Exploitation of Windows WMF on the web

2005-12-28 Thread Daniel Bonekeeper
*** PAY ATENTION BEFORE CLICK ON ANY LINK ON THAT MESSAGE *** I don't know if this thing is already known, but I just got this when I was "navigating" on a certain website. It was a sucession of hidden from diferent domains, ending on: http://69.50.183.34/m.html It will then call another frame,

Re: Exploitation of Windows WMF on the web

2005-12-30 Thread psgw
If you have the latest Norton Defintions you will not be ale to save the WMF file to your hard drive. It will be detected as being infected with "Bloodhound.Exploit.56" http://securityresponse.symantec.com/avcenter/venc/data/bloodhound.exploit.56.html