Timberway.com - UPDATED - Windows WMF Files Security Warning |
![]() |
Your Internet Marketing Solution |
Windows WMF Files- URGENT SECURITY WARNING - January 2006Zero-Day Security Exploit Hits Windows for New Year 2006
This is not a joke or a hoax. It is one of the most serious Windows security warnings to date. A zero-day (0-day) exploit is one where there is basically no warning and no patch before the exploit is in the wild. In other words, it's out there and almost everyone is susceptible. A major security flaw exists in Windows WMF files. It appears that the files may not even appear to be WMF files. The files can hide (actually, they can call...) almost any executable code including viruses, worms, trojan horses, and root kits. Malicious WMF files can be received in emails, from Web pages, from instant messages, from file sharing, etc. Just viewing an image executes the code. You don't have to click on anything. Even indexing a file with a tool such as Google Desktop Search executes the code. References:
The first version of this exploit appeared on or about December 27, 2005, and there are now several versions in the wild. But the most serious development is that a group apparently created an easy tool for turning any WMF file into a carrier for any malicious code - the sort of tool anyone can use. And they released it over the New Years' holiday weekend. And the latest one, in fact, has already been included in spam emails sent on New Years' Day, 2006. This security warning applies to at least Windows 2000, Windows XP (SP1 and SP2), and Windows 2003, and the exploit has been proven to successfully attack fully patched systems. It is believed to also affect Windows 3.x, Windows 95, Windows 98, and Windows ME as well, although that is not yet proven. But it uses a "feature," not a bug, of the WMF file format. WMF files were apparently designed to be able to call executable code. And since this feature has been out there a long time, it is believed that older Windows versions are likely to be vulnerable. Internet Explorer will trigger the exploit without warning when an image is viewed. Newer versions of Firefox will prompt you before opening the image. There is no official patch from Microsoft. Microsoft is not expected to have a patch available for Windows 2000 and Windows XP until at least January 9, 2006. There is, however, a workaround that has been create by one of the leading experts on low-level Windows programming and some of the top security analysts in the world. We strongly recommend that you visit the SANS Internet Storm Center and read more. If you are not familiar with SANS, they are one of the leading security education and certification organizations. The Internet Storm Center brings together security analysts from all over the world to monitor and track security exploits and malicious code. Do yourself a favor - go to the SANS Internet Storm Center now and read the WMF FAQ. Follow their instructions to install the unofficial patch made available by Ilfak Guilfanov. SANS has reviewed the patch and tested it and believes it is the best solution until Microsoft releases an official patch. Also follow their instructions to manually unregister a related DLL. This is not foolproof, but it is the best protection available currently. Get the instructions from the SANS Internet Storm Center: http://isc.sans.org/ Technorati tags: Microsoft Windows Security
Related links:
|
|
||||||||
| HomeInternet Marketing NewsInternet Marketing ArticlesInternet Marketing Tools and ServicesInternet Marketing Books, Ebooks, and CoursesWeb Site TemplatesWeb HostingWebmaster News » Get Your Name As Your URL On Facebook Tonight » Google Announces AdWords Keywords Changes » Best XHTML and CSS Style Guide » Technorati Tags Snippet for Etomite CMS » AWeber Updated Their Paypal Email Parser » Yahoo My Web 2.0 Beta » Search Engine Research Resources » SEO Expert Analyzes Google Patent » CNBC Airs The eBay Effect On Television Tonight » Microsoft Fiddler HTTP Debugger Tool » Microsoft Releases Specifications And Architectural Overview Of Windows Longhorn RSS » Microsoft Windows Longhorn Loves RSS » FTC Testing Anti-Spam Standards » RSS in the Microsoft Longhorn Operating System » Webmaster and Web Developer Resource Links » The Peoples Choice Podcast Awards » New Section Added - Search Engine Optimization: SEO News » New - A Free Keyword Density Tool for Search Engine Optimization SEO » Free Stock Photos » Etomite Content Management System - CMS Upgrade » Google PageRank - Not Important? » Microsoft Still Searching For The Search Engine Pot Of Gold » Domain Names Sell For Six Figures » Joel Comm, The King of AdSense Struck Again... and I'm Impressed... » Bill Gates is Retiring from Microsoft! » UPDATED - Windows WMF Files Security Warning » New Web Site Template Store Launches » Best Logo Company According to Wired Magazine » Search Engine Ranking Factors in SEO » Internet Wars - Internet Backbone Feud Shuts Down the Web » Free Keyword Density Tool » Opera Eliminates Ad Banner and Licensing Fee » HTML, XHTML, CSS, Table-less Web Design Tutorial » Google Talk Launches » FREE Ebook: Search Engine Optimization Made Easy, by Brad Callen » Syndicate Streaming Video News To Your Web Site » Google RSS News Feeds and Atom News Feeds for Google News » Macromedia Studio 8, Macromedia Dreamweaver 8, Flash 8 Professional, and Fireworks 8 » What Does A Search Engine Spider See? » Market Your Local Business Locally » Cross-Browser Compatibility » Tutorials for Webmasters and Programmers » Microsoft Enters Voice Over IP (VoIP) Internet Telephone Market » Make Your Website Cross-Browser Compatible » Blog Makes $40,000 a Month » Google AdWords Keywords » Google CPM Ads Meet Lukewarm Reception » Firefox Browser Downloaded 50 Million Times » Internet Explorer 7 News » Search Engines Gearing Up for Video Searches and Services » How to Double Your AdSense Income Instantly » How to Steal to the Top of Google » Flash Deadly Sins That Can Kill Your Web Business » Clickalyzer Web Traffic Intelligence Gets Even Better » Google Syndicates Local Search and Maps » Opera Browser Version 8 Released » CSS Zen Garden » Google Web Accelerator May Cause Problems For Web Applications » Google AdSense Poll » PHP Zend Core for Oracle » New Google Sitemaps Tool » Easily Sell Multiple Products Through One Clickbank Account » Yahoo! Releases New Search Engine - Yahoo! Mindset » Google Toolbar PageRank Is Coming Back » Google Toolbar PageRank PR Grayed Out » New - A Free Link Popularity Tool and other Search Engine Optimization Tools » Methods of Website Promotion » Really Bad Websites » Cloak Affiliate Links to Prevent Affiliate Commission Theft » Can you have improved usability and improved search engine rankings placement? » Web Color Scheme Generator » Webmaster Stress Relief » Become an authority site in Google » Get indexed quickly at Google » Rosalind Gardner - link color affects web traffic » Block Google Autolink » WordPress Blog Security Upgrade » Broadband High-Speed Internet Service RisingMom Execs - Work At Home MomsSearch this siteSite MapContact UsAdditional Internet Marketing Webmaster Resources Links Directory Search Engine Optimization: SEO News | |||||||||
| Home | Site Map | Site Map 2 | Site Map 3 | Search | Search 2 | ||
Copyright 2005 by Timberway.com - Your Internet Marketing Solution - All Rights Reserved |
||