Jump to content

Recommended Posts

Posted

I have downloaded the "unofficial" (but got out a heck of a lot quicker than M$) patch. Haven't tested it yet, but will do. SANS released it as an MSI- which is very handy indeed. And you can uninstall the patch *when* MS release a fix- which will be (they say) January 10th.

 

Bump.

 

I'm getting fed up with their excuses really.

 

Me.Close

 

Paul :-)

Posted
Posting from the safety of my Linux desktop box at the moment. There's already a lot of worms/trojans/adware floating about abusing this bug. Just what exactly is MS playing at?
Posted

You're right Geoff: this has really made me take stock. I have been using Mac OS and Ubuntu to surf from at home since hearing of this and until I have applied the *temporary* fix I won't be surfing with Windows. But really, this is just another straw that keeps snapping that old camel's back!

 

Aren't there something like 80 variants of the exploit out there already? Disgusting.

 

Paul :-(

Posted

I've tested and done a limited deployment of the unofficial patch. I also added a startup script to unregister the shimgvw.dll.

 

We already block .wmf on the proxy, but if it's a decision to between a peer-reviewed unofficial patch or wait for microsoft to provide a working patch - no contest. We'll be rolling out the unofficial patch tonight / next workstation reboot.

Posted

The official patch is out ... and tested

 

Took one known infected email and dropped it onto a virtual machine.

 

No problems at all ... will monitor over tonight and if ok will allow it through WSUS tomorrow.

Posted
Does it uninstall cleanly if you remove the GPO from the machines scope? (assuming your rolling it out with AD).

 

Yes: On a mix of 2K SP4, XP SP2 clients and AD2003. However, YMMV / may include nuts etc.

 

Probably should include this from SANS.org:

http://isc.sans.org/diary.php?rss&storyid=1018

 

We have received reports and researched an issue with Ilfak's patch AND/OR deregistering SHIMGWV.DLL causing printing issues.

De-registering SHIMGVW.DLL can cause printer issues. This has been verified.

 

Pedro a fellow SANS handler provided this:

"From Microsoft Windows Server 2003 Inside Out

By William R. Stanek The client first uses the print driver to partially render the document into EMF and then spools the EMF file to the print server. The print server converts the EMF file to final form and then queues the file to the printer queue (printer)."

 

ScottF another SANS handler states "I have seen a few new printing bugs...basically the printer spooler tray icon pops up and says there is an error and then prints without a problem" this was when SHIMGWV.DLL was deregistered.

It appears that Ilfak Guilfanov's patch can also cause printer problems.

 

Paul Shane reported

"It seems that users printing with Lotus 1-2-3 V5 for windows (yes...the old version), running on Windows XP, cannot print with the hexblog patch installed. As soon as the patch is uninstalled and the machine is rebooted, printing works."

 

Finally JimC another SANS handler writing about Ilfak's patch states:

"Actually, I guess this one doesn't surprise me too much. The "legitimate" use of the SETABORTFUNC Escape() call in gdi32.dll is for printing. We have heard of a couple of other widely scattered situations where some sort of printing function was disrupted by the unofficial patch.

 

Only a few cases of printer problems have been reported so far. Over 100,000 people have installed the patch and/or deregistered the shimgwv.dll.

I've tested and pushed out the official patch as well, but won't be removing the unofficial one until it's deployed.

Posted
We have shoved the official patch out today at work using WSUS (I still cannot believe it took 5 days to download all the updates to it (we downloaded everything, the works thats 58GB of updates). The kiddies are back next week, hopefully that is going to keep us virus free.
Posted

I deployed the official patch yesterday through WSUS and it installed just fine. It was good Microsoft responded earlier than their 10th January patch schedule.

 

There will be quite a few updates released on the 10th January though, so the patching for this month isn't over just yet!

Posted
Wonderful! I have already been driven round the twist with the popping up restart your computer now screen on my servers and workstations this week (just deployed WSUS over Crimbo so they are catching up with all the updates) and it sure gets annoying as you say later, and it is about 5 minutes later!. But lets hope this patch hold up
Posted
Wonderful! I have already been driven round the twist with the popping up restart your computer now screen on my servers and workstations this week (just deployed WSUS over Crimbo so they are catching up with all the updates) and it sure gets annoying as you say later, and it is about 5 minutes later!. But lets hope this patch hold up

 

You can use Group Policy to adjust this btw - just so you know ;)

 

I havent tho - it is annoying isn't it? lol :)

 

Left the fileserver restarting earlier thanks to pesky update needing restart hehe

 

Nath.

Posted
Excellent Nathan, I will look at that tomorrow, the old SUS was nicer in that way, as an admin we could say we will restart later, and a week later we could still have not restarted and we would never be told again, and thats how I want it for us admins, as I acidently shut down the mailserver today by accident by just hitting return on another program, but the update popup came over it and I was on the phone and looking at the door at the same time and next thing I saw was Outlook saying no server connection! Whoopse! Thank goodnes it only take 3 mins to come back up.
Posted

Due to certain matters i have at work, I'm thinking of scheduling a server restart later on when no one is about.

 

If i can schedule it after the script i have restarts all the XP workstations and when WSUS updates & installs the updates, then I'm on a winner.

 

The trouble is that it all takes sooo long - especially with a fairly long tape backup taking place too - so its gonna be difficult to juggle all these schedules.

 

Ah well... ;)

 

Nath.

Posted
I am lucky, my system backup went from about 13hrs a night down to about 1hr 15. You ask how I achieved this! By changing server! Thats it!!! My ultrium 1 is now working at full speed by swapping from a ML370G2 to a DL380G4. Its flying. As for restarts, I tend to hot restart them when assemblies are on or during lunchtime, the kids don't matter at lunch, the staff are key, so whilst they are eating, rebooting a couple will not harm anybody.
Posted

IMPORTANT!!!!!

 

The following websites http://stats4all.cc/ and http://stats4all.ws/ contain malicious code which exploits the recent Windows WMF vulnerability.

 

By checking SINA records revealed the address: http://stats4all.cc/fa/p1hWwY7jFLNnwA/expl1.wmf

 

The WMF filename and time detected matches that of Sophos which successfully detected and deleted the virus. This was on a system which already had the Official Microsoft patch applied. I'm unsure of the severity on unpatched systems, however for those of you with your own proxies, block these sites straight away!

Posted

If you read the thread most of us applied that patch or intended to a full week ago! It's probably not worth installing now since most if not all networks will be installing Microsoft's patch- also released a short time ago (no doubt in retaliation to the unofficial patch and media coverage of the exploit).

 

I'm still browsing at home with Ubuntu and OS X. With the exploit expanding I think this is something that will definitely haunt MS for a time.

 

Paul

Posted

Here's a snort rule (taken from Bleeding Snort) to pick up all known variants of the WMF exploit.

 

#by mmlange
alert tcp any any -> $HOME_NET any (msg:"BLEEDING-EDGE CURRENT WMF Exploit"; flow:established; content:"|01 00 09 00 00 03 52 1f 00 00 06 00 3d 00 00 00|"; content:"|00 26 06 0f 00 08 00 ff ff ff ff 01 00 00 00 03 00 00 00 00 00|"; reference: url,[url]www.frsirt.com/exploits/20051228.ie_xp_pfv_metafile.pm.php;[/url] classtype:attempted-user; sid:2002734; rev:1;)

# By Frank Knobbe, 2005-12-28. Additional work with Blake Harstein and Brandon Franklin.
# flow_depth (of http_inspect_server) has to be set to 0. Recommend second Snort instance with that config.
# Note that these rules will fail to detect the exploit when the HTTP response is gzipped.
# There is also a possibility for evasion, but a version that catches it will incurr massive amount of FPs.
#
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"BLEEDING-EDGE EXPLOIT WMF Escape Record Exploit - All Ports - v3"; flow:established,from_server; flowbits:isnotset,bleeding_wmf_expl; flowbits:isnotset,bleeding_wmf_expl_v1; content:"|00 09 00 00 03|"; content:"|00 00|"; distance:10; within:12; flowbits:set,bleeding_wmf_expl; flowbits:noalert; classtype:unknown; reference:url,[url]www.frsirt.com/english/advisories/2005/3086;[/url] sid:2002733; rev:7;)
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"BLEEDING-EDGE EXPLOIT WMF Escape Record Exploit - All Ports - v1"; flow:established,from_server; flowbits:isnotset,bleeding_wmf_expl; flowbits:isnotset,bleeding_wmf_expl_v1; content:"|00 09 00 00 01|"; content:"|00 00|"; distance:10; within:12; flowbits:set,bleeding_wmf_expl_v1; flowbits:noalert; classtype:unknown; reference:url,[url]www.frsirt.com/english/advisories/2005/3086;[/url] sid:2002759; rev:1;)

# Thes rules have to be there for both 
alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"BLEEDING-EDGE EXPLOIT WMF Escape Record Exploit - Version 1"; flowbits:isset,bleeding_wmf_expl_v1; pcre:"/\x26[\x00-\xff]\x09\x00/"; flowbits:unset,bleeding_wmf_http; flowbits:unset,bleeding_wmf_expl; flowbits:unset,bleeding_wmf_expl_v1; classtype:attempted-user; threshold:type limit, track by_src, count 1,seconds 120; reference:url,[url]www.frsirt.com/english/advisories/2005/3086;[/url] sid:2002758; rev:2;)
alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"BLEEDING-EDGE EXPLOIT WMF Escape Record Exploit - Version 3"; flowbits:isset,bleeding_wmf_expl; pcre:"/\x26[\x00-\xff]\x09\x00/"; flowbits:unset,bleeding_wmf_http; flowbits:unset,bleeding_wmf_expl; flowbits:unset,bleeding_wmf_expl_v1; classtype:attempted-user; threshold:type limit, track by_src, count 1,seconds 120; reference:url,[url]www.frsirt.com/english/advisories/2005/3086;[/url] sid:2002742; rev:5;)

Posted

It is unfortunate two new security issues have been found so soon after the WMF patch was released, however on a brighter note at least MS will patch it. If the problems are serious enough, I'm sure they'll release an out of cycle patch.

 

All these updates will be included in XP SP3 and of course Vista which'll hopefully be the last of this particular problem.

Posted

Well 2000 SP3 and later supports Automatic Updates just like XP, you can go to Microsoft Update or in a domain environment, 2000 can receive updates from SUS or WSUS. I don't see it's a major problem.

Microsoft will never release SP5, however they have released Update Rollup 1 for 2000 SP4 users. I believe at some point in the future they'll release Update Rollup 2, 3, 4...

 

As for W9x users I honestly think it's time to upgrade. I see no justification other than financial or specialised environments which require the use of such an old operating system.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...