<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Blocking those WMF's at the email border</title><link>http://msmvps.com/blogs/bradley/archive/2005/12/28/79925.aspx</link><description>Okay so even before I blocked the WMF's via ISA server so that they are blocked while surfing...the first thing I did [ because I knew easily how to do this ] was to go into my antivirus program that protects my Exchange server and add WMF file extensions</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Blocking those WMF's at the email border</title><link>http://msmvps.com/blogs/bradley/archive/2005/12/28/79925.aspx#190118</link><pubDate>Fri, 20 Oct 2006 00:03:51 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:190118</guid><dc:creator>Nikki</dc:creator><description>&lt;p&gt;goodsite.NikkfromLA.(USA)&lt;a rel="nofollow" target="_new" href="http://megspace.com/lifestyles/uldiaz1/10mg-diazepam.html"&gt;http://megspace.com/lifestyles/uldiaz1/10mg-diazepam.html&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=190118" width="1" height="1"&gt;</description></item><item><title>Start of the New Year</title><link>http://msmvps.com/blogs/bradley/archive/2005/12/28/79925.aspx#80198</link><pubDate>Tue, 03 Jan 2006 08:28:34 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:80198</guid><dc:creator>Nick Whittome - "The Naked MVP" </dc:creator><description>Back to work for me…&amp;amp;amp;nbsp;&amp;amp;amp;nbsp;&amp;amp;amp;nbsp; I am sure that today people will be calling the office to ask...&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80198" width="1" height="1"&gt;</description></item><item><title>Start of the New Year</title><link>http://msmvps.com/blogs/bradley/archive/2005/12/28/79925.aspx#80196</link><pubDate>Tue, 03 Jan 2006 08:28:22 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:80196</guid><dc:creator>Nick Whittome - "The Naked MVP" </dc:creator><description>Back to work for me…&amp;amp;amp;nbsp;&amp;amp;amp;nbsp;&amp;amp;amp;nbsp; I am sure that today people will be calling the office to ask...&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80196" width="1" height="1"&gt;</description></item><item><title>Conscientious Risk Management and WMF</title><link>http://msmvps.com/blogs/bradley/archive/2005/12/28/79925.aspx#80182</link><pubDate>Mon, 02 Jan 2006 20:02:49 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:80182</guid><dc:creator>Jesper's Blog</dc:creator><description>This past week there have been a lot of questions about the WMF vulnerability, what Microsoft is doing,...&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80182" width="1" height="1"&gt;</description></item><item><title>Conscientious Risk Management and WMF</title><link>http://msmvps.com/blogs/bradley/archive/2005/12/28/79925.aspx#80181</link><pubDate>Mon, 02 Jan 2006 19:41:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:80181</guid><dc:creator>Jesper's Blog</dc:creator><description>This past week there have been a lot of questions about the WMF vulnerability, what Microsoft is doing,...&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80181" width="1" height="1"&gt;</description></item><item><title>Are you WMF'd to death yet?</title><link>http://msmvps.com/blogs/bradley/archive/2005/12/28/79925.aspx#80045</link><pubDate>Fri, 30 Dec 2005 23:52:36 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:80045</guid><dc:creator>Dana Epp's ramblings at the Sanctuary</dc:creator><description>Wondering why you haven't seen any feedback from me on the most recent 0-day exploit on Windows, which takes advantage of a vulnerability in the graphics rendering engine? I took a vacation away from the computer for a few days to catch up on some technical reading, and come back to a plethora of information that pretty much sums up anything I would say. In a blog post in the next few days, I will post just WHAT I was reading, as its pretty interesting. I'm shaking my head as I absorb some of this new stuff. Anyways, as a summary of the past few days where the world has been screaming that the sky is falling, here is the nitty gritty that matters (at least from my POV) Before you do anything, go read the Microsoft Security Advisory (MSA 912840) on the matter. According to guys over at Sunbelt, Microsoft may be incorrectly stating that software DEP will help mitigate against this threat. Seems that hardware DEP works, software DEP from Microsoft does not. No one has reported if some of the other software DEP agents defend against this attack or not. Susan has a great post on how to filter out WMF attachments on Exchange. Jesper has an excellent post on how to block certain extensions with ISA. Even when he goes on holidays he has time to play with ISA :) The easiest fix (temporarily) is to unregister the vulnerable code, using &amp;amp;quot;REGSVR32 /U SHIMGVW.DLL&amp;amp;quot; (without the quotes of course) from Start-&amp;amp;gt;Run I disagree with Susan that it is too drastic to unregister the DLL. It's quite trival a fix to signficantly mitigate against this threat without impacting the rest of the system. So you don't get pretty thumbnails. But you do prevent the exploit through this attack vector (I will point out it won't stop against someone opening an exploited WMF in MS Paint etc). And with the ability to push this out to all the desktops pretty quickly with a script... it takes no time to toggle it on/off. YMMV of course. That's pretty much all you will hear from me on the WMF issue for now. You can read the other 1,000,000 blog posts about it for more information....&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80045" width="1" height="1"&gt;</description></item><item><title>re: Blocking those WMF's at the email border</title><link>http://msmvps.com/blogs/bradley/archive/2005/12/28/79925.aspx#79958</link><pubDate>Thu, 29 Dec 2005 17:09:48 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:79958</guid><dc:creator>Alun Jones</dc:creator><description>This is true - content is what matters, not extension.  As for &amp;quot;any extension&amp;quot;, that's not quite true - you would need an extension that feeds into the graphics rendering engine.  If you feel that's a sufficiently dangerous threat to concern yourself with it, you could block all graphics, or you could block all files with content that identifies it as a WMF, if you have a content-based filter.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=79958" width="1" height="1"&gt;</description></item><item><title>re: Blocking those WMF's at the email border</title><link>http://msmvps.com/blogs/bradley/archive/2005/12/28/79925.aspx#79955</link><pubDate>Thu, 29 Dec 2005 15:05:50 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:79955</guid><dc:creator>Alex Lee</dc:creator><description>There are reports that for this exploit, a malicious file can carry any extension.  Not just WMF.  See the 23:19 update on this Internet Storm Center Handler's Diary(&lt;a rel="nofollow" target="_new" href="http://isc.sans.org/diary.php?date=2005-12-29"&gt;http://isc.sans.org/diary.php?date=2005-12-29&lt;/a&gt;).&lt;br&gt;&lt;br&gt;On the other hand, Susan's post is more about the mechanics of blocking files by extension right on your server.  Nice.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=79955" width="1" height="1"&gt;</description></item><item><title>re: Blocking those WMF's at the email border</title><link>http://msmvps.com/blogs/bradley/archive/2005/12/28/79925.aspx#79935</link><pubDate>Thu, 29 Dec 2005 09:47:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:79935</guid><dc:creator>Nick Pieters</dc:creator><description>Well i don't know if trend is checking also checking the mails who come from the pop3 connector, guess so.&lt;br&gt;&lt;br&gt;I did everything on my isa server, smtp screener installed and blocked wmf for emails and downloads/http.&lt;br&gt;&lt;br&gt;Fun thing is that it works also for pop3 connector, so it works verry effectively for spam even with pop3 connector!&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=79935" width="1" height="1"&gt;</description></item></channel></rss>