ieXbeta Board: Sites Exploit Windows Image Flaw - ieXbeta Board

Jump to content

OS Topic Title Guidelines

Please preface your operating system topic titles as follows:

  • For Microsoft's Windows product line, use "[WIN]".
  • For Apple's Mac OS series, use "[MAC]".
  • For Linux distributions, use "[LNX]".
  • For customizations, use "[CSTM]".

Thank you.
  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Sites Exploit Windows Image Flaw Rate Topic: -----

#1 User is offline   Singh400 

  • Punjabi Shera
  • PipPipPipPipPip
  • Group: Retired Crew
  • Posts: 6370
  • Joined: 24-June 04
  • Gender:Male
  • Location:Earth
  • Interests:ermmmmm gettin drunk, havin a laff, and screwin up my skool computers :D

Posted 29 December 2005 - 03:16 PM

http://www.iexbeta.com/images/news/icons/view.gif Advisories: F-Secure Article | Sunbelt Article | Security Focus Article
http://www.iexbeta.com/images/news/icons/view.gif View: Full Article
http://www.iexbeta.com/images/news/icons/globe.gif News source: BBC News | Technology
0

#2 User is offline   Ely 

  • Member
  • PipPip
  • Group: Members
  • Posts: 311
  • Joined: 04-September 02

Posted 29 December 2005 - 04:26 PM

There's currently a momentary fix while Microsoft puts out a patch:

1.
Click Start, click Run, type "regsvr32 -u %windir%\system32\shimgvw.dll" (without the quotation marks), and then click OK.

2.
A dialog box appears to confirm that the un-registration process has succeeded. Click OK to close the dialog box.


Impact of Workaround: The Windows Picture and Fax Viewer will no longer be started when users click on a link to an image type that is associated with the Windows Picture and Fax Viewer.

To undo this change, re-register Shimgvw.dll by following the above steps. Replace the text in Step 1 with “regsvr32 %windir%\system32\shimgvw.dll” (without the quotation marks).

And here's Microsoft official statement:

http://www.microsoft...ory/912840.mspx
0

#3 User is offline   Singh400 

  • Punjabi Shera
  • PipPipPipPipPip
  • Group: Retired Crew
  • Posts: 6370
  • Joined: 24-June 04
  • Gender:Male
  • Location:Earth
  • Interests:ermmmmm gettin drunk, havin a laff, and screwin up my skool computers :D

Posted 29 December 2005 - 10:45 PM

@Ely, Thanks for the heads up on the fix.
0

#4 User is offline   madTaMsKi 

  • tehmad1
  • PipPipPipPipPip
  • Group: Retired Crew
  • Posts: 6076
  • Joined: 04-September 02
  • Gender:Male
  • Location:Glasgow, Scotland
  • Interests:Burdz!

Posted 30 December 2005 - 12:59 AM

Another impact of this de-registration process is that image thumbnails/explorer previews will no longer be displayed....

It's a bit of a pain in the ass, as I like these features, and to not have use of the Windows Picture and Fax Viewer is crap too! :(

Hopefully MS will close this hole soon <_<
0

#5 User is offline   Jizzylax 

  • It's Butters!
  • PipPipPipPipPip
  • Group: Members
  • Posts: 6847
  • Joined: 25-October 02
  • Gender:Male
  • Location:C-Bus, Ohio

Posted 30 December 2005 - 02:20 AM

WOW i feel so insecure! if i just so happen to go to one of these few websites on the billions of websites to choose from on the internet, i guess i'd be screwed! oh but what are the odds of that? not very great. MEH.
0

#6 User is offline   Ely 

  • Member
  • PipPip
  • Group: Members
  • Posts: 311
  • Joined: 04-September 02

Posted 30 December 2005 - 02:47 AM

View PostmadTaMsKi, on Dec 29 2005, 23:59, said:

Another impact of this de-registration process is that image thumbnails/explorer previews will no longer be displayed....

It's a bit of a pain in the ass, as I like these features, and to not have use of the Windows Picture and Fax Viewer is crap too! :(

Hopefully MS will close this hole soon <_<


Well you can still use Windows Picture & Fax viewer with no problem and you can continue to see all types of graphic files except for WMF types, yeah the thumbnails is a side effect, but hey its not really a big deal, and you can always instantly turn the feature ON or OFF, its not like you once you do it you cannot reverse it or have to reboot or something, its takes a second to register then de-register the .dll that's much better than risking to be infected, To give you an idea, you could get infected right here on this board if some bad person decides to embed an infected graphic on their post. So watch out!
Unregister the DLL is not a big deal.
0

#7 User is offline   madTaMsKi 

  • tehmad1
  • PipPipPipPipPip
  • Group: Retired Crew
  • Posts: 6076
  • Joined: 04-September 02
  • Gender:Male
  • Location:Glasgow, Scotland
  • Interests:Burdz!

Posted 30 December 2005 - 09:45 AM

@Ely, strange the Windows Picture and Fax viewer stopped working for me when I ran the above command :huh:
0

#8 User is offline   Quactaur 

  • Harder, Better, Faster, Stronger
  • PipPipPipPip
  • Group: Members
  • Posts: 1457
  • Joined: 02-June 04
  • Location:United Kingdom of Great Britain and Ireland

Posted 30 December 2005 - 11:52 AM

@MadTamski: same for me, too.

I'm using irfran view now, but its not as good as Win Pic/Fax for just flicking through images quickly.
0

#9 User is offline   Ely 

  • Member
  • PipPip
  • Group: Members
  • Posts: 311
  • Joined: 04-September 02

Posted 30 December 2005 - 04:02 PM

My bad, sorry guys it does indeed disable Windows Picture & Fax viewer, You can then use Irfanview while this thing is fixed or you simply register/de-register the .dll whenever you need to browse through pictures of faxes, Sorry for the missleading information guys.
0

#10 User is offline   XP_2600 

  • Version 5.1
  • PipPipPipPipPip
  • Group: Members
  • Posts: 3288
  • Joined: 09-September 02

Posted 01 January 2006 - 10:08 AM

Well, i dont mind to stop using Windows pictures and fax viewer i used to use ACDSee long time go, but i dont agree to disable thumbnail view, you lose one of the old important feature in any OS, i just wonder how is the exploit work ? is it related to the way which Windows use to handle and show images using shimgvw.dll? so how about another browsers for example is they use the same dll ? anyway how about the patch is it out yet ?
0

#11 User is offline   Singh400 

  • Punjabi Shera
  • PipPipPipPipPip
  • Group: Retired Crew
  • Posts: 6370
  • Joined: 24-June 04
  • Gender:Male
  • Location:Earth
  • Interests:ermmmmm gettin drunk, havin a laff, and screwin up my skool computers :D

Posted 01 January 2006 - 09:25 PM

This is now classified as exteremly criictal flaw. There is a new wmf exploit, MUCH worse than the one discovered on the 28th dec.

I would advise that everyone read the follow links, and visit them reguarly to keep themsevles updated.

http://isc.sans.org/...rss&storyid=996
http://www.f-secure.com/weblog/
http://www.microsoft...ory/912840.mspx
http://www.hexblog.c...2/wmf_vuln.html (unofficial patch)

recommened action: disable windows picture and fax viewer (link), and apply the unofficial patch.
0

#12 User is offline   Oleg 

  • n00b
  • Pip
  • Group: Members
  • Posts: 10
  • Joined: 27-December 05

Posted 01 January 2006 - 11:41 PM

Here Is hotfix http://sunbeltblog.b...guilfanovs.html
0

#13 User is offline   Singh400 

  • Punjabi Shera
  • PipPipPipPipPip
  • Group: Retired Crew
  • Posts: 6370
  • Joined: 24-June 04
  • Gender:Male
  • Location:Earth
  • Interests:ermmmmm gettin drunk, havin a laff, and screwin up my skool computers :D

Posted 01 January 2006 - 11:48 PM

@Oleg: Thanks for the heads up.
0

#14 User is offline   Oleg 

  • n00b
  • Pip
  • Group: Members
  • Posts: 10
  • Joined: 27-December 05

Posted 02 January 2006 - 05:16 AM

Here Is link to WMF Vulnerability checker: http://sunbeltblog.b...ty-checker.html
0

#15 User is offline   JDC 

  • jcbeyond
  • PipPip
  • Group: Members
  • Posts: 84
  • Joined: 05-September 02

Posted 04 January 2006 - 02:31 AM

hay people check out my link and the comments on Neowin.

http://www.neowin.ne...1#comment429164

This post has been edited by JDC: 04 January 2006 - 07:20 PM

0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users