Linked by Thom Holwerda on Wed 25th Jan 2006 21:16 UTC, submitted by Varg Vikernes
Thread beginning with comment 89727
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
"An exploit is not the same thing as allowing people to install viruses and such without user intervention.... which happens to be exactly what I said."
Yes it is, and yes it does.
I watched that video and I thought ... what a nightmare. I wonder how many people were extorted out of $39.95 a year by that.
How can you sleep at night running a Windows system exposed to the internet?




Member since:
2006-01-04
The WMF flaw allowed arbitrary code to be executed. There were sites in the wild actively exploiting this to install malware. If you used IE to visit such a site, you WOULD have malware installed with no interaction required.
Go see this video for yourself:
http://www.websensesecuritylabs.com/images/alerts/wmf-movie.wmv
Note that since WMF files can be embedded, the URL wouldn't need to show the WMF extension the way the one in the demo does. Everything after that point is fully automatic with a then-current XP SP2 box.