Announcement

Collapse
No announcement yet.

Update on the WMF exploit.

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Update on the WMF exploit.

    Microsoft is in the early stages of testing it's patch but it is reported to not be available for download till early next week. In the mean time, here is a list of sites to block that the exploit uses to download spyware from.

    toolbarbiz[dot]biz
    toolbarsite[dot]biz
    toolbartraff[dot]biz
    toolbarurl[dot]biz
    buytoolbar[dot]biz
    buytraff[dot]biz
    iframebiz[dot]biz
    iframecash[dot]biz
    iframesite[dot]biz
    iframetraff[dot]biz
    iframeurl[dot]biz
    freecat[dot]biz

    Replace the [dot] with an actual dot. If you don't know how to block sites, with IE open, click Tools/Internet Options then click Security, restricted sites and then the Sites box on the right and enter them in.

    This is still not a "FIX" but can reduce your chances of getting it.

    If you live under a rock or are just not aware of the exploit, it is a nasty one. My employee set up a simulated system with an infected file and he said it infects you just as fast as the demonstration you may have viewed shows. Users can be infected simply by visiting a web site with an image file containing the WMF exploit. Internet Explorer users are at the greatest risk of automatic infection while Firefox and Opera browser users are prompted with a question whether they’d like to open the WMF image or not. They get infected too if they answer ‘Yes’.

    Matt

  • #2
    Re: Update on the WMF exploit.

    <font color="aqua">Thanks, Matt, much appreciated info! - [img]/images/graemlins/toast.gif[/img] </font>
    Dave ->

    "would someone answer that damn phone?!?!"

    Comment


    • #3
      Re: Update on the WMF exploit.

      Excellent. [img]/images/graemlins/toast.gif[/img] I've been following this nasty bastard ever since I heard about it from MichaelMadeja. My question is if there's any way to block those particular sites in Firefox. You mentioned that in Firefox, users are prompted with a question whether they'd like to open the WMF file or not. I've had it happen and I always hit NO!!!! No troubles so far, and I hope it stays that way... [img]/images/graemlins/eek.gif[/img]

      Comment


      • #4
        Re: Update on the WMF exploit.

        good deal, thanks!

        at first i thought the WMF stood for White Male/Female, so i thought it was a singles ad exploit.
        ...that taste like tart, lemon yogart

        Comment


        • #5
          Re: Update on the WMF exploit.

          matt, thanks for posting that. i feel for you guys.
          Sully Guitars - Built by Rock & Roll
          Sully Guitars on Facebook
          Sully Guitars on Google+
          Sully Guitars on Tumblr

          Comment


          • #6
            Re: Update on the WMF exploit.

            Thanks Matt for the heads up [img]/images/graemlins/toast.gif[/img]

            Comment


            • #7
              Re: Update on the WMF exploit.

              Phew....thank God none of my regular porn sites are on that list
              I live on the edge of danger facing life and death every single day.....then I leave her at home and go disarm bombs.

              Comment


              • #8
                Re: Update on the WMF exploit.

                [ QUOTE ]
                <font color="aqua">Thanks, Matt, much appreciated info! - [img]/images/graemlins/toast.gif[/img] </font>

                [/ QUOTE ] +1 I did all that like you said. Anything else we should do?
                Scott
                Be without fear in the face of your enemies. Be brave and upright, that God may love thee. Speak the truth always, even if it leads to your death. Safeguard the helpless and do no wrong.

                Comment


                • #9
                  Re: Update on the WMF exploit.

                  Thanks Matt, did that.

                  Comment


                  • #10
                    Re: Update on the WMF exploit.

                    Um, been living under a rock. What's with this?

                    Comment


                    • #11
                      Re: Update on the WMF exploit.

                      Your best advise is to stay away from a lot of web sites untill the real patch is released and whatever you do, do not open any WMF attachments to emails or click on any links in strange emails.

                      Keep your anti-virus up to date as often as you can but none of the major Anti-Virus providers claim to be able to block the WMF attacks.

                      Matt

                      Comment

                      Working...
                      X