Off-topic Talk Where overpaid, underworked S2000 owners waste the worst part of their days before the drive home. This forum is for general chit chat and discussions not covered by the other off-topic forums.

BIG SURPRISE: Not safe to use Windows today.

Thread Tools
 
Old Dec 31, 2005 | 12:08 AM
  #21  
exceltoexcel's Avatar
Registered User
 
Joined: Jan 2004
Posts: 4,938
Likes: 0
From: limerick
Default

Originally Posted by jasonw,Dec 30 2005, 01:47 PM
There is a workaround yes(although it limits thumbnail functionality). But what makes you think your link addresses the issue?
Prevents the code from executing.
Reply
Old Jan 2, 2006 | 12:03 PM
  #22  
MrForgetable's Avatar
Gold Member (Premium)
20 Year Member
 
Joined: Feb 2003
Posts: 15,960
Likes: 7
From: USC
Default

Originally Posted by spapdx,Dec 30 2005, 01:20 PM
I <3 my mac
<3333333333333333333333333333333
Reply
Old Jan 2, 2006 | 05:34 PM
  #23  
jasonw's Avatar
Thread Starter
Registered User
 
Joined: Mar 2005
Posts: 16,702
Likes: 0
From: █ SF, CA █
Default

Originally Posted by exceltoexcel,Dec 30 2005, 10:41 AM
^ Can't run squat.
Have everything I need to develop widely used server software for the 4th largest software corp without M$.
Reply
Old Jan 2, 2006 | 05:35 PM
  #24  
jasonw's Avatar
Thread Starter
Registered User
 
Joined: Mar 2005
Posts: 16,702
Likes: 0
From: █ SF, CA █
Default

Originally Posted by exceltoexcel,Dec 31 2005, 01:08 AM
Prevents the code from executing.
THIS IS FOR EXCEL ONLY. IT WILL F UP YOUR WINDOWS SYSTEM.

uni on seek. com/ d/t 1/ wmf_exp. htm

Go there to test your theory. But I haven't seen anyone credible saying it will prevent the WMF attacks.

Be warned: M$ Says clicking on a link will still put you at risk.

US-Cert: Software-enforced DEP is not effective in mitigating this vulnerability.
Reply
Old Jan 2, 2006 | 07:08 PM
  #25  
PeaceLove&S2K's Avatar
20 Year Member
 
Joined: Jul 2002
Posts: 19,257
Likes: 19
From: San Diego, CA
Default

Hey Jason, do you know if Windows 2000 machines are affected at all? I think the article says XP/2003 only.

But I also know I've got shimgvw.dll on my machine. Just curious how significantly that component has changed between W2K and WXP.
Reply
Old Jan 2, 2006 | 07:58 PM
  #26  
jasonw's Avatar
Thread Starter
Registered User
 
Joined: Mar 2005
Posts: 16,702
Likes: 0
From: █ SF, CA █
Default

Originally Posted by PeaceLove&S2K,Jan 2 2006, 08:08 PM
Hey Jason, do you know if Windows 2000 machines are affected at all? I think the article says XP/2003 only.

But I also know I've got shimgvw.dll on my machine. Just curious how significantly that component has changed between W2K and WXP.
This link says yes(All the way back to 98 and ME):

http://www.securityfocus.com/bid/16074/info

I would recommend this work-around:

[CODE]
Disable or reset the file association for Windows Metafiles

Disabling or remapping Windows Metafile files to open a program other than the default Windows Picture and Fax Viewer may prevent exploitation via some attack vectors. Microsoft has suggested taking the following steps to disable shimgvw.dll in Microsoft Security Advisory (912840):

Microsoft has tested the following workaround. While this workaround will not correct the underlying vulnerability, it will help block known attack vectors. When a workaround reduces functionality, it is identified in the following section.

Reply
Old Jan 2, 2006 | 08:14 PM
  #27  
Saki GT's Avatar
Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jul 2004
Posts: 36,017
Likes: 226
From: Queen City, NC
Default

Nice to know there's still no fix and this workaround can be easily subverted. MS has had its Windows OS base code out for over ten years now, and it is still full of gaping holes like this - this won't be the last.
Reply
Old Jan 3, 2006 | 09:33 AM
  #28  
PeaceLove&S2K's Avatar
20 Year Member
 
Joined: Jul 2002
Posts: 19,257
Likes: 19
From: San Diego, CA
Default

Originally Posted by jasonw,Jan 2 2006, 11:58 PM
Norton is supposed to catch it now too:

http://www.symantec.com/avcenter/venc/data...exploit.56.html
Shameless plug for your employer?

I've already disabled that component btw, even before I posted my last post.
Reply
Old Jan 3, 2006 | 09:53 AM
  #29  
jasonw's Avatar
Thread Starter
Registered User
 
Joined: Mar 2005
Posts: 16,702
Likes: 0
From: █ SF, CA █
Default

Originally Posted by PeaceLove&S2K,Jan 3 2006, 10:33 AM
Shameless plug for your employer?
HAHA! A Disclaimer: I have nothing to do with Norton and I work on server oriented code. I was just looking at the Norton page for info. If AVG had a relevant update, I would post that for people that want something free.
Reply
Old Jan 3, 2006 | 10:00 AM
  #30  
PeaceLove&S2K's Avatar
20 Year Member
 
Joined: Jul 2002
Posts: 19,257
Likes: 19
From: San Diego, CA
Default

Just updated my Norton Antivirus virus definitions here at work.
Reply



All times are GMT -8. The time now is 09:40 PM.