FutureQuest, Inc. FutureQuest, Inc. FutureQuest, Inc.

FutureQuest, Inc.
Go Back   FutureQuest Community > General Site Owner Support (All may read/respond) > General Computing
User Name
Password  Lost PW

 
Thread Tools Display Modes
Old 12-28-2005, 06:13 PM   Postid: 142909
kitchin
Site Owner
 
kitchin's Avatar

Forum Notability:
1115 pts: A True Crowd-pleaser!
[Post Feedback]
 
Join Date: Jan 2001
Location: Virginia
Posts: 2,883
wmf (windows media file) critical security threat, etc. etc.

Watch out for WMF's on bad web sites. On Firefox, you at least have to click something for it to happen. On IE it infects automatically.
http://blogs.washingtonpost.com/securityfix/
http://secunia.com/advisories/18255/
kitchin is offline  
Old 12-30-2005, 10:16 AM   Postid: 142983
softprose
Registered User

Forum Notability:
0 pts:
[Post Feedback]
 
Join Date: Jan 2005
Location: North Jersey
Posts: 5
Re: WMF Vulnerability leads to compromised computers

*** ALL USES OF WINDOWS, PLEASE READ BELOW. ***
There is a very major security problem with Windows, all variants back to Windows 98.
All systems are at risk. Many are already infected. There are few options for an effective defense.

See our web page on this issue:
http://www.softprose.com/information...irus/wmf.shtml

Greetings,
This is an urgent advisory of a real-life threat to all Windows computers.
The Windows Metafile Format (*.WMF) image format, developed by Microsoft, has been shown to have a critical flaw that allows ALL VARIANTS of Windows computers after and including Windows 98 to be taken over by criminals SIMPLY BY VIEWING images on a web page or images contained in Email- Including preview.
The WMF vulnerability is not a virus in itself- it is, instead, known as an "Exploit", or a pathway that a Virus (or spyware, or any number of malware variants) can use to be inserted into a computer. Unfortunately, the bad guys found this hole before the "white hats" got involved, so this problem is already showing up on user's computers.

This is a SEVERE problem, that is already being exploited for commercial and criminal gain. The spyware program "Winhound" is the most common, and prominent, example using this security hole, but many other programs have been found that are taking advantage of it. Many of these programs use stealth techniques to hide on your PC, and record keystrokes, logins, credit card, and all sorts of other information of interest to criminal enterprises.
Other commercial programs using this security hole include Winfixer and AVGold. There will probably be many more…

Although Winhound is a very busy, obvious, and obnoxious infestation, it is not the worst- the worst infestation is that which you do not know about. There is no defense currently available for this problem, and fully-patched systems are being infected. No current antivirus software is defending against this threat. As there is a direct financial incentive, the number and variety of softwares using this security flaw are expanding exponentially in number.

This has the capacity of being the single greatest security threat ever discovered. The number of machines that are vulnerable include every single Windows computer in the world. There is currently no organized defense. The number and variety of attacks are quite large, and they are not being addressed at this time by security products.

The pictures DO NOT NECESSARILY have a *.WMF extension! WMF files will execute just fine if they are called *.gif, *.jpg, *.bmp, and other names! ANY GRAPHIC FILE can conceal the infection.

IF YOU ARE INFECTED, the standard solutions may apply:
SpyBot Search & Destroy, in the current version 1.4, has been somewhat effective against WinHound.
See: www.safer-networking.org/
AdAware and Microsoft AntiSpyware are both possible resources for an infection, although they have not been particularly strong against the versions of WinHound that we have encountered.
For AdAware, see: http://www.lavasoftusa.com/
For Microsoft AntiSpyware, see:
http://www.microsoft.com/athome/secu...e/default.mspx

Insuring that your AntiVirus is current and up to date is quite critical, along with running periodic Scans. These scans are optional. Users may wish to run manual scans of their system, after updating their antivirus. Note that currently NO anti-virus program is offering a full defense. The partial defenses that they can offer are being built on an hourly basis.

Please note: The worst infestations are those you do not know about. It is entirely possible for your machine to become a "zombie" client of some Eastern European or Asian organized crime gang without you knowing anything about it. The days of clumsy amateur software are OVER in this business- This is professional, international, and closely focused on an increasingly valuable bottom line. There is big money in Cybercrime; please be careful.
A "key logger" program on your computer can record all credit card numbers, all passwords, all login data. This is an increasingly common security threat for individuals or organizations of any size.

THE ONLY CURRENT "FIX" is to disable the primary vector for Windows Metafile Format (WMF) support.
The below "FIX" will only work on:
Windows XP Service Pack 1; Windows XP Service Pack 2;
Windows Server 2003; and Windows Server 2003 Service Pack 1
It does not appear to be currently possible to disable all variants of WMF support. However, the primary software tool used by Windows XP and 2003 Server for working with WMF files are the core software libraries for the "Windows Picture and Fax Viewer", which can be disabled. This should have the effect of making it impossible for your computer to view WMF files. However, this change may have UNEXPECTED problems with other software. However, it is the only practical defense at this point in time, and is STRONGLY recommended.
The below fix involves serious changes. Be aware that this removes the primary means of support for WMF files, which may cause some graphics programs to either not run or demonstrate eccentric behavior. But we really suggest you do this, as described below.
Note that Maintenance clients of SoftProse Technology, Inc. have had this code added to their login routine in two batch files, wmf_off.bat (and wmf_on.bat). There may be confirmation dialogs for these changes. Copies of these batch files are available from our WMF Vulnerability page at http://www.softprose.com/information...irus/wmf.shtml.

Below was originally suggested by MICROSOFT, who now seems to be formulating a different response.
(SEE: http://www.kb.cert.org/vuls/id/181038)

Un-register the Windows Picture and Fax Viewer (Shimgvw.dll)
1. Click Start, click Run, type "regsvr32 -u %windir%\system32\shimgvw.dll"
(without the quotation marks), and then click OK.
2. A dialog box appears to confirm that the un-registration process has succeeded.
Click OK to close the dialog box.

Impact of Workaround: The Windows Picture and Fax Viewer will no longer be started
when users click on a link to an image type that is associated with the Windows Picture and Fax Viewer.

To undo this change, re-register Shimgvw.dll by following the above steps.
Replace the text in Step 1 with “regsvr32 %windir%\system32\shimgvw.dll” (without the quotation marks).

What if I have Windows 2000, or Windows 9X or ME?
What if you cannot disable WMF support?
What can you do to defend yourself?
Below are Four Suggestions:

1) Don't use Internet Explorer for surfing the Internet. Internet Explorer has been broken for years; there is and has been no security from your computer being taken over. Instead of IE, download and install the latest version of FireFox, currently at Version 1.5:
http://www.mozilla.com/firefox/
Set FireFox to be your default browser. You have to either answer a confirmation dialog or download the image to be infected with FireFox. (Internet Explorer users have NO defense.)
Note that FireFox will not fully protect you- BUT users will have to click a confirmation dialog or accept a download before they can become infected! DON'T ACCEPT ANY CONFIRMATION DIALOG OR DOWNLOAD ANYTHING unless you know EXACTLY what you are accepting into your computer!

2) Remove all "toolbars" from your computer- Google, Yahoo, etc. Also remove all third-party "Search" tools.
This advice may be a little draconian, but we stand by it. (We never liked toolbars, anyway.) This is a real issue, as the Google toolbar in particular will INDEX ALL WMF files on your computer automatically- and this process will EXECUTE the code contained in these WMF files! So if you have Google Toolbar installed, and your Email downloads one of these pictures, it may execute EVEN IF YOU DON'T LOOK AT IT, thanks to the Google indexing process. We are not sure what all the other toolbars do that may be similar- but do you really need them? Don't take the chance.

3) Email places us all at risk. This is a major challenge for all Email users. The extent and nature of the infection process is still not fully understood, and any advice here will probably need the assistance of an update to the programs involved.

FOR ALL EMAIL USERS:
Be especially aggressive in deleting Emails from strangers.
DON'T OPEN ANYTHING if you don't know where it is from. JUST KILL IT. Suppress your natural curiosity.

For Outlook Users:
View Menu>Preview Pane - Turn it OFF.
Consider switching to the free version of Eudora, which has better controls over graphics. http://www.eudora.com/

For Eudora Users:
Go to Tools>Options>Display.
Remove the checks on:
Automatically download HTML graphics
Display graphics in messages

4) Set your machine to receive Windows Updates automatically.
In a world where attacks can occur in hours, the Microsoft automatic update function "Windows Update" has become increasingly important to protecting your computer. Most computers managed by SoftProse Technology, Inc. are set to automatically download and install updates from Microsoft. If you have not configured your machine this way yet, please consider this as an important defense in an increasingly dangerous Internet-enabled world.
Note that the new Microsoft Update offers more features (Office software updates are included), but requires that Microsoft "certify" that your installation of Windows is "genuine" and not a bootleg copy. For most users, this should be a simple test to pass successfully. If for whatever reason your machine fails this test, please consider re-installing or upgrading to a legal copy of Windows. Be aware that Microsoft makes Microsoft Update an optional feature today, but soon may make it a requirement.
See: http://update.microsoft.com/microsoftupdate
(Requires Internet Explorer)

(NOTE: Like Linux, you can also create a limited login on your PC that will deny the ability to install software or to write files to system folders. (In Windows XP, this is actually called a "Limited Account".) Using the PC with a restriction such as this should stop most "malware" from installing itself and taking over your computer. A Windows computer can have more than one login. A separate Administrator login would have full rights but would only be used for PC maintenance. Most users would dislike this system intensely, but we are slowly getting used to this as a standard method for using, and defending, Windows computers. This is not a total defense- But may help in some scenarios, such as with this problem.)

For more info on this WMF vulnerability:

http://www.kb.cert.org/vuls/id/181038
http://www.microsoft.com/technet/sec...ry/912840.mspx
http://www.f-secure.com/weblog/archi....html#00000753
http://searchsecurity.techtarget.com...154914,00.html
http://blogs.zdnet.com/Spyware/index.php?p=734
__________________
[SIZE=3][FONT=Arial][b]SoftProse Technology, Inc.[/b][/FONT] [/SIZE][SIZE=2][FONT=Arial]
[URL=http://www.softprose.com]http://www.softprose.com[/URL]
[I]"We Speak Software"[/I]
268 Washington Ave, Clifton NJ 07011
(973) 760-9453 | (888) 478-6490 [/FONT] [/SIZE]
softprose is offline  
Old 12-31-2005, 10:46 PM   Postid: 143028
softprose
Registered User

Forum Notability:
0 pts:
[Post Feedback]
 
Join Date: Jan 2005
Location: North Jersey
Posts: 5
Re: UPDATE: WMF Vulnerability leads to compromised computers

12/31/05 Update:
Reports are that Microsoft is frantically trying to develop a patch for this problem. However, some people could not wait, including the computer scientist Ilfak Guilfanov (hexblog.com) who would not allow this problem to exist on HIS machine any longer. So he fixed it. This patch installs a special DLL that removes the software hook that the WMF Vulnerability uses. It may cause problems with some software. It has only been tested on Windows XP, 2003, and Windows 2000 Pro that we are aware of. CAUTION: Microsoft's fix and this fix may not be compatible. Be prepared to REMOVE this patch before installing the Microsoft fix, when it becomes available. (This may be an issue with individuals who's machines update automatically, which is the recommended configuration for Windows Update.)
Note that unlike the solution below for Windows XP / 2003, this patch does NOT disable the ability to view or use WMF files.
To download the patch, go to:
http://www.hexblog.com/2005/12/wmf_vuln.html
There is also an MSI version of the patch, for system administrators.
Download from: http://users.utu.fi/vpjsuu/wmfhotfix/
This patch is now being updated very frequently, and will continue to evolve as it is tested and rewritten to support more systems and configurations. Keep in touch with the page where you downloaded your copy of the patch from to be aware of any problems found.
To remove the patch once it has been installed, go to:
Control Panel>Add Remove Software>"Windows WMF Metafile Vulnerability HotFix" (Eventually Microsoft will have an "Official" fix.)
There is a known incompatibility with "Yahoo antispyware" that detects this patch as spyware, but does not remove it automatically.
NOTE: SoftProse Technology Inc. is not installing this patch on client computers, preferring instead to wait for the Windows Update service to install a solution automatically on our few clients who still have machines running Windows 2000 Professional. For our Windows XP users, we suggest (and have arranged to install) the original fix, being the removal of WMF support from Windows XP / 2003 as outlined below.
However, if you surf the web with a Windows 2000 computer we STRONGLY recommend that you consider installing this patch immediately, with all the caveats mentioned above and reading completely the text on the website from where you download the patch - READ THE DIRECTIONS!)
__________________
[SIZE=3][FONT=Arial][b]SoftProse Technology, Inc.[/b][/FONT] [/SIZE][SIZE=2][FONT=Arial]
[URL=http://www.softprose.com]http://www.softprose.com[/URL]
[I]"We Speak Software"[/I]
268 Washington Ave, Clifton NJ 07011
(973) 760-9453 | (888) 478-6490 [/FONT] [/SIZE]
softprose is offline  
Old 12-31-2005, 11:37 PM   Postid: 143029
Andilinks
Site Owner
 
Andilinks's Avatar

Forum Notability:
338 pts: An Honor To Be Around
[Post Feedback]
 
Join Date: Apr 2002
Location: San Antonio, Texas
Posts: 7,184
Re: wmf (windows media file) critical security threat, etc. etc.

Matt Cutts gives a pretty simple fix.

Quote:
...but if you want to be safe until a patch is available, click Start->Run and then type “regsvr32 /u shimgvw.dll” to disable the vulnerable DLL.

Update: Note that if you disable this DLL, you’ll lose the ability to preview images with a double click. What to do about that? I’d install the excellent Paint.net program from Washington State University. Then follow this support page from MSFT on how to change your file associations to use Paint.net to open your images. You’ll have to do it once for each filetype (.jpg, .gif, .png) that you want to view.
http://www.mattcutts.com/blog/wmf-vulnerability/

I changed my file associations to mspaint.exe to avoid loading a 50 MB app each time I double click a graphic.
__________________
@AndiFashion Twitter #fashion #shopping #clothing . . . @andilinks Twitter #economy #politics #news
Andilinks is offline  
Old 12-31-2005, 11:41 PM   Postid: 143030
Wassercrats
Site Owner
 
Wassercrats's Avatar

Forum Notability:
291 pts: An Honor To Be Around
[Post Feedback]
 
Join Date: Nov 2001
Posts: 6,950
Re: wmf (windows media file) critical security threat, etc. etc.

Quote:
Originally Posted by Andilinks
Matt Cutts gives a pretty simple fix.
...
http://www.mattcutts.com/blog/wmf-vulnerability/
That's what softprose said deep in his first post:
Quote:
Un-register the Windows Picture and Fax Viewer (Shimgvw.dll)
1. Click Start, click Run, type "regsvr32 -u %windir%\system32\shimgvw.dll"
(without the quotation marks), and then click OK.
2. A dialog box appears to confirm that the un-registration process has succeeded.
Click OK to close the dialog box.
Basically. I don't know the difference.
Wassercrats is offline  
Old 12-31-2005, 11:47 PM   Postid: 143032
Andilinks
Site Owner
 
Andilinks's Avatar

Forum Notability:
338 pts: An Honor To Be Around
[Post Feedback]
 
Join Date: Apr 2002
Location: San Antonio, Texas
Posts: 7,184
Re: wmf (windows media file) critical security threat, etc. etc.

Oh. For those who like me found the first post too deep, I repeated it...

I have trouble with huge blocks of text from people I don't know, Matt Cutts has been very reliable and less verbose.

I've just been (finally) reading Malcolm Gladwell's second book Blink. Somehow these simpler solutions just seem better.
__________________
@AndiFashion Twitter #fashion #shopping #clothing . . . @andilinks Twitter #economy #politics #news
Andilinks is offline  
Old 01-01-2006, 10:30 AM   Postid: 143053
softprose
Registered User

Forum Notability:
0 pts:
[Post Feedback]
 
Join Date: Jan 2005
Location: North Jersey
Posts: 5
Re: wmf (windows media file) critical security threat, etc. etc.

1/1/2005 Update:
This post, and others, are repeated at:
http://www.softprose.com/information...irus/wmf.shtml
NOTE: These posts are long because the issue is IMPORTANT.
This is a complex issue in a complex world, which is not getting any simpler.
Protect yourself. Read, Study, Understand, and Defend Yourself.
The infections are truly awful to remove, even IF you have the ability to detect them. Hundreds of malware organizations are using this attack vector, with more added daily. They are throwing the kitchen sink at computers- Not one downloader, but three, four, five of them. Rootkits. TCP/IP stack takeovers. Permanent modifications of core Windows DLL's. You don't want to get one of these infections!
***
CAUTION: MS Paint (Microsoft's simple little paint program) is DANGEROUS. MS Paint bypasses the fix installed for Windows XP by the popular RegSrv32 patch, according to FSecure. You will still be vulnerable to the WMF Vulnerability if you open files in MS Paint- Avoid using this program until this problem has a fix from Microsoft itself.
The WMF Vulnerability problem continues to evolve, and grow more complex. Additional WMF Vulnerabilities appear to have been discovered by the "Bad Guys". There is a "Happy New Year" email going around using one of the newer techniques, and a "*.jpg" file that is actually a re-named WMF file; it will infect your computer if read or seen in a "preview" window.
Please note that Preview functions in Email are very dangerous and should be turned OFF, unless you have Windows XP and have disabled WMF support as described in the original post above. (Or have Windows 2000 Pro and have installed the Third Party Patch, also described in the 12/31/05 Update above.) And the Google Toolbar (among other third-party Search tools) will index this file if downloaded and will then execute the attached software and infect your computer WITHOUT needing Preview, if you have not taken any of the defensive measures discussed here.
An excellent site for keeping up to date with this problem is:
http://www.f-secure.com/weblog/
FSecure has been on the "bleeding edge" of this problem, and they have a chatty but educational running discussion of new issues, updates, fixes, and problems with the WMF Vulnerability.
New Repair Tools:
For a discussion of repair after infection, see:
http://forums.spywareinfo.com/index.php?showtopic=61446
The "cure" outlined there is time consuming and quite technical.
Some new tools include:
Fsecure has a free RootKit detector, BlackLight, for a limited time:
http://www.f-secure.com/blacklight/
Sysinternals has a free RootKit Detector at:
http://www.sysinternals.com/utilitie...trevealer.html
Ewido is specifically designed to detect and attack Trojans, such as Keyloggers. This is a very popular attack mode for the WMF Vulnerability. They offer a 14 day free trial:
http://www.ewido.net/en/
SpySweeper PC Magazine top-rated this product. It costs $25 per year, and has some installation issues, especially with the free 30 day trial. Still, it detects RootKits and many other sophisticated threats:
http://www.webroot.com/consumer/prod...per/index.html
Note: This problem is NOT OVER once you have applied one of the suggested fixes in these posts. (Or compiled at http://www.softprose.com/information...irus/wmf.shtml) It continues to evolve. We are all under attack by serious programmers looking for big money rewards.
Please Be Careful.
__________________
[SIZE=3][FONT=Arial][b]SoftProse Technology, Inc.[/b][/FONT] [/SIZE][SIZE=2][FONT=Arial]
[URL=http://www.softprose.com]http://www.softprose.com[/URL]
[I]"We Speak Software"[/I]
268 Washington Ave, Clifton NJ 07011
(973) 760-9453 | (888) 478-6490 [/FONT] [/SIZE]

Last edited by softprose : 01-01-2006 at 11:10 AM.
softprose is offline  
Old 01-01-2006, 01:16 PM   Postid: 143062
Andilinks
Site Owner
 
Andilinks's Avatar

Forum Notability:
338 pts: An Honor To Be Around
[Post Feedback]
 
Join Date: Apr 2002
Location: San Antonio, Texas
Posts: 7,184
Re: wmf (windows media file) critical security threat, etc. etc.

Thank you for your concern SoftProse.

This FQ forum is an important place but it doesn't get the traffic that you seem to think this urgent story deserves. You should promote it at these other more popular locations since they all seem to be ignoring it at this hour (though I have seen a few mentions in recent days):

http://del.icio.us/tag/security
http://digg.com/security
http://slashdot.org/
http://tech.memeorandum.com/
http://www.schneier.com/blog/
http://www.ethicalhacker.net/

Perhaps there are others here more knowlegeable about security who can comment.

Andi
__________________
@AndiFashion Twitter #fashion #shopping #clothing . . . @andilinks Twitter #economy #politics #news
Andilinks is offline  
Old 01-03-2006, 10:23 PM   Postid: 143197
softprose
Registered User

Forum Notability:
0 pts:
[Post Feedback]
 
Join Date: Jan 2005
Location: North Jersey
Posts: 5
Re: wmf (windows media file) critical security threat, etc. etc.

1/3/2006 Update:
(See all info with links at: http://www.softprose.com/information...irus/wmf.shtml)
Microsoft has a fix- but will not release it until January 10th, as part of the regularly scheduled Windows Update program. (Thank you, Microsoft...) We continue to hear about infected computers from vendors, clients, friends, and family. Entire networks are being shut down due to serious infestations.
The Hexblog.net website is down, probably overwhelmed as it had been offering the preferred fix for the WMF Vulnerability.
The website was at: http://www.hexblog.com/2005/12/wmf_vuln.html
An alternative site for this patch is (immediate download) from:
http://handlers.sans.org/tliston/wmffix_hexblog11.exe
Read the 12/31/05 Update above for cautions about this patch; you may want to uninstall it before Microsoft's January 10th Windows Update to avoid possible conflicts.
There are only two possible defences for this problem at this point in time- The RegSrv32 Patch for Windows XP / 2003 (see below for instructions) and the Third-Party patch by the computer scientist Ilfak Guilfanov (hexblog.com) - And his site is currently down; the patch can be downloaded from the alternative site listed in this message.
__________________
[SIZE=3][FONT=Arial][b]SoftProse Technology, Inc.[/b][/FONT] [/SIZE][SIZE=2][FONT=Arial]
[URL=http://www.softprose.com]http://www.softprose.com[/URL]
[I]"We Speak Software"[/I]
268 Washington Ave, Clifton NJ 07011
(973) 760-9453 | (888) 478-6490 [/FONT] [/SIZE]
softprose is offline  
Old 01-04-2006, 12:44 PM   Postid: 143236
Andilinks
Site Owner
 
Andilinks's Avatar

Forum Notability:
338 pts: An Honor To Be Around
[Post Feedback]
 
Join Date: Apr 2002
Location: San Antonio, Texas
Posts: 7,184
Re: wmf (windows media file) critical security threat, etc. etc.

This thread is getting an astonishing number of views. Google doesn't show any backlinks, it must be high in the SERPS somewhere. In any case it's getting interest way beyond the usual forum traffic.

There is this:
http://news.ft.com/cms/s/0d644d5e-7b...0779e2340.html

and this:

It's not a bug, it's a feature
__________________
@AndiFashion Twitter #fashion #shopping #clothing . . . @andilinks Twitter #economy #politics #news
Andilinks is offline  


Currently Active Users Viewing This Thread: 1 (0 members and 1 visitors)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:39 PM.


Running on vBulletin®
Copyright © 2000 - 2010, Jelsoft Enterprises Ltd.
Hosted & Administrated by FutureQuest, Inc.
Images & content copyright © 1998-2010 FutureQuest, Inc.
FutureQuest, Inc.