CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer

WMF exploit in horsey-ducky

 
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Hexblog [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
windyday

Trooper
Trooper


Joined: Jan 02, 2006
Posts: 32
Location: USA

PostPosted: Fri Jan 06, 2006 9:58 pm    Post subject: WMF exploit in horsey-ducky
Reply with quote

Hello Very Happy ,

I'm trying to understand the WMF exploit in simple terms. Is it fair to say that the WMF exploit is like an open door into a vulnerable computer. Someone could then control functions of your computer through this doorway? When the Microsoft patch is put in, it closes this doorway? Do I have the horsey ducky down? Question

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Fri Jan 06, 2006 10:52 pm    Post subject:
Reply with quote

Actually you can take a look here:

CastleCops Link/a6445-WMF_Exploit_FAQ.html

Look half way down for some pictures.

The WMF exploit takes advantage of a vulnerability in the graphics rendering engine. This engine is the one that provided the open door thru which the WMF exploit got in.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16505

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Fri Jan 06, 2006 11:03 pm    Post subject:
Reply with quote

The exploit is like the person coming into your house. Of course you're vulnerable if the door isn't locked; someone with nefarious intentions could waltze right in. Most (all?) vulnerabilities and the exploits that take advantage could be thought of in these terms but what makes this different is just how entry is acheived and what results.

Usually a knock on the door is required and the malware has to be invited in.(the user has to open a malware-laden file) to gain entry. Many have to leave a means to defeat the door lock or unlock the back door or a window for instance. A vulnerability to be sure but it takes a couple of steps and usual "safe practices" can guard against them.

In this case, the WMF exploit doesn't need to be invited in (the exploit activates automatically without a file being knowingly opened)! Plus the exploit doesn't have to leave a "call home" hook. It could come in with all the malware required to accomplish the objective in that bulging briefcase! That's why such an exploit is termed to be "zero day"; it all happens immediately, in a flash! Boom, you're a statistic!

And because such an exploit bypasses the due diligence of responsible computer users (i.e. be suspicious of unknown files and don't open them before verifying they are legit) even savvy users can be caught.

The known exploit payload is bad enough -- variants of SpyAxe; spyware which fools the computer owner into buying SpyAxe to get rid of supposed malware (for a price Shocked ). If purchased, to add insult to injury, the package rids the computer of other spyware but leaves hooks to benefit Spyware purveyers.

However this vulnerability could allow *any* known malware to be packaged within the wmf file as the exploit payload! Thus trojans, keyloggers, viruses, etc. could be installed just by browsing to a site. As soon as the site is accessed the wmf file is executed by the browser and the exploit is triggered. No file is opened. No alarms go off (AVs are having trouble keeping up with the variants). The computer is infected.


_________________
imageCastleCopsWiki
Back to top
View users profile Send private message
windyday

Trooper
Trooper


Joined: Jan 02, 2006
Posts: 32
Location: USA

PostPosted: Sat Jan 07, 2006 8:05 am    Post subject:
Reply with quote

Thank you Paul and Ikeb for your information.

Ikeb, what a great explanation! If a computer was attacked sucessfully by the WMF exploit, wouldn't the new Microsoft patch close the "door", so there is no longer a vulnerability for more malware packaged within the WMF to get into the system? (obviously you would have to deal with all the damage "inside the house when the door was left open". Is this the way it works?

Back to top
View users profile Send private message
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16505

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Sat Jan 07, 2006 9:49 am    Post subject:
Reply with quote

As I understand it, the MS fix (or Ilfak's interum fix for that matter) prevents that bulging briefcase, stuffed full with the malware payload, from being opened. In effect it remains sealed.


_________________
imageCastleCopsWiki
Back to top
View users profile Send private message
IP: 207.112.*.*

Guest






PostPosted: Thu Dec 28, 2006 12:21 pm    Post subject:
Reply with quote

Paul wrote:
Actually you can take a look here:

CastleCops Link/a6445-WMF_Exploit_FAQ.html

Look half way down for some pictures.

The WMF exploit takes advantage of a vulnerability in the graphics rendering engine. This engine is the one that provided the open door thru which the WMF exploit got in.

Back to top
Display posts from previous:   
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Hexblog All times are GMT
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer