Windows patch
Microsoft has published the patch for the WMF security hole. If you run Windows and you ever view images whose pedigrees you're not 100% certain of -- like, say, if you ever visit non-trusted web sites, or you view images people send you via email or IM -- you should apply this patch now. Don't wait for the automatic updates to run. (If you don't know what I'm talking about, you should read the security bulletin. Microsoft even admits it's a critical update.)
I'm going to leave LJ image placeholders turned on for a day or two, just in case this fix doesn't do it. (Image placeholders prevent posted images from automatically showing on your friends page, which is useful if you read any open communities where malicious images could be posted.)
I'm going to leave LJ image placeholders turned on for a day or two, just in case this fix doesn't do it. (Image placeholders prevent posted images from automatically showing on your friends page, which is useful if you read any open communities where malicious images could be posted.)
no subject
no subject
no subject
no subject
How the WMF bug works (simplified)
WMF files include the ability to run arbitrary code if the image fails to render correctly. This was an intentionally added feature so that, for example, if a program rendered a bad print job (as a WMF with canned error-handling code), the job could remove itself from the queue and/or warn the user that it hadn't rendered correctly. Insane today, but back in Windows 3.0 days (when the WMF format was designed and networking was an optional add-on), it was a clever hack. To exploit, just use an intentionally-mangled image, and include evil code as an "error handler" that's called when the image fails to render.
Some places (http://www.f-secure.com/weblog/archives/archive-012006.html#00000761) are assuming that we'll be seeing more WMF exploits because there are a few other ways to call code from a WMF file, and Microsoft has probably only fixed the specific function that's being exploited right now.
Re: How the WMF bug works (simplified)
no subject
no subject