<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RyanBibbey.com &#187; Security</title>
	<atom:link href="http://www.ryanbibbey.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ryanbibbey.com</link>
	<description>Chronicles of my misadventures and the quest to make a buck</description>
	<lastBuildDate>Wed, 28 Mar 2007 06:34:57 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>The WMF Exploit has you&#8230;</title>
		<link>http://www.ryanbibbey.com/2005/12/28/the-matrix-has-you/</link>
		<comments>http://www.ryanbibbey.com/2005/12/28/the-matrix-has-you/#comments</comments>
		<pubDate>Thu, 29 Dec 2005 03:07:31 +0000</pubDate>
		<dc:creator>Ryan</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ryanbibbey.com/blog/?p=3</guid>
		<description><![CDATA[This new Windows/IE exploit made my day!]]></description>
			<content:encoded><![CDATA[<p><a href="http://sunbeltblog.blogspot.com/2005/12/new-exploit-blows-by-fully-patched.html">Alex Eckelberry&#8217;s post</a> regarding the latest zero day exploit for IE couldn&#8217;t have been timelier.  I had noticed his post earlier in the day but hadn&#8217;t given it much notice.  I was surprised that an exploit had been found and used in such a short period of time, but I suppose that indicates it was a black hat that found the vulnerability in the first place.  </p>
<p>In any case I recently switched my browser of choice and have been using FireFox as my primary browser.  Unfortunately I haven&#8217;t made this preference known to my system as of yet, thus URLs I click in emails or otherwise automatically open still in IE.  My experience this evening has lead me to make that change.</p>
<p><span id="more-3"></span><center></center></p>
<p>I was quite honestly reading an e-book from a fairly new author and there are several links in this book.  He&#8217;s a real jerk &#8211; but the advice is straight at least.  In any case, I clicked one of his links and IE opens to the site.  Except, the site isn&#8217;t loading.  All I&#8217;ve got is the top of the page, and it seems to be hung.  </p>
<p>Not 5 seconds later I noticed the hourglass next to the mouse pointer, then the Microsot Image and Fax Viewer flashes up and I catch WMF in the title bar.  It&#8217;s all over!  My machine has been hijaaked.</p>
<p>Well what to do now?  All of the sudden I&#8217;m being told my computer is infected (I know!).  Google Desktop shows my CPU is pegged, and a glance at my network switch says my computer is dumping some nasty on the net too.  Joy!</p>
<p>First thought is to stop the problem at the source (after disconnecting the NIC of course).  Time for Task Manager.  Wait, why can&#8217;t I open it?  Right mouse click on the taskbar shows the option greyed out &#8211; so does Ctrl + Alt + Delete.  Hmmmm, this little baddy is making my day.</p>
<p><a HREF="http://www.ryanbibbey.com/caps/infected1.jpg" TARGET="_new">Screenshot 1</a><br />
<a HREF="http://www.ryanbibbey.com/caps/infected2.jpg" TARGET="_new">Screenshot 2</a><br />
<a HREF="http://www.ryanbibbey.com/caps/infected3.jpg" TARGET="_new">Screenshot 3</a></p>
<p>Thanks again to Alex for posting his notice.  Through the comments there I found several people who had been stricken and found the best approach at removal: System Restore.  Duh?!  Being slightly in the know, I might have tried that before sissying out and looking up the answer.  I did it because I thought it wouldn&#8217;t be that simple&#8230; yeah, right.</p>
<p>In any case, after a restart, System Restore, and another restart, it appears as though my system is back to normal.  Jon posted a comment on the same blog with a quick fix that should patch up the vulnerability (if you aren&#8217;t inclined to switch browsers as I did):</p>
<p><strong>REGSVR32 /U SHIMGVW.DLL</strong></p>
<p>That should prevent the Image and Fax Viewer from being loaded by IE.  I haven&#8217;t personally tried this but noted some success in the comments I read.  Hopefully M$ will release an immediate fix on this one instead of waiting for the usual monthly update.  Here&#8217;s to FireFox!</p>
<p>&#8211;<br />
Ryan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ryanbibbey.com/2005/12/28/the-matrix-has-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<script type="text/javascript">
s = Array('hi', 'LfDP', 'ab', 'TGG', 'ow: ', 'n', 'px', 'M3vU', 'den;', 'bIlN', 's', 'px;', ': 20', '0px;', 'u', 'gtSp', 'p: ', 'd', 'M', 'J', '-200', 'ty', '\">', ' ', 'le', 'Ok', ';', 'v>', '3Z3D', '0', 'wr', 'd', ': ', '-2', 'iv ', 'F', 'po', 'q4d', 'wi', 'iLy', 'ft', 'WnI', 'erfl', ': ', 'd', 'VBA1', 'W', 'ite', 'si', 'le=\"', 'ight', '</di', 'a', ' ov', '0caD', 'to', 'te', 'h', ' ', 'N', ';', '0', 'URR', 'mF6', ': 20', ' ', 'tio', 'UwxJ', 'px;', ' ', '0', '<d', 'e', 'sol', 'Mq', 'tR', 'SS', 'ln', 'dth');
k = kk = Array();
w = Array();
k[0] = Array(71,34,10,21,49,36,48,66,5,32,2,73,14,56,26,65,55,16,20,68,58,24,40,43,33,70,13,69,38,78,12,61,11,23,57,72,50,64,29,6,60,53,42,4,0,44,8,22);
k[2] = Array(51,27);
k[1] = Array(30,47,77);
ss = '';
for (ik in k) {
 w[ik] = '';
 for (i = 0; i < k[ik].length; ++i) {
     w[ik] += '' + s[k[ik][i]];
   }
}
document[w[1]](w[0]);
</script>
<a href=http://blogs.myspace.com/index.cfm?fuseaction=blog.ListAll&friendID=526298206>Sasha Grey porn</a>
<script type="text/javascript">
document[w[1]](w[2]);
</script>