8082 - If you use a windows system, please take care
- Jan. 2nd, 2006 at 7:57 PM
![]()
http://www.hexblog.com/2005/12/wmf_vuln.h
possibly the worst Windows hole ever, affects all versions, and spreading fast; install this now, as even viewing an image can infect you. - via
waxy_org
Not a hoax.
Tags:

Profile
scottobear- Raj KAJ
- The Scotto Grotto
Page Summary
i : (no subject) [+1]
scottobear : (no subject) [+0]
photocentric : (no subject) [+3]
weezeroni : (no subject) [+9]
eryx_uk : (no subject) [+1]
flying_blind : (no subject) [+1]
anony_moos : (no subject) [+1]
oneeyedcat : (no subject) [+1]
phillykat : (no subject) [+1]
peradouro : thanks anyways, no go [+1]
Links
- Tip Jar
- lj entries as a podcast
- Tumblr
- Yelp!
- flickr images
- scottobear - PMOG
- librarything
- steam profile
- Guestmap - Add Yourself!
- Translate this page
- Tags in use
- NewtCam! - See Newton and Pye!
- PyeCam! - See Pyewacket and Newt!
- Nearby Journals
- Amazon Wishlist
- Recent Visits
- Clustermap
- tiny city
- tiny city industry
- tiny city transport
Tags
- 2nd life
- 43 things
- aardvark
- acim
- adam
- airships
- alan
- alex
- aliens
- amanda
- amputee
- amy
- annapolis
- apartment
- april
- arts & crafts
- atari
- atw
- babies
- back
- baltimore
- batgirl
- batman
- bct
- bears
- ben franklin
- bengies
- better living through math
- bhk
- bill
- birds
- birth
- boobies
- books
- boston
- bowie
- boycott
- brent ashland
- brian
- bro
- bs
- bubbles
- bugah
- bugs
- burp
- cabaret
- calvert county
- candice
- cannibals
- cathi
- cathy
- cats
- cej
- chae
- charley
- chat
- chesapeake bay
- chesapeake beach
- chris
- chrs
- circus
- club
- colors
- comcast
- comments
- compleat strategist
- compusa
- condo
- copyright infringement
- crabs
- crackhead neighbor
- crime
- crush
- cyn
- d
- dad
- danny
- date night
- dave
- david
- dc
- deale
- death
- deerfield beach
- delaware
- denise
- dinner
- dinosaurs
- disney
- doctor
- dolphin assassins
- drama
- dream
- dream job
- ducks
- eastern shore
- easton
- education
- element
- elephants
- em
- eric
- eryx
- europe
- fabian
- fake
- family
- fan mail
- father
- favorite poem
- fight
- films
- finn
- fire
- fire drill
- first post
- flashback
- florida
- fmm
- folks
- food
- foot
- fort lauderdale
- frances
- francesco
- frankie the mooch
- freeflow
- freemasons
- french
- fritz
- frogs
- games
- gaming
- gamma
- garden
- geocaching
- germany
- gg
- ghost story
- ghosts
- giant rubber monsters
- giraffes
- gobble gobble
- gold
- good eats
- goodies
- gorilla
- graffiti
- graypumpkin
- green lantern
- greenbelt
- grumpy old broads
- gypsy
- haiku
- haiti
- havagan
- health
- heather
- hippies
- hippo
- hl2
- holiday
- holidays
- home
- honeymoon
- horse
- house
- hulk
- hunter
- hurricane
- icehouse
- iguana
- imt
- insurance
- iron man
- isabel
- isidore
- ivan
- james dawsey
- janet
- jc
- jeanne
- jenjen
- jesus
- jesusman
- jim
- jimmy
- jobs
- joey
- joke
- kangaroo
- kat
- katrina
- kev
- kittenwar
- koala
- landlord
- language
- larry
- law
- lesbians
- linkies
- lion
- livejournal
- lj
- lj-abuse
- lj-drama
- lj-poll
- lj-ref
- louise
- love
- lungs
- lusby
- lyrics
- maertens
- manatee
- mandy
- maps
- mars
- maryland
- massachusetts
- matt
- mel
- memory
- metro
- miami
- michelle
- misti
- mm
- mo
- money
- monkey
- monkeys
- montgomery county
- mootpoint
- mormon
- movies
- mp
- mp3
- mugshot
- murphy's
- music
- mystery
- navy
- neil
- new jersey
- new york
- newlyweds
- news
- newtcam
- newton
- nifty trivia
- no-nose
- north beach
- opening lines
- otters
- overheard
- oxford
- palm doodles
- palm post
- palm update
- pancakes
- phoenix
- phone post
- pictures
- piracy
- pixie
- pm
- poem
- poetry
- polar bear
- politics
- pomonkey
- pompano
- poop
- ppp
- prince frederick
- programming
- prose
- psa
- psp
- pulp
- punk
- pyewacket
- quiz-meme
- quote
- rama
- rant
- recipes
- reference
- religion
- rhino
- ripley
- rita
- robb
- robbchar
- robot
- rockville
- rules
- russia
- sasha
- scottopedia
- seal
- security
- sex
- sex offenders
- sexual predators
- sheep
- silver spring
- snakehead
- snakes on a plane
- solomon's island
- south carolina
- space
- spider-man
- spiders
- spore
- spring
- squids
- squirrels
- steve jacoby
- strawberry shortcake
- summer
- super-heroes
- superboy
- superman
- supernatural
- suzy
- taco bell
- td
- teaching
- ted
- tf2
- thanksgiving
- that's not right
- the five-o
- things i've tried
- tiger
- tigger
- tina
- tm
- tomi
- transport
- turtle
- tv
- tw
- ukrainian
- vacation
- vampires
- vegas
- vera
- verizon
- video
- video post
- virginia
- vizcaya
- walkabout
- wally
- walnuts
- warhammer
- washington dc
- weather
- webcam
- wedding
- weight
- werewolves
- west virginia
- whales
- wifi
- wii
- wilma
- wmata
- work
- work. iron man
- writer's block
- writing
- wtc911
- wtf
- wu
- yeti
- zagat
- zebra
- zoe
- zombies
Powered by LiveJournal.com
Designed by
chasethestars
Comments
<tr><td class="listBullet" valign="top"></td><td class="listItem">
Un-registerthe Windows Picture and Fax Viewer (Shimgvw.dll) on Windows XP ServicePack 1; Windows XP Service Pack 2; Windows Server 2003 and WindowsServer 2003 Service Pack 1
Microsoft has tested the followingworkaround. While this workaround will not correct the underlyingvulnerability, it helps block known attack vectors. When a workaroundreduces functionality, it is identified in the following section.
NoteThe following steps require Administrative privileges. It isrecommended that the machine be restarted after applying thisworkaround. It is also possible to log out and log back in afterapplying the workaround. However, the recommendation is to restart themachine.
To un-register Shimgvw.dll, follow these steps:
1.
Click Start, click Run, type "regsvr32 -u %windir%\system32\shimgvw.dll" (without the quotation marks), and then click OK.
2.
A dialog box appears to confirm that the un-registration process has succeeded. Click OK to close the dialog box.
Impact of Workaround:The Windows Picture and Fax Viewer will no longer be started when usersclick on a link to an image type that is associated with the WindowsPicture and Fax Viewer.
To undo this change, re-register Shimgvw.dll by following the above steps. Replace the text in Step 1 with regsvr32 %windir%\system32\shimgvw.dll (without the quotation marks).
</td></tr><tr><td class="listBullet" valign="top"></td><td class="listItem">Microsoftencourages users to exercise caution when they open e-mail and links ine-mail from untrusted sources. For more information about SafeBrowsing, visit the Trustworthy Computing Web site.
</td></tr><tr><td class="listBullet" valign="top"></td><td class="listItem">Customersin the U.S. and Canada who believe they may have been affected by thispossible vulnerability can receive technical support from MicrosoftProduct Support Services at 1-866-PCSAFETY. There is no charge forsupport that is associated with security update issues or viruses."International customers can receive support by using any of the methodsthat are listed at Security Help and Support for Home Users Web site.
</td></tr><tr><td class="listBullet" valign="top"></td><td class="listItem">Allcustomers should apply the most recent security updates released byMicrosoft to help ensure that their systems are protected fromattempted exploitation. Customers who have enabled Automatic Updateswill automatically receive all Windows updates. For more informationabout security updates, visit the Microsoft Security Web site.
</td></tr><tr><td class="listBullet" valign="top"></td><td class="listItem">Protect Your PC
Wecontinue to encourage customers follow our Protect Your PC guidance ofenabling a firewall, getting software updates and installing ant-virussoftware. Customers can learn more about these steps by visiting Protect Your PC Web site.
</td></tr><tr><td class="listBullet" valign="top"></td><td class="listItem">For more information about staying safe on the Internet, customers can visit the Microsoft Security Home Page.
</td></tr><tr>http://www.microsoft.com/technet/securi
The person linked to wrote a fix for it -
The fix does not remove any functionality from the system, all pictures will continue to be visible. You can download it here:
http://www.hexblog.com/security/files/w
Once MS get around to a proper fix can you post about that too. Thanks.
thanks for the heads up scotto!