Today's critical Windows security hole

General discussions not related to the Vibe, Matrix, or any other vehicle. (follow posting rules)
Post Reply
User avatar
joatmon
Posts: 10178
Joined: Fri Mar 21, 2003 5:19 am
Location: Room 101

Today's critical Windows security hole

Post by joatmon »

another hole in windows http://news.com.com/Trojan+del....htmlQuote »Trojan delivers unwanted gift to Windows PCsBy Elinor MillsStaff Writer, CNET News.comPublished: December 28, 2005, 4:04 PM PST A new Trojan horse program was infecting PCs on Wednesday, exploiting a hole in Windows systems to sneak onto computers, then dropping adware or spyware or turning them into zombies, according to several Internet security companies.The Trojan, dubbed Exploit-WMF (Windows Meta File), was rated a category 2 level risk, meaning it had the potential to continue to spread, said Dave Cole, director of security response at Symantec.The exploit "is misusing a function in the WMF library in Windows," dropping onto the machine a downloader Trojan "that pulls down its big brother, a more sophisticated Trojan" from a server on the Internet, he said."Then it might try to pull down adware, spyware or a bot program," that can turn the computer into a zombie to be used for attacking other machines or sending spam, or just leave a hole on the computer through which sensitive data could be stolen, Cole said.Kaspersky Lab rated the vulnerability "highly critical" and predicted that "new modifications of these programs may well appear in the near future."The WMF vulnerability affects computers running Windows XP with service pack 1 and service pack 2, as well as Windows Server 2003 with service pack 0 and service pack 1. It can be exploited when an Internet Explorer user, or Firefox user under certain circumstances, visits a Web site that has malicious code on it or when a user previews .wmf format files with Windows Explorer, Kaspersky said in a statement.The WMF library allows the computer to handle particular image types of Windows machines, Cole said. There is no patch for it yet from Microsoft, although antivirus vendors had released software to help protect against it, he said."Microsoft is investigating new public reports of a possible vulnerability in Windows and will continue to investigate the reports to help provide additional guidance for customers," a Microsoft spokesperson wrote in an e-mail. "Upon completion of this investigation, Microsoft will take the appropriate action to protect customers, which may include providing a fix through the monthly release process or issuing a security advisory, depending on customer needs."Windows users can get more information about security issues at http://support.microsoft.com/security.
Image
northvibe
Posts: 7641
Joined: Tue Jul 05, 2005 2:25 pm

Post by northvibe »

a computer is only as secure as how the user sets it up - is my moto.
drunkengirlfriend
Posts: 112
Joined: Thu Oct 20, 2005 3:49 am

Re: (northvibe)

Post by drunkengirlfriend »

Quote, originally posted by northvibe »a computer is only as secure as how the user sets it up - is my moto.I completely agree but some people have no clue what they are doing.I guess it's time to take Drunken's advice and get a Mac.
Kari
Posts: 3259
Joined: Sat Sep 06, 2003 3:01 am

Re: (drunkengirlfriend)

Post by Kari »

Quote, originally posted by drunkengirlfriend »I guess it's time to take Drunken's advice and get a Mac. Definitely. At least until they start writing Mac trojan horses and virii...which I hope they don't, or at least that there isn't as much to exploit. Although the market share is still so small it's not really worth messing with to write a virus I guess.
GenVibe Global Moderator
4azdmunky
Posts: 445
Joined: Fri Dec 23, 2005 11:57 am

Re: Today's critical WIndows security hole (joatmon)

Post by 4azdmunky »

Yea, my Baracudda at work blocked about 50 of these over the last two days. A security update is due out by Tuesday, you can DL a network installer until then if you need it.
drunkenmaxx
Posts: 6300
Joined: Mon Jul 21, 2003 6:19 am

Re: (Kari)

Post by drunkenmaxx »

Quote, originally posted by Kari »Definitely. At least until they start writing Mac trojan horses and virii...which I hope they don't, or at least that there isn't as much to exploit. Although the market share is still so small it's not really worth messing with to write a virus I guess. it's because all the real nerds who write that stuff are pc freaks!
chew aura pizza cheat main"the world in my hands, there's noone left to hear you scream, noone's there for you"
User avatar
ColonelPanic
Posts: 8436
Joined: Sun Jan 05, 2003 8:48 am
Location: South Central Indiana

Re: (drunkenvibe)

Post by ColonelPanic »

Quote, originally posted by drunkenvibe »it's because all the real nerds who write that stuff are pc freaks! ...and they're probably all writing that crap under Linux. I mean, if they wrote this junk under its native platform, wouldn't that cripple their productivity? Hard to keep things going when your own work keeps infecting your box every ten minutes. lol! Ahh, I love Linux. And my Mac.

Attached files
03 Vibe base. Born 10/14/2002 06:07 AM
Auto, Moon & Tunes, power package. 143k
Neptune/dying clearcoat/primer grey. :lol:

Image

'21 Elantra Limited - 2.0L/IVT
'15 Escape SE - 1.6L EcoBoost (hers)
Image Image
Post Reply