Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Windows MetaFiles still vulnerable
Search Topic:
Uniqs:
73167
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Outpost not blocking traffic on Windows shutdown »
« JaimeSmile Trojan  
page: 1 · 2 · 3 ...41 · 42 · 43 · 44 · 45
AuthorAll Replies


SpannerITWks
Premium
join:2005-04-22

reply to redxii
Re: Windows MetaFiles still vulnerable

Here's my 1.17 Test Results on 98SE -

Attempting to copy the ZIP contents into a new folder - Nothing gets transferred, AntiVir jumps in to block and error copying files box.

Disable my AV -

rtf -



bmp -



OK and XnView opens with nothing to show.

jpeg - same as bmp

gif - same as bmp

jpg - same as bmp

png - same as bmp

tiff - same as bmp

emf -



OK



OK and XnView opens with nothing to show.

wmf - same as emf

ico -

nothing, unless i right to choose open with Notepad



OK and i get garbage.

Calc doesn't launch @ any time with any !

Spanner
--
I Only Know What I Know, But I'm Learning all The Time - Stay Safe - Spanner intheWorks/SpannerITWks


ZOverLord
Premium
join:2003-10-20
Minneapolis, MN
reply to redxii
So far looks like MOST 98 users have nothing to worry about.


trparky
Bite My Shiny Metal Ass
Premium,MVM
join:2000-05-24
Cleveland, OH
clubs:
·AT&T U-Verse

reply to redxii
Just tested the new 1.17 files on Windows XP by ZOverLord See Profile. Disabled my AV and attempted to run it. Nothing. Notta'. Zero. Zilch.

Turned my AV back on (the one that is bundled with ZoneLabs Security Suite) and it detected them after I scanned the folder.
--
WedgeAntilles250

Tom's Rant


ZOverLord
Premium
join:2003-10-20
Minneapolis, MN
But you had already installed the Microsoft official patch correct?


ZOverLord
Premium
join:2003-10-20
Minneapolis, MN

reply to redxii
FYI looks like there IS an unsupported patch for 98. More info here:

»www.nod32.ch/en/download/tools.php
--
Black, Grey and White Hats Unite here -> »testing.OnlyTheRightAnswers.com


SpannerITWks
Premium
join:2005-04-22

reply to redxii
Hi Z and everybody,

I posted about this the other day, with screenys of the install etc. I guess you musta missed it making all your tests for us ! Thanx again.

»Re: Windows MetaFiles still vulnerable

»Re: Windows MetaFiles still vulnerable

»Re: Windows MetaFiles still vulnerable

Spanner
--
I Only Know What I Know, But I'm Learning all The Time - Stay Safe - Spanner intheWorks/SpannerITWks

KyeU

join:2003-12-31
Canada
reply to redxii
v1.17 has no change in how the WMF Headers and Escape function and parameter are written (from v1.16).


redxii
too big to fail
Premium,Mod
join:2001-02-26
Texas
If they are going to pull something off then they are going to atleast do it after Tuesday so there's a one month window for the script kiddies they cater to.

mysec
Premium
join:2005-11-29

reply to ZOverLord
said by ZOverLord See Profile :

Most systems have notepad in BOTH the windows directory and the Windows\system32 directory

There it is - My directory is WINNT so you need %windir% (I think) to get the path.



tytfhtfjh

@telus.net

reply to redxii
I used Quickview and it asked to use a default viewer, then after I closed quickview, it was in the background

Here it is with less strings still running.......dont know if this help or not, avg didnt see nothing till i did a quicktest


tytfhtfjh

@telus.net

reply to redxii
HMMMMMMM, maybe I can use the xp patch on 98.......oh o



Maybe just put the files somewhere.....


ZOverLord
Premium
join:2003-10-20
Minneapolis, MN

reply to redxii
Why not just use the 3rd Party patch for 98, it works, and try the test again with my test files, everything should be just fine then?
--
Black, Grey and White Hats Unite here -> »testing.OnlyTheRightAnswers.com


tytfhtfjh

@telus.net
reply to redxii
I would if I could find one


ZOverLord
Premium
join:2003-10-20
Minneapolis, MN


2 edits
said by tytfhtfjh :

I would if I could find one
Your Kidding Right? Look here:

»www.nod32.ch/en/download/tools.php

Then use my test files again

Most Current Version of Test Files ("Version 1.17")

»Windows MetaFiles still vulnerable
--
Black, Grey and White Hats Unite here -> »testing.OnlyTheRightAnswers.com


SpannerITWks
Premium
join:2005-04-22

reply to ZOverLord
tytfhtfjh

Read back just a little up the thread, and you'll also see info + links of my posts with Pics of the ESET 98 fix install i did !

Spanner
--
I Only Know What I Know, But I'm Learning all The Time - Stay Safe - Spanner intheWorks/SpannerITWks


ZOverLord
Premium
join:2003-10-20
Minneapolis, MN

said by SpannerITWks See Profile :

tytfhtfjh

Read back just a little up the thread, and you'll also see info + links of my posts with Pics of the ESET 98 fix install i did !

Spanner
Yep, I missed your post the first time, sorry about that.

I guess others may not know that this patch is available. Have pretty much gone to the major sites and linked back here to let others know.
--
Black, Grey and White Hats Unite here -> »testing.OnlyTheRightAnswers.com

KyeU

join:2003-12-31
Canada
reply to redxii
Proxomitron filters updated yet again to match all variants (to v1.17). Get them here: »Browser Security Pack v4.56 [Proxomitron]


EricJ1137

@sisna.com

 reply to ZOverLord
Win 98/ME patch

Has anyone had success with the Win 98/ME patch from NOD32? Is it reasonably safe?

»www.nod32.ch/en/download/tools.php

I'm wondering if I should distribute this to my win98-using friends & family...

KyeU

join:2003-12-31
Canada

said by EricJ1137 :

Has anyone had success with the Win 98/ME patch from NOD32? Is it reasonably safe?
So far, I've only heard good things about it.

Never heard reports of it causing any slowdown or crashes.

Charles770

join:2004-11-08
France

said by KyeU See Profile :

Never heard reports of it causing any slowdown or crashes.
Sorry, but it's not what I had seen.

Look here:
- SpannerITWks
»Windows MetaFiles still vulnerable :

"Well i installed the ESET patch
...
I retried a number of those WMF tests including the real Live ones. On my 98SE PC i didn't notice anything different from the past few days of testing. I got exactly the same results as before with the usual protections kicking in, and/or nothing untoward occurring. Even without my AV running and allowing the tests through my defensive apps as before there was no change."


- and then caffeinator
»Windows MetaFiles still vulnerable :

"Since I have a 98SE box
...
I tried the eset one...called a GDI patch..shoulda known..it ate a whole 1% off my starting resources. UGH. Slowed the box like mad."


So maybe, more experiences or sources?

Charles.
Thread is
Forums » Up and Running » Security » SecurityOutpost not blocking traffic on Windows shutdown »
« JaimeSmile Trojan  
page: 1 · 2 · 3 ...41 · 42 · 43 · 44 · 45


Thursday, 26-Nov 07:06:21 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [105] New AT&T Ad Campaign Hits Back At Verizon
· [104] Time Warner Cable Fires Broadside At Broadcasters
· [95] Apple Joins AT&T Verizon Snark Fest
· [85] New Bill Takes Aim At Higher Verizon ETFs
· [63] TiVo Sees Record Customer Losses
· [48] In-Flight Internet Headed For Bumpy Landing?
· [34] Senators Want ACTA Made Public
· [32] Despite Billions In USF Fees, U.S. Libraries Lack Bandwidth
· [30] Earthlink Suffers From Major E-mail Outage
· [30] AT&T Offers New Prepaid Wireless plans
Most people now reading
· Whats the big deal about being "Old School"....? [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· Slow speeds in the evenings [TekSavvy]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [Config] cisco asa 5505 with multiple outside IP addresses [Cisco]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]
· USA made drywall problems. [Home Repair & Improvement]
· Opening a file download dialog from a JavaScript function. [Webmasters and Developers]
· Reasons #137/#138 to Love Windows Home Server [Microsoft Help]