"><b>ZOverLord</b></A> : Just a Heads Up, I created some tests that launch Notepad, more info here:<br><br>&raquo;<A HREF="/forum/remark,15115819~days=9999~start=620#15167424">Windows MetaFiles still vulnerable</A><br><br>These were created so that we will have the most CURRENT examples. I am NOT sure if what people are testing with have been made from the latest 1.14 Metasploit release, so these are CURRENT!<br><SMALL>--<br>Black, Grey and White Hats Unite here -> &raquo;<A HREF="http://testing.OnlyTheRightAnswers.com" >testing.OnlyTheRightAnswers.com</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15167876</guid>
<pubDate>Wed, 04 Jan 2006 12:26:56 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15167719</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : I tried all of  ZOverLord <A HREF="/useremail/u/889138"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> files that were created with the latest version 1.14 of the exploit:<br><br>notepad.bmp<br>notepad.gif<br>notepad.jpeg<br>notepad.jpg<br>notepad.png<br>notepad.tiff<br>notepad.wmf<br><br>and F-Secure (after being set to scan all files, I can't stress that enough) picked off every one of them.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15167719</guid>
<pubDate>Wed, 04 Jan 2006 12:07:19 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15167681</link>
<description><![CDATA[<A HREF="/useremail/u/996768"><b>jbob</b></A> : Yep...Guess I should have read it a little closer as I did the second time.  Good demo.  A lot of work copying and pasting all the dialog boxes as well.<br><br>My question about AV apps ability to scan and recognize a renamed wmf file still is valid I think.  Scanning based on header info might be a better choice perhaps expecially WMF based files.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15167681</guid>
<pubDate>Wed, 04 Jan 2006 12:02:14 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15167442</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : If you read round two you will see that in F-Secure default configuration it doesn't scan wmf files hence the exploit was free to do its thing and stuff got ugly from there on.  In round two I made one simple adjustment and won the fight.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15167442</guid>
<pubDate>Wed, 04 Jan 2006 11:28:57 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15167273</link>
<description><![CDATA[<A HREF="/useremail/u/996768"><b>jbob</b></A> : As John2G mentioned it looked like your AV app WAS working in the first test so I assume you "Allowed" all the exploits to continue in the first round to see what would happen.<br><br>Waiting for round two results.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15167273</guid>
<pubDate>Wed, 04 Jan 2006 11:00:21 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15167246</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : Round two go to me as I knocked this bad boy on his butt and laid him out cold :D  I'll update my wmf attack page with the required information and then we can go looking for bigger bad dogs then this puppy.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15167246</guid>
<pubDate>Wed, 04 Jan 2006 10:56:35 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15167232</link>
<description><![CDATA[<A HREF="/useremail/u/1193253"><b>SpannerITWks</b></A> : I think it would a good idea to block both Headers + Extentions, if people are able to.<br><br>Spanner]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15167232</guid>
<pubDate>Wed, 04 Jan 2006 10:54:38 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15167136</link>
<description><![CDATA[<A HREF="/useremail/u/996768"><b>jbob</b></A> : You bring up an interesting point, although it has been discussed adnauseum by now, however I don't think specifically in regards to AV apps.  I have my AV set to scan all files.  It has been reported that this new updated exploit might be able to fool many AV/IPS apps, initially at least.  If so how?  Perhaps the AV/IPS/AT vendors can simply be set to block/detect a WMF file based on header info(not by extension).  Not sure it they can do this now.  Then the user can simply block all WMF looking files before no matter the content.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15167136</guid>
<pubDate>Wed, 04 Jan 2006 10:38:57 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15167042</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : There appears to be two main factors here.  First not all AV's are scanning wmf files (scanning all files would be best as a metafile is determined by a header within the file and not by its extension) and second running as non admin is always a good idea.  If we can get all the AV guys onside then picking off this exploit becomes much easier.  I would ask/recommend everyone take a look at what files your AV isn't scanning and take the appropriate steps to fix it if needed.  The metafile exploit is what I call an enabler exploit in that its the key that unlocks the door and tends to get overlooked as everyone is staring at the beast that came through the door afterwards.  Take away the key and the beast can't get in, simple.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15167042</guid>
<pubDate>Wed, 04 Jan 2006 10:22:32 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166920</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : I don't want to be picky, but all your interesting link shows is how F-Secure handled various trojans. Any half decent AV or AT should be able to nail them. All that has changed with this new exploit is the method of delivery of the trojans. The exploit itself is too small to do any  damage, as the maximum space allocated in RAM is 1.7K: all it is doing is install a downloader.<br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166920</guid>
<pubDate>Wed, 04 Jan 2006 10:02:55 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166762</link>
<description><![CDATA[<A HREF="/useremail/u/461260"><b>deadi</b></A> : Alrighty! Windows Onecare caught it, and quarantined. This is a updated XP Pro SP2 pc, updated Onecare. It would not allow it to run.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15166762?c=947789&ret=L2ZvcnVtL3IxNTE2NTY5Ny54bWw%3D"><IMG class="apic" BORDER=0 TITLE="182038 bytes" WIDTH=600  SRC="/r0/download/947789.thumb600~ecbe0a8897425dc85708c84ef5dd1c4c/onecare2.bmp/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166762</guid>
<pubDate>Wed, 04 Jan 2006 09:38:37 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166725</link>
<description><![CDATA[<A HREF="/useremail/u/1029026"><b>koma3504</b></A> :  Im a few links Please. Im fixen to Wipe one But be a chance to test. TrendMIcro.<br><br>Thanks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166725</guid>
<pubDate>Wed, 04 Jan 2006 09:32:26 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166704</link>
<description><![CDATA[<A HREF="/useremail/u/570051"><b>novaflare</b></A> : <div class="bquote"><SMALL>said by  norwegian <A HREF="/useremail/u/1159554"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>you don't have RedXII1234 paying you for this test at all ??<br>Sounds like admins are in for a wakeup.<br>;)<br> </DIV>Why would i be in for a wake up? Ive done 2 things diffrent to protect my self used the unoffical patch and unregged the dll. I probably would not ever get infected via this route any ways as i dont surf the sites that would be the top users of the exploit.<br><br>Now this is one patch that I will install regardless of any potential risk of it hoseing my system. Simply put I use thumb nail and preview to find my textures etc for the 3d models I make.<br><br>It would take alot more than this to scare me in to cripling my self by running as a limited user.<br><SMALL>--<br>DSLR security chat at us.ausirc.net chanel #dslr_sec lets pack this channelopen source dns server for *nix and windows &raquo;<A HREF="http://powerdns.com" >powerdns.com</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166704</guid>
<pubDate>Wed, 04 Jan 2006 09:26:49 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166694</link>
<description><![CDATA[<A HREF="/useremail/u/1196782"><b>Red Dragon</b></A> : Ouch that is nasty I would want to nuke badly.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166694</guid>
<pubDate>Wed, 04 Jan 2006 09:25:01 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166692</link>
<description><![CDATA[<A HREF="/useremail/u/247350"><b>3SGTE</b></A> : Wouldn't it have been less work to try as non-admin first?<br><SMALL>--<br>Everything in this post is pure BS!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166692</guid>
<pubDate>Wed, 04 Jan 2006 09:24:58 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166690</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : Just ATTEMPTED to download the file that Link Logger sent me... avast Home(FREE), at standard settings, didn't like it one bit! ;) Avast had it's hissy fit before any download dialog box appeared, and never did appear(avast killed it!).<br>Done with an IE based browser - SlimBrowser. <br>*NO* patch, *NO* unregistered .dll. <br>No worries! <br><br>NOTE: Yesterday's Update added WMF scanning to Default File Types. If set to "All File Types" you would have been protected anyways BEFORE the Update.<br><br>Happy Hunting!<br>I'm setting avast back up to MY settings now... just a wee bit higher! <br><SMALL>--<br>Think outside the Fox... <A HREF="http://www.opera.com/">Opera</A></SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/15166690?c=947784&ret=L2ZvcnVtL3IxNTE2NTY5Ny54bWw%3D"><IMG TITLE="35996 bytes" BORDER=0 WIDTH=242 HEIGHT=273 SRC="/r0/download/947784~12e2d14f58180e4a1a1b9ef93f71d1a0/ScreenShot012.jpg"></A><br>Default File Types</TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15166690?c=947785&ret=L2ZvcnVtL3IxNTE2NTY5Ny54bWw%3D"><IMG class="apic" BORDER=0 TITLE="157560 bytes" WIDTH=600 HEIGHT=452 SRC="/r0/download/947785.thumb600~940ff34957f06a7fba62392ca8cdfa9a/ScreenShot013.jpg/thumb.jpg" ALT="Click for full size"></A><br>Normal settings</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15166690?c=947786&ret=L2ZvcnVtL3IxNTE2NTY5Ny54bWw%3D"><IMG class="apic" BORDER=0 TITLE="292940 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/947786.thumb600~15367e3ffbc8836456f36f115c90ed2a/ScreenShot015.jpg/thumb.jpg" ALT="Click for full size"></A><br>avast got pissed!</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166690</guid>
<pubDate>Wed, 04 Jan 2006 09:24:41 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166674</link>
<description><![CDATA[<A HREF="/useremail/u/1095658"><b>packetscan</b></A> : Silly Wabbit]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166674</guid>
<pubDate>Wed, 04 Jan 2006 09:21:56 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166581</link>
<description><![CDATA[<A HREF="/useremail/u/269961"><b>astirusty</b></A> : <div class="bquote"><SMALL>said by  Link Logger <A HREF="/useremail/u/356416"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR> So I'm getting ready to run a test using a non-admin level user and see how much of a difference that makes.  </DIV>Great!  I was just going to ask you if you could try this if you had not already.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166581</guid>
<pubDate>Wed, 04 Jan 2006 09:03:10 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166442</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : Bravo! I've done it myself on occasion, it's satisfying... in an odd way. :)<br><br>Tear it up Link Logger! <br><br>@ Spanner, Yeah, most of the AVs out there have this covered already! Thanks for showing AntiVir getting "upset" at the file! ;)<br><SMALL>--<br>Think outside the Fox... <A HREF="http://www.opera.com/">Opera</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166442</guid>
<pubDate>Wed, 04 Jan 2006 08:33:36 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166408</link>
<description><![CDATA[<A HREF="/useremail/u/1159554"><b>norwegian</b></A> : you don't have RedXII1234 paying you for this test at all ??<br>Sounds like admins are in for a wakeup.<br>;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166408</guid>
<pubDate>Wed, 04 Jan 2006 08:26:47 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166397</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : For the last couple of days I have tested a pile of sites with one of my systems and it has defected every attack thus far, but I wanted to see what would happen with a 'default' system and it wasn't good.  Now the trick is to go back and try a couple more tests and see what the factors are to defending against this, so we can pass on the 'easy way' to protection with some facts and tests to back up the suggestions.  So I'm getting ready to run a test using a non-admin level user and see how much of a difference that makes.  I will spend a little more time looking at the default settings for the AV and see if it really does skip scanning wmf files by default.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166397</guid>
<pubDate>Wed, 04 Jan 2006 08:24:00 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166377</link>
<description><![CDATA[<A HREF="/useremail/u/1159554"><b>norwegian</b></A> : <div class="bquote"><SMALL>said by  astirusty <A HREF="/useremail/u/269961"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR><div class="bquote"><SMALL>said by  Link Logger <A HREF="/useremail/u/356416"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><BR><BR>Houston we have a problem, and as soon as I pick up my teeth with my broken arm and figure out a way to describe the carnage the score is Windows Metafile Exploit 1, me 0.  The sequence of events was worthy to say the least and hopefully I caught them all.</DIV>Blake: <br>Thanks for trying this and trying to separate fact from fiction.  Also for being upfront enough to pass on the outcome.  Hopefully your results will wake a few more people up before they get woke up the hard way.<br> </DIV>This sort of work should be more accessable to the general public so they can start to really understand the issue more, but then i guess if they even read it, some software company will want to sue you for publishing it freely]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166377</guid>
<pubDate>Wed, 04 Jan 2006 08:20:48 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166361</link>
<description><![CDATA[<A HREF="/useremail/u/269961"><b>astirusty</b></A> : <div class="bquote"><SMALL>said by  Link Logger <A HREF="/useremail/u/356416"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Houston we have a problem, and as soon as I pick up my teeth with my broken arm and figure out a way to describe the carnage the score is Windows Metafile Exploit 1, me 0.  The sequence of events was worthy to say the least and hopefully I caught them all.</DIV>Blake: <br>Thanks for trying this and trying to separate fact from fiction.  Also for being upfront enough to pass on the outcome.  Hopefully your results will wake a few more people up before they get woke up the hard way.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166361</guid>
<pubDate>Wed, 04 Jan 2006 08:14:44 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166328</link>
<description><![CDATA[<A HREF="/useremail/u/1193253"><b>SpannerITWks</b></A> : Never default ! I've customised them to Include everything except some folders with some FW + Security tests + Rootkit stuff in etc ! Otherwise my AV/AT keeps trying to eliminate them lol. <br><br>Spanner<br><SMALL>--<br>I Only Know What I Know But I'm Learning all The Time -Stay Safe - Spanner intheWorks/SpannerITWks</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166328</guid>
<pubDate>Wed, 04 Jan 2006 08:06:26 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166271</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : Is your AV running with its default settings or have you modified them at any time?<br><br>Blake]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166271</guid>
<pubDate>Wed, 04 Jan 2006 07:50:26 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166230</link>
<description><![CDATA[<A HREF="/useremail/u/1193253"><b>SpannerITWks</b></A> : Hi LinkLogger,<br><br>Well like i said i was up 4 it, Again !<br><br>I went to the www that you PM'd me and immediately AntiVir kicked in -<br><br><A HREF="http://imageshack.us"> <IMG SRC="http://img250.imageshack.us/img250/9201/lltest1avvideo0ut.png"> </A><br><br>I disabled AV + DL'd the CABM8R7T-WMF file<br><br><A HREF="http://imageshack.us"> <IMG SRC="http://img250.imageshack.us/img250/4240/lltest1cabm8r7twmf2qq.png"> </A><br><br>Like some of the others it's 15.6kb file. Still with AV disabled i DC it -<br><br><A HREF="http://imageshack.us"> <IMG SRC="http://img245.imageshack.us/img245/6642/sdvideowmf8gw.png"> </A><br><br>OK'd SD + XnView launched with this -<br><br><A HREF="http://imageshack.us"> <IMG SRC="http://img245.imageshack.us/img245/3374/xnvvideoemf6nc.png"> </A><br><br>Process Explorer + my FW + logs + everything else all showing normal behaviour.<br><br>Nothing else happened @ ALL ! I have BOClean running which would have jumped on it if it was active, and Winsonar would also have blocked ANY unknown EXE that tried to run too. This is an identical Live test to the ones i did yesterday + posted about earlier.<br><br>So in in the clear once more i'm pleased to report !<br><br>EDIT -<br><br>I have always set my AV etc to scan all files, makes sense i think.<br><br>Spanner<br><SMALL>--<br>I Only Know What I Know But I'm Learning all The Time -<br><br> Stay Safe - <br><br>Spanner intheWorks<br>/SpannerITWks</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166230</guid>
<pubDate>Wed, 04 Jan 2006 07:37:56 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15166215</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : Can you please check your AntiVirus and see if it scans wmf, gif, doc, jpg, etc file types or if it scan all files, as it would be best if it scanned them all until we get the patch from Microsoft on this one.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15166215</guid>
<pubDate>Wed, 04 Jan 2006 07:32:01 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15165977</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : OK here are the screen shots and such from this attack &raquo;<A HREF="http://www.linklogger.com/wmf_attack.htm" >www.linklogger.com/wmf_attack.htm</A> its an ugly one.  F-Secure was able to fight most of it off but the damage to the security center is concerning enough to make you want to nuke and pave this system.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15165977</guid>
<pubDate>Wed, 04 Jan 2006 05:58:43 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15165935</link>
<description><![CDATA[<A HREF="/useremail/u/1193253"><b>SpannerITWks</b></A> : Hi,<br><br>Yeah i'm up 4 it !<br><br>I've visited all the www's i could find and also all the tests i'm aware of, as posted in the Meta thread, and so far 100% success to me + 98SE.<br><br>If you provide the goods + info etc then i'll do it.<br><br>EDIT -<br><br>I'm sure mysec + others will join in too.<br><br>Spanner<br><SMALL>--<br>I Only Know What I Know But I'm Learning all The Time -<br><br> Stay Safe - <br><br>Spanner intheWorks<br>/SpannerITWks</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15165935</guid>
<pubDate>Wed, 04 Jan 2006 05:20:20 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15165802</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : First the setup, Windows XP SP2 fully patched, with F-Secure trial antivirus with updated signature (due expire in a month, important).  XP SP2 had the firewall enabled (also important latter on), and I had completed a full scan with F-Secure before the test and the system was clean.  I was running as an admin level user (just because so many do). Now I have a whack of screen shots that I will place on my web site which shows the carnage as the user would see it and it wasn't pretty (think of an old hairy fat guy in a thong in you would pretty well have the picture as to how ugly this was).  By the time this attack was over, it was over for my test system and the system's defenses were all pretty well toast, resulting in the system being wide open for future attacks of almost any kind (not to mention the keyloggers running on it).<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15165802</guid>
<pubDate>Wed, 04 Jan 2006 03:50:20 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15165698</link>
<description><![CDATA[<A HREF="/useremail/u/279131"><b>jig</b></A> : do tell?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15165698</guid>
<pubDate>Wed, 04 Jan 2006 03:07:49 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15165697</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : Houston we have a problem, and as soon as I pick up my teeth with my broken arm and figure out a way to describe the carnage the score is Windows Metafile Exploit 1, me 0.  The sequence of events was worthy to say the least and hopefully I caught them all.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15165697</guid>
<pubDate>Wed, 04 Jan 2006 03:07:04 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15165272</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : Ineffective = good]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15165272</guid>
<pubDate>Wed, 04 Jan 2006 01:05:45 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15165238</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : So ineffective in your test is good then, meaning no infection.<br><br>Blake]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15165238</guid>
<pubDate>Wed, 04 Jan 2006 00:59:44 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15165189</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : I tested 8 unique. 7 wild, and 1 I made myself.<br><br>Hexblog 1.4 Fix: 8 of 8 ineffective. wmf_dcode still crashed explorer in gdi32.dll but didn't do anything<br><br>Leaked Fix: 8 of 8 ineffective. wmf_dcode still crashed explorer in gdi32.dll but didn't do anything<br><br>Ineffective means it just says "No preview available." Nothing happens.<br><SMALL>--<br>Open Source -&gt; Close Minded<BR>Microsoft Windows 2000/XP Security: <A HREF="http://redxii.blogspot.com">Some Assembly Required</A>.<BR>Excessive use of "$" as in "M$" may make you look like a fool.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15165189</guid>
<pubDate>Wed, 04 Jan 2006 00:52:55 EDT</pubDate>
</item>

<item>
<title>Re: Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15165117</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Go git 'em Fudd! :D <br><br> <IMG SRC="http://www.ezthemes.com/previews/e/elmerfu2.jpg"> <br><br> Sparrow <A HREF="/useremail/u/731068"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15165117</guid>
<pubDate>Wed, 04 Jan 2006 00:42:36 EDT</pubDate>
</item>

<item>
<title>Taking off the gloves, help me get punched out</title>
<link>http://www.dslreports.com/forum/remark,15165063</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : OK IM me your meanest, nastiest, most low down scum sucking, butt kicking, evilest, vile, polluted, vicious, malicious windows metafile spewing site as I'm look to get infected or boot the infection attempt square in the nuts.  Its time to get where the rubber meets the road and get to the truth of this latest event.<br><br>Anyone else have a bunch of victim systems they are willing to sacrifice to the malware gods, sign on and we will test these evil sites and see what happens to the various defense methods already claiming victory over this menace to the <STRIKE>golf</STRIKE> computer industry (sorry watched Caddy Shack again the other night, great movie).<br><br>We can sit around and bitch about this and speculate what works and what doesn't and how nasty this bad boy metafile attack is or we can go hunting and testing get down to the truth of the matter.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15165063</guid>
<pubDate>Wed, 04 Jan 2006 00:30:00 EDT</pubDate>
</item>

</channel>
</rss>
