republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Windows MetaFiles still vulnerable
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Outpost not blocking traffic on Windows shutdown »
« JaimeSmile Trojan  
AuthorAll Replies


justsomebodynew

@direcpc.com


from:
antdude See Profile

reply to redxii
Re: Windows MetaFiles still vulnerable

Some people just do not get it.

This is not a bug in windows. This WMF feature being exploited is included in all versions of Windows. It is a design decision by Microsoft that allows WMF files to execute arbitrary code.

See F-Secures latest BLOG entry at
»www.f-secure.com/weblog/

Sure right now some of the WMF exploit code only targets certain versions of Windows but the underlying flaw still exists and Code can be written to target any version of Windows the attackers choose. Right now it appears as if the older versions like Windows 98 are not being targeted by the payloads included in the WMF exploits in the wild but it would be trival for them to design an attack that would target the same flaw in older Windows versions.

So until Microsoft rewrites the code in Windows and chages the way Windows is designed to handle WMF files all computers running Windows are at risk.

Even computers using the Ilfak Guilfanov patch may still be at risk if their are more exploitable functions in Windows Metafile handling other than the SetAbort escape sequence that has been fixed. It is unknown at this time what other exploitable functions exist deep in the Windows designed handling of Windows Meta Files. Hopefully no other flaws exist but without access to the Windows source code it could not be confirmed.

So sure use the patch as it is the best option right now but do not feel just because all current exploits appear to be solved that their are not others out there that can be dangerous. So until Microsoft comes clean and fixes the problems with Windows Meta files handling I would consider any access to them a risk.

inTulsa
Premium
join:2002-02-24

said by justsomebodynew :

Some people just do not get it.

This is not a bug in windows. This WMF feature being exploited is included in all versions of Windows. It is a design decision by Microsoft that allows WMF files to execute arbitrary code.
Nope. The SETABORTPROC was designed and intended for 16-Bit Windows. It's a deprecated piece of garbage that isn't supposed to be used any longer. But now we know it's still there, even Win 2003, in all of its former glory.

said by »msdn.microsoft.com/library/defau···0d6b.asp :
The following printer escapes are obsolete. They are provided only for compatibility with 16-bit versions of Windows.
That's the section where you'll find the SETABORTPROC vector.

If the "design decision" by Microsoft was to keep 16-bit security issues compatible in all its current and future versions, then we are indeed doomed. I prefer to think it might be a "mistaken oversight" instead of a "design decision".
Thread is
Forums » Up and Running » Security » SecurityOutpost not blocking traffic on Windows shutdown »
« JaimeSmile Trojan  


Thursday, 08-Jan 00:33:00 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [160] New Comcast Throttling System 100% Online
· [111] After 10 Years Of Service, Charter Declares Home 'Unserviceable'
· [105] iTunes Dumps The DRM
· [71] AT&T, Verizon Stocks Tumble
· [54] Feds Start Wait List For DTV Converter Coupons
· [52] Cable To Grab 75% Of New Subs In 2009
· [46] DOCSIS 3.0 Gets Faster
· [39] Verizon Again Tweaks DSL Bundles
· [38] Netflix Via LG HDTVs
· [36] New Zealand's 'One Strike' Piracy Law
Most people now reading
· Customers punished and sent to ERX06 ! [TekSavvy]
· Can't order UVerse and then cancel TV later [AT&T U-verse]
· How to download windows 7 beta [Microsoft help]
· aluminium wiring? [Home Repair & Improvement]
· anyone else getting high pings and slow speeds now? [TekSavvy]
· MLPPP: Fail - ERX06 [TekSavvy]
· Powering AC worklights off of DC batteries [Home Repair & Improvement]
· [Speed] Speed Issues and High Latency in Downtown Chicago [Comcast HSI]
· Bay Area MASSIVE packet loss (North Bay) [Comcast HSI]
· Bandwidth Limits - All discussion here [Comcast HSI]