Re: A Very Dangerous Worm in Windows Metafile Images (WMF)



On Mon, 02 Jan 2006 16:29:10 GMT, Rich Webb
<bbew.ar@xxxxxxxxxxxxxxxxxx> wrote:

>On 2 Jan 2006 07:24:05 -0800, Winfield Hill
><Winfield_member@xxxxxxxxxxx> wrote:
>
>>Frank Bemelman wrote...
>>>
>>>> I've finally installed Opera ...
>>
>> Doesn't matter, it's picture links that get you, and Opera will
>> show a picture if asked to.
>
>Opera can be set to automatically download application/x-msmetafile
>and .wmf file types. I've set mine to dump any that it comes across
>into c:/null. As nearly as I can tell from testing here with self-made
>wmf files, this works correctly as a quarantine measure.
>
>The display of wmf images by Opera can also be affected by whether the
>user has installed file viewers beyond the vanilla MS handlers. I use
>IrfanView aka IView as a general-purpose viewer and it is the registered
>system wmf viewer. I *do not* know whether IView passes wmf images to a
>lower-level system DLL for decoding, though.
>
>Quarantine seems to be the safest route. The wmf file types are (were)
>very rare either as web images or in e-mail; mostly used to embed
>graphic images in Word and such.


A wmf file can be renamed by the exploiter to .jpg, .gif, .bmp,
anything. Windows, stupid and voracious as it is, can be fed
"file.jpg" but will execute it as a wmf. So just dumping wmf files
isn't good enough. Such a file can merely be *in a folder*, not even
opened, and do its thing.

Install the patch!

Oh, I looked all over the Microsoft security site and can find no
mention of this exploit. How come some freelance blogger can write a
fix in hours, and Microsoft stays silent?

John

.



Relevant Pages

  • Re: A Very Dangerous Worm in Windows Metafile Images (WMF)
    ... >>> I've finally installed Opera ... ... > Doesn't matter, it's picture links that get you, and Opera will ... The display of wmf images by Opera can also be affected by whether the ... The wmf file types are ...
    (sci.electronics.design)
  • Re: MS (in)security warning
    ... You have to use IE for the test since all you see with Firefox and Opera is the text TEST WMF FILE. ... With IE you see the graphic image rendered, and when you click on it, you see a small popup offering some options, such as to Save or Print the image file. ... Has anyone seen this exploit with an email client such as Outlook, OE, Opera, Thunderbird, Netscape, etc.? ...
    (alt.comp.anti-virus)
  • Re: A Very Dangerous Worm in Windows Metafile Images (WMF)
    ... The display of wmf images by Opera can also be affected by whether the ... IrfanView aka IView as a general-purpose viewer and it is the registered ... The wmf file types are ...
    (sci.electronics.design)