StevieO
August 26th, 2009, 05:56 PM
211594
Renewed interest has been show in Image file exploits - malware enbeded in .jpg, .doc - http://www.wilderssecurity.com/showthread.php?t=251875
So for those that wern't around at the time, or maybe have forgotten ...
Here's how the WMF exploit all started in December 2005, then spread around the world, and the resulting aftermath.
-
First worm using the new WMF vulnerability has been found - http://www.f-secure.com/weblog/archives/archive-122005.html
-
Deep investigation commenced on grc.com
-
" The guys at F-Secure, while they were fetching a file in a DOS box, it infected their machine because they had Google's desktop search system going. And it turns out, when they fetched the file, Google's desktop system indexed it. And the process of indexing the file caused the exploit to run. "
-
A SERIOUS new Windows vulnerability - http://www.grc.com/sn/sn-020.htm
The Windows MetaFile (WMF) Vulnerability - http://www.grc.com/sn/sn-021.htm
The Windows MetaFile Backdoor? - http://www.grc.com/sn/sn-022.htm
WMF MICE detection utility - http://www.grc.com/wmf/wmf.htm
-
Lots of testing started on Wilders + broadbandreports, amongst lots of other places. These are just a few examples of all the threads and posts in various areas -
New Windows Vulnerability - http://www.wilderssecurity.com/showthread.php?t=113044
Help me understand this .wmf exploit a little better - http://www.wilderssecurity.com/showthread.php?t=114052
BOClean, WMF and Limited User Accounts? - http://www.wilderssecurity.com/showthread.php?t=113506
" The exploit is a datafile that runs in WMP, at the system level so being a limited user isn't going to buy you anything. Tricks like this, using programs like WMP that are part of the OS now are how malware authors are getting around the confines of limited user. "
Windows MetaFiles still vulnerable - http://www.broadbandreports.com/forum/remark,15115819
UNTIL This Is Repaired By MICROSOFT - http://www.broadbandreports.com/forum/remark,15138954
More Graphics Vulnerabilities - http://www.broadbandreports.com/forum/remark,15206213
-
" Leo and Steve close the backdoor on the controversial Windows WMF MetaFile Image code Execution (MICE) vulnerability. They discuss everything that's known about it, separate the facts from the spin, explain exactly which Windows versions are vulnerable and why, and introduce a new piece of GRC freeware - MouseTrap - which determines whether any Windows or Linux/WINE system has 'MICE' " - http://www.grc.com/sn/sn-023.htm
-
Windows Metafile vulnerability - http://en.wikipedia.org/wiki/Windows_Metafile_vulnerability
Renewed interest has been show in Image file exploits - malware enbeded in .jpg, .doc - http://www.wilderssecurity.com/showthread.php?t=251875
So for those that wern't around at the time, or maybe have forgotten ...
Here's how the WMF exploit all started in December 2005, then spread around the world, and the resulting aftermath.
-
First worm using the new WMF vulnerability has been found - http://www.f-secure.com/weblog/archives/archive-122005.html
-
Deep investigation commenced on grc.com
-
" The guys at F-Secure, while they were fetching a file in a DOS box, it infected their machine because they had Google's desktop search system going. And it turns out, when they fetched the file, Google's desktop system indexed it. And the process of indexing the file caused the exploit to run. "
-
A SERIOUS new Windows vulnerability - http://www.grc.com/sn/sn-020.htm
The Windows MetaFile (WMF) Vulnerability - http://www.grc.com/sn/sn-021.htm
The Windows MetaFile Backdoor? - http://www.grc.com/sn/sn-022.htm
WMF MICE detection utility - http://www.grc.com/wmf/wmf.htm
-
Lots of testing started on Wilders + broadbandreports, amongst lots of other places. These are just a few examples of all the threads and posts in various areas -
New Windows Vulnerability - http://www.wilderssecurity.com/showthread.php?t=113044
Help me understand this .wmf exploit a little better - http://www.wilderssecurity.com/showthread.php?t=114052
BOClean, WMF and Limited User Accounts? - http://www.wilderssecurity.com/showthread.php?t=113506
" The exploit is a datafile that runs in WMP, at the system level so being a limited user isn't going to buy you anything. Tricks like this, using programs like WMP that are part of the OS now are how malware authors are getting around the confines of limited user. "
Windows MetaFiles still vulnerable - http://www.broadbandreports.com/forum/remark,15115819
UNTIL This Is Repaired By MICROSOFT - http://www.broadbandreports.com/forum/remark,15138954
More Graphics Vulnerabilities - http://www.broadbandreports.com/forum/remark,15206213
-
" Leo and Steve close the backdoor on the controversial Windows WMF MetaFile Image code Execution (MICE) vulnerability. They discuss everything that's known about it, separate the facts from the spin, explain exactly which Windows versions are vulnerable and why, and introduce a new piece of GRC freeware - MouseTrap - which determines whether any Windows or Linux/WINE system has 'MICE' " - http://www.grc.com/sn/sn-023.htm
-
Windows Metafile vulnerability - http://en.wikipedia.org/wiki/Windows_Metafile_vulnerability