Results 1 to 11 of 11

Thread: Windows Zero-Day Flaw being exploited

  1. #1
    IRC ADMIN DO's Avatar
    Join Date
    Oct 2004
    Location
    /dev/null
    Posts
    223
    Blog Entries
    2

    Windows Zero-Day Flaw being exploited

    Released on December 28th, the Windows .WMF exploit has been a nasty one, and according to the SANS Internet Storm Center, things will only get worse.

    On December 31st, a new and improved version of the WMF exploit had been published. The new exploit generated WMF files that were different enough to bypass nearly all Anti-Virus and IDS signatures. Different methods of distributing the virus, such as e-mails and instant messenger chats have already been seen in the wild, as more and more worms and trojans have been utilising the exploit to gain access to computers running the Windows operating system.

    "I've written more than a few diaries, and I've often been silly or said funny things, but now, I'm being as straightforward and honest as I can possibly be: the Microsoft WMF vulnerability is bad. It is very, very bad." Stated Tom Liston in the SANS Internet Storm Center Diary.

    SANS and many other security sites recommend un-registering Shimgvw.dll (Microsoft picture and fax viewer) and using the unofficial patch to protect aginst the virus, until Microsoft can release an official patch. A virus scanner isn't enough to protect against some of the more advanced variants of the exploit.

    "The word from Redmond isn't encouraging. We've heard nothing to indicate that we're going to see anything from Microsoft before January 9th." Said Liston in the diary.

    Microsoft Security Advisory (912840)
    F-Secure Weblog

    It just keeps getting worst:
    http://www.informationweek.com...D=174904839&pgno=1


    Becareful fellow GWers
    irc.gotwoot.net #gotwoot

    Kitkat makes great signatures!

  2. #2
    Missing Nin Lefty's Avatar
    Join Date
    May 2004
    Location
    Bellevue, WA
    Age
    40
    Posts
    1,138

    Windows Zero-Day Flaw being exploited

    Thank God I use a mac. I feel for the Window users stuck with all these tojans viruses and worms.

  3. #3

    Windows Zero-Day Flaw being exploited

    The only problem I ever got was the Blaster.32 thing a couple years back. As unlikely as it sounds, I've never had any other problems with Windows.

  4. #4
    If I could change my name
    to Saberfire... I would
    Deadfire's Avatar
    Join Date
    Sep 2005
    Location
    Canada
    Posts
    1,263

    Windows Zero-Day Flaw being exploited

    I've ready have had to fix about 10-15 computers hit by it....interesting stuff it is
    image fail!

  5. #5
    That one lazy guy. LaZie's Avatar
    Join Date
    Apr 2004
    Location
    Midgar
    Age
    34
    Posts
    1,246

    Windows Zero-Day Flaw being exploited

    Oh nooooooes!

  6. #6
    Vampiric Minion Kraco's Avatar
    Join Date
    Oct 2005
    Location
    :noitacoL
    Age
    45
    Posts
    17,860

    Windows Zero-Day Flaw being exploited

    I actually installed a few days ago the unofficial patch from Ilfak Guilfanov (mentioned in F-secure webblog). Thought I doubt it was needed with my surfing habits... But who knows. I do visit some disreputable sites, like one Gotwoot Evolution, after all...

    Doing something about this can certainly be recommended to those who actively search for images, like new anime fanart.

  7. #7
    That one lazy guy. LaZie's Avatar
    Join Date
    Apr 2004
    Location
    Midgar
    Age
    34
    Posts
    1,246

    Windows Zero-Day Flaw being exploited

    Or porn and hentai [img]i/expressions/face-icon-small-tongue.gif[/img]

  8. #8
    Jounin Cal_kashi's Avatar
    Join Date
    Apr 2004
    Location
    Silicon Valley
    Age
    41
    Posts
    792

    Windows Zero-Day Flaw being exploited

    I've never had a virus/worm/trojan (etc) problem and I've abusing wintendo and PC's for many years now.
    When man invented the bicycle he reached the peak of his attainments. Here was a machine of precision and balance for the convenience of man. And (unlike subsequent inventions for man's convenience) the more he used it, the fitter his body became. Here, for once, was a product of man's brain that was entirely beneficial to those who used it, and of no harm or irritation to others. Progress should have stopped when man invented the bicycle. ~Elizabeth West, Hovel in theHills

  9. #9

    Windows Zero-Day Flaw being exploited

    Originally posted by: LaZyKiD
    Or porn and hentai
    You just gotta know where to look [img]i/expressions/face-icon-small-happy.gif[/img]

  10. #10
    ANBU Captain Paulyboy's Avatar
    Join Date
    Jul 2004
    Location
    Texas
    Age
    35
    Posts
    560

    Windows Zero-Day Flaw being exploited

    Im not the master of Technical Computers and all, so this is all for windows users? I have winxp version 2002!!!!!!
    No one but the enemy will ever teach you how to destroy and conquer. Only the enemy shows you where you are weak. Only the enemy tells you when he is strong. And the rules of the game are what you can do to him and what you can stop him from doing to you. I am your enemy from now on. From now on, I am your teacher."
    -Mazer Rackham

  11. #11

    Windows Zero-Day Flaw being exploited

    Originally posted by: DragonOutlaw
    Released on December 28th, the Windows .WMF exploit has been a nasty one, and according to the SANS Internet Storm Center, things will only get worse.

    On December 31st, a new and improved version of the WMF exploit had been published. The new exploit generated WMF files that were different enough to bypass nearly all Anti-Virus and IDS signatures. Different methods of distributing the virus, such as e-mails and instant messenger chats have already been seen in the wild, as more and more worms and trojans have been utilising the exploit to gain access to computers running the Windows operating system.

    "I've written more than a few diaries, and I've often been silly or said funny things, but now, I'm being as straightforward and honest as I can possibly be: the Microsoft WMF vulnerability is bad. It is very, very bad." Stated Tom Liston in the SANS Internet Storm Center Diary.

    SANS and many other security sites recommend un-registering Shimgvw.dll (Microsoft picture and fax viewer) and using the unofficial patch to protect aginst the virus, until Microsoft can release an official patch. A virus scanner isn't enough to protect against some of the more advanced variants of the exploit.

    "The word from Redmond isn't encouraging. We've heard nothing to indicate that we're going to see anything from Microsoft before January 9th." Said Liston in the diary.

    Microsoft Security Advisory (912840)
    F-Secure Weblog

    It just keeps getting worst:
    http://www.informationweek.com...D=174904839&pgno=1


    Becareful fellow GWers
    ZOMG thx for the heads up

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •