1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Anti-Virus Protection for WMF Flaw Still Inconsistent

Discussion in 'Security and Privacy' started by charlesvar, 2006/01/01.

  1. 2006/01/01
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    http://www.eweek.com/article2/0,1895,1907102,00.asp

    I did run into one instance of this with NAV2005, it did catch it in IE's TIF.

    Haven't had any instances with NOD.

    Regards - Charles
     
  2. 2006/01/01
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0

  3. to hide this advert.

  4. 2006/01/01
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hi Jim,

    Are you using MS' Data Execution Prevention settings to affect all programs

    No I'm not, I'll enable on this OS and see what effect it has. I just read your post about it in my thread a few minutes ago.

    Ok, turned it on. So far no performance diferences. Up to now had the "essential" option turned on.

    Regards - Charles
     
    Last edited: 2006/01/01
  5. 2006/01/02
    SpywareDr

    SpywareDr SuperGeek WindowsBBS Team Member

    Joined:
    2005/12/31
    Messages:
    3,752
    Likes Received:
    338
  6. 2006/01/04
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Windows DEP works as it should on my (64-bit AMD) machine:
     
    Arie,
    #5
  7. 2006/01/04
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    The way I interpret the FAQ's from the following MSKB, DEP is not effective against the software aspects of this malware.
    http://www.microsoft.com/technet/security/advisory/912840.mspx
    However, most people seem to agree that Ilfak's patch does the job.
    http://www.grc.com/sn/notes-020.htm
    But note that things are moving very quickly and MS's own patch (earlier announced to be released Jan. 10) may already be available (though I cannot find the link and there is nothing on Windows Update).

    Arie--I cannot understand the significance of your attachment. Does it mean that DEP is blocking the use of Ilfak's patch? I have not seen this message on WinXP Pro SP2.
     
  8. 2006/01/04
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    From MS:
    Since I have a 64-bit AMD CPU I have hardware DEP.

    http://support.microsoft.com/kb/875352

     
    Arie,
    #7
  9. 2006/01/04
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    No, I haven't installed the patch. I would never install a 3rd party patch for my OS.

    It is blocking the buffer overflow that is used to test (by his test program) for the vulnerability.
     
    Arie,
    #8
  10. 2006/01/05
    SpywareDr

    SpywareDr SuperGeek WindowsBBS Team Member

    Joined:
    2005/12/31
    Messages:
    3,752
    Likes Received:
    338
    FWIW
    1. Both the Internet Storm Center and F-Secure have endorsed Ilfak Guilfanov's unofficial patch (posted above).
      MSNBC: Windows PCs face 'huge' virus threat
      http://msnbc.msn.com/id/10684853/

    2. The patch is reversable by removing it in Add/Remove Programs, "Windows WMF Metafile Vulnerability Hotfix ".

    3. http://www.grc.com/sn/notes-020.htm
    4. Ilfak Guilfanov is the main author of Interactive Disassembler Pro and arguably one of the best low-level Windows experts in the world.
     
    Last edited: 2006/01/05
  11. 2006/01/05
    charlesvar

    charlesvar Inactive Alumni Thread Starter

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    When I hit the test site for WMF - got warnings from ZAP, NOD and NAV and SSM. So haven't installed the patch either, I'll wait for MS's fix.

    With DEP turned on, not a peep with the test for this flaw, so I just turned it back to the default setting.

    For those that run ZA Pro v6.X - below is what the warning looks like:

    Regards - Charles
     
    Last edited: 2006/01/05
  12. 2006/01/05
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    MS have/will release a MFT patch today - Thursday Jan 5, earlier than planned and ahead of several other security updates next Tuesday.

    The security update will be available at 2:00 pm PT as MS06-001
     
  13. 2006/01/05
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.