Previous Entry | Next Entry

Not Safe!

Geotargethttp://www.hexblog.com/2005/12/wmf_vuln.html

possibly the worst Windows hole ever, affects all versions, and spreading fast; install this now, as even viewing an image can infect you. - via [info]waxy_org

Not a hoax.

Tags:

Comments

[info]i wrote:
Jan. 3rd, 2006 01:12 am (UTC)
why would i install a "patch" for windows that wasn't released by microsoft??????
[info]scottobear wrote:
Jan. 3rd, 2006 01:24 am (UTC)
Here is microsoft's manual way of fixing things -

<tr><td class="listBullet" valign="top"></td><td class="listItem">

Un-registerthe Windows Picture and Fax Viewer (Shimgvw.dll) on Windows XP ServicePack 1; Windows XP Service Pack 2; Windows Server 2003 and WindowsServer 2003 Service Pack 1

Microsoft has tested the followingworkaround. While this workaround will not correct the underlyingvulnerability, it helps block known attack vectors. When a workaroundreduces functionality, it is identified in the following section.

NoteThe following steps require Administrative privileges. It isrecommended that the machine be restarted after applying thisworkaround. It is also possible to log out and log back in afterapplying the workaround. However, the recommendation is to restart themachine.

To un-register Shimgvw.dll, follow these steps:

1.

Click Start, click Run, type "regsvr32 -u %windir%\system32\shimgvw.dll" (without the quotation marks), and then click OK.

2.

A dialog box appears to confirm that the un-registration process has succeeded. Click OK to close the dialog box.

Impact of Workaround:The Windows Picture and Fax Viewer will no longer be started when usersclick on a link to an image type that is associated with the WindowsPicture and Fax Viewer.

To undo this change, re-register Shimgvw.dll by following the above steps. Replace the text in Step 1 with regsvr32 %windir%\system32\shimgvw.dll (without the quotation marks).

</td></tr><tr><td class="listBullet" valign="top"></td><td class="listItem">

Microsoftencourages users to exercise caution when they open e-mail and links ine-mail from untrusted sources. For more information about SafeBrowsing, visit the Trustworthy Computing Web site.

</td></tr><tr><td class="listBullet" valign="top"></td><td class="listItem">

Customersin the U.S. and Canada who believe they may have been affected by thispossible vulnerability can receive technical support from MicrosoftProduct Support Services at 1-866-PCSAFETY. There is no charge forsupport that is associated with security update issues or viruses."International customers can receive support by using any of the methodsthat are listed at Security Help and Support for Home Users Web site.

</td></tr><tr><td class="listBullet" valign="top"></td><td class="listItem">

Allcustomers should apply the most recent security updates released byMicrosoft to help ensure that their systems are protected fromattempted exploitation. Customers who have enabled Automatic Updateswill automatically receive all Windows updates. For more informationabout security updates, visit the Microsoft Security Web site.

</td></tr><tr><td class="listBullet" valign="top"></td><td class="listItem">

Protect Your PC

Wecontinue to encourage customers follow our Protect Your PC guidance ofenabling a firewall, getting software updates and installing ant-virussoftware. Customers can learn more about these steps by visiting Protect Your PC Web site.

</td></tr><tr><td class="listBullet" valign="top"></td><td class="listItem">

For more information about staying safe on the Internet, customers can visit the Microsoft Security Home Page.

</td></tr><tr>
[info]scottobear wrote:
Jan. 3rd, 2006 01:23 am (UTC)
Well, it's your call, of course. I trust this site and programmer, and the expoit is real, with a description of how the expolit works and what it does.

http://www.microsoft.com/technet/security/advisory/912840.mspx

[info]photocentric wrote:
Jan. 3rd, 2006 01:58 am (UTC)
Thanks for the head's up.
[info]scottobear wrote:
Jan. 3rd, 2006 02:05 am (UTC)
cheers! please read how to remove it, too, should you need to do so, later on!
[info]photocentric wrote:
Jan. 3rd, 2006 02:26 am (UTC)
I saved a copy of the web page in the folder with the hotfix so I'll be able to remember how to remove the patch.
[info]scottobear wrote:
Jan. 3rd, 2006 02:27 am (UTC)
groovy! I did the same thing. :D
[info]weezeroni wrote:
Jan. 3rd, 2006 03:11 am (UTC)
What's a hole, and what does it expoloit and how panicked should I be??? Small words and slowly, ok Scotto? And this patch is safe to install? I trust you over AOL. Actually over lots of people. And entities. Now that I think about it :)
[info]scottobear wrote:
Jan. 3rd, 2006 03:17 am (UTC)
Well, the basic story is this - A security issue with all windows operating systems allows a picture, a video file or the like to run a program that can do mean things to your machine.

The person linked to wrote a fix for it -

The fix does not remove any functionality from the system, all pictures will continue to be visible. You can download it here:

http://www.hexblog.com/security/files/wmffix_hexblog14.exe
[info]weezeroni wrote:
Jan. 3rd, 2006 03:27 am (UTC)
I don't want mean stuff. I hate means stuff. Besides, my brother has informed me that, in technical terms, my computer is already "infested with evil." I will install it. Thank you Pumpkin!
[info]scottobear wrote:
Jan. 3rd, 2006 03:28 am (UTC)
uhoh... well, has your bro helped put nay anti-virus or anti-spyware on your system?

[info]weezeroni wrote:
Jan. 3rd, 2006 03:30 am (UTC)
Yes, and cleaners. Although at this point, it has been agreed by all the manly computer persons in my life that the best solution would be to wipe the whole thing clean and reinstall hopefully uncorrupted stuff. Clean slate.
[info]scottobear wrote:
Jan. 3rd, 2006 03:17 am (UTC)
the patch seems safe to install - I've had it running for about 12 hours now.
[info]weezeroni wrote:
Jan. 3rd, 2006 03:25 am (UTC)
And it hasn't hampered anything?
[info]scottobear wrote:
Jan. 3rd, 2006 03:27 am (UTC)
nope! if you need to remove it for anything, there are instructions on the site, too.
[info]weezeroni wrote:
Jan. 3rd, 2006 03:27 am (UTC)
Fab. Thank you!
[info]scottobear wrote:
Jan. 3rd, 2006 03:29 am (UTC)
happy to help!
[info]eryx_uk wrote:
Jan. 3rd, 2006 03:12 am (UTC)
Thanks for the heads up. Installed.

Once MS get around to a proper fix can you post about that too. Thanks.
[info]scottobear wrote:
Jan. 3rd, 2006 03:18 am (UTC)
absolutely... hopefully, they'll issue a security relase within the next few days.
[info]flying_blind wrote:
Jan. 3rd, 2006 05:05 am (UTC)
All patched. Thanks. I'll pass this along.
[info]scottobear wrote:
Jan. 3rd, 2006 02:34 pm (UTC)
patch
good deal! thanks for passing it along!
[info]anony_moos wrote:
Jan. 3rd, 2006 08:25 am (UTC)
thanks for this dude. I know naff all about computers, but going on the fact you told me to, I have downloaded it!
[info]scottobear wrote:
Jan. 3rd, 2006 11:11 am (UTC)
Hope I'm helping to keep you safe!
[info]oneeyedcat wrote:
Jan. 3rd, 2006 01:01 pm (UTC)
Hey!

thanks for the heads up scotto!

[info]scottobear wrote:
Jan. 3rd, 2006 02:32 pm (UTC)
cheers!
[info]phillykat wrote:
Jan. 5th, 2006 12:32 am (UTC)
thanks bud
[info]scottobear wrote:
Jan. 5th, 2006 12:44 am (UTC)
cheers!
[info]peradouro wrote:
Jan. 5th, 2006 07:22 am (UTC)
thanks anyways, no go
Got the email but tiny brain puter has old haggard system I reckon. Prog downloaded but message said it wouldn't work with system. SO, I'll save it in my email til I get a real puterachine stead o this here borrowed laptop with mangled typeness. TY muchly.
[info]scottobear wrote:
Jan. 5th, 2006 11:15 am (UTC)
Re: thanks anyways, no go
best of luck! just be careful where you surf this week!

Latest Month

July 2008
S M T W T F S
  12345
6789101112
13141516171819
20212223242526
2728293031  

Tags

Powered by LiveJournal.com
Designed by [info]chasethestars