home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

Sites exploit Windows image flaw

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 2636
Discussions: 200,520, Posts: 2,374,493, Members: 245,842
Old December 29th, 2005, 03:47 PM   Digg it!   #1 (permalink)
Ultimate Member
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 1,199
Sites exploit Windows image flaw

Quote:
The US net watchdog, the Computer Emergency Response Center (Cert), and security firms have issued warnings about certain types of image files called Windows Metafiles.

Quote:
"Exploit code has been publicly posted and used to successfully attack fully-patched Windows XP SP2 systems," said Cert. "However, other versions of the Windows operating system may be at risk as well."

Quote:
Experts said numerous websites were taking advantage of the flaw to sneak into computers and install spyware.

BBC
__________________
Well, if crime fighters fight crime and fire fighters fight fire, what do freedom fighters fight? They never mention that part to us, do they?
-George Carlin
nomaxim is offline   Reply With Quote
Old December 29th, 2005, 03:52 PM     #2 (permalink)
I do Ouchy-Bleedy.
 
no1_vern's Avatar
 
Join Date: Apr 2002
Location: Albany, Ga.
Posts: 10,580
http://www.techimo.com/newsapp/index.pl?photo=15546

AND:
http://www.f-secure.com/weblog/

Quote:
Microsoft's bulletin confirms that this vulnerability applies to all the main versions of Windows: Windows ME, Windows 2000, Windows XP and Windows 2003.

They also list the REGSVR32 workaround. It's a good idea to use this while waiting for a patch. To quote Microsoft's bulletin:

Un-register the Windows Picture and Fax Viewer (Shimgvw.dll)

1. Click Start, click Run, type "regsvr32 -u %windir%\system32\shimgvw.dll"
(without the quotation marks), and then click OK.

2. A dialog box appears to confirm that the un-registration process has succeeded.
Click OK to close the dialog box.

Impact of Workaround: The Windows Picture and Fax Viewer will no longer be started
when users click on a link to an image type that is associated with the Windows Picture and Fax Viewer.

To undo this change, re-register Shimgvw.dll by following the above steps.
Replace the text in Step 1 with “regsvr32 %windir%\system32\shimgvw.dll” (without the quotation marks).

This workaround is better than just trying to filter files with a WMF extension. There are methods where files with other image extensions (such as BMP, GIF, PNG, JPG, JPEG, JPE, JFIF, DIB, RLE, EMF, TIF, TIFF or ICO) could be used to exploit a vulnerable machine.

__________________
They say technology slows down for no one. I know it outruns my wallet. I figure its because my wallet isn't light enough yet.
no1_vern is online now   Reply With Quote
Old December 29th, 2005, 03:56 PM     #3 (permalink)
Ultimate Member
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 1,199
US-CERT Technical Cyber Security Alert TA05-362A

Quote:
Since there is no known patch for this issue at this time, US-CERT is recommending sites follow several potential workarounds.

nomaxim is offline   Reply With Quote
Old December 31st, 2005, 01:15 PM     #4 (permalink)
Ultimate Member
 
SeanC's Avatar
 
Join Date: Oct 2001
Location: Toronto Canada
Posts: 4,695
A good work around is to not open pictures from the web until you have the patch or to ensure that something else is set as the default to open the pictures - like GIMP or something else.
__________________
AMD Phenom Q9500 Quad-Core 2.2ghz / Asus M3A78-EMH HDMI / 4GB PC667 RAM / 320GB SATA II
SeanC is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
Cannot create WinXP image in Windows 2000 RIS server Samshen Applications and Operating Systems 1 April 14th, 2005 03:52 PM
Not a Vaild Windows Image george17 Technical Support 4 November 15th, 2004 11:52 AM
Windows 2000 Exploit EvilRick Security and Privacy Issues 3 July 21st, 2004 10:41 AM
sudden barrage of worms/viruses of windows code flaw? I2n0ld General Tech Discussion 4 May 19th, 2004 03:59 PM
'Critical' flaw found in Windows shawshank62 General Tech Discussion 16 July 26th, 2003 05:34 AM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (1658)
FT HOOD attack: 7 killed 12 injured (70)
HELP!!! What do you think of this s.. (25)
windows 7 retail and rtm (5)
Review My Build (6)
Looking for a graphic card that wil.. (30)
My 1st pc build (40)
PC Modern Warfare 2: it's much wors.. (12)
core i7 extreme 975, nvidia 9400gt (9)
Aero in Vista (7)
Building my first computer (13)
[F@H SPAM 11/1/09]New month . . . n.. (34)
Internet very slow since updating A.. (10)
slaving laptop drive (7)
Recent Discussions
nvidia geforce 9500GT 1gig DDR2 (3)
[F@H SPAM 11/1/09]New month . . . new.. (34)
[F@H SPAM 11/08/09] Where has all the.. (0)
Endless BSOD to Recovery Manager loop.. (0)
HELP!!! What do you think of this sys.. (25)
New Processor, Monitor will not turn .. (3)
Determining ip route and serial addre.. (8)
can u beat freecell # 1941? (11)
Dell 8300 Graphics Problems (1)
I have words with double underlines a.. (2)
Internet very slow since updating AVG.. (10)
My Pc wont start after i interupted D.. (0)
windows 7 retail and rtm (5)
New processor technical problem (0)
boot from CD-ROM in chipset via P4M80.. (2)
Powe Director v8 (0)
Windows Experience Index is screwed u.. (3)
Review My Build (6)
FAT32 to NTFS file system in Win2kpro (4)
Motherboards and my curse... (25)
2009 Build (4)
My 1st pc build (40)
Freezing During Music/Movies (1)
ext. sound card laptop to stereo syst.. (2)
Remote Desktop via SSH and error mess.. (2)


All times are GMT -4. The time now is 02:27 PM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28