  SpannerITWks Premium join:2005-04-22
| reply to redxii Re: Windows MetaFiles still vulnerable
Here's my 1.17 Test Results on 98SE -
Attempting to copy the ZIP contents into a new folder - Nothing gets transferred, AntiVir jumps in to block and error copying files box.
Disable my AV -
rtf -
bmp -
OK and XnView opens with nothing to show.
jpeg - same as bmp
gif - same as bmp
jpg - same as bmp
png - same as bmp
tiff - same as bmp
emf -
OK
OK and XnView opens with nothing to show.
wmf - same as emf
ico -
nothing, unless i right to choose open with Notepad
OK and i get garbage.
Calc doesn't launch @ any time with any !
Spanner -- I Only Know What I Know, But I'm Learning all The Time - Stay Safe - Spanner intheWorks/SpannerITWks |
|
  ZOverLord Premium join:2003-10-20 Minneapolis, MN | reply to redxii So far looks like MOST 98 users have nothing to worry about. |
|
  trparky Bite My Shiny Metal Ass Premium,MVM join:2000-05-24 Cleveland, OH clubs:
·AT&T U-Verse
| reply to redxii Just tested the new 1.17 files on Windows XP by ZOverLord . Disabled my AV and attempted to run it. Nothing. Notta'. Zero. Zilch.
Turned my AV back on (the one that is bundled with ZoneLabs Security Suite) and it detected them after I scanned the folder. -- WedgeAntilles250
Tom's Rant |
|
  ZOverLord Premium join:2003-10-20 Minneapolis, MN | But you had already installed the Microsoft official patch correct? |
|
  ZOverLord Premium join:2003-10-20 Minneapolis, MN
| reply to redxii FYI looks like there IS an unsupported patch for 98. More info here:
»www.nod32.ch/en/download/tools.php -- Black, Grey and White Hats Unite here -> »testing.OnlyTheRightAnswers.com |
|
  SpannerITWks Premium join:2005-04-22
| reply to redxii Hi Z and everybody,
I posted about this the other day, with screenys of the install etc. I guess you musta missed it making all your tests for us ! Thanx again.
»Re: Windows MetaFiles still vulnerable
»Re: Windows MetaFiles still vulnerable
»Re: Windows MetaFiles still vulnerable
Spanner -- I Only Know What I Know, But I'm Learning all The Time - Stay Safe - Spanner intheWorks/SpannerITWks |
|
 KyeU
join:2003-12-31 Canada | reply to redxii v1.17 has no change in how the WMF Headers and Escape function and parameter are written (from v1.16). |
|
  redxii too big to fail Premium,Mod join:2001-02-26 Texas | If they are going to pull something off then they are going to atleast do it after Tuesday so there's a one month window for the script kiddies they cater to. |
|
 mysec Premium join:2005-11-29
| reply to ZOverLord said by ZOverLord :Most systems have notepad in BOTH the windows directory and the Windows\system32 directory There it is - My directory is WINNT so you need %windir% (I think) to get the path.
|
|
  tytfhtfjh
@telus.net
| reply to redxii I used Quickview and it asked to use a default viewer, then after I closed quickview, it was in the background Here it is with less strings still running.......dont know if this help or not, avg didnt see nothing till i did a quicktest |
|
  tytfhtfjh
@telus.net
| reply to redxii HMMMMMMM, maybe I can use the xp patch on 98.......oh o
Maybe just put the files somewhere..... |
|
  ZOverLord Premium join:2003-10-20 Minneapolis, MN
| reply to redxii Why not just use the 3rd Party patch for 98, it works, and try the test again with my test files, everything should be just fine then? -- Black, Grey and White Hats Unite here -> »testing.OnlyTheRightAnswers.com |
|
  tytfhtfjh
@telus.net | reply to redxii I would if I could find one |
|
  ZOverLord Premium join:2003-10-20 Minneapolis, MN
2 edits | said by tytfhtfjh :
I would if I could find one Your Kidding Right? Look here:
»www.nod32.ch/en/download/tools.php
Then use my test files again 
Most Current Version of Test Files ("Version 1.17")
»Windows MetaFiles still vulnerable -- Black, Grey and White Hats Unite here -> »testing.OnlyTheRightAnswers.com |
|
  SpannerITWks Premium join:2005-04-22
| reply to ZOverLord tytfhtfjh
Read back just a little up the thread, and you'll also see info + links of my posts with Pics of the ESET 98 fix install i did !
Spanner -- I Only Know What I Know, But I'm Learning all The Time - Stay Safe - Spanner intheWorks/SpannerITWks |
|
  ZOverLord Premium join:2003-10-20 Minneapolis, MN
| said by SpannerITWks :tytfhtfjh Read back just a little up the thread, and you'll also see info + links of my posts with Pics of the ESET 98 fix install i did ! Spanner Yep, I missed your post the first time, sorry about that.
I guess others may not know that this patch is available. Have pretty much gone to the major sites and linked back here to let others know. -- Black, Grey and White Hats Unite here -> »testing.OnlyTheRightAnswers.com |
|
 KyeU
join:2003-12-31 Canada | reply to redxii Proxomitron filters updated yet again to match all variants (to v1.17). Get them here: »Browser Security Pack v4.56 [Proxomitron] |
|
  EricJ1137
@sisna.com
| reply to ZOverLord Win 98/ME patch
Has anyone had success with the Win 98/ME patch from NOD32? Is it reasonably safe?
»www.nod32.ch/en/download/tools.php
I'm wondering if I should distribute this to my win98-using friends & family... |
|
 KyeU
join:2003-12-31 Canada
| said by EricJ1137 :
Has anyone had success with the Win 98/ME patch from NOD32? Is it reasonably safe? So far, I've only heard good things about it.
Never heard reports of it causing any slowdown or crashes. |
|
 Charles770
join:2004-11-08 France
| said by KyeU :Never heard reports of it causing any slowdown or crashes. Sorry, but it's not what I had seen.
Look here: - SpannerITWks »Windows MetaFiles still vulnerable :
"Well i installed the ESET patch ... I retried a number of those WMF tests including the real Live ones. On my 98SE PC i didn't notice anything different from the past few days of testing. I got exactly the same results as before with the usual protections kicking in, and/or nothing untoward occurring. Even without my AV running and allowing the tests through my defensive apps as before there was no change."
- and then caffeinator »Windows MetaFiles still vulnerable :
"Since I have a 98SE box ... I tried the eset one...called a GDI patch..shoulda known..it ate a whole 1% off my starting resources. UGH. Slowed the box like mad."
So maybe, more experiences or sources?
Charles. |
|