+ Reply to Thread
Page 1 of 2 12 LastLast
Results 1 to 10 of 18
  1. #1
    Senior Member ItalianFamily's Avatar
    Join Date
    Dec 2005
    Location
    ITalia
    Posts
    152

    Lightbulb Exploit WMF exploit

    http://www.frsirt.com/exploits/20051...etafile.pm.php

    http://www.frsirt.com/exploits/20060...mpareto.pm.php


    Risk of Windows WMF attacks jumps 'significantly,' security firm warns
    'WMF exploitation has started to take off in the wild,' says an iDefense official

    There's more to this story:

    > Microsoft says 'wait for us' as WMF threat climbs
    > Windows WMF flaw: How to protect against attacks
    > Update: Microsoft patch for WMF flaw to be released Jan. 10
    > Malicious hackers exploit zero-day Windows flaw

    Related to this topic

    > Sidebar: CISOs Move Beyond Tech

    Additional Resources

    Security White Papers

    Exploring Spyware and Adware Risk Assessment

    This paper posits a working definition of spyware and adware, and considers several ways in which this definition allows the impact from the introduction of these ...

    More Security white papers
    Symantec's Antispyware Approach and Solutions:Empowering Organizations...
    Building Blocks of Transparent Web Security: Server-Gated Cryptography...
    Managing Complexity with Integrated Message Management

    Security Webcasts

    Cyber-Terrorism and Security

    In this webcast from Storage Networking World, author Dan Verton says corporations can be viewed as the weakest links in the country's infrastructure, and IT storage ...

    More Security webcasts
    Selling Security to the CFO

    Security Briefings

    Patch Management
    This executive bulletin discusses patch management strategies and related security issues. Also included are reports on wireless LAN security and training issues.

    Download this bulletin, for a limited time, compliments of PatchLink

    More Security briefings
    Spyware
    Building an Antivirus Defense
    The E-mail Security Imperative
    Our Hottest Security Tips

    News Story by Sharon Machlis

    JANUARY 01, 2006 (COMPUTERWORLD) - Attempts to exploit a flaw in Windows WMF files have "become increasingly serious over the past two days" with "significant developments ... in the past few hours," according to a New Year's Day alert issued by iDefense Inc.
    "Risk has gone up significantly in the past 24 hours for any network still not protected against the WMF exploit," it said.


    Attacks are carried out through a vulnerability in the way Windows XP and Windows Server 2003 handle corrupted Windows Metafile graphic files (see "Malicious hackers exploit zero-day Windows flaw"). So far, it appears that Windows Data Execution Prevention software or disabling Windows' shimgvw.dll file will block WMF attacks to date, according to iDefense.


    The HappyNY.A attack has been using an e-mail with the subject "happy new year" and includes the attached file HappyNewYear.jpg. That file, actually a hostile WMF file, installs the Bifrose backdoor Trojan in the victim's system when the file executes.


    Websense Security Labs says it is tracking "several dozen" Web sites seeking to use the WMF vulnerability. More information is available on the Websense blog at www.websensesecuritylabs.com/blog.


    "WMF exploitation has started to take off in the wild," iDefense spokesman Ken Dunham said in an e-mail statement. "Dozens if not hundreds of WMF exploiting sites are likely to be reported in the coming days and weeks.


    "A new, upgraded WMF exploit was posted to the public today and is highly functional," Dunham added.


    For more on this, see "How to protect against Windows WMF attacks".

  2. #2
    Senior Member ThemanBehindTheBars's Avatar
    Join Date
    Nov 2005
    Posts
    128
    yeah i have heard of this thing on secunia by the way any one knows how to compile the exploit code i mean wht is the language used to code the exploit at
    http://www.frsirt.com/exploits/20051...etafile.pm.php

  3. #3
    Member Natok's Avatar
    Join Date
    Dec 2005
    Posts
    41
    u cannot compile this one... its a module for metasploit framework...
    www.metasploit.org

    br

    Natok

  4. #4
    Senior Member -silent-'s Avatar
    Join Date
    May 2005
    Posts
    1,374
    yeah read about this on illmob.org the other day

    looks like they had to take there site down


    Due To Government Pressure The website will be taking a undetermined vacation... -Illmob staff
    00101101 01110011 01101001 01101100 01100101 01101110 01110100 00101101


  5. #5
    Senior Member ItalianFamily's Avatar
    Join Date
    Dec 2005
    Location
    ITalia
    Posts
    152

    Cool

    lol illmob.org problem govern I don't understand because thing treated the website illmob.org memory to have visited if I am not wrong it had many rat bacdoor
    Natok very interesting the WebSite metasploit.org

  6. #6
    Senior Member -silent-'s Avatar
    Join Date
    May 2005
    Posts
    1,374
    yeah i would never download anything from there

    it was a while back now when there was disccusion about illmob back-dooring there apps

    but have some intresting stuff on main page to read now and again
    00101101 01110011 01101001 01101100 01100101 01101110 01110100 00101101


  7. #7
    Senior Member
    Join Date
    Jun 2005
    Location
    one nation, under fraud
    Posts
    477
    rofl.. the whole site is still there, the only different is the index page had the govt. pressure message. they have tons of texts on various subjects. yeah i heard illwill has been under investigation for quite some time now regarding his attempts to sell the leaked windows source code to an undercover agent. anyone else heard about this? I believe I read it on CNN or some other news site during the summer. I'll post a link if I can find one.


  8. #8
    Senior Member ThemanBehindTheBars's Avatar
    Join Date
    Nov 2005
    Posts
    128
    wht is a metaspoit framework thing looks like you are talking a very advanced topic in here cool weird,, well how could i build the wmf file then???? anyone interested

    cheers:confused:

  9. #9
    hot rod
    Guest

    Microsoft Windows WMF Download and Exec Exploit

    ThemanBehindTheBars wht is a metaspoit framework thing looks like you are talking a very advanced topic in here cool weird,, well how could i build the wmf file then???? anyone interested cheers

    here is 1 you can compile in c++ and use.
    Attached Files Attached Files

  10. #10
    Junior Member
    Join Date
    Nov 2005
    Posts
    19
    Yep, very easy to use, hot rod!

    Also found this one (compiled, too) there:
    http://www.illmob.org/files/0day/wmf-maker.rar

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. the new phpbb exploit is cool
    By LttCoder in forum Off-Topic
    Replies: 9
    Last Post: 28-11-2006, 19:48
  2. Exploit - enter here it will take you to google!!
    By -silent- in forum Off-Topic
    Replies: 9
    Last Post: 30-07-2005, 00:59

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Search Engine Friendly URLs by vBSEO 3.6.0 ©2011, Crawlability, Inc.