Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Potential new unpatched IE exploit ? ~ Yes...may affect other Browsers also...
Websense Security Labs ^ | Dec 28 2005 11:19AM | Websense Security Labs Blog Staff

Posted on 12/28/2005 2:55:03 PM PST by Ernest_at_the_Beach

This alert is a follow-up to a post made yesterday on our blog: http://www.websensesecuritylabs.com/blog/

Websense® Security Labs™ has discovered numerous websites exploiting an unpatched Windows vulnerability in the handling of .WMF image files. The websites which have been uncovered at this point are using the exploit to distribute Spyware applications and other Potentially Unwanted Soware. The user's desktop background is replaced with a message warning of a spyware infection and a "spyware cleaning" application is launched. This application prompts the user to enter credit card information in order to remove the detected spyware. The background image used and the "spyware cleaning" application vary between instances. In addition, a mail relay is installed on the infected computer and it will begin sending thousands of SPAM messages.

We are currently tracking thousands of websites distributing exploit code from iFrameCASH BIZ. A similar zero-day vulnerability being exploited by this entity was discussed earlier this month:http://www.websensesecuritylabs.com/alerts/alert.php?AlertID=364

There is currently no patch available. Visiting an infected webpage with Internet Explorer on a fully-patched XP Service Pack 2 computer causes immediate infection. Earlier Firefox users are vulnerable but they are first prompted to display the WMF image. If a filesystem indexing service (such as Google Desktop) is installed, users of Firefox and even text-based browsers can become infected.

(Excerpt) Read more at websensesecuritylabs.com ...


TOPICS: Crime/Corruption; Extended News; Foreign Affairs; News/Current Events; Technical
KEYWORDS: backdoor; computer; exploit; exploits; firefox; internetexploiter; lookoutexpress; lowqualitycrap; malware; microsoft; openrelay; patch; security; securityflaw; spam; spamware; spyware; trojan; trojans; virus; windows; windowsxp; winfixer2005; wmf; worm; wrongtitle
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-70 next last
To: Ernest_at_the_Beach

This one is a really nasty one. One could get infected by just visiting a website with .WMF files.


41 posted on 12/28/2005 8:23:55 PM PST by Baraonda (Demographic is destiny. Don't hire 3rd world illegal aliens nor support businesses that hire them.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: staytrue
Are you talking about Microsoft programmers or the virus writers ?

How about including Microsoft management?

42 posted on 12/28/2005 8:45:30 PM PST by TechJunkYard
[ Post Reply | Private Reply | To 40 | View Replies]

To: MediaMole

"'m beginning to think that the best option for most people would be a dual-boot system with Windows and Linux. Run Windows for the gaming and the applications that aren't available on Linux and run Linux for internet browsing, e-mail, etc."

I'm running Linux, and Windows XP Pro in VMWare. No web surfing in Windows - office, etc. only. All data is saved to a Samba share on Linux. If Windows takes a dump, I replace the VMware image I'm using with a fresh copy.


43 posted on 12/28/2005 11:14:09 PM PST by adam_az (It's the border, stupid!)
[ Post Reply | Private Reply | To 15 | View Replies]

To: nnn0jeh

ping


44 posted on 12/28/2005 11:14:52 PM PST by kalee
[ Post Reply | Private Reply | To 1 | View Replies]

To: Company Man

Suggestions to change it to?

I can find the file type and all but don't comprehend the extended information that's displayed under "Advanced" tab where it's set to open with, etc.


45 posted on 12/29/2005 3:42:22 AM PST by MillerCreek
[ Post Reply | Private Reply | To 8 | View Replies]

To: Reaganwuzthebest

I have Norton AV 2006 and have it selected to disable all ActiveX and Java. Can't see some content on the internet but that's the least of my worries.

When I NEED to interact with a TRUSTED, knowntobereliable site, I modify as necessary, but for general internet use, everyone should just disable those functions. And use "High" Internet security setting, AND use a few other trusted, reliable programs like Spybot Search & Destroy (which blocks a lot of spyware and malware and hacking attempts and will actually close down your browser if anything very terrible attempts to correspond)...

Most people are just far too available on the internet and that's why they have so many of these bugs. And their bugs become bugs for everyone else, so it's important for everyone to try to take control over security on their desktops.


46 posted on 12/29/2005 3:47:39 AM PST by MillerCreek
[ Post Reply | Private Reply | To 19 | View Replies]

To: flashbunny
or if you're just using your computer for web, email, mp3s, photos, etc. Get a mac mini for $500 and stop worry about all the spyware and viruses.

Better yet, save the five hundred and d/l a copy of Mepis Linux or Kubuntu. Both are idiot proof to install on every machine I have tried and easy enough to run that my technophobe wife has no problems at all with them. She now prefers linux to windows.

47 posted on 12/29/2005 4:09:58 AM PST by chronic_loser ((Handle provided free of charge as flame bait for the neurally vacant.))
[ Post Reply | Private Reply | To 18 | View Replies]

To: Ernest_at_the_Beach

What if you turn off your spyware detection alert?


48 posted on 12/29/2005 4:23:00 AM PST by wolfcreek
[ Post Reply | Private Reply | To 1 | View Replies]

To: MillerCreek
When I NEED to interact with a TRUSTED, knowntobereliable site, I modify as necessary, but for general internet use, everyone should just disable those functions.

That's good advice, on the Internet zone I always keep Javascript/ActiveX disabled, not only does it help protect users somewhat against exploits but you don't get popups either.

49 posted on 12/29/2005 5:00:05 AM PST by Reaganwuzthebest
[ Post Reply | Private Reply | To 46 | View Replies]

To: Reaganwuzthebest; MillerCreek; Cicero; Baraonda; backhoe; DonnerT; Abcdefg; Company Man
on the Internet zone I always keep Javascript/ActiveX disabled,

But this is a different exploit.....I don't think that helps with this one!

From Cicero's posting # 38 above......and see Company Man posting at #25.

***********************************************

A new exploit has been discovered in the wild that affects fully patched Windows XP SP2 systems, according to reports by security firms F-Secure and Sunbelt. The malicious code takes advantage of a vulnerability in the WMF graphics rendering engine to automatically download and install malware.

WMF, or Windows Metafile, is a vector based image format used by Microsoft's operating systems. SHIMGVW.DLL is loaded to render the images and contains a flaw that opens the door for a malformed WMF image to cause remote code execution and potentially allow for a full system compromise.

Microsoft previously fixed a vulnerability affecting WMF and EMF files in November. That problem affected Windows 2000, XP and Windows Server 2003.

50 posted on 12/29/2005 6:33:34 AM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 49 | View Replies]

To: wolfcreek
What if you turn off your spyware detection alert?

Why would you do that?

This is a new exploit....see above!

51 posted on 12/29/2005 6:35:34 AM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 48 | View Replies]

To: Ernest_at_the_Beach
But this is a different exploit.....I don't think that helps with this one!

That's what I was looking for and didn't see. Microsoft will probably patch it by their next release so the safest course in XP till then would be to unregister the shimgvw.dll file and do all surfing in a restricted account.

52 posted on 12/29/2005 6:38:05 AM PST by Reaganwuzthebest
[ Post Reply | Private Reply | To 50 | View Replies]

To: Reaganwuzthebest

See #50 for some additional detail.


53 posted on 12/29/2005 6:40:21 AM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 19 | View Replies]

To: Reaganwuzthebest
This is criminal:

********************************************

From the Websense Security Labs Website:

December 24, 2005

  Phishing Alert:   Lansing Automakers Federal Credit Union

Alert Details Alert Detection Alert Prevention

Websense® Security Labs™ has received reports of a new phishing attack that targets customers of Lansing Automakers Federal Credit Union. Users receive a spoofed email, which claims that due to unauthorized access, their account access has been limited until further personal information is provided. The email provides users with a link to a fraudulent website, where they are prompted to enter their account and password.

This phishing site is hosted in Denmark and was up at the time of this alert.

Phishing email sample:

Dear LANSING AUTOMAKERS F.C.U. Customer,
      
We recently reviewed your account, and suspect that your LANSING AUTOMAKERS F.C.U. Internet Banking account may have been accessed by an unauthorized third party.
Protecting the security of your account and of the LANSING AUTOMAKERS F.C.U. network is our primary concern. Therefore, as a preventative measure, we have temporarily limited access to sensitive account features.
 
To restore your account access, please take the following steps to ensure that your account has not been compromised:
 
1. Login to your LANSING AUTOMAKERS F.C.U. Internet Banking account. In case you are not enrolled for Internet Banking, you will have to fill in all the required information, including your name and your account number.
 
2. Review your recent account history for any unauthorized withdrawals or deposits, and check you account profile to make sure not changes have been made. If any unauthorized activity has taken place on your account, report this to LANSING AUTOMAKERS F.C.U. Bank staff immediately.
 
To get started, please click the link below:

<LINK REMOVED> 
We apologize for any inconvenience this may cause, and appreciate your assistance in helping us maintain the integrity of the entire LANSING AUTOMAKERS F.C.U. Bank system. Thank you for attention to this matter.

Sincerely,
 LANSING AUTOMAKERS F.C.U. Team
 Please do not reply to this e-mail. Mail sent to this address cannot be answered. For assistance, log in to your LANSING AUTOMAKERS F.C.U. Bank account and choose the "Help" link in the header of any page.

Phishing screenshot:

 

54 posted on 12/29/2005 6:43:30 AM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 52 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...
OK. I'm late to this thread (I don't FReep during the evening lately).

Ping to those who haven't discovered it yet.

55 posted on 12/29/2005 6:50:09 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
This is criminal

Yup, a jail sentence of about 20 years ought to do it.

56 posted on 12/29/2005 7:03:09 AM PST by Reaganwuzthebest
[ Post Reply | Private Reply | To 54 | View Replies]

To: Ernest_at_the_Beach

Yes, I realize that this latest is a different exploit than in reference to the Java/ActiveX disablement mentioned earlier -- but I was (earlier, Java/AX) including a tangential security helps, that's all, that it's wise to have those two capabilities turned off, both in the browser and set to be suppressed by your firewall.


57 posted on 12/29/2005 7:03:55 AM PST by MillerCreek
[ Post Reply | Private Reply | To 50 | View Replies]

To: adam_az

Your browser setup sounds intriguing and yet, I don't understand most of it! Ha...you lost me after Windows XP Pro.

~;-D

I'll go look into "VMWare" and see if I can learn sumthin'.


58 posted on 12/29/2005 7:12:00 AM PST by MillerCreek
[ Post Reply | Private Reply | To 43 | View Replies]

To: Company Man

Question: How, if I wanted to, would I undo that command?


59 posted on 12/29/2005 7:21:45 AM PST by Clara Lou (A conservative is a liberal who has been mugged by reality. --I. Kristol)
[ Post Reply | Private Reply | To 25 | View Replies]

To: MillerCreek

VMWare is system virtualization software. In a nutshell, I have Windows XP running as a program INSIDE Linux. The entire Windows "filesystem" is just a few files inside Linux.


60 posted on 12/29/2005 7:22:06 AM PST by adam_az (It's the border, stupid!)
[ Post Reply | Private Reply | To 58 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-70 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson