PDA

View Full Version : .ANI Microsoft Vulnerability


paranoidj
02-04-2007, 04:05 PM
https://forums.wow-europe.com/thread.html?topicId=268867360&sid=1

A recent vulnerability in Microsoft Windows has been brought to our attention. The vulnerability lies in the handling of malformed ANI files (files used for Animated Cursors). In order for this attack to be carried out, a user can simply visit a Web site hosting malicious code that exploits the vulnerability or view a specially crafted e-mail message or email attachment sent to them by an attacker.

As a best practice, players should always exercise extreme caution when opening or viewing, even in the preview pane, unsolicited emails and email attachments from both known and unknown sources. Also be wary of links contained in emails, posted to ANY forums, or provided on web sites.

It appears that Internet Explorer 6 and 7 running on a fully patched Windows XP SP2 and Vista are vulnerable to this attack. Windows XP SP0 and SP1 do not appear to be vulnerable, nor does Firefox 2.0.

Microsoft have posted the following Security Advisory regarding this:
http://www.microsoft.com/technet/security/advisory/935423.mspx

There are also posts regarding this on the McAfee Avert Labs Blog here:
http://www.avertlabs.com/research/blog/?p=230



Microsoft as of yet havnt released a hotifx for this vulnerability so it has high potential of being used to spread another wave of keyloggers since the exploit can be imbedded within a webpage. eEye have released a patch for the time being which should protect players from being effected by the exploit. You can download the patch from the link below.

http://research.eeye.com/html/alerts/zeroday/20070328.html

:D

Dark Matter
02-04-2007, 04:24 PM
<--Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3

Phew.

moopy
02-04-2007, 05:36 PM
But but.. it's all a conspiracy!!!! If you claim that IE is any more dangerous than other browsers, you must be a commie mutant traitor tree hugger!!!!one

..and so forth.

MixiMan
02-04-2007, 06:30 PM
I bet that was what changed my password yesterday :P

amgyn
02-04-2007, 08:03 PM
some more links on the news...
http://news.com.com/Attackers+exploit+zero-day+Windows+flaw/2100-1002_3-6172208.html

and the patch is going to be available this week from microsoft.. probably by tommorow...
http://news.com.com/Microsoft+to+issue+cursor+flaw+patch+early/2100-1002_3-6172364.html

sad thing is microsoft dev's knew about this in december, yet they didnt tackle it and patch it till somebody exploited it. :-/

ferofax
03-04-2007, 07:59 AM
...god bless the ammunition. firefox is the shiznit. internet explorer is like a really high wall with a gaping hole somewhere. you just gotta find it. =/

Gekothan
03-04-2007, 08:23 AM
...god bless the ammunition. firefox is the shiznit. internet explorer is like a really high wall with a gaping hole somewhere. you just gotta find it. =/

Nah, IE is more like a large, flimsy drywall that's had a tank drive through it :P

moopy
03-04-2007, 02:43 PM
sad thing is microsoft dev's knew about this in december, yet they didnt tackle it and patch it till somebody exploited it. :-/

That's quick by their standards. Some remote root holes have been in the wild and reported for 6-12 months before they fixed them. Last year, a fully patched IE was vulnerable many more days than it was safe.

Xlorep DarkHelm
03-04-2007, 04:37 PM
<--Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3

Phew.

Similar, except replace the "Windows" parts with "Linux" and we're all set.

Stigg
03-04-2007, 05:50 PM
I wonder if I can use this as an excuse as why I put a virus on my work computer...