Please Scroll Down to See Forums Below
napsgear
genezapharmateuticals
domestic-supply
puritysourcelabs
Research Chemical SciencesUGFREAKeudomestic
napsgeargenezapharmateuticals domestic-supplypuritysourcelabsResearch Chemical SciencesUGFREAKeudomestic

***Huge Virus Threat Rocks Microsoft, WARNING***

  • Thread starter Thread starter BrothaBill
  • Start date Start date
B

BrothaBill

Guest
NEW YORK (CNNMoney.com) - The new year is off to a rocky start at Microsoft, where security experts are scrambling to confront a potentially massive virus threat to Windows PCs.

According to a report Tuesday in the Financial Times, the latest vulnerability involves a flaw which allows hackers to infect computers using programs inserted into image files. The threat was discovered last week. But it mushroomed over the weekend, when a group of hackers published the source code they used to exploit the flaw.

What makes this threat particularly vicious, according to the Times, is that unwitting victims can infect their computers simply by viewing a web page, e-mail, or instant message that includes a contaminated image. That differs from most virus attacks, which require a user to actually download an infected file.

"The potential [security threat] is huge," Mikko Hypponen, chief research officer at F-Secure, an antivirus company, told the Times. "It's probably bigger than for any other vulnerability we've seen.

"Any version of Windows is vulnerable right now," said Mr. Hypponen, including every Windows system shipped since 1990.

Microsoft said a security patch would be available for the problem on Tuesday, January 10 after it has passed rigorous testing procedures.

Because of the severity of the threat, the SANS Institute, a computer security group, has released a patch for the vulnerability until Microsoft's fix is available next week.


DOWNLOAD TEMPORARY PATCH HERE
 
Would it not be adequate to disable the file association for .wmf files, at least until the next case of Windows rot is highlighted?
 
98 users are getting left in the cold. It's bound to promote some more sales of WinXP along with a trickle to Apple and Linux.
 
blut wump said:
98 users are getting left in the cold. It's bound to promote some more sales of WinXP along with a trickle to Apple and Linux.

With my home gym, hot tub/deck in the spring, and my dreams of owning a G5...it looks like I'm gonna be one broke mother fucker for the first half of 2006 :(.

Hackers who do this shit, if I ever run into one of these guys...I'm gonna take them down, step on their throat until they turn a pale shade of blue...and then stuff a Windoze install disk in every orifice of their dead worthless bodies.

I'm ok :)
 
How can you get infected?
 
blut wump said:
Here's a description of the vulnerability
http://www.kb.cert.org/vuls/id/181038

You can become infected by allowing the Windows GDI (graphic interface) to attempt to deal with a suitably malformed wmf (Windows Meta-File) image.

Thx

So the best to do now is download the unofficial patch and then you need Windows Installer to execute it (the .MSI file)???
 
That depends on your idea of best. I moved away from Windows two or three years ago.

In that description of the vuln., it mentions how to disable the wmf file-association which, while not fixing the problem, prevents its exploitation.
 
Top Bottom