Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Potential new unpatched IE exploit ? ~ Yes...may affect other Browsers also...
Websense Security Labs ^ | Dec 28 2005 11:19AM | Websense Security Labs Blog Staff

Posted on 12/28/2005 2:55:03 PM PST by Ernest_at_the_Beach

This alert is a follow-up to a post made yesterday on our blog: http://www.websensesecuritylabs.com/blog/

Websense® Security Labs™ has discovered numerous websites exploiting an unpatched Windows vulnerability in the handling of .WMF image files. The websites which have been uncovered at this point are using the exploit to distribute Spyware applications and other Potentially Unwanted Soware. The user's desktop background is replaced with a message warning of a spyware infection and a "spyware cleaning" application is launched. This application prompts the user to enter credit card information in order to remove the detected spyware. The background image used and the "spyware cleaning" application vary between instances. In addition, a mail relay is installed on the infected computer and it will begin sending thousands of SPAM messages.

We are currently tracking thousands of websites distributing exploit code from iFrameCASH BIZ. A similar zero-day vulnerability being exploited by this entity was discussed earlier this month:http://www.websensesecuritylabs.com/alerts/alert.php?AlertID=364

There is currently no patch available. Visiting an infected webpage with Internet Explorer on a fully-patched XP Service Pack 2 computer causes immediate infection. Earlier Firefox users are vulnerable but they are first prompted to display the WMF image. If a filesystem indexing service (such as Google Desktop) is installed, users of Firefox and even text-based browsers can become infected.

(Excerpt) Read more at websensesecuritylabs.com ...


TOPICS: Crime/Corruption; Extended News; Foreign Affairs; News/Current Events; Technical
KEYWORDS: backdoor; computer; exploit; exploits; firefox; internetexploiter; lookoutexpress; lowqualitycrap; malware; microsoft; openrelay; patch; security; securityflaw; spam; spamware; spyware; trojan; trojans; virus; windows; windowsxp; winfixer2005; wmf; worm; wrongtitle
Navigation: use the links below to view more comments.
first 1-5051-70 next last
Washington Post also comented on this here:

Exploit Released for Unpatched Windows Flaw

1 posted on 12/28/2005 2:55:05 PM PST by Ernest_at_the_Beach
[ Post Reply | Private Reply | View Replies]

To: ShadowAce; rdb3

Another one.....


2 posted on 12/28/2005 2:55:54 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
From the Washington Post an excerpt:

According to an overnight post at the SANS Internet Storm Center, the link provided at Bugtraq when clicked on successfully drops a Trojan horse program (on) fully patched Windows XP SP2 machines. The Trojan will then download a fake anti-spyware/virus program which asks user to purchase a registered version of software in order to remove threats it claims are resident on the user's machine.

3 posted on 12/28/2005 3:01:21 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

I don't understand why they keep calling this a browser exploit. It is strictly a Windows exploit. How the malicious WMF file is downloaded is irrelevant.


4 posted on 12/28/2005 3:01:54 PM PST by sigSEGV
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
This application prompts the user to enter credit card information in order to remove...

What? Your not supposed to enter your info?

LVM

5 posted on 12/28/2005 3:03:35 PM PST by LasVegasMac (The only thing slowing me down is the A**hole in front of me!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
Some Detail here:

December 28, 2005
Malicious Website / Malicious Code: Zero-day IE .WMF Exploit

************************************************************

A screen....

***********************************************


6 posted on 12/28/2005 3:06:16 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 3 | View Replies]

To: LasVegasMac; sigSEGV

This one may fool some people!


7 posted on 12/28/2005 3:07:39 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Ernest_at_the_Beach

A simple way of dealing with this until the patch is released is to change the .WMF file type to invoke something other than Windows Fax and Picture Viewer until this issue is resolved.


8 posted on 12/28/2005 3:08:39 PM PST by Company Man
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

AVG finally removed the virus from my computer.( I think).

I quit using ie because of that virus, downloaded firefox. It looks like the new AVG download takes care of winfixer 2005.


9 posted on 12/28/2005 3:10:44 PM PST by Lokibob (Spelling and typos are copyrighted. Please do not use.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Knitebane; Squantos

Ping!


10 posted on 12/28/2005 3:11:49 PM PST by hiredhand (My kitty disappeared. NOT the rifle!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
Below is an attached video of a machine being infected with all the components. As you can see several pieces of Potentially Unwanted Software (P.U.S) are installed and by simply viewing the MWF image you are infected without a prompt or warning screen.

This is an example of how P.U.S. (AKA "Greyware") vendors are using known and unknown exploits combined with deception to install code.

http://www.websensesecuritylabs.com/images/alerts/wmf-movie.wmv

11 posted on 12/28/2005 3:12:21 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Lokibob

Hope it works for you........I got this crap with Firefox.


12 posted on 12/28/2005 3:14:35 PM PST by newcthem (9/11- not terrorists - just troubled youths.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: sigSEGV

Not only "strictly a Windows exploit", but apparently also limited to XP w/ SP2.

I guess I'll just have to turn my new firewall settings up another couple of notches (I'm running 2000 Pro SP5), knock off surfing for a bit and go shut off my daughter's XP setup. (Lord, I'm tired of debugging that computer!!)


13 posted on 12/28/2005 3:15:39 PM PST by Unrepentant VN Vet
[ Post Reply | Private Reply | To 4 | View Replies]

To: newcthem

I got it by using "save image as".

Now im upset that firefox can bring it back.

Try AVG free virus killer. It can't hurt, anyway.


14 posted on 12/28/2005 3:19:34 PM PST by Lokibob (Spelling and typos are copyrighted. Please do not use.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Ernest_at_the_Beach

This has been building for a month or so.

I'm beginning to think that the best option for most people would be a dual-boot system with Windows and Linux. Run Windows for the gaming and the applications that aren't available on Linux and run Linux for internet browsing, e-mail, etc.

Another option is to use a cheap machine solely for the net and keep the important computer off the net or behind a secondary firewall -- only using the net for system updates and browsing extremely trusted sites.


15 posted on 12/28/2005 3:20:40 PM PST by MediaMole
[ Post Reply | Private Reply | To 7 | View Replies]

To: All
More detail:

Microsoft Windows WMF Handling Arbitrary Code Execution

***********************


Microsoft Windows WMF Handling Arbitrary Code Execution

Secunia Advisory: SA18255 Print Advisory  
Release Date: 2005-12-28

Critical:
Extremely critical
Impact: System access
Where: From remote
Solution Status: Unpatched

OS: Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Web Edition
Microsoft Windows XP Home Edition
Microsoft Windows XP Professional

Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.

Description:
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to an error in the handling of corrupted Windows Metafile files (".wmf"). This can be exploited to execute arbitrary code by tricking a user into opening a malicious ".wmf" file in "Windows Picture and Fax Viewer" or previewing a malicious ".wmf" file in explorer (i.e. selecting the file). This can also be exploited automatically when a user visits a malicious web site using Microsoft Internet Explorer.

NOTE: Exploit code is publicly available. This is being exploited in the wild.

The vulnerability has been confirmed on a fully patched system running Microsoft Windows XP SP2. Microsoft Windows XP SP1 and Microsoft Windows Server 2003 SP0 / SP1 are reportedly also affected. Other platforms may also be affected.

Solution:
Do not open or preview untrusted ".wmf" files and set security level to "High" in Microsoft Internet Explorer.

16 posted on 12/28/2005 3:21:59 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MediaMole

I've been saying that for awhile also....not many people listening though!


17 posted on 12/28/2005 3:23:32 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 15 | View Replies]

To: MediaMole

or if you're just using your computer for web, email, mp3s, photos, etc. Get a mac mini for $500 and stop worry about all the spyware and viruses.


18 posted on 12/28/2005 3:27:38 PM PST by flashbunny (To err is human. But to really screw something up, have the government try to fix it.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Ernest_at_the_Beach

I'd imagine Javascript/ActiveX would need to be enabled for web sites to exploit the bug in IE but it doesn't say other than unregistering shimgvw.dll. That file doesn't even show up in Windows 98SE so I'm not sure if that OS is vulnerable, it appears to be XP and Windows 2003 Web Server only.


19 posted on 12/28/2005 3:28:48 PM PST by Reaganwuzthebest
[ Post Reply | Private Reply | To 1 | View Replies]

To: MediaMole

Yep...I run Debian Linux. Win-XP runs in VM-Ware on my workstation. I never touch the net with XP.


20 posted on 12/28/2005 3:39:37 PM PST by hiredhand (My kitty disappeared. NOT the rifle!)
[ Post Reply | Private Reply | To 15 | View Replies]

To: flashbunny

This kind of stuff is gonna drive a lot of people to Macs!


21 posted on 12/28/2005 3:40:15 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 18 | View Replies]

To: Company Man

Take a look at the link to the Washington Post and tell us if that is the workaround describe there..


22 posted on 12/28/2005 3:42:32 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Ernest_at_the_Beach; ShadowAce
Bttt...
23 posted on 12/28/2005 3:44:18 PM PST by tubebender (You can't make Chicken Soup from Chicken Poop...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Reaganwuzthebest

I would doubt they would even check Windows98.


24 posted on 12/28/2005 3:45:00 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 19 | View Replies]

To: Ernest_at_the_Beach
Windows users can protect themselves from this exploit by entering the following command:

Start - Run - regsvr32 /u shimgvw.dll

25 posted on 12/28/2005 3:46:26 PM PST by Company Man
[ Post Reply | Private Reply | To 1 | View Replies]

To: Company Man

Thanks!


26 posted on 12/28/2005 3:51:52 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 25 | View Replies]

To: Ernest_at_the_Beach

Aha! That is what I was working to remove from my boss' home computer. They use XP Home, but were running IE BUCK-NAKED! No firewall, no antivirus, no spyware protection, no nuthin. They just signed up for broadband and within an hour they were sporting that second photo of yours. The yellow picture on the black background is an overlay on the desktop.


27 posted on 12/28/2005 3:57:30 PM PST by Big Giant Head (I should change my tagline to "Big Giant Pancake on my Head")
[ Post Reply | Private Reply | To 6 | View Replies]

To: Ernest_at_the_Beach

If people would just read the screen they would not go much further. Bad grammar and misspelled words (see the screen shots above) should tip you off that you shouldn't click there.

We do computer repairs - it amazes me at the people who bring their computers in every month (and pay us 49 bucks) to get this crap removed. They click and download EVERYTHING! If it's free it MUST be OK!

We take in at least 490 bucks a week for this stuff.

Some folks just never learn or they don't want to learn.

Of course I am assuming that people who own computers will be able to determine bad grammar and misspelled words. Maybe I give too much credit....


28 posted on 12/28/2005 3:57:41 PM PST by msrngtp2002
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

bttt


29 posted on 12/28/2005 4:06:01 PM PST by shield (The fear of the LORD is the beginning of knowledge: but fools despise wisdom and instructions.Pr 1:7)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Company Man
What does "Start - Run - regsvr32 /u shimgvw.dll" accomplish?
30 posted on 12/28/2005 4:16:18 PM PST by DonnerT (What'cha gonna do when he comes for us, Bad Boy, Bad Boy?)
[ Post Reply | Private Reply | To 25 | View Replies]

To: Big Giant Head; msrngtp2002

ROFL!

See #27!


31 posted on 12/28/2005 4:16:27 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 27 | View Replies]

To: backhoe; Howlin; Brad's Gramma

fyi


32 posted on 12/28/2005 4:18:01 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 31 | View Replies]

To: DonnerT

I think it disables the Microsoft Picture and Fax viewer, which allegedly is used to infect you computer.


33 posted on 12/28/2005 4:35:25 PM PST by Abcdefg
[ Post Reply | Private Reply | To 30 | View Replies]

To: Lokibob

AVG rules!!!! Been using it for almost 2 years now. Finds and kills what norton and macafee miss, I have first hand experience. AVG and Microsoft's anti spyware are a powerful combination.


34 posted on 12/28/2005 4:37:14 PM PST by Imperialist
[ Post Reply | Private Reply | To 9 | View Replies]

To: Ernest_at_the_Beach
Thanks- Ill pass the info along.

People who write, or propagate, this trash should be flogged in public. And triple fined for lost time & damages.

35 posted on 12/28/2005 4:38:10 PM PST by backhoe (-30-)
[ Post Reply | Private Reply | To 32 | View Replies]

To: backhoe

This one looks like a money oriented enterprise!


36 posted on 12/28/2005 5:48:47 PM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 35 | View Replies]

To: backhoe
And it's not like MS can't afford it, either. :-)

People who write, or propagate, this trash should be flogged in public. And triple fined for lost time & damages.

37 posted on 12/28/2005 5:59:02 PM PST by Salo (He hath touched me with his noodly appendage. Ramen.)
[ Post Reply | Private Reply | To 35 | View Replies]

To: Ernest_at_the_Beach

More from Beta News:

'Really Bad' Exploit Threatens Windows
By Nate Mook, BetaNews
December 28, 2005, 1:30 PM
A new exploit has been discovered in the wild that affects fully patched Windows XP SP2 systems, according to reports by security firms F-Secure and Sunbelt. The malicious code takes advantage of a vulnerability in the WMF graphics rendering engine to automatically download and install malware.

WMF, or Windows Metafile, is a vector based image format used by Microsoft's operating systems. SHIMGVW.DLL is loaded to render the images and contains a flaw that opens the door for a malformed WMF image to cause remote code execution and potentially allow for a full system compromise.

Microsoft previously fixed a vulnerability affecting WMF and EMF files in November. That problem affected Windows 2000, XP and Windows Server 2003.

"We have a number of sites that we have found with this exploit. Different sites download different spyware. We only had a handful of websites using this new exploit but now we are seeing many more using this to install bad stuff. These image files can be modified very easily to download any malware or virus," said Alex Eckelberry, CEO of Sunbelt Software.

"I hit one site with a fully patched XP system last night and it was pretty intense -- it went right through and infected my machine."

F-Secure's Mika Pehkonen warned that, "Right now, fully patched Windows XP SP2 machines are vulnerable, with no known patch." The company is detecting the offending WMF files as W32/PFV-Exploit.A, .B and .C.

"Note that you can get infected if you visit a web site that has an image file containing the exploit. Internet Explorer users might automatically get infected. Firefox users can get infected if they decide to run or download the image file," Pehkonen added.

Microsoft has been notified of the issue and it could opt to issue an emergency patch, apart from its standard Patch Tuesday security bulletins. "We expect Microsoft to issue a patch on this as soon as they can," says F-Secure.

Sunbelt's Eckelberry echoes that sentiment: "Folks, I've seen it with my own eyes and this is a really bad exploit. Be careful out there."


38 posted on 12/28/2005 6:21:52 PM PST by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 1 | View Replies]

To: backhoe
People who write, or propagate, this trash should be flogged in public. And triple fined for lost time & damages.

I was thinking more along the lines of drawing and quartering and then mincing them into half inch cubes.

39 posted on 12/28/2005 6:44:16 PM PST by Swordmaker (Beware of Geeks bearing GIFs.)
[ Post Reply | Private Reply | To 35 | View Replies]

To: backhoe
People who write, or propagate, this trash should be flogged in public.

Are you talking about Microsoft programmers or the virus writers ?

40 posted on 12/28/2005 7:57:02 PM PST by staytrue (MOONBAT conservatives are those who would rather lose to a liberal than support a moderate)
[ Post Reply | Private Reply | To 35 | View Replies]

To: Ernest_at_the_Beach

This one is a really nasty one. One could get infected by just visiting a website with .WMF files.


41 posted on 12/28/2005 8:23:55 PM PST by Baraonda (Demographic is destiny. Don't hire 3rd world illegal aliens nor support businesses that hire them.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: staytrue
Are you talking about Microsoft programmers or the virus writers ?

How about including Microsoft management?

42 posted on 12/28/2005 8:45:30 PM PST by TechJunkYard
[ Post Reply | Private Reply | To 40 | View Replies]

To: MediaMole

"'m beginning to think that the best option for most people would be a dual-boot system with Windows and Linux. Run Windows for the gaming and the applications that aren't available on Linux and run Linux for internet browsing, e-mail, etc."

I'm running Linux, and Windows XP Pro in VMWare. No web surfing in Windows - office, etc. only. All data is saved to a Samba share on Linux. If Windows takes a dump, I replace the VMware image I'm using with a fresh copy.


43 posted on 12/28/2005 11:14:09 PM PST by adam_az (It's the border, stupid!)
[ Post Reply | Private Reply | To 15 | View Replies]

To: nnn0jeh

ping


44 posted on 12/28/2005 11:14:52 PM PST by kalee
[ Post Reply | Private Reply | To 1 | View Replies]

To: Company Man

Suggestions to change it to?

I can find the file type and all but don't comprehend the extended information that's displayed under "Advanced" tab where it's set to open with, etc.


45 posted on 12/29/2005 3:42:22 AM PST by MillerCreek
[ Post Reply | Private Reply | To 8 | View Replies]

To: Reaganwuzthebest

I have Norton AV 2006 and have it selected to disable all ActiveX and Java. Can't see some content on the internet but that's the least of my worries.

When I NEED to interact with a TRUSTED, knowntobereliable site, I modify as necessary, but for general internet use, everyone should just disable those functions. And use "High" Internet security setting, AND use a few other trusted, reliable programs like Spybot Search & Destroy (which blocks a lot of spyware and malware and hacking attempts and will actually close down your browser if anything very terrible attempts to correspond)...

Most people are just far too available on the internet and that's why they have so many of these bugs. And their bugs become bugs for everyone else, so it's important for everyone to try to take control over security on their desktops.


46 posted on 12/29/2005 3:47:39 AM PST by MillerCreek
[ Post Reply | Private Reply | To 19 | View Replies]

To: flashbunny
or if you're just using your computer for web, email, mp3s, photos, etc. Get a mac mini for $500 and stop worry about all the spyware and viruses.

Better yet, save the five hundred and d/l a copy of Mepis Linux or Kubuntu. Both are idiot proof to install on every machine I have tried and easy enough to run that my technophobe wife has no problems at all with them. She now prefers linux to windows.

47 posted on 12/29/2005 4:09:58 AM PST by chronic_loser ((Handle provided free of charge as flame bait for the neurally vacant.))
[ Post Reply | Private Reply | To 18 | View Replies]

To: Ernest_at_the_Beach

What if you turn off your spyware detection alert?


48 posted on 12/29/2005 4:23:00 AM PST by wolfcreek
[ Post Reply | Private Reply | To 1 | View Replies]

To: MillerCreek
When I NEED to interact with a TRUSTED, knowntobereliable site, I modify as necessary, but for general internet use, everyone should just disable those functions.

That's good advice, on the Internet zone I always keep Javascript/ActiveX disabled, not only does it help protect users somewhat against exploits but you don't get popups either.

49 posted on 12/29/2005 5:00:05 AM PST by Reaganwuzthebest
[ Post Reply | Private Reply | To 46 | View Replies]

To: Reaganwuzthebest; MillerCreek; Cicero; Baraonda; backhoe; DonnerT; Abcdefg; Company Man
on the Internet zone I always keep Javascript/ActiveX disabled,

But this is a different exploit.....I don't think that helps with this one!

From Cicero's posting # 38 above......and see Company Man posting at #25.

***********************************************

A new exploit has been discovered in the wild that affects fully patched Windows XP SP2 systems, according to reports by security firms F-Secure and Sunbelt. The malicious code takes advantage of a vulnerability in the WMF graphics rendering engine to automatically download and install malware.

WMF, or Windows Metafile, is a vector based image format used by Microsoft's operating systems. SHIMGVW.DLL is loaded to render the images and contains a flaw that opens the door for a malformed WMF image to cause remote code execution and potentially allow for a full system compromise.

Microsoft previously fixed a vulnerability affecting WMF and EMF files in November. That problem affected Windows 2000, XP and Windows Server 2003.

50 posted on 12/29/2005 6:33:34 AM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 49 | View Replies]


Navigation: use the links below to view more comments.
first 1-5051-70 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson