±Recent Visitors

Recent Visitors to Com-Central!

±User Info-big


Welcome Anonymous

Nickname
Password

Membership:
Latest: cgsimpson
New Today: 0
New Yesterday: 0
Overall: 6645

People Online:
Members: 0
Visitors: 932
Total: 932
Who Is Where:
 Visitors:
01: Community Forums
02: Community Forums
03: Community Forums
04: Community Forums
05: Community Forums
06: Community Forums
07: Photo Gallery
08: Community Forums
09: Community Forums
10: Community Forums
11: Home
12: Home
13: Member Screenshots
14: Statistics
15: News
16: Member Screenshots
17: Home
18: Photo Gallery
19: Photo Gallery
20: Community Forums
21: Downloads
22: Member Screenshots
23: Community Forums
24: Photo Gallery
25: Home
26: Community Forums
27: Photo Gallery
28: Home
29: Community Forums
30: Community Forums
31: Community Forums
32: Photo Gallery
33: Community Forums
34: Photo Gallery
35: Photo Gallery
36: Photo Gallery
37: Community Forums
38: Community Forums
39: CPGlang
40: Community Forums
41: Community Forums
42: Community Forums
43: Community Forums
44: Home
45: Photo Gallery
46: Community Forums
47: Downloads
48: Photo Gallery
49: Photo Gallery
50: Photo Gallery
51: Home
52: Community Forums
53: Community Forums
54: Community Forums
55: News Archive
56: Photo Gallery
57: Community Forums
58: Community Forums
59: Community Forums
60: Member Screenshots
61: Community Forums
62: Community Forums
63: Member Screenshots
64: Home
65: Home
66: Community Forums
67: Home
68: Home
69: Photo Gallery
70: Community Forums
71: Community Forums
72: Community Forums
73: Community Forums
74: Community Forums
75: Community Forums
76: Community Forums
77: Photo Gallery
78: Community Forums
79: Community Forums
80: Your Account
81: Photo Gallery
82: Community Forums
83: Photo Gallery
84: Community Forums
85: Community Forums
86: Community Forums
87: Community Forums
88: CPGlang
89: Home
90: Home
91: Community Forums
92: Photo Gallery
93: Community Forums
94: Community Forums
95: Community Forums
96: Photo Gallery
97: Photo Gallery
98: Community Forums
99: Home
100: Member Screenshots
101: Community Forums
102: News Archive
103: Community Forums
104: Community Forums
105: Photo Gallery
106: Member Screenshots
107: CPGlang
108: Community Forums
109: Community Forums
110: Community Forums
111: Photo Gallery
112: Community Forums
113: Photo Gallery
114: Community Forums
115: Community Forums
116: Community Forums
117: Photo Gallery
118: Community Forums
119: Community Forums
120: Photo Gallery
121: Member Screenshots
122: Community Forums
123: Community Forums
124: CPGlang
125: Community Forums
126: Downloads
127: Community Forums
128: Community Forums
129: Community Forums
130: Community Forums
131: Community Forums
132: Community Forums
133: Photo Gallery
134: Community Forums
135: Community Forums
136: Downloads
137: Photo Gallery
138: Community Forums
139: Community Forums
140: Photo Gallery
141: Community Forums
142: Community Forums
143: Photo Gallery
144: Community Forums
145: Community Forums
146: Photo Gallery
147: Photo Gallery
148: Community Forums
149: Community Forums
150: Community Forums
151: Community Forums
152: Your Account
153: Community Forums
154: Photo Gallery
155: Community Forums
156: Community Forums
157: Photo Gallery
158: Community Forums
159: Photo Gallery
160: Photo Gallery
161: Your Account
162: Photo Gallery
163: Photo Gallery
164: Member Screenshots
165: Community Forums
166: Community Forums
167: Community Forums
168: Home
169: Community Forums
170: Community Forums
171: Photo Gallery
172: Photo Gallery
173: Photo Gallery
174: Community Forums
175: Community Forums
176: Photo Gallery
177: Community Forums
178: Photo Gallery
179: Community Forums
180: Community Forums
181: Photo Gallery
182: Photo Gallery
183: Community Forums
184: Community Forums
185: Photo Gallery
186: Photo Gallery
187: Photo Gallery
188: Downloads
189: Downloads
190: Community Forums
191: Community Forums
192: Member Screenshots
193: Your Account
194: Community Forums
195: Community Forums
196: Community Forums
197: Photo Gallery
198: Photo Gallery
199: Member Screenshots
200: Community Forums
201: Photo Gallery
202: Home
203: Community Forums
204: Community Forums
205: Community Forums
206: Community Forums
207: Photo Gallery
208: Community Forums
209: Photo Gallery
210: Community Forums
211: Community Forums
212: Member Screenshots
213: Community Forums
214: Photo Gallery
215: Community Forums
216: Photo Gallery
217: Community Forums
218: Community Forums
219: Photo Gallery
220: Member Screenshots
221: Community Forums
222: Photo Gallery
223: Downloads
224: Community Forums
225: Home
226: Community Forums
227: CPGlang
228: Community Forums
229: Community Forums
230: Member Screenshots
231: Photo Gallery
232: Community Forums
233: Photo Gallery
234: Community Forums
235: Photo Gallery
236: Home
237: Your Account
238: Community Forums
239: Photo Gallery
240: Photo Gallery
241: Home
242: Photo Gallery
243: Member Screenshots
244: Community Forums
245: Photo Gallery
246: Community Forums
247: Community Forums
248: Photo Gallery
249: Photo Gallery
250: Community Forums
251: Community Forums
252: Photo Gallery
253: Community Forums
254: Photo Gallery
255: Photo Gallery
256: Community Forums
257: Community Forums
258: Community Forums
259: Community Forums
260: Your Account
261: Downloads
262: Community Forums
263: Photo Gallery
264: Community Forums
265: Photo Gallery
266: Community Forums
267: Community Forums
268: Community Forums
269: Community Forums
270: Community Forums
271: Photo Gallery
272: Community Forums
273: Community Forums
274: Community Forums
275: Photo Gallery
276: Downloads
277: Community Forums
278: Community Forums
279: Photo Gallery
280: Community Forums
281: Community Forums
282: Home
283: Community Forums
284: Community Forums
285: Community Forums
286: Community Forums
287: Community Forums
288: Home
289: Your Account
290: Community Forums
291: Home
292: Community Forums
293: Downloads
294: Home
295: Photo Gallery
296: Photo Gallery
297: Community Forums
298: Your Account
299: Community Forums
300: Photo Gallery
301: Home
302: Community Forums
303: News Archive
304: Photo Gallery
305: Community Forums
306: Home
307: Home
308: Photo Gallery
309: Photo Gallery
310: Community Forums
311: Photo Gallery
312: Community Forums
313: Community Forums
314: Home
315: Community Forums
316: Community Forums
317: Community Forums
318: Community Forums
319: Photo Gallery
320: Community Forums
321: Photo Gallery
322: Community Forums
323: Photo Gallery
324: Community Forums
325: Community Forums
326: News
327: Community Forums
328: Community Forums
329: Photo Gallery
330: Photo Gallery
331: Community Forums
332: Community Forums
333: Community Forums
334: Community Forums
335: Photo Gallery
336: Member Screenshots
337: Statistics
338: Member Screenshots
339: Community Forums
340: Community Forums
341: Community Forums
342: Photo Gallery
343: News
344: Photo Gallery
345: Community Forums
346: Community Forums
347: Photo Gallery
348: Community Forums
349: Home
350: Community Forums
351: Community Forums
352: Community Forums
353: Your Account
354: Community Forums
355: Community Forums
356: Community Forums
357: Downloads
358: Photo Gallery
359: Community Forums
360: Community Forums
361: Community Forums
362: Community Forums
363: Community Forums
364: Community Forums
365: Photo Gallery
366: Home
367: Community Forums
368: Member Screenshots
369: Community Forums
370: Community Forums
371: Photo Gallery
372: Photo Gallery
373: Home
374: Photo Gallery
375: Community Forums
376: Photo Gallery
377: Community Forums
378: Community Forums
379: Photo Gallery
380: Community Forums
381: Community Forums
382: Downloads
383: Community Forums
384: Community Forums
385: Community Forums
386: Photo Gallery
387: Photo Gallery
388: Home
389: Community Forums
390: Community Forums
391: Member Screenshots
392: Community Forums
393: Community Forums
394: Community Forums
395: Community Forums
396: Community Forums
397: Community Forums
398: Community Forums
399: Your Account
400: Community Forums
401: Member Screenshots
402: Photo Gallery
403: Photo Gallery
404: Community Forums
405: Photo Gallery
406: Photo Gallery
407: Community Forums
408: Photo Gallery
409: Community Forums
410: CPGlang
411: Photo Gallery
412: Community Forums
413: Community Forums
414: Community Forums
415: Community Forums
416: Member Screenshots
417: Community Forums
418: Community Forums
419: Photo Gallery
420: Community Forums
421: Photo Gallery
422: Community Forums
423: Community Forums
424: Home
425: Community Forums
426: Photo Gallery
427: Home
428: Community Forums
429: Member Screenshots
430: Community Forums
431: Photo Gallery
432: Photo Gallery
433: Photo Gallery
434: Community Forums
435: Community Forums
436: Community Forums
437: Community Forums
438: Photo Gallery
439: Downloads
440: Photo Gallery
441: Downloads
442: Community Forums
443: Your Account
444: Photo Gallery
445: Downloads
446: Member Screenshots
447: Community Forums
448: Community Forums
449: Photo Gallery
450: Photo Gallery
451: Community Forums
452: News
453: Community Forums
454: Home
455: Photo Gallery
456: Photo Gallery
457: Community Forums
458: Community Forums
459: Community Forums
460: Home
461: CPGlang
462: Community Forums
463: Downloads
464: Community Forums
465: Member Screenshots
466: Home
467: Home
468: Community Forums
469: Statistics
470: Photo Gallery
471: Community Forums
472: Community Forums
473: Community Forums
474: Photo Gallery
475: Statistics
476: Photo Gallery
477: Member Screenshots
478: Community Forums
479: Community Forums
480: Community Forums
481: Home
482: Community Forums
483: Your Account
484: Community Forums
485: Your Account
486: Community Forums
487: Community Forums
488: Home
489: Community Forums
490: Community Forums
491: Home
492: Community Forums
493: Photo Gallery
494: Photo Gallery
495: CPGlang
496: Community Forums
497: Community Forums
498: Community Forums
499: Downloads
500: Photo Gallery
501: Statistics
502: Community Forums
503: Your Account
504: Community Forums
505: Photo Gallery
506: Home
507: Photo Gallery
508: Community Forums
509: Community Forums
510: Community Forums
511: Community Forums
512: Community Forums
513: Community Forums
514: Home
515: Community Forums
516: Community Forums
517: Photo Gallery
518: Home
519: Community Forums
520: News
521: Downloads
522: Photo Gallery
523: Your Account
524: Community Forums
525: Community Forums
526: Community Forums
527: Community Forums
528: Statistics
529: Community Forums
530: Photo Gallery
531: Home
532: Community Forums
533: Community Forums
534: Community Forums
535: Downloads
536: Photo Gallery
537: Downloads
538: Community Forums
539: Community Forums
540: Community Forums
541: Community Forums
542: Community Forums
543: Community Forums
544: Your Account
545: Community Forums
546: Community Forums
547: Home
548: Downloads
549: Home
550: Home
551: News Archive
552: Home
553: Photo Gallery
554: Community Forums
555: Community Forums
556: Community Forums
557: Community Forums
558: Photo Gallery
559: Community Forums
560: Community Forums
561: Community Forums
562: Photo Gallery
563: Community Forums
564: Photo Gallery
565: Community Forums
566: Your Account
567: Member Screenshots
568: CPGlang
569: Community Forums
570: Community Forums
571: Community Forums
572: Community Forums
573: Community Forums
574: Home
575: Community Forums
576: Photo Gallery
577: Community Forums
578: Community Forums
579: Community Forums
580: Community Forums
581: Your Account
582: Photo Gallery
583: Community Forums
584: News
585: Community Forums
586: Community Forums
587: Home
588: Community Forums
589: Community Forums
590: Community Forums
591: Statistics
592: Community Forums
593: Community Forums
594: Photo Gallery
595: Community Forums
596: Community Forums
597: Community Forums
598: Community Forums
599: Home
600: Community Forums
601: Community Forums
602: Community Forums
603: Photo Gallery
604: Community Forums
605: Community Forums
606: Photo Gallery
607: Home
608: Community Forums
609: Community Forums
610: Community Forums
611: Community Forums
612: Photo Gallery
613: Community Forums
614: Your Account
615: Community Forums
616: Community Forums
617: Community Forums
618: Community Forums
619: CPGlang
620: Community Forums
621: Community Forums
622: Community Forums
623: Photo Gallery
624: Community Forums
625: Community Forums
626: Community Forums
627: Community Forums
628: Home
629: Community Forums
630: Statistics
631: Community Forums
632: Community Forums
633: Community Forums
634: Community Forums
635: Community Forums
636: Community Forums
637: Community Forums
638: Home
639: Photo Gallery
640: Photo Gallery
641: Home
642: Photo Gallery
643: Community Forums
644: Photo Gallery
645: Community Forums
646: Photo Gallery
647: Photo Gallery
648: Downloads
649: Community Forums
650: Community Forums
651: Photo Gallery
652: Community Forums
653: CPGlang
654: Community Forums
655: Community Forums
656: Community Forums
657: Member Screenshots
658: Photo Gallery
659: Community Forums
660: Downloads
661: Home
662: Community Forums
663: Community Forums
664: Community Forums
665: Community Forums
666: Community Forums
667: Community Forums
668: Community Forums
669: Photo Gallery
670: Home
671: Community Forums
672: Photo Gallery
673: Community Forums
674: Photo Gallery
675: Photo Gallery
676: Community Forums
677: Community Forums
678: Community Forums
679: Community Forums
680: Community Forums
681: Community Forums
682: Community Forums
683: Home
684: Community Forums
685: Community Forums
686: Photo Gallery
687: CPGlang
688: Community Forums
689: Home
690: Community Forums
691: Community Forums
692: Community Forums
693: Downloads
694: Community Forums
695: Community Forums
696: Home
697: Community Forums
698: Community Forums
699: Community Forums
700: Community Forums
701: Community Forums
702: Your Account
703: Photo Gallery
704: Photo Gallery
705: Photo Gallery
706: Member Screenshots
707: Photo Gallery
708: Community Forums
709: Community Forums
710: Community Forums
711: Member Screenshots
712: Community Forums
713: Community Forums
714: Community Forums
715: Home
716: Photo Gallery
717: Community Forums
718: Member Screenshots
719: Community Forums
720: Community Forums
721: CPGlang
722: Member Screenshots
723: News Archive
724: Community Forums
725: Community Forums
726: Community Forums
727: Community Forums
728: Community Forums
729: Community Forums
730: Community Forums
731: Community Forums
732: Photo Gallery
733: Community Forums
734: Community Forums
735: Photo Gallery
736: Community Forums
737: Community Forums
738: Photo Gallery
739: Photo Gallery
740: Photo Gallery
741: Photo Gallery
742: Community Forums
743: Member Screenshots
744: News Archive
745: Photo Gallery
746: Photo Gallery
747: Community Forums
748: Community Forums
749: Community Forums
750: Community Forums
751: Photo Gallery
752: Community Forums
753: Community Forums
754: Downloads
755: Photo Gallery
756: Community Forums
757: Member Screenshots
758: Community Forums
759: Photo Gallery
760: Community Forums
761: Photo Gallery
762: Community Forums
763: Community Forums
764: Community Forums
765: Community Forums
766: Community Forums
767: Downloads
768: Photo Gallery
769: Community Forums
770: Home
771: Member Screenshots
772: Community Forums
773: Community Forums
774: Community Forums
775: Photo Gallery
776: Community Forums
777: Community Forums
778: Community Forums
779: Photo Gallery
780: Community Forums
781: Photo Gallery
782: Photo Gallery
783: Your Account
784: Member Screenshots
785: Community Forums
786: Home
787: Community Forums
788: Community Forums
789: Community Forums
790: Community Forums
791: Your Account
792: Community Forums
793: Statistics
794: Community Forums
795: Home
796: Photo Gallery
797: Community Forums
798: Photo Gallery
799: Community Forums
800: Photo Gallery
801: Home
802: Photo Gallery
803: Community Forums
804: Community Forums
805: Community Forums
806: Community Forums
807: Community Forums
808: Photo Gallery
809: Community Forums
810: News Archive
811: Community Forums
812: Photo Gallery
813: Community Forums
814: Photo Gallery
815: Community Forums
816: Photo Gallery
817: Community Forums
818: Community Forums
819: Community Forums
820: Community Forums
821: Home
822: Photo Gallery
823: Community Forums
824: Community Forums
825: Community Forums
826: Community Forums
827: Photo Gallery
828: Community Forums
829: Community Forums
830: Community Forums
831: CPGlang
832: Community Forums
833: Community Forums
834: Photo Gallery
835: Photo Gallery
836: Photo Gallery
837: Home
838: Community Forums
839: Community Forums
840: Photo Gallery
841: Community Forums
842: Community Forums
843: Community Forums
844: Community Forums
845: CPGlang
846: Member Screenshots
847: Photo Gallery
848: Community Forums
849: Community Forums
850: Home
851: Community Forums
852: Community Forums
853: Community Forums
854: Downloads
855: Photo Gallery
856: Community Forums
857: Community Forums
858: Downloads
859: Community Forums
860: Community Forums
861: Member Screenshots
862: Community Forums
863: Community Forums
864: Downloads
865: Member Screenshots
866: Your Account
867: Community Forums
868: Photo Gallery
869: CPGlang
870: Photo Gallery
871: Community Forums
872: Home
873: Home
874: Community Forums
875: Photo Gallery
876: Home
877: Home
878: Downloads
879: Community Forums
880: Photo Gallery
881: Photo Gallery
882: Downloads
883: Downloads
884: Photo Gallery
885: Home
886: Community Forums
887: Photo Gallery
888: Community Forums
889: Community Forums
890: Community Forums
891: Community Forums
892: Photo Gallery
893: Photo Gallery
894: Photo Gallery
895: Community Forums
896: Photo Gallery
897: Photo Gallery
898: Community Forums
899: Photo Gallery
900: Home
901: Community Forums
902: Community Forums
903: Community Forums
904: Community Forums
905: Downloads
906: Photo Gallery
907: Downloads
908: Photo Gallery
909: Community Forums
910: Member Screenshots
911: Downloads
912: CPGlang
913: Community Forums
914: Community Forums
915: Downloads
916: Statistics
917: Photo Gallery
918: Photo Gallery
919: Member Screenshots
920: Community Forums
921: Community Forums
922: Photo Gallery
923: Community Forums
924: Community Forums
925: Downloads
926: Photo Gallery
927: Member Screenshots
928: Photo Gallery
929: Community Forums
930: Community Forums
931: Community Forums
932: Photo Gallery

Staff Online:

No staff members are online!
This looks like a bad one! :: Archived
Resolve issues with your computer problems here or read about the latest computer parts and information.
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ›  Hardware

Topic Archived View previous topic :: View next topic  
Author Message
JG300-Ascout
Power User

Offline Offline
Joined: Jan 05, 2005
Posts: 6257
Location: Cyberspace
PostPosted: Sun Jan 01, 2006 5:53 pm
Post subject: This looks like a bad one!

www.foxnews.com/story/...44,00.html

Advice on impementing the fix from y'all?
__________________________________________________________
'Extremely Critical Flaw' in Windows Discovered, Already Exploited
Friday, December 30, 2005
By Lisa Vaas




Microsoft Corp. has issued a security advisory for what Secunia is deeming an "extremely critical flaw" in Windows Metafile Format (.wmf) that is now being exploited on fully patched systems by malicious attackers.
Websense Security Labs is tracking thousands of sites distributing the exploit code from a site called iFrameCASH BUSINESS.
That site and numerous others are distributing spyware and other unwanted software, replacing users' desktop backgrounds with a message that warns of spyware infection and which prompts the user to enter credit card information to pay for a "spyware cleaning" application to remove the detected spyware.
Vulnerable operating systems include a slew of Windows Server 2003 editions: Datacenter Edition, Enterprise Edition, Standard Edition and Web Edition.
Also at risk are Windows XP Home Edition and Windows XP Professional, making both home users and businesses open to attack.
In this fluid attack, researchers have kept up a steady stream of new details about the extent of the exploit's reach, with Google Desktop being the latest reported vector.
F-Secure reported on Wednesday that Google Desktop tries to index image files with the exploit, executing it in the process. F-Secure reports that this exploitation-via-indexing may wind up occurring with other desktop search engines as well.
(Story continues below)


Google had no immediate comment. To avoid the problem, security experts suggest disabling the feature's indexing of media files, or to remove Google Desktop altogether.
A workaround called REGSVR32 has been posted and was included in Microsoft's advisory. However, it should be noted that as of Thursday evening, some security researchers were reporting that the workaround is not fully successful.
The workaround is as follows, as quoted from the advisory:
Un-register the Windows Picture and Fax Viewer (Shimgvw.dll)
1. Click Start, click Run, type "regsvr32 -u %windir%system32shimgvw.dll" (without the quotation marks), and then click OK.
2. A dialog box appears to confirm that the un-registration process has succeeded.
� Click OK to close the dialog box.
Impact of Workaround: The Windows Picture and Fax Viewer will no longer be started when users click on a link to an image type that is associated with the Windows Picture and Fax Viewer.
To undo this change, re-register Shimgvw.dll by following the above steps. Replace the text in Step 1 with "regsvr32 %windir%system32shimgvw.dll" (without the quotation marks).
F-Secure notes that this workaround beats filtering .wmf files, given that files with other image extensions � such as BMP, GIF, JPG, JPEG, TIFF, etc. � can be used to exploit machines.
F-Secure also recommends filtering domains at corporate firewalls. These sites should be listed as off-limits:
toolbarbiz.business
toolbarsite.biz
toolbartraff.biz
toolbarurl.biz
buytoolbar.biz
buytraff.biz
iframebiz.biz
iframecash.biz
iframesite.biz
iframetraff.biz
iframeurl.business
F-Secure notes that it's seen 57 versions of this malicious .wmf file exploit as of Thursday, detected as PFV-Exploit.
The security firm is predicting that, even though the exploit has only been used to install spyware or fake antispyware/antivirus software thus far, it anticipates that real viruses will start to spread soon.
According to the Sunbelt Software blog, "any application that automatically displays a WMF image" can be a vector for infection, including older versions of Firefox, current versions of Opera, Outlook and all current versions of Internet Explorer on all Windows versions.
"This is a zero-day exploit, the kind that give security researchers cold chills," according to Sunbelt's blog. "You can get infected by simply viewing an infected WMF image."
According to F-Secure, Trojan downloaders are taking advantage of the vulnerability to install Trojan-Downloader.Win32.Agent.abs, Trojan-Dropper.Win32.Small.zp, Trojan.Win32.Small.ga and Trojan.Win32.Small.ev.
F-Secure also reports that some of the Trojans install hoax anti-malware programs such as Avgold.
F-Secure traced the exploit to Russian sites, one of which is allegedly registered to former Soviet Union President Mikhail Gorbachev.
Sunbelt warns that users are likely to get infected by being directed to one of the sites via spam that offer dirty pictures, free software or other bait.
The attack works by tricking users into opening malicious ".wmf" files in "Windows Picture and Fax Viewer" or by previewing such a file by selecting it in Windows Explorer. The attack can also be triggered automatically when visiting malicious Web sites via Internet Explorer.
Although Secunia deemed the flaw highly critical, at least one security researcher was dismissive of the bug's severity.
Pete Lindstrom, research director for Spire Security LLC, said that at this stage in the game, anything that requires user interaction is hardly worth notice.
"There's no such thing as 'extremely critical' when user interaction is required," Lindstrom said. "That's just silly."
But as far as using IE goes, download of malicious software is automatic, happening immediately upon going to the site, pointed out Alex Eckelberry, president of Sunbelt Software.
"There is no user interaction required," he wrote in an e-mail exchange. "You hit the Web site, you get hit immediately. No prompts, nothing."
John Pescatore, an analyst with Gartner Inc., said that this type of attack may be slowed down by requiring users to click on a malicious .wmf file or to go to a malicious Web site, but that doesn't mean it won't spread fast, given users' willingness to click on bait.
"One of these [attacks] where clicking on a URL [is involved], those can spread pretty fast," he said, given users' proclivity to click away.
"We do online consumer studies. Two years ago, 30 percent had fallen for phishing [schemes]. They entered their user name, password or credit card information. This year, many fewer completely fell for them, but they still clicked on the link in the phishing e-mail."
Given the rise of keystroke loggers that can automatically be downloaded onto a user's system after the user visits a malicious site, that means the Web-surfing population is still ripe for phishing, Pescatore said.
"They're still clicking on links, and whenever malicious software gets installed, that's when you get a critical rating, because all sorts of bad things can happen."
According to Secunia, the vulnerability is caused by an error in handling corrupted .wmf files � a graphics file format used to exchange graphics information between Microsoft Windows applications that can hold vector and bit-mapped images.
Secunia confirmed the vulnerability on a fully patched system running Windows XP SP2. The advisory said that Windows Server 2003 SP0 and SP1 systems have also reportedly been affected.
A Microsoft spokesman told eWEEK in an e-mail exchange on Wednesday that Microsoft "is investigating new public reports of a possible vulnerability in Windows," although he didn't give an ETA for a patch.
"Microsoft will continue to investigate the public reports to help provide additional guidance for customers," he said. "Upon completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a fix through our monthly release process or issuing a security advisory, depending on customer needs."
The spokesman went on to encourage customers to follow Microsoft's Protect Your PC guidelines of enabling a firewall, getting software updates and installing anti-virus software.
Customers who think they've been affected can also contact Product Support Services, which is at 1-866-PCSAFETY in North America or at support.microsoft.com/security for outside North America.
Microsoft also advises customers who think they've been attacked to contact their local FBI office or to post the incident on www.ifccfbi.gov. Customers outside the United States should contact the national law enforcement agency in their country, the spokesman said.
The advisory issued by Microsoft later on Wednesday said that Microsoft is aware of the code, which allows an attacker "to execute arbitrary code in the security context of the logged-on user, when such user is visiting a Web site that contains a specially crafted Windows Metafile (WMF) image."
Microsoft's advisory echoed Lindstrom's take, however, stating that attackers have "no way to force users to visit a malicious Web site."
Instead, the advisory continued, attackers have to persuade users to visit the sites, "typically by getting them to click a link that takes them to the attacker's Web site."
The advisory said that Microsoft would either be issuing a patch through its monthly release process or would provide an out-of-cycle security update, "depending on customer needs."
Microsoft's spokesman declined to state how many customers had reported that they had been victimized by the attack.
Secunia advised that users avoid opening or previewing untrusted .wmf files, as well as set security level to "High" in IE.
Lindstrom noted that the long-term answer to dealing with what he called this type of "flotsam and jetsam" of constant security alerts is to install host intrusion prevention software to designate what software is allowed to run on a system and what it's allowed to do.
As far as the short-term response to this particular vulnerability goes, Lindstrom echoed Secunia's advisory when it comes to untrusted files: "Don't click on it," he said.
Editor's Note: This story was updated to include Microsoft's statement, more on the recommended workaround and more details about the exploit from Sunbelt and F-Secure.

_________________
"All facts go to clearly prove that Shades is a thrice-cursed traitor & mentally deranged person steeped in inveterate enmity toward mankind"
Back to top
View user's profile Photo Gallery
Shadow_Bshwackr
Janitor

Offline Offline
Joined: Jan 21, 2005
Posts: 7015
Location: Central Illinois, USA
PostPosted: Wed Jan 04, 2006 11:51 am
Post subject: Re: This looks like a bad one!

Thanks for the heads up on this one Ascout! I don't know about anyone else, but I like and use WMP quite often... Wink
Back to top
View user's profile Visit poster's website Photo Gallery
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ›  Hardware
Page 1 of 1
All times are GMT - 6 Hours

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.