CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 930
Comments: 25
block bottom
spacer spacer
image Advisories!: Newest WMF Exploit Patch Saves the Day image
Trojans
Interim WMF Exploit Savior

We've all been following the dramatic story of the whole wmf exploit and how it is easily spoofed into other image types. The last day of 2005 the wmf exploit exploded into other various venues such as instant messages, email, and more. Various tools have been setup to try and catch or filter out the wmf exploit, but last night it has mutated. Newest variations change the header and tail of the wmf exploit making its signature difficult to locate.

Drum roll please...

Ilfak Guilfanov who is being billed as one of the foremost experts in Windows low level technology has released a temporary/interim patch for Windows.


(check often for updates, this is version 1.4)


Technical details: "this is a DLL which gets injected to all processes loading user32.dll. It patches the Escape() function in gdi32.dll. The result of the patch is that the SETABORT escape sequence is not accepted anymore."

Once Microsoft releases an official patch, or if the above doesn't work, you can uninstall it from your Add/Remove Programs menu. It'll be listed as "Windows WMF Metafile Vulnerability HotFix".

The Internet Storm Center gives this patch its stamp of approval:


We have very carefully scrutinized this patch. It does only what is advertised, it is reversible, and, in our opinion, it is both safe and effective.

The word from Redmond isn't encouraging. We've heard nothing to indicate that we're going to see anything from Microsoft before January 9th.

The upshot is this: You cannot wait for the official MS patch, you cannot block this one at the border, and you cannot leave your systems unprotected.

So there you have it, don't trust the firewall filters, don't trust the antivirus vendors, don't wait for Microsoft. Install the patch immediately. If you are running a Windows operating system the patch doesn't support, time to shut it off and wait.



Ref: grc.com, sunbeltblog, hexblog

Note: WMF Hotfix is at version 1.4 now which supports batch installation.
Posted on Sunday, 01 January 2006 @ 11:35:27 UTC by Paul (28319 reads)
[ Trackback ]
image

"Advisories!: Newest WMF Exploit Patch Saves the Day" | Login/Create an Account | 10 comments | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Newest WMF Exploit Patch Saves the Day (Score: 1)
by Ikeb (sampade@storm.ca)  on Sunday, 01 January 2006 @ 13:28:13 UTC
(User Info | Send a Message)
Paul, would it be possible to set up a mirror at CCSP? I've tried downloading this partch a few times and just can't get through.



Re: Newest WMF Exploit Patch Saves the Day (Score: 1)
by Ikeb (sampade@storm.ca)  on Sunday, 01 January 2006 @ 13:45:16 UTC
(User Info | Send a Message)
I finally did get through ... but it still might be a good idea to mirror this one.



Re: Newest WMF Exploit Patch Saves the Day (Score: 1)
by wawadave  on Sunday, 01 January 2006 @ 14:09:30 UTC
(User Info | Send a Message | _JOURNAL) http://groups.msn.com/wawadave
i have known about this for two days. and was trying to get it tested i see sunblet did and an expert here did give me a quick once over.
i just installed this all seems well.



Re: Newest WMF Exploit Patch Saves the Day (Score: 1)
by mrrockford  on Sunday, 01 January 2006 @ 14:31:27 UTC
(User Info | Send a Message | _JOURNAL) http://de.castlecops.com
http://de.castlecops.com/temporar_wmf_exploit_patch



Re: Newest WMF Exploit Patch Saves the Day (Score: 1)
by AplusWebMaster  on Sunday, 01 January 2006 @ 14:32:23 UTC
(User Info | Send a Message) http://www.apluswebmaster.net/
Aleternate download site available:
...per: http://isc.sans.org/diary.php?storyid=999

MD5: 14d8c937d97572deb9cb07297a87e62a - wmffix_hexblog13.exe

Also, it is recommended that shimgvw.dll be unregistered:
- See http://isc.sans.org/diary.php?storyid=994
(What can I do to protect myself?)

.



Re: Newest WMF Exploit Patch Saves the Day (Score: 1)
by wawadave  on Sunday, 01 January 2006 @ 14:35:01 UTC
(User Info | Send a Message | _JOURNAL) http://groups.msn.com/wawadave
An alturnative d/l site!!!
http://isc.sans.org/diary.php?storyid=999



Re: Newest WMF Exploit Patch Saves the Day (Score: 1)
by AplusWebMaster  on Sunday, 01 January 2006 @ 23:03:54 UTC
(User Info | Send a Message) http://www.apluswebmaster.net/
An msi installer file has been created. You can get it via links starting here:

Updated version of Ilfak Guilfanov's patch / .msi file
- http://isc.sans.org/diary.php?storyid=999
Last Updated: 2006-01-01 23:13:01 UTC
...We have also created a .msi file suitable for unattended installation from version 1.3 of the patch. It can be downloaded from a link on this page*.

* http://handlers.sans.org/tliston/WindowsMetafileFix.html [handlers.sans.org]

.



Did I do this correctly? (Score: 1)
by MedTxInMich  on Wednesday, 04 January 2006 @ 16:50:55 UTC
(User Info | Send a Message)
Was it supposed to just install in my programs folder? I was kinda surprised when that happened. I figured it was supposed to go someplace more technical and that there would be instructions enclosed with the download, but, hey, if that's all the more I have to do, no complaints, here! I'm rather the computer end-user! Give me your average office software package, and I can adapt pretty quickly. Give me a computer innard issue, and I panic unbelievably quickly. It's sad, really. *blush*

Thanks for any help and thanks for covering our hides until Microsoft gets its hide in gear,
Carol


 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· PHP HomePage
· Microsoft
· Microsoft
· HotScripts
· W3 Consortium
· More about Trojans
· News by Paul


Most read story about Trojans:
Newest WMF Exploit Patch Saves the Day

block bottom
Article Rating
spacer
Average Score: 5
Votes: 6


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer