home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

Sites exploit Windows image flaw

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1831
Discussions: 200,923, Posts: 2,379,099, Members: 246,290
Old December 29th, 2005, 03:47 PM   Digg it!   #1 (permalink)
Ultimate Member
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 1,199
Sites exploit Windows image flaw

Quote:
The US net watchdog, the Computer Emergency Response Center (Cert), and security firms have issued warnings about certain types of image files called Windows Metafiles.

Quote:
"Exploit code has been publicly posted and used to successfully attack fully-patched Windows XP SP2 systems," said Cert. "However, other versions of the Windows operating system may be at risk as well."

Quote:
Experts said numerous websites were taking advantage of the flaw to sneak into computers and install spyware.

BBC
__________________
Well, if crime fighters fight crime and fire fighters fight fire, what do freedom fighters fight? They never mention that part to us, do they?
-George Carlin
nomaxim is offline   Reply With Quote
Old December 29th, 2005, 03:52 PM     #2 (permalink)
I do Ouchy-Bleedy.
 
no1_vern's Avatar
 
Join Date: Apr 2002
Location: Albany, Ga.
Posts: 10,642
http://www.techimo.com/newsapp/index.pl?photo=15546

AND:
http://www.f-secure.com/weblog/

Quote:
Microsoft's bulletin confirms that this vulnerability applies to all the main versions of Windows: Windows ME, Windows 2000, Windows XP and Windows 2003.

They also list the REGSVR32 workaround. It's a good idea to use this while waiting for a patch. To quote Microsoft's bulletin:

Un-register the Windows Picture and Fax Viewer (Shimgvw.dll)

1. Click Start, click Run, type "regsvr32 -u %windir%\system32\shimgvw.dll"
(without the quotation marks), and then click OK.

2. A dialog box appears to confirm that the un-registration process has succeeded.
Click OK to close the dialog box.

Impact of Workaround: The Windows Picture and Fax Viewer will no longer be started
when users click on a link to an image type that is associated with the Windows Picture and Fax Viewer.

To undo this change, re-register Shimgvw.dll by following the above steps.
Replace the text in Step 1 with “regsvr32 %windir%\system32\shimgvw.dll” (without the quotation marks).

This workaround is better than just trying to filter files with a WMF extension. There are methods where files with other image extensions (such as BMP, GIF, PNG, JPG, JPEG, JPE, JFIF, DIB, RLE, EMF, TIF, TIFF or ICO) could be used to exploit a vulnerable machine.

__________________
They say technology slows down for no one. I know it outruns my wallet. I figure its because my wallet isn't light enough yet.
no1_vern is online now   Reply With Quote
Old December 29th, 2005, 03:56 PM     #3 (permalink)
Ultimate Member
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 1,199
US-CERT Technical Cyber Security Alert TA05-362A

Quote:
Since there is no known patch for this issue at this time, US-CERT is recommending sites follow several potential workarounds.

nomaxim is offline   Reply With Quote
Old December 31st, 2005, 01:15 PM     #4 (permalink)
Ultimate Member
 
SeanC's Avatar
 
Join Date: Oct 2001
Location: Toronto Canada
Posts: 4,698
A good work around is to not open pictures from the web until you have the patch or to ensure that something else is set as the default to open the pictures - like GIMP or something else.
__________________
AMD Phenom Q9500 Quad-Core 2.2ghz / Asus M3A78-EMH HDMI / 4GB PC667 RAM / 320GB SATA II
SeanC is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
Cannot create WinXP image in Windows 2000 RIS server Samshen Applications and Operating Systems 1 April 14th, 2005 03:52 PM
Not a Vaild Windows Image george17 Technical Support 4 November 15th, 2004 11:52 AM
Windows 2000 Exploit EvilRick Security and Privacy Issues 3 July 21st, 2004 10:41 AM
sudden barrage of worms/viruses of windows code flaw? I2n0ld General Tech Discussion 4 May 19th, 2004 03:59 PM
'Critical' flaw found in Windows shawshank62 General Tech Discussion 16 July 26th, 2003 05:34 AM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (2856)
Obama the Muslim (13)
Why is Khalid Sheikh Mohammed even .. (9)
Is the PSU I received dead? (10)
windows vista security holes (8)
Foreign voltage (10)
Print spooler problem (13)
HIS HD5770 graphic card question (15)
Install XP pro and a Vista laptop ?.. (9)
Dept. of HS: NSA 'Helped' Develop V.. (15)
A good PSU? (10)
New Computer wont recognize XP disc (7)
Ideal cheap graph card for PC-Gamin.. (15)
EVGA 9800 gtx help with finding a g.. (8)
Recent Discussions
Fire in DVD (0)
radeon x850xt platinum & shader 3 (2)
The NTDVM CPU has encountered an ille.. (24)
[F@H SPAM 11/16/09] ! 1/2 months to r.. (34)
Wireless speakers for PC? (11)
Print spooler problem (13)
Help getting around port 80 for camer.. (2)
Display shows 3x5 inch in middle of s.. (3)
windows vista security holes (8)
monitor will not turn on at all, (1)
World's largest Monopoly Game using G.. (331)
Foreign voltage (10)
FiOS modem/router interfering with ne.. (7)
Browsers wont load websites (2)
Virus Doctor Popup? (1)
Dept. of HS: NSA 'Helped' Develop Vis.. (15)
Install XP pro and a Vista laptop ?? (9)
EVGA 9800 gtx help with finding a goo.. (8)
Modern Warfare For the PC (32)
Problem with speed step/turbo boost? (1)
Modern Warfare 2: Who Bought It? (61)
SIS 740 and Widescreen (8)
Baffling Problem with my CPU/MoBo's. .. (0)
HIS HD5770 graphic card question (15)
Best file format to play on Windows H.. (0)


All times are GMT -4. The time now is 10:09 PM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28