Home > Security News > New WMF worm in wild; unofficial fixes circulating
Security News:
EMAIL THIS

New WMF worm in wild; unofficial fixes circulating

By Anne Saita, News Director
02 Jan 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Finnish security firm F-Secure announced today a new worm that arrives in instant messages and directs gullible users to a malicious Web site, courtesy of the Windows Meta File flaw that made headlines last week. Meantime, security programmers continue to analyze the exploit to drum up their own fixes until Microsoft releases one.

The vulnerability, a design flaw in the way Windows handles its image files, stands a chance of becoming a huge headache this week as more refined exploits are released and enterprise users return from a long holiday break.

Originally designed to assist when a print job needed to be canceled during spooling, the function has been rigged by malicious coders to compromise machines running Windows XP (including those with the SP 2 patch installed), ME, 2000 and Windows Server 2003 by hiding malicious code on a Web page or e-mail containing .wmf files. Vendors reported last week that the flaw is primarily being used to sneak spyware onto computers.
Recent news coverage

Windows flaw now 'extremely critical'

Sony BMG settles DRM lawsuits

Some security experts initially downplayed the chance of an epidemic, given users must manually visit an infected page and the attackers must host the site. But exploit writers continue to find new ways to draw users to these vulnerable images, including what appears to be a worm burrowing through MSN Messenger lists, appearing as a message from familiar sources asking them to visit a site containing this partial file name: /xmas-2006 FUNNY.jpg, according to F-Secure's blog. The Helsinki-based company a day earlier warned of an e-mail containing an infected image called HappyNewYear.jpg. "When the HappyNewYear.jpg hits the hard drive and is accessed (file opened, folder viewed, file indexed by Google Desktop), it executes and downloads a Bifrose backdoor (detected by us as Backdoor.Win32.Bifrose.kt) from www[dot]ritztours.com," according to the blog. "Admins, filter this domain at your firewalls. It's going to get worse."

The Internet Explorer browser automatically views an infected image without warning, thus triggering the exploit. However, other competing browsers, such as The Mozilla Foundation's popular Firefox open-source browser, also is at risk since it's protections do little to prevent an infected image from opening, researchers report.

SANS's Internet Storm Center (ISC) on Monday took the unusual step of endorsing an unofficial fix being distributed via Russian programmer Ilfak Guilfanov's blog. "Browsing the Web was not safe anymore, regardless of the browser," Guilfanov wrote. "Microsoft will certainly come up with a thoroughly tested fix for it in the future, but meanwhile I developed a temporary fix - I badly needed it."

The programmer said his patch doesn't delete any functionality from the system, so all pictures will continue to be visible. He also cautioned that once Microsoft comes through with a patch, administrators should uninstall his fix. "This is a DLL which gets injected to all processes loading user32.dll," he explained. "It patches the Escape() function in gdi32.dll. The result of the patch is that the SETABORT escape sequence is not accepted anymore.

"I can imagine situations when this sequence is useful," he continued. "My patch completely disables this escape sequence, so please be careful. However, with the fix installed, I can browse files, print them and do other things."

ISC diary handlers also note other researchers racing to protect machines ahead of exploits such as the IM worm F-Secure announced on its blog today. Guilfanov's, as of now, appeared most popular. Handler Marcus Sachs also reminded enterprise security administrators to be careful when installing any fix. "Be sure to test the patch above before deploying it across an enterprise," he wrote. "While the handlers (including me) are running it on our own personal systems and it works as advertised, we can't vouch for any special software you might have in your own systems that could be disabled after the patch is installed."

Tags: Malware, Viruses, Trojans and SpywareEmail and Messaging Threats (spam, phishing, instant messaging)VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Malware, Viruses, Trojans and Spyware
How to defend against rogue DHCP server malware
New Trojan stealing FTP credentials, attacking FTP websites
Cybercriminals exploit Michael Jackson, Farrah Fawcett deaths
When BIOS updates become malware attacks
Antispyware buying guide for Indian enterprises
PCI compliance requirement 5: Antivirus
Hacker attack techniques and tactics: Understanding hacking strategies
Rootkit Hunter demo: Detect and remove Linux rootkits
Botnet threats and countermeasures
Conficker worm much smaller than feared

Email and Messaging Threats (spam, phishing, instant messaging)
Unified communications: Securing a converged infrastructure
Chained Exploits: How to prevent phishing attacks from corporate spies
3FN.net ISP shutdown interrupts spam campaigns
Swine flu outbreak results in spam pandemic
What does 'invoked by uid 78' mean?
Economy fuels malware, spam
Internet Explorer 8 includes a bevy of security features
Adobe JBIG2 exploits being spammed, IBM warns
Fierce competition prompted new Cisco email security options
Cisco brings email security appliances closer to SaaS
Email and Messaging Threats (spam, phishing, instant messaging) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
directory traversal  (SearchSecurity.com)
government Trojan  (SearchSecurity.com)
Kraken  (SearchSecurity.com)
man in the browser  (SearchSecurity.com)
polymorphic malware  (SearchSecurity.com)
RavMonE virus  (SearchSecurity.com)
RFID virus  (SearchSecurity.com)
Rock Phish  (SearchSecurity.com)
Zotob  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts