<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Analysis of an Ecard Exploit Page in Security</title>
<link>http://www.dslreports.com/forum/r18866575</link>
<description></description>
<language>en</language>
<pubDate>Thu, 04 Dec 2008 13:26:31 EDT</pubDate>
<lastBuildDate>Thu, 04 Dec 2008 13:26:31 EDT</lastBuildDate>

<item>
<title>Re: Analysis of an Ecard Exploit Page</title>
<link>http://www.dslreports.com/forum/remark,18867201</link>
<description><![CDATA[<A HREF="/useremail/u/594412"><b>TK Junk Mail</b></A> : <div class="bquote"><SMALL>said by  MagnusM <A HREF="/useremail/u/425724"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Ecard worm uses the MS06-006 Windows Media Player Plug-In EMBED Overflow Exploit to install the worm file on vulnerable systems. This means that unless you have KB911564 installed, you can get infected by just clicking the link in an Ecard email. <br> </DIV>What about Vista? The original exploit you ID'd is for XP. Is there a similar Vista exploit that needs patching?<br><SMALL>--<br>--<BR><A HREF="http://tinyurl.com/2a9xcb">Internet News</A><BR><A HREF="http://tinyurl.com/bqv2h">My BLOG</A><BR><A HREF="http://tinyurl.com/yz8xto">My Web Page</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18867201</guid>
<pubDate>Mon, 13 Aug 2007 19:12:39 EDT</pubDate>
</item>

<item>
<title>Re: Analysis of an Ecard Exploit Page</title>
<link>http://www.dslreports.com/forum/remark,18867148</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : thanks, magnus.. i have been downloading a lot of those ecard.exe files and then uploading them to "virustotal", sometimes submitting them to av-vendors, as well.. <br><br>today, i noticed that something was strange with the webpage where i was downloading another one of the ecard files from and i wanted someone to look at it, though i never contacted anyone about it.. <br><br>i have been kind of paranoid because when i tried to download the ecard file, the first time, i clicked cancel but then it downloaded anyway, where "antivir" then flagged it.. (uhg) i didn't have all of my security-apps up at the time, either.. <br><br>i wasn't able to find anything that indicated that my computer was infected by the malware.. i booted into safe mode and looked for the "spooldr.exe" and "spool.sys" files..<br><br>i also tried going through the same routine again, only with my other security-apps running to see if anything was flagged, but it wasn't..<br><br>the ecard files that i downloaded today would infect the cdrom.sys file instead of the tcpip.sys file.. <br><br>i am glad that misec is at least looking into this zhelatin stuff..<br><br>as for checking for the patch, running the "belarc advisor" would be one way to do it, or (for me) to look at the update-history at the "windows updates" website.. belarc seems like the easy way to do it..<br><br>i deleted all of the windows updates log files, so i can't check those..  <br><br>update: i just ran the "belarc advisor" and i can see that i have the update, according to the belarc advisor..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18867148</guid>
<pubDate>Mon, 13 Aug 2007 19:03:11 EDT</pubDate>
</item>

<item>
<title>Re: Analysis of an Ecard Exploit Page</title>
<link>http://www.dslreports.com/forum/remark,18866998</link>
<description><![CDATA[<A HREF="/useremail/u/744566"><b>dannyboy 950</b></A> : Kinda odd doing a search I found a uninstall folder for it but not the file itself.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18866998</guid>
<pubDate>Mon, 13 Aug 2007 18:42:17 EDT</pubDate>
</item>

<item>
<title>Re: Analysis of an Ecard Exploit Page</title>
<link>http://www.dslreports.com/forum/remark,18866725</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Something along the lines of:<br><br>1] Click on "Start"<br>2] Then on "Search"<br><br>In the left-hand viewer pane:<br><br>3] Click on the "Advanced Options" checkbox<br>4] In the text box "Search for files or folders named", type: <B>*911564</B>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18866725</guid>
<pubDate>Mon, 13 Aug 2007 17:58:37 EDT</pubDate>
</item>

<item>
<title>Analysis of an Ecard Exploit Page</title>
<link>http://www.dslreports.com/forum/remark,18866575</link>
<description><![CDATA[<A HREF="/useremail/u/425724"><b>MagnusM</b></A> : I just finished analyzing an Ecard exploit page; thought it might be interesting to some. Basically, the Ecard worm uses the MS06-006 Windows Media Player Plug-In EMBED Overflow Exploit to install the worm file on vulnerable systems. This means that unless you have KB911564 installed, you can get infected by just clicking the link in an Ecard email. <br><br>The full analysis is available here: &raquo;<A HREF="http://blog.misec.net/2007/08/13/analysis-of-an-ecard-exploit-page/" >blog.misec.net/2007/08/13/analys&middot;&middot;&middot;it-page/</A><br><br>I also have a question that someone might be able to help answer: What is the easiest way a user can check if he has the KB911564 patch installed? In my analysis, I suggest checking for the presence of the file C:\Windows\KB911564.log -- perhaps someone can suggest a better way for less experienced users? (I deliberated whether to suggest "wmic qfe" in a Command Prompt, but I doubt many less computer-literate users will find it easy to do that.)<br><SMALL>--<br>Mischel Internet Security<BR><A HREF="http://www.misec.net">http://www.misec.net</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18866575</guid>
<pubDate>Mon, 13 Aug 2007 17:36:46 EDT</pubDate>
</item>

</channel>
</rss>
