Forum Sveta kompjutera

Nazad   Forum Sveta kompjutera > Test Run > Operativni sistemi
Uputstvo Članstvo Kalendar Današnje poruke Pretraži

Operativni sistemi Windows, Mac OS, DOS...

 
 
Alatke vezane za temu Vrste prikaza
Stara 15.1.2006, 18:29   #1
Highlander
information junkie
 
Avatar korisnika Highlander
 
Član od: 3.11.2005.
Lokacija: MAX Highlands
Poruke: 2.160
Zahvalnice: 616
Zahvaljeno 686 puta na 401 poruka
Slanje poruke preko MSN-a korisniku Highlander Slanje poruke preko Skypea korisniku Highlander
Određen forumom wmf rupa

Za one koji nisu znali, prenosim vam vesti o otkrivenoj rupi u Windowsu, koja može da se iskoristi za instaliranje virusa i kojekakvih mallware-a!
WHAT IS IT?
There is a new exploit out that uses WMF (windows metafile format) files to infect a computer. All you have to do to get infected is view a webpage that has the image on it. That means the forums can be a vector for infection tool
WHAT DOES IT AFFECT?
The exploit affects Firefox, Internet Explorer, and any other browser that downloads the file into the cache on the local machine. The file could also be a WMF renamed to any other image, or even a text filetype. Anything that puts the image exploit onto your computer or opens it up in windows fax viewer or the part of windows that generates thumbnails of WMF files is a vulnerability. This means any vector that puts the image onto your computer (wget, browser, email, IM, etc) can potentially cause the problem.
This affects anyone on Windows (98, 98SE, ME, 2000, XP, 2003). USING FIREFOX DOES NOT ELIMINATE THE RISK as the file is still downloaded to your cache in most cases, but it does reduce your chances somewhat since the image is often not displayed in the browser. But if you then interact with the file in any way (thumbnail it, Google Desktop) that causes it to be handled by the windows GDI responsible for WMF then you will have problems. Once again, YOU CAN BE CAUGHT BY THIS EXPLOIT EVEN IF THE IMAGE DOES NOT SHOW IN THE BROWSER. If you use Windows, your system is vulnerable.
WHAT DOES IT DO?
The exploit can be used to drop viruses, trojans, installers etc onto your computer when the exploit is activated (when the file is parsed by the part of windows with the problem). There have been several reports of trojans being downloaded, which then download other things, other spyware, etc. Some of these are "SpyAxe", "AYL" trojan downloader, "ASC" trojan, and other stuff.

Poslednja ispravka: Highlander (16.1.2006 u 10:25)
Highlander je offline   Odgovor sa citatom ove poruke
 

Bookmarks sajtovi


Vaš status
Ne možete postavljati teme
Ne možete odgovarati na poruke
Ne možete slati priloge uz poruke
Ne možete prepravljati svoje poruke

BB kod: uključeno
Smajliji: uključeno
[IMG] kod: uključeno
HTML kod: isključeno



Sva vremena su po Griniču +2 h. Sada je 23:37.


Powered by vBulletin® verzija 3.8.7
Copyright ©2000–2025, vBulletin Solutions, Inc.
Hosted by Beograd.com