pickwick, Calirto et 7 utilisateurs inconnus

 Mot :   Pseudo :  
 
Bas de page
Auteur
 Sujet :

Nouveau virus/exploit WMF - soyez sur vos gardes

 
n°9120
dstz
Posté le 04-01-2006 à 16:37:22  profilanswer
 

Vu sur un forum US, désolé si il y a deja eu un thread sur le sujet, je n'ai pas trouvé.
 
http://img336.imageshack.us/img336/5359/reptile34nr9jj.png
 
 

Citation :

UPDATE: Unofficial word from Microsoft is that the patch is DONE but it will be out January 10 as part of their regular schedule. They are testing it and localizing it for languages. Keep your Antivirus up to date and continue to follow the updated threat mitigation procedures below. If you are worried about new variations coming out faster than your Antivirus updates, see bullet point #9 for some temporary patches- both of which appear to remove the vulnerability.
 
 
WHAT IS IT?
There is a new exploit (with several variations) out that uses WMF (windows metafile format) files to infect a computer. The problem is in a file called GDI32.DLL, a part of Microsoft Windows that extracts information from WMF files. When a WMF file is created in a certain way, it can execute commands on the computer without a person's knowledge. The exploit makes use of this to take control of a computer and install spyware, log personal information, send spam, or any other conceivable thing.
 
 
WHAT DOES IT DO?
This exploit is so easy to modify that new versions are popping up constantly, making it hard to say exactly what a particular variation will do. The exploit can be used to drop viruses, trojans, installers etc onto your computer when the exploit is activated (when the file is parsed by the part of windows with the problem). It does not do anything by itself until it is activated. Most reports so far have been of trojans being downloaded, which then download other things, other spyware, etc. Some of these are "SpyAxe", "AYL" trojan downloader, "ASC" trojan, and other stuff. There are also reports of variations that will install a "keylogger" program to capture everything you type into the computer; variations that will shut off services (antivirus, for instance) on your computer; variations that use your comptuer to send spam, and so forth. Generally it can be said that whatever the exploit it used for, it's up to no good.
 
Here's a video of what one version is doing: http://www.websensesecuritylabs.com...s/wmf-movie.wmv (thanks Merijin).
 
(...)
 
 
HOW DOES IT SPREAD?
All you have to do to get infected is view a webpage that has the image on it, or access an infected image that is on your computer. It does not matter how the image ends up on your computer, just that it does. The file could also be a WMF renamed to any other image type, or possible other filetypes. Anything that puts the image exploit onto your computer or opens it up in windows fax viewer or the part of windows that generates thumbnails of WMF files is a vulnerability. This means any vector that puts the image onto your computer (wget, browser, email, IM, etc) can potentially cause the problem.
 
Current variations of the exploit are spreading using
- Fake instant messages telling you to click a link; clicking the link downloads or displays the picture
- Emails with a picture included or attached
- Web pages with the picture on them
- Anything else that could put your computer in contact with the image file

 
That means the forums can be a vector for infection too. (In fact, user Blue Reptile has already been permabanned for putting the exploit in his signature.)
 
 
WHO IS VULNERABLE?
This affects anyone on Windows (3.0, 3.1, 3.11, 95, 98, 98SE, ME, 2000, XP, 2003). The vulnerability is is Windows itself. Firefox, Internet Explorer, and any other browser that displayes or downloads the file into the cache on the local machine is one way the image can get onto your computer. Thus, USING FIREFOX DOES NOT ELIMINATE THE RISK as the file is still downloaded to your cache in most cases, but it does reduce your chances somewhat since the image is often not displayed in the browser. But if you then interact with the file in any way (thumbnail it, Google Desktop, hover over with the mouse) that causes it to be handled by the windows subsystem responsible for WMF then you will have problems. Once again, YOU CAN BE CAUGHT BY THIS EXPLOIT EVEN IF THE IMAGE DOES NOT SHOW IN THE BROWSER. If you use Windows, your system is vulnerable.
 
 
 
WHAT YOU CAN DO TO HELP PROTECT YOURSELF
1. SCAN YOUR COMPUTER - Update your defs and scan your comptuer. Even if you think you are safe, scan your Windows computer anyway. If you don't have antivirus software, NOD32 TRIAL VERSION is a good one and works as a trial for 30 days. Update the definitions right away after installing - they auto-update but you want to be sure you have the latest. I have personally tested NOD32 and found that it's AMON on-access scanner stopped the image as soon as it was saved to the cache, before it was able to execute anything.
 
Most AV companies should have definitions updated by now, but check to be sure that they protect against the actual exploit itself, not just against whatever trojan the exploit drops on the computer. NOTE: SCAN ALL FILES. Some AV solutions only scan "infectable" files and do not scan image files because the program thinks they are safe. Check for an option to scan all file types and make sure that is enabled.
 
Now that almost all AV software has some kind of definition for it, you can really use whatever you want and are comfortable with. So it's not like anyone is pushing you to go pay for NOD32 if you are already happy with what you have. There are still pros and cons to using each particular software.
 
Whichever AV you use, just make sure that:
1) You have your realtime scanner turned on for now, and
2) You set it to scan all files, including images (not just exe's anymore!), and
3) The AV software of your choice detects the actual exploit (all variations) and not just the payload it drops once activated.
 
 
2. USE AN ALTERNATIVE BROWSER - Using Firefox or an alternative browser will reduce your risk because it does not display the image. However the image is still downloaded to your cache, and some browsers prompt you to open the file - which you should not do!
 
3. TURN OFF SALR's feature that makes text links into images. If you have that feature turned on, someone could make just a text link that displays the infected image in your browser.
 
4. TURN OFF GOOGLE DESKTOP or anything else that does indexing of files on your computer.
 
5. USE COMMON SENSE - Don't go to links you don't trust, don't open files you aren't expecting, including suspicious email or IM's, etc.
 
6. KEEP ON TOP OF WINDOWS UPDATES - Hopefully they can fix this one quickly, but you really should be up-to-date on everything else anyway.
 
7. AVOID IMAGE SEARCHING and visiting webpages you don't trust. Some of the places this image has been popping up are: eBay XBOX auctions, porn sites, google image search, wikipedia, myspace, other forums, etc - places where people can post their own images. If you have a competent realtime scanner that can catch the image before it executes anything you are ahead of the game here.
 
 
BONUS TECHY STUFF
8. DISABLE WINDOWS THUMBNAILS - You can try unhooking the part of Windows that views those image files. To do this, click Start -> Run and type regsvr32 /u shimgvw.dll then press OK. You will get a confirmation message. To undo this, repeat but type regsvr32 shimgvw.dll instead. Note: This only has a minimal benefit - it only disables the image viewer itself. It doesn't prevent against viewing the exploit image in Internet Explorer, for example. Messing around with this is at your own risk
 
9. APPLY TEMPORARY PATCHES to fix the vulnerability in GDI32.DLL. There are two patches - choose only one to install. Forum user R1CH, the Ron Jeremy of Coding, has come up with a patched file that can eliminate the problem. Download R1CH's latest patch here and read the instructions within carefully before using. Ilfak Guilfanov, an Internet Security Expert™ has also produced a temporary patch. You install these patches at your own risk since it's not an official Microsoft patch. NOTE: ONLY INSTALL ONE OF THESE PATCHES. You will probably want to undo the patch right before applying the official Microsoft fix when it is released.
 
10. TEST/VERIFY IF YOU ARE SAFE - If you want to test that your temporary patch and/or antivirus is working, forum user R1CH, the Ron Jeremy of Coding, has created a test file that can do this for you. THIS IS NOT AN EXPLOIT, IT IS A TEST THAT R1CH CREATED. "Here's a sample, safe exploit to determine whether you are vulnerable (shutdown dialog) or patched (simple crash/nothing): http://r-1.ch/test.wmf " WARNING: If your antivirus does not catch this, and the shutdown dialog pops up, then you will have to go to Start -> Run -> type shutdown -a and press ENTER before the timer expires, or your computer will reboot.
 
 
 
BOTTOM LINE: If you use Windows, you will not be 100% safe from this exploit until the problem in windows is patched - there is no official patch yet.


 
 
edit:
infos et patch non officiel + peut-être le patch officiel qui aurai leaké: http://www.grc.com/sn/notes-020.htm


Message édité par dstz le 04-01-2006 à 16:42:51
n°9121
Arl-Guhr
kan g faim je mange
Posté le 04-01-2006 à 18:45:54  profilanswer
 

j prefere prendre le risque d'attendre un patch via win update  
 
 [:taiste]


---------------
il s'appel le ronge me doute
n°9122
dstz
Posté le 04-01-2006 à 19:05:28  profilanswer
 

Vi je comprend, en attendant les conseils habituels s'imposent, plus le fait de configurer son AV pour scanner les images en temps réel (ce qui n'est pas forcement le cas par défaut).

n°9123
sebx
boulet cherche canon
Posté le 04-01-2006 à 22:11:40  profilanswer
 

le winupdate est planifié pour le 10  ;)


---------------
Célibataire & béhémiste de service
Gentil Organisateur des rencontres matbe
JH 27 ans, bon salaire, propriétaire, roulant en berline Allemande cherche femme pour mariage, bébés et + si affinités
n°9124
LostSoul
Aventurier casqué
Posté le 05-01-2006 à 07:25:41  profilanswer
 

de toute façon y'a que les idiots qui ouvrent des wmf douteux ... et y'a aussi que les idiots qui utilisent media player


---------------
(pas de signature ce jour)
[ www.in-wonderland.net | www.start64.com | www.majorgeeks.com ]
n°9125
swimcoyote
Taliban emmental
Posté le 05-01-2006 à 07:38:01  profilanswer
 

LostSoul a écrit :

de toute façon y'a que les idiots qui ouvrent des wmf douteux ... et y'a aussi que les idiots qui utilisent media player


 
???
 
Pasque les média player cay mal ?  [:bbloup:3]  

n°9126
sebx
boulet cherche canon
Posté le 05-01-2006 à 08:47:32  profilanswer
 

il est très bien media player  :heink:
 
j'ai teste VLC pendant les vacances... ben je l'utilisais juste pour la télé de free parce que sinon, c'est pas vraiment une réussite le brol...


---------------
Célibataire & béhémiste de service
Gentil Organisateur des rencontres matbe
JH 27 ans, bon salaire, propriétaire, roulant en berline Allemande cherche femme pour mariage, bébés et + si affinités
n°9127
dstz
Posté le 05-01-2006 à 09:26:02  profilanswer
 

Petite précision on ne parle pas des *WMV mais des *WMF. Nuance.  
( http://filext.com/detaillist.php?e [...] rch=Search )
 
 
Puisqu'on est parti HS: avec bsplayer, media player classic et vlc il n'y a pas de raison d'utiliser wmp, et c'est tant mieux. De la a dire que seuls les idiots utilisent wmp je ne le ferais pas. Le monde ne s'arrête pas a matbe et battlefield 2.

n°9129
swimcoyote
Taliban emmental
Posté le 05-01-2006 à 11:18:58  profilanswer
 

sebx a écrit :

il est très bien media player  :heink:
 
j'ai teste VLC pendant les vacances... ben je l'utilisais juste pour la télé de free parce que sinon, c'est pas vraiment une réussite le brol...


 
Niveau compatibilité y'a rien de mieux.  
 
Genre le codec à deux balles ou les association de codecs merdiques que ni bsplayer ni mpc (et bien entendu ni winamp et ni WMP) n'arrive à lire correctement, et ben ca passe nickel sous vlc.
 
A l'inverse, j'ai jamais vu le cas ou quand vlc n'arrivais pas à lire qqchose, un autre player y arrivais.
 
Ce n'est que mon expérience perso, mais vu la bonne réputation du soft sur le web, je serais tenté de dire qu'il n'est pas aussi mauvais que tu le dit. Reste que son interface est nullissime et que pour se balader au sein des fichier c'est pas facile facile.

n°9130
sebx
boulet cherche canon
Posté le 05-01-2006 à 11:22:20  profilanswer
 

swimcoyote a écrit :

Ce n'est que mon expérience perso, mais vu la bonne réputation du soft sur le web, je serais tenté de dire qu'il n'est pas aussi mauvais que tu le dit. Reste que son interface est nullissime et que pour se balader au sein des fichier c'est pas facile facile.


 
c'est de ça que je parlais  :jap:
 
pour le reste, j'ai jamais eu une vidéo que wmp n'arrivait pas à lire donc je vois pas pourquoi je me servirais de VLC (à part pour la télé de free :/ )


Message édité par sebx le 05-01-2006 à 11:22:55

---------------
Célibataire & béhémiste de service
Gentil Organisateur des rencontres matbe
JH 27 ans, bon salaire, propriétaire, roulant en berline Allemande cherche femme pour mariage, bébés et + si affinités
n°9131
little
In vino veritas
Posté le 05-01-2006 à 11:27:12  profilanswer
 

LostSoul a écrit :

de toute façon y'a que les idiots qui ouvrent des wmf douteux ... et y'a aussi que les idiots qui utilisent media player


 
 
S'il existait pas il faudrait l'inventer ce Lost !   :lol:

n°9133
Baron
KAAMELOTT!
Posté le 05-01-2006 à 14:17:58  profilanswer
 

pour la première partie, il a totalement raison

n°9134
cruciforme
Artiste incompris
Posté le 05-01-2006 à 14:25:08  profilanswer
 

LostSoul a écrit :

de toute façon y'a que les idiots qui ouvrent des wmf douteux ... et y'a aussi que les idiots qui utilisent media player


Suffit qu'on te file une page web verolée je pense.


---------------
Avec un grand C.. Membre du Club des Nostalgiques d'EUROSPORT| Les recettes de ma copine - RTBF, je t'aime..
n°9154
rix
Posté le 05-01-2006 à 18:36:47  profilanswer
 

il y a un patch sur le  site de nod32  je lai télécharger ce matin ;-)  
http://www.nod32.lu/home/home.php


Message édité par rix le 05-01-2006 à 18:37:57
n°9161
schumacher
Posté le 05-01-2006 à 23:28:04  profilanswer
 

Correctif officiel disponible sur windowsupdate depuis ce soir.
 
Plus d'infos ici :
 
http://www.microsoft.com/technet/s [...] 6-001.mspx


Message édité par schumacher le 05-01-2006 à 23:28:21
n°9162
Ashe
reenignE esreveR
Posté le 05-01-2006 à 23:52:18  profilanswer
 

Cool, vais pouvoir ressortir mon CD de cliparts d'Office 95 :D


---------------
Globe trotter/SDF - Reims, France
Joy, beautiful spark of the gods, Daughter of Elysium, We enter fire imbibed, Heavenly, thy sanctuary.
Trombi Matbe
n°9170
sebx
boulet cherche canon
Posté le 06-01-2006 à 09:04:33  profilanswer
 

ça sert encore le wmf  :??:


---------------
Célibataire & béhémiste de service
Gentil Organisateur des rencontres matbe
JH 27 ans, bon salaire, propriétaire, roulant en berline Allemande cherche femme pour mariage, bébés et + si affinités

Aller à :
Ajouter une réponse