Author |
Message |
ElevenBravo
King
Joined: Wed Apr 16, 2003 2:18 pm Posts: 1976 Location: Sexy Town
|
 Windows PCs face ‘huge’ virus threat
http://news.ft.com/cms/s/0d644d5e-7bb3- ... e2340.html
[quote]Computer security experts were grappling with the threat of a newweakness in Microsoft’s Windows operating system that could put hundreds of millions of PCs at risk of infection by spyware or viruses.
The news marks the latest security setback for Microsoft, the world’s biggest software company, whose Windows operating system is a favourite target for hackers.
[b]“The potential [security threat] is huge,â€
_________________ Contrary to popular belief, America is not a democracy, it is a Chucktatorship.
|
Mon Jan 02, 2006 7:58 pm |
|
 |
RB
Emperor
Joined: Wed Apr 16, 2003 1:25 am Posts: 2560
|
Someone know something about symptomes?
_________________ ++
|
Tue Jan 03, 2006 6:38 am |
|
 |
Arathorn
Minor Diety
Joined: Tue Apr 01, 2003 10:23 am Posts: 3956 Location: Amsterdam
|
I believe you can be infected by opening images. If you do that, a website is opened wich can infect you.
If you use the latest Firefox you will be prompted before the file is opened.
_________________ Melchett: As private parts to the gods are we: they play with us for their sport!
|
Tue Jan 03, 2006 7:37 am |
|
 |
Satis
Felix Rex
Joined: Fri Mar 28, 2003 6:01 pm Posts: 16701 Location: On a slope
|
I thought it was a meta-tag overflow kind of vulnerability, like the mp3 one.
Ie, if Windows attempts to parse the image (ie, for display on screen) a specially crafted file will overflow the buffer into system memory. Someone that knows what they're doing could turn that into anything...they could use it to install a trojan horse, virus, spyware, whatever.
I think this is it:
http://www.microsoft.com/technet/securi ... 4-028.mspx
_________________ They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety.
|
Tue Jan 03, 2006 8:42 am |
|
 |
Satis
Felix Rex
Joined: Fri Mar 28, 2003 6:01 pm Posts: 16701 Location: On a slope
|
meh, that's not it, my bad. It's a vulnerability in wmf files. (Windows Metafile). Way back when they were built so you could embed executables in them, which allowed you to cancel print jobs (or something)...and that backwards support has been rolled into every version of Windows ever. It took someone this long to figure it out and exploit it.
_________________ They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety.
|
Wed Jan 04, 2006 8:05 am |
|
 |
Arathorn
Minor Diety
Joined: Tue Apr 01, 2003 10:23 am Posts: 3956 Location: Amsterdam
|
A patch will be out on the tenth.
_________________ Melchett: As private parts to the gods are we: they play with us for their sport!
|
Wed Jan 04, 2006 9:50 am |
|
 |
Satis
Felix Rex
Joined: Fri Mar 28, 2003 6:01 pm Posts: 16701 Location: On a slope
|
there's already an unoffical patch from a 3rd party dude. It is recommended by most of the large antivirus vendors that users apply the unofficial patch.
http://www.hexblog.com/index.html
_________________ They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety.
|
Wed Jan 04, 2006 11:18 am |
|
 |
Mole
Minor Diety
Joined: Fri Apr 11, 2003 5:09 pm Posts: 4004 Location: Walsall, West Mids, UK
|
I learned of this a week or so ago, but the description I read left me confused. I was wondering "what are the effects" of it? But this WMF problem is not a virus, so there are no symptoms. Basically, it's a gateway for the virus, not the virus it self.
Correct me, If I'm wrong.
_________________ Games to complete: GTA IV [100%] (For Multiplayer next!) Fallout 3 [50%] Rock Band [35%] http://www.cafepress.com/SmeepProducts
|
Wed Jan 04, 2006 11:19 am |
|
 |
Arathorn
Minor Diety
Joined: Tue Apr 01, 2003 10:23 am Posts: 3956 Location: Amsterdam
|
I think that's about it.
Can't be arsed about installing the unofficial patch, the official one is coming next week anyway.
_________________ Melchett: As private parts to the gods are we: they play with us for their sport!
|
Wed Jan 04, 2006 11:25 am |
|
 |
Satis
Felix Rex
Joined: Fri Mar 28, 2003 6:01 pm Posts: 16701 Location: On a slope
|
yea, that's correct. It's just a hole. Whatever actually invades the hole would have effects, but that depends entirely on what gets stuffed in. It could be used to install viruses, spyware, keyloggers, trojans, porn, games, SETI@home, or anything else the exploiter could possibly want to do.
_________________ They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety.
|
Wed Jan 04, 2006 11:26 am |
|
 |
ElevenBravo
King
Joined: Wed Apr 16, 2003 2:18 pm Posts: 1976 Location: Sexy Town
|
_________________ Contrary to popular belief, America is not a democracy, it is a Chucktatorship.
|
Wed Jan 04, 2006 1:52 pm |
|
 |
Satis
Felix Rex
Joined: Fri Mar 28, 2003 6:01 pm Posts: 16701 Location: On a slope
|
hey there 11b, you got some holes that need stuffing? 
_________________ They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety.
|
Wed Jan 04, 2006 4:26 pm |
|
 |
Satis
Felix Rex
Joined: Fri Mar 28, 2003 6:01 pm Posts: 16701 Location: On a slope
|
here's an interesting interview with the guy that released the unofficial patch.
http://blogs.securiteam.com/index.php/archives/176
_________________ They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety.
|
Fri Jan 06, 2006 4:02 pm |
|
 |
Mole
Minor Diety
Joined: Fri Apr 11, 2003 5:09 pm Posts: 4004 Location: Walsall, West Mids, UK
|
You guys got the update? I do believe it installed on my computer yesterday.
_________________ Games to complete: GTA IV [100%] (For Multiplayer next!) Fallout 3 [50%] Rock Band [35%] http://www.cafepress.com/SmeepProducts
|
Sat Jan 07, 2006 8:28 am |
|
 |
RB
Emperor
Joined: Wed Apr 16, 2003 1:25 am Posts: 2560
|
_________________ ++
|
Sun Mar 12, 2006 2:28 am |
|
|