Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

New WMF Exploit version emerges - ISC returns to Yellow alert

There is a "new and improved" edition of the WMF exploit that does not use a WMF extension.  It also varies in size randomly to better evade AV detection.  A code Yellow alert has been issued by the Internet Storm Center.  There is little or no AV protection available, so extra caution should be used.

New exploit released for the WMF vulnerability - YELLOW
http://isc.sans.org/diary.php?storyid=992 

A copy of the actual exploit can be found at FrSIRT for anyone wanting to review the code, but please use caution.  The exploit generates files with the following characteristics:

* with a random size;
* no .wmf extension, (.jpg), but could be any other image extension actually;
* a random piece of junk in front of the bad call; carefully crafted to be larger than the MTU on an ethernet network;
* a number of possible calls to run the exploit are listed in the source;
* a random trailer

Comments

Microsoft Most Valuable Professional said:

   McAfee has just updated their website with information related to the new WMF variant. ...
# December 31, 2005 8:33 PM

My IT Forum Technology Blogs said:

# December 31, 2005 8:33 PM

Microsoft Most Valuable Professional said:

   McAfee has just updated their website with information related to the new WMF variant. ...
# January 1, 2006 5:09 AM

Microsoft Most Valuable Professional said:

   McAfee has just updated their website with information related to the new WMF variant. ...
# January 1, 2006 5:17 AM

My IT Forum Technology Blogs said:

# January 1, 2006 6:35 AM

My IT Forum Technology Blogs said:

# January 2, 2006 6:11 AM

Microsoft Most Valuable Professional said:


In the various forums I participate in, I saw that many administrators worked during the holiday...
# January 2, 2006 6:12 AM

Microsoft Most Valuable Professional said:


In the various forums I participate in, I saw that many administrators worked during the holiday...
# January 2, 2006 7:39 AM

Microsoft Most Valuable Professional said:


In the various forums I participate in, I saw that many administrators worked during the holiday...
# January 2, 2006 7:55 AM

Microsoft Most Valuable Professional said:


In the various forums I participate in, I saw that many administrators worked during the holiday...
# January 2, 2006 7:58 AM