Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Taking off the gloves, help me get punched out
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
(topic move) HJT Log Spy Axe »
« Notepad thoughts.  
AuthorAll Replies


Link Logger
Premium,MVM
join:2001-03-29
Calgary, AB
·Shaw

reply to Link Logger
Re: Taking off the gloves, help me get punched out

Houston we have a problem, and as soon as I pick up my teeth with my broken arm and figure out a way to describe the carnage the score is Windows Metafile Exploit 1, me 0. The sequence of events was worthy to say the least and hopefully I caught them all.

Blake
--
Vendor: Firewall Logging Software »www.SonicLogger.com - SonicWall and 3Com »www.LinkLogger.com - Linksys, Netgear and Zyxel


jig

join:2001-01-05
Hacienda Heights, CA
do tell?

astirusty
Premium
join:2000-12-23
Henderson, NV
·AT&T Southwest

 reply to Link Logger
said by Link Logger See Profile :

Houston we have a problem, and as soon as I pick up my teeth with my broken arm and figure out a way to describe the carnage the score is Windows Metafile Exploit 1, me 0. The sequence of events was worthy to say the least and hopefully I caught them all.
Blake:
Thanks for trying this and trying to separate fact from fiction. Also for being upfront enough to pass on the outcome. Hopefully your results will wake a few more people up before they get woke up the hard way.


norwegian
Premium
join:2005-02-15
Outback
·WestNet Broadband

said by astirusty See Profile :

said by Link Logger See Profile :

Houston we have a problem, and as soon as I pick up my teeth with my broken arm and figure out a way to describe the carnage the score is Windows Metafile Exploit 1, me 0. The sequence of events was worthy to say the least and hopefully I caught them all.
Blake:
Thanks for trying this and trying to separate fact from fiction. Also for being upfront enough to pass on the outcome. Hopefully your results will wake a few more people up before they get woke up the hard way.
This sort of work should be more accessable to the general public so they can start to really understand the issue more, but then i guess if they even read it, some software company will want to sue you for publishing it freely


Link Logger
Premium,MVM
join:2001-03-29
Calgary, AB
·Shaw

reply to astirusty
For the last couple of days I have tested a pile of sites with one of my systems and it has defected every attack thus far, but I wanted to see what would happen with a 'default' system and it wasn't good. Now the trick is to go back and try a couple more tests and see what the factors are to defending against this, so we can pass on the 'easy way' to protection with some facts and tests to back up the suggestions. So I'm getting ready to run a test using a non-admin level user and see how much of a difference that makes. I will spend a little more time looking at the default settings for the AV and see if it really does skip scanning wmf files by default.

Blake
--
Vendor: Firewall Logging Software »www.SonicLogger.com - SonicWall and 3Com »www.LinkLogger.com - Linksys, Netgear and Zyxel


norwegian
Premium
join:2005-02-15
Outback

1 edit
you don't have RedXII1234 paying you for this test at all ??
Sounds like admins are in for a wakeup.

astirusty
Premium
join:2000-12-23
Henderson, NV
·AT&T Southwest

 reply to Link Logger
said by Link Logger See Profile :

So I'm getting ready to run a test using a non-admin level user and see how much of a difference that makes.
Great! I was just going to ask you if you could try this if you had not already.


novaflare
The Dragon Was Here
Premium
join:2002-01-24
Barberton, OH

reply to norwegian
said by norwegian See Profile :

you don't have RedXII1234 paying you for this test at all ??
Sounds like admins are in for a wakeup.

Why would i be in for a wake up? Ive done 2 things diffrent to protect my self used the unoffical patch and unregged the dll. I probably would not ever get infected via this route any ways as i dont surf the sites that would be the top users of the exploit.

Now this is one patch that I will install regardless of any potential risk of it hoseing my system. Simply put I use thumb nail and preview to find my textures etc for the 3d models I make.

It would take alot more than this to scare me in to cripling my self by running as a limited user.
--
DSLR security chat at us.ausirc.net chanel #dslr_sec lets pack this channelopen source dns server for *nix and windows »powerdns.com
Forums » Up and Running » Security » Security(topic move) HJT Log Spy Axe »
« Notepad thoughts.  


Tuesday, 10-Nov 23:30:57 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [125] Moto Sold About 100,000 Droids
· [94] Verizon Keeps Swinging At AT&T
· [86] VoIP Over 3G Still Not Working For iPhone
· [67] Government Will Release Some Telco Wiretap Lobbying Documents
· [62] Verizon's Hanging Up On Rural America
· [48] Verizon's Higher ETFs Annoy Senator
· [34] Bill Would Force ISPs To Block Financial Scams
· [31] Sprint Announces Job Cuts
· [24] Mediacom Hints At 50, 100 Mbps Speeds
· [24] Google Offers Free Holiday Airport Wi-Fi
Most people now reading
· Massive Slowdowns? [cover,1584]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· Windows 7 boot manager editing questions [Microsoft Help]
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· House inspector failed to find major gas leak [Home Repair & Improvement]
· I had enough! Let's go out on the street!! STOP THROTTLING!! [Canadian Broadband]
· [Connectivity] Slow Route and Bad RDNS [Comcast HSI]
· netTalk tk6000 [VOIP Tech Chat]