Forum Home
Press F1
 
Thread ID: 64842 2005-12-30 08:33:00 very bad windows exploit robsonde (120) Press F1
Post ID Timestamp Content User
416615 2005-12-30 08:33:00 grc.com

have a read.....

a new exploit that has no patch yet...

the above page give a tempory fix, i dont know if it works or if its safe but if you want to you can turn off the part of windows that has the bug.

expect a virus or worm using this exploit with in the week.
robsonde (120)
416616 2005-12-30 08:47:00 Read what Microsoft have to say here (www.microsoft.com).

Oxie (Lyn)
Oxie (1318)
416617 2005-12-30 10:04:00 "Symantec said the exploit is designed to download and run a program from the Web that downloads several malicious files, including tools that attackers could use to control vulnerable computers via Internet relay chat (IRC) channels."

Ho hum. Use - Firewall, AV, Anti-spyware, non-MS browser, etc etc. I've said it before, relying on MS to "fix" the O/S with their patches is like trying to make a bucket by putting sticking plasters on a sieve.
pctek (84)
416618 2006-01-01 01:23:00 Ho hum. Use - Firewall, AV, Anti-spyware, non-MS browser, etc etc.


this is NOT an IE thing, it is a windows thing.

any image file that gets on to your system from any source on any version of windows can act as a virus.

this is not just images files either... any file that windows can give a thumbnail of is affected such as movie files.

i do agree that use of Firewall, AV, Anti-spyware, non-MS browser is a good thing but i this case it may not help you much.
robsonde (120)
416619 2006-01-01 22:29:00 grc.com

have a read.....

a new exploit that has no patch yet...

the above page give a tempory fix, i dont know if it works or if its safe but if you want to you can turn off the part of windows that has the bug.

expect a virus or worm using this exploit with in the week.



it.slashdot.org

and now the worm is out.
robsonde (120)
416620 2006-01-04 05:18:00 there is an unoffical fix at www.grc.com

sevral security companys recomend this fix, MS hope/expect to have a patch out on the 10th.

An important Note about Antivirus signatures: As useful as anti-virus protection is as a first line of defense, new WMF exploits are succeeding at bypassing them. So A-V cannot be relied upon. The only safe measure is to install Ilfak's vulnerability suppression solution until Microsoft has updated the GDI32.DLL file and permanently resolved this problem.
robsonde (120)
416621 2006-01-04 05:38:00 Yup, info on the patch due to be released on the 10th here (www.microsoft.com) Speedy Gonzales (78)
416622 2006-01-04 05:54:00 this is NOT an IE thing, it is a windows thing.

any image file that gets on to your system from any source on any version of windows can act as a virus.

this is not just images files either... any file that windows can give a thumbnail of is affected such as movie files.

i do agree that use of Firewall, AV, Anti-spyware, non-MS browser is a good thing but i this case it may not help you much.
Well I have ZA, NOD32, Counterspy and RegDefend all resident.
I don''t have thumbnails among other things enabled in my modified WIndows install.
And I keep away from dodgy websites.
Seems to work - haven't had an infection yet. Except once which was selfinflicted and fairly deliberately installed.
In which case theres always Ghost.
:-)
pctek (84)
416623 2006-01-04 06:00:00 Well I have ZA, NOD32, Counterspy and RegDefend all resident.
I don''t have thumbnails among other things enabled in my modified WIndows install.
And I keep away from dodgy websites.
Seems to work - haven't had an infection yet. Except once which was selfinflicted and fairly deliberately installed.
In which case theres always Ghost.
:-)


fair call.....

as long as you know the risk and are happy with it.
robsonde (120)
416624 2006-01-04 06:18:00 Trojan remover the latest version now has the vuln in its database .

And it can now, also scan a system for vulnerable WMF files .
Speedy Gonzales (78)
1 2 3