Re: A Very Dangerous Worm in Windows Metafile Images (WMF)
- From: Mike Monett <gqtacfwfjfmx@xxxxxxxxxxxxx>
- Date: Mon, 02 Jan 2006 03:40:50 -0800
John Larkin wrote:
[...]
> It took the genius of Bill Gates to design an os that allows worms to
> be resident in viewable images. As I recall, Windows had the same
> problem with true jpeg files once.
>
> "When in doubt, execute it."
>
> John
According to the CERT advisory, a wmf file can have many extensions:
------------------------------------------------------------------
"Please note that Windows Metafile data may be saved with an
extension other than WMF. A file with any extension that is
associated with Windows Picture and Fax Viewer can be used to
exploit this vulnerability. By default, Windows Picture and Fax
Viewer is associated with the following file extensions:"
"BMP DIB GIF EMF JFIF JPE JPEG JPG PNG TIF TIFF WMF"
http://www.kb.cert.org/vuls/id/181038
------------------------------------------------------------------
The IM worm that was released yesterday was "http://[snip]/xmas-2006
FUNNY.jpg".
So we can't tell if an image file is safe by looking at the extension.
Pure chaos.
Mike Monett
.
- Follow-Ups:
- Re: A Very Dangerous Worm in Windows Metafile Images (WMF)
- From: John Larkin
- Re: A Very Dangerous Worm in Windows Metafile Images (WMF)
- From: Roger Johansson
- Re: A Very Dangerous Worm in Windows Metafile Images (WMF)
- From: Rich Grise
- Re: A Very Dangerous Worm in Windows Metafile Images (WMF)
- From: Frank Bemelman
- Re: A Very Dangerous Worm in Windows Metafile Images (WMF)
- References:
- A Very Dangerous Worm in Windows Metafile Images (WMF)
- From: Mike Monett
- Re: A Very Dangerous Worm in Windows Metafile Images (WMF)
- From: John Larkin
- A Very Dangerous Worm in Windows Metafile Images (WMF)
- Prev by Date: Re: A Very Dangerous Worm in Windows Metafile Images (WMF)
- Next by Date: Re: A Very Dangerous Worm in Windows Metafile Images (WMF)
- Previous by thread: Re: A Very Dangerous Worm in Windows Metafile Images (WMF)
- Next by thread: Re: A Very Dangerous Worm in Windows Metafile Images (WMF)
- Index(es):
Relevant Pages
|
Loading