Members Login
Username 
 
Password 
    Remember Me  
Post Info TOPIC: New Serious Windows Security Issue


Doesn't Do Windows



Status: Offline
Posts: 25589
Date:
New Serious Windows Security Issue



This is not a joke.

There is a new, very serious Windows security issue that was discovered just a few days ago but is already being exploited.

You can get in trouble just by viewing an infected image. This could be an image on a website or sent within an email.

At minimum, be very careful about the websites you visit and turn off image viewing in email until Windows comes out with a patch.

If you want to protect yourself, there is a command you can run to turn off the feature in Windows that the bad guys are using for this. Doing this command will make it so your computer will no longer display thumbnails of your pictures when you are browsing your system. There is also code to turn this back after Windows has provided a patch and you have updated. I am going to run this command myself.

This information comes from a very trusted site. If you want to protect your machine, This Site will show you how to turn this off and later back on.

You've been warned.




__________________




Grand Poobah

    



Status: Offline
Posts: 36897
Date:

aw dang it!   

__________________
"And like Web, I enjoy throwing JR under the bus.  Problem is, it's usually under the special bus that I ride every day". Ghostdancer 12-18-09


Doesn't Do Windows



Status: Offline
Posts: 25589
Date:


I just ran that command on my own machine here and it did indeed make it so I no longer see thumbnails but that feature is what this "virus" is using.



__________________




Grand Poobah

    



Status: Offline
Posts: 36897
Date:

I just checked out the security link at microsoft.com. All them folks must be off this week hey?

__________________
"And like Web, I enjoy throwing JR under the bus.  Problem is, it's usually under the special bus that I ride every day". Ghostdancer 12-18-09


2011 Super Bowl Champions!

Status: Offline
Posts: 29950
Date:

Thanks for the tip web.  An easy thing to turn off, and looks just as easy to turn back on later after the fix.  Very cool!


 



__________________


Doesn't Do Windows



Status: Offline
Posts: 25589
Date:


I have an update on this issue.

It turns out that the previous command that was given as a "fix" is only a "help" and doesn't completely fix the issue. That did originate from Microsoft.

There is now a 3rd party fix to this issue. It can be found back at This Site. If you ran the earlier command, you should turn that back on first with the instructions. Then download the fix from the link in the green box. That will install a program that will fix the hole and will make it so you can uninstall it later if you need to once Microsoft provides an update. This will fix the issue and make thumbnails work again. This does not work on Windows older than 2000. There is still no known fix on 98 and older.

I have ran this fix on my own machine here with no problems.

Again this is a serious issue. This is not your typical virus that you have to run to get infected. This comes through viewing a malicious image. With this left open, the bad guys can easily install anything he wants on your system by using a carefully coded image. Exploits are already being seen coming through email, web, pages, and now an MSN worm as well. As more people get infected, this is only going to spread faster.





__________________




2011 Super Bowl Champions!

Status: Offline
Posts: 29950
Date:

Web, you are the best!

It's like Freeze-Frame has it's very own IT department!

I downloaded the fix and my 'puter is now safe. Thanks man!

__________________
Anonymous

Date:

Thanks Web- I will do it when I get home!

__________________


Doesn't Do Windows



Status: Offline
Posts: 25589
Date:


I normally don't worry too much about viruses because our antivirus should be up to date and able to stop those. I can't stress enough how serious this one is. It could be as simple as one of the advertisers putting one of these carefully crafted images on this very page and installing software on your machine to do what ever they want it to.

One example is a "key logger". Someone could use this to install a program that sits in memory and records your every keystroke and periodically emails that back to the hacker. Then all they have to do is look through the file and find usernames and passwords that you are using to access your financial sites.

This one has me worried, and I expect we will see MAJOR damage done before it is stopped.



__________________




2011 Super Bowl Champions!

Status: Offline
Posts: 29950
Date:

Well, I honestly appreciate that you not only point out the fact there's a problem, but you even take the time to direct us to the fix.

Most of us don't keep up with all that stuff, and by the time we knew about it on our own it could very well be too late!

You've earned the "Best unpaid IT guy in America" award...

__________________


Doesn't Do Windows



Status: Offline
Posts: 25589
Date:

UPDATE: Microsoft has now patched this problem. It was in the update that took FFR off the air during the night.

If you have not ran the temporary fix, update your Windows now!

Edit: It still only fixes Windows 2,000 and higher. If you are still running '98, or lower you are still at risk and no patch has been created yet.





-- Edited by WebGuy at 10:24, 2006-01-06

__________________


Anonymous

Date:

Thanks I did last night!

__________________
Page 1 of 1  sorted by
 
Quick Reply

Please log in to post quick replies.

Tweet this page Post to Digg Post to Del.icio.us


Create your own FREE Forum
Report Abuse
Powered by ActiveBoard