Zelaron Gaming Forum  
Stats Arcade Portal Forum FAQ Community Calendar Today's Posts Search
Go Back   Zelaron Gaming Forum > The Zelaron Nexus > Forum News, Suggestions and Discussion

 
 
Thread Tools Display Modes

 
Warning: Images can give you a virus (temp fix released)
Reply
Posted 2006-01-02, 06:49 PM
This is a general warning for those of you who don't keep up on this sort of thing.

SomethingAwful Forums said:
WHAT IS IT?
There is a new exploit out that uses WMF (windows metafile format) files to infect a computer. All you have to do to get infected is view a webpage that has the image on it, or access an infected image that is on your computer. That means the forums can be a vector for infection too.

WHO IS VULNERABLE?
The exploit affects Firefox, Internet Explorer, and any other browser that displayes or downloads the file into the cache on the local machine. The file could also be a WMF renamed to any other image type, or possible other filetypes. Anything that puts the image exploit onto your computer or opens it up in windows fax viewer or the part of windows that generates thumbnails of WMF files is a vulnerability. This means any vector that puts the image onto your computer (wget, browser, email, IM, etc) can potentially cause the problem.

This affects anyone on Windows (98, 98SE, ME, 2000, XP, 2003). USING FIREFOX DOES NOT ELIMINATE THE RISK as the file is still downloaded to your cache in most cases, but it does reduce your chances somewhat since the image is often not displayed in the browser. But if you then interact with the file in any way (thumbnail it, Google Desktop, hover over with the mouse) that causes it to be handled by the windows subsystem responsible for WMF then you will have problems. Once again, YOU CAN BE CAUGHT BY THIS EXPLOIT EVEN IF THE IMAGE DOES NOT SHOW IN THE BROWSER. If you use Windows, your system is vulnerable.

WHAT DOES IT DO?
The exploit can be used to drop viruses, trojans, installers etc onto your computer when the exploit is activated (when the file is parsed by the part of windows with the problem). It does not do anything by itself until it is activated. There have been several reports of trojans being downloaded, which then download other things, other spyware, etc. Some of these are "SpyAxe", "AYL" trojan downloader, "ASC" trojan, and other stuff.
http://forums.somethingawful.com/sho...0&pagenumber=1
Old
Profile PM WWW Search
Grav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrow
 
 
Grav
 



 
Reply
Posted 2006-01-02, 06:57 PM in reply to Grav's post "Warning: Images can give you a virus..."
phew i guess opera is safe
Old
Profile PM WWW Search
Mantralord seldom sees opportunities until they cease to beMantralord seldom sees opportunities until they cease to beMantralord seldom sees opportunities until they cease to beMantralord seldom sees opportunities until they cease to be
 
 
Mantralord
 



 
Reply
Posted 2006-01-02, 06:59 PM in reply to Mantralord's post starting "phew i guess opera is safe"
"Any application that automatically displays a WMF image will cause the userÂ’s machines to get infected. This includes older versions of Firefox, current versions of Opera, Outlook and all current version of Internet Explorer on all versions of Windows."

Linux is immune, of course.
Old
Profile PM WWW Search
Grav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrow
 
 
Grav
 



 
Reply
Posted 2006-01-02, 07:10 PM in reply to Mantralord's post starting "phew i guess opera is safe"
Mantralord said:
phew i guess opera is safe

I use opera, but it still keeps a cache unless you set it at 0mb
Old
Profile PM WWW Search
Hades-Knight is neither ape nor machine; has so far settled for the in-between
 
 
Hades-Knight
 



 
Reply
Posted 2006-01-02, 07:12 PM in reply to Grav's post "Warning: Images can give you a virus..."
Is there anyway Microsoft can make an update that blocks this?
Old
Profile PM WWW Search
Dar_Win enjoys the static noises of ten television sets simultaneously tuned to 412.84 MHzDar_Win enjoys the static noises of ten television sets simultaneously tuned to 412.84 MHz
 
 
Dar_Win
 



 
Reply
Posted 2006-01-02, 09:51 PM in reply to Dar_Win's post starting "Is there anyway Microsoft can make an..."
Yeah, how can I make this not happen to me?
Old
Profile PM WWW Search
Jamesadin is neither ape nor machine; has so far settled for the in-betweenJamesadin is neither ape nor machine; has so far settled for the in-between
 
 
Jamesadin
 



 
Reply
Posted 2006-01-02, 09:54 PM in reply to Jamesadin's post starting "Yeah, how can I make this not happen to..."
Aside from some annoying .dll edits that could help temporarily? Wait for a patch and avoid questionable sites.

Don't worry, nobody here is clever enough to pull it off.
Old
Profile PM WWW Search
Grav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrow
 
 
Grav
 



 
Reply
Posted 2006-01-03, 04:34 AM in reply to Grav's post starting "Aside from some annoying .dll edits..."
I beg to differ.
Attached Images
File Type: jpg haxed.JPG (1.8 KB, 45 views)
Old
Profile PM WWW Search
!King_Amazon! simplifies with no grasp of the basics!King_Amazon! simplifies with no grasp of the basics!King_Amazon! simplifies with no grasp of the basics!King_Amazon! simplifies with no grasp of the basics!King_Amazon! simplifies with no grasp of the basics!King_Amazon! simplifies with no grasp of the basics!King_Amazon! simplifies with no grasp of the basics
 
 
!King_Amazon!
 



 
Reply
Posted 2006-01-03, 09:05 AM in reply to !King_Amazon!'s post starting "I beg to differ."
You bitch! I just had to reinstall win

::edit::

Damnit! I had to do it ag

::edit::

OMFG STOP FUCKING UP MY WINDOWS INSTALL, VIRUS!!1
D3V said:
This message is hidden because D3V is on your ignore list.
What is it they say about silence being golden?
Old
Profile PM WWW Search
Medieval Bob enjoys the static noises of ten television sets simultaneously tuned to 412.84 MHzMedieval Bob enjoys the static noises of ten television sets simultaneously tuned to 412.84 MHz
 
 
Medieval Bob
 



 
Reply
Posted 2006-01-03, 10:01 AM in reply to Medieval Bob's post starting "You bitch! I just had to reinstall win..."
Better not go to imageshack.com!

Get it! Image Shack! Images Hack! z0mg!
Old
Profile PM WWW Search
!King_Amazon! simplifies with no grasp of the basics!King_Amazon! simplifies with no grasp of the basics!King_Amazon! simplifies with no grasp of the basics!King_Amazon! simplifies with no grasp of the basics!King_Amazon! simplifies with no grasp of the basics!King_Amazon! simplifies with no grasp of the basics!King_Amazon! simplifies with no grasp of the basics
 
 
!King_Amazon!
 



 
Reply
Posted 2006-01-03, 04:10 PM in reply to !King_Amazon!'s post starting "Better not go to imageshack.com! Get..."
I remember reading something about this in a book, and how it was like the "be-all end-all" of viruses. And now it's happening. Creepy.


KagomJack said:
My girth isn't anything to bitch and moan about in long, elaborate paragraphs.
Old
Profile PM WWW Search
JRwakebord enjoys the static noises of ten television sets simultaneously tuned to 412.84 MHzJRwakebord enjoys the static noises of ten television sets simultaneously tuned to 412.84 MHz
 
 
JRwakebord
 



 
Reply
Posted 2006-01-03, 04:54 PM in reply to JRwakebord's post starting "I remember reading something about this..."
The end-all of viruses is Ice-9.
D3V said:
This message is hidden because D3V is on your ignore list.
What is it they say about silence being golden?
Old
Profile PM WWW Search
Medieval Bob enjoys the static noises of ten television sets simultaneously tuned to 412.84 MHzMedieval Bob enjoys the static noises of ten television sets simultaneously tuned to 412.84 MHz
 
 
Medieval Bob
 



 
Reply
Posted 2006-01-03, 05:57 PM in reply to JRwakebord's post starting "I remember reading something about this..."
Except that a virus can't work that way. In order to be classified as a virus, it has to be capable of self-propogation. This is a method usable for a trojan, which could in turn launch a virus.
Old
Profile PM WWW Search
WetWired read his obituary with confusionWetWired read his obituary with confusionWetWired read his obituary with confusionWetWired read his obituary with confusion
 
 
WetWired
 



 
Reply
Posted 2006-01-03, 06:18 PM in reply to WetWired's post starting "Except that a virus can't work that..."
Why the fuck does every exploit involving Windows "give the offender complete control of your PC?"
Old
Profile PM WWW Search
Grav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrow
 
 
Grav
 



 
Reply
Posted 2006-01-04, 11:30 AM in reply to Grav's post starting "Why the fuck does every exploit..."
Because M$oft = Satan?


KagomJack said:
My girth isn't anything to bitch and moan about in long, elaborate paragraphs.
Old
Profile PM WWW Search
JRwakebord enjoys the static noises of ten television sets simultaneously tuned to 412.84 MHzJRwakebord enjoys the static noises of ten television sets simultaneously tuned to 412.84 MHz
 
 
JRwakebord
 



 
Reply
Posted 2006-01-04, 03:37 PM in reply to JRwakebord's post starting "Because M$oft = Satan?"
JRwakebord said:
Because M$oft = Satan?
Bill Gates=Satan
M$soft= Worse than the US Gov =\
XBL: GreatThanatos69
Old
Profile PM WWW Search
Great-Thanatos is neither ape nor machine; has so far settled for the in-betweenGreat-Thanatos is neither ape nor machine; has so far settled for the in-between
 
 
Great-Thanatos
 



 
Reply
Posted 2006-01-04, 04:17 PM in reply to Great-Thanatos's post starting "Bill Gates=Satan M$soft= Worse than..."
Here's a temporary fix until the official patch is released.

http://www.hexblog.com/index.html

The fix should not interfere with the patch Microsoft eventually releases and can be removed afterwards.
Old
Profile PM WWW Search
Grav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrowGrav never puts off to tomorrow what can be done the day after tomorrow
 
 
Grav
 



 
Reply
Posted 2006-01-05, 10:08 AM in reply to Grav's post "Warning: Images can give you a virus..."
You must admit, it's all pretty clever. I wonder who thought it all up, putting trojans and whatever in WMF files?
Old
Profile PM WWW Search
Lenny simplifies with no grasp of the basicsLenny simplifies with no grasp of the basicsLenny simplifies with no grasp of the basicsLenny simplifies with no grasp of the basicsLenny simplifies with no grasp of the basicsLenny simplifies with no grasp of the basics
 
 
Lenny
 
 

Bookmarks

« Previous Thread | Next Thread »

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules [Forum Rules]
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -6. The time now is 11:38 PM.
'Synthesis 2' vBulletin 3.x styles and 'x79' derivative
by WetWired the Unbound and Chruser
Copyright ©2002-2008 zelaron.com
Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
This site is best seen with your eyes open.