pmsumner: (Default)
posted by [personal profile] pmsumner at 07:34pm on 02/01/2006 under
The newly developed WMF exploit. It's not big news yet other than in geek circles, but it's bad news.

Essentially, just by downloading, viewing, opening an image, or even just going to a web page with an image on it, it's possible that you could become infected by any virus, trojan, worm, malware, bot or backdoor software that the host wants. And this time it does appear to be this simple.

Literally - go to web page in IE, image loads, you're infected.
Or... Someone sends you picture by email which you load up, you're infected.


http://www.f-secure.com/weblog/ has lots of information and links on this. There's stuff on every major security software website, there's an official MS announcement about it but no official patch. There's an unofficial patch out which does a damn good job, apparently, but still. This isn't good.


It appears that during the design of the WMF (Windows MetaFile?) file format, it was decided that there would be a need to allow some executable information... why?! This is the core of the exploit, and the broken implementation means that when the picture's loaded up, the broken code allows any arbitrary code to be executed. This can then be used to download and execute trojans or virii or whathaveyou.
Music:: Simpsons on Sky One
Mood:: worried

Reply

This account has disabled anonymous posting.
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

May

SunMonTueWedThuFriSat
      1
 
2
 
3
 
4
5
 
6
 
7
 
8
 
9
 
10
 
11
 
12
 
13
 
14
 
15
 
16
 
17
 
18
 
19
 
20
 
21
 
22
 
23
 
24
 
25
 
26
 
27
 
28
 
29
 
30
 
31