Jump to content


Windows Flaw Spawns Dozens Of Attacks


18 replies to this topic

#1 Donna

    Retired P2L Queen!

  • P2L Staff
  • PipPipPipPip
  • 12,330 posts
  • Gender:Female
  • Location:B.C Canada

Posted 03 January 2006 - 03:52 PM

Quote

A flaw in Microsoft's Windows Meta File has spawned dozens of attacks since its discovery last week, security experts warned Tuesday.

The attacks so far have been wide-ranging, the experts said, citing everything from an MSN Messenger worm to spam that attempts to lure people to click on malicious Web sites.

The vulnerability can be easily exploited in Windows XP with Service Pack 1 and 2, as well as Windows Server 2003, security experts said. Older versions of the operating system, including Windows 2000 and Windows ME, are also at risk, though in those cases the flaw is more difficult to exploit, said Mikko Hypponen, chief research officer at F-Secure.

"Right now, the situation is bad, but it could be much worse. The potential for problems is bigger than we have ever seen," Hypponen said. "We estimate 99 percent of computers worldwide are vulnerable to this attack."

More On This

========

Latest from Microsoft:
fix is still being tested and isn't expected to be released until next week

#2 _*Speed_*

  • Guests

Posted 03 January 2006 - 05:54 PM

Sounds scary and deadly :X. Hope its fixes soon. ;)

#3 Jamie Huskisson

    Retired P2L Staff

  • Members
  • PipPipPipPip
  • 3,648 posts
  • Gender:Male
  • Location:Nottingham, UK

Posted 03 January 2006 - 06:32 PM

and another bug there and another bug there, another bug gets hacked!

#4 Donna

    Retired P2L Queen!

  • P2L Staff
  • PipPipPipPip
  • 12,330 posts
  • Gender:Female
  • Location:B.C Canada

Posted 03 January 2006 - 08:16 PM

View PostJay, on Jan 3 2006, 03:32 PM, said:

and another bug there and another bug there, another bug gets hacked!

lol

You should have more control on your bugs Jay, ;) Oh wait UK Bugs are in danger as well, already showed you that.

#5 Silwolffe

    P2L Jedi

  • Members
  • PipPipPip
  • 707 posts
  • Gender:Male
  • Location:Florida, USA

Posted 03 January 2006 - 08:25 PM

Oh noes! Thanks for the heads up Donna! ;)

#6 ktd

    * Something Ain't Right *

  • Members
  • PipPipPip
  • 549 posts
  • Gender:Male

Posted 03 January 2006 - 09:28 PM

Is it just me or is almost every virus compatible with my computer? For once it's just not me with a big chance of getting a virus!

#7 syndrome

    P2L patient #4819

  • Twodded Staff
  • PipPipPipPip
  • 1,311 posts
  • Location:Nottingham, UK
  • Interests:Photoshop, Tennis, PS2, web design, CS:S

Posted 04 January 2006 - 05:08 AM

I've heard that if you are using IE then the file can just install itself after viewing a page with an infected image, if you are using Firefox then at least you get a dialog box asking if you want ot install the file.

I've also heard that some webmasters have been disabling sig banners on their forums incase on of them is infected.

#8 codie

    Jedi In Training

  • Members
  • PipPip
  • 474 posts
  • Location:New Zealand, Queenstown
  • Interests:Snow boarding, graphic design, computer games, GIRLS, going to movies, mountain biking, music, playing guitar, eating, traveling around the world and taking phtographs, thats all i can think of for now.

Posted 04 January 2006 - 05:26 AM

am i glad i sold my PC and got my mac :) ... no offence to windows users :D


better go warn my friends and turn off the PC upsatirs its neva used

#9 Donna

    Retired P2L Queen!

  • P2L Staff
  • PipPipPipPip
  • 12,330 posts
  • Gender:Female
  • Location:B.C Canada

Posted 04 January 2006 - 05:43 AM

View Postsyndrome, on Jan 4 2006, 02:08 AM, said:

I've heard that if you are using IE then the file can just install itself after viewing a page with an infected image, if you are using Firefox then at least you get a dialog box asking if you want ot install the file.

I've also heard that some webmasters have been disabling sig banners on their forums incase on of them is infected.

I wouldn't be surprised, they are taking this as pretty serious, if you have a forum and allow dymamic sigs I'd suggest disabling them asap.

So just be a little more cautious than normal.

========
codie, Macs are still very vunerable to viruses. :)

#10 adam123

    Retired P2L Staff

  • Members
  • PipPipPipPip
  • 2,306 posts
  • Location:London, UK
  • Interests:Programming and stuff.

Posted 04 January 2006 - 05:46 AM

just wait till vista comes and all will be fi...oh wait no it'll be just as bug ridden as XP :D *cough*linux*cough* :)

#11 codie

    Jedi In Training

  • Members
  • PipPip
  • 474 posts
  • Location:New Zealand, Queenstown
  • Interests:Snow boarding, graphic design, computer games, GIRLS, going to movies, mountain biking, music, playing guitar, eating, traveling around the world and taking phtographs, thats all i can think of for now.

Posted 04 January 2006 - 06:37 AM

Yes i know they are but this attack seems to be only windows based (or is it not)

i absolutly know tht macs get viruses as it has happnd to me once

#12 l3lueMage

    Wanna Be Moderator

  • Publishing Betazoids
  • PipPipPipPip
  • 4,596 posts
  • Gender:Male
  • Location:San Francisco Bay Area

Posted 04 January 2006 - 02:17 PM

Or you just get norton, Microsoft Spyware, ZoneAlarm Pro...and you should be safe...Thats what I have......atleast I think Im safe :ph34r:

#13 Donna

    Retired P2L Queen!

  • P2L Staff
  • PipPipPipPip
  • 12,330 posts
  • Gender:Female
  • Location:B.C Canada

Posted 04 January 2006 - 05:39 PM

View Postl3lueMage, on Jan 4 2006, 11:17 AM, said:

Or you just get norton, Microsoft Spyware, ZoneAlarm Pro...and you should be safe...Thats what I have......atleast I think Im safe :)

No you won't be safe, did you read the entire article? ;)

Take this as very serious and all precautions you can.

#14 Stu

    Retired P2L Staff

  • Publishing Betazoids
  • PipPipPipPip
  • 1,761 posts
  • Gender:Male

Posted 04 January 2006 - 09:38 PM

by the sound of things it doesnt look like there are any precautions we can take - apart from crossing our fingers :ph34r:

#15 Donna

    Retired P2L Queen!

  • P2L Staff
  • PipPipPipPip
  • 12,330 posts
  • Gender:Female
  • Location:B.C Canada

Posted 04 January 2006 - 09:40 PM

There is one they are kinda recommending

USE AT YOUR OWN RISK

http://www.hexblog.com/

A site hosting unauthorized protection against the Microsoft WMF flaw has been taken offline after being swamped by users trying to protect themselves from a growing list of threats.

Ilfak Guilfanov's personal Web site was switched off by his hosting provider on Wednesday morning after hordes of Microsoft users scrambled to download his unofficial patch against the Windows Meta File vulnerability, according to antivirus company F-Secure.

The site was temporarily closed as "half the planet tried to download WMFFIX_HEXBLOG.EXE." reported F-Secure in its blog.

At the time of writing, the unofficial patch is again available from Guilfanov's site. It's also available from the Sunbelt Blog.

Microsoft has advised businesses not to use the patch, as the company cannot guarantee it will work. But with no official patch due to be released until next week, security experts are urging businesses to use the unofficial patch because of the serious nature of the WMF vulnerability.

News Source

#16 InFnit

    P2L Jedi

  • Members
  • PipPipPip
  • 822 posts
  • Interests:My interests are my:<br><br>iidsite - http://iid.outer-heaven.net<br>iidblog - http://iid.outer-heaven.net/blog/<br>iidcommunity - http://iid.outer-heaven.net/forums/<br>P2L - http://www.pixel2life.com

Posted 05 January 2006 - 01:06 AM

View Postadam123, on Jan 4 2006, 10:46 AM, said:

just wait till vista comes and all will be fi...oh wait no it'll be just as bug ridden as XP :ph34r: *cough*linux*cough* :ph34r:

I believe Vista is based on the 2003 platform not XP....meaning they would have learned from their mistakes with XP. Plus this time they are being 'transparent' meaning more bugs will be spotted before releasing to the public.

I have nothing to say about this virus except, "How sad"

#17 Canen Art

    P2L Staff

  • P2L Staff
  • PipPipPipPip
  • 1,494 posts
  • Gender:Male
  • Location:Utah, USA
  • Interests:I love taking photos of nature. That includes everything from the little bugs and animals all the way to natures beautiful landscapes.

Posted 05 January 2006 - 06:50 AM

Thank you for the heads up Donna.

Regards,

Jason :)

#18 _*Speed_*

  • Guests

Posted 05 January 2006 - 07:45 PM

I believe its patched now right?

#19 Jaymz

    Retired P2L Staff

  • Members
  • PipPipPipPip
  • 4,104 posts

Posted 05 January 2006 - 08:05 PM

http://www.pixel2life.com/forums/index.php...topic=17732&hl=

Official Microsoft patch released. Topic closed as this is solved ;)





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users