IMPORTANT: WMF Vulnerability Exploited

Well, I suppose I owe an apology. But in my defense I wasn't really like nah-nah-na-poo-poo, it was more of a funny poke :D

But, point taken, when it comes to statistics and security measures, fact checking should be performed.

*Bows head in shame*
 
Well well, looks like the "unofficial" patch did cause problems after all.
Now you know why extensive testing before releasing a patch to millions of people is crucial and takes time.

> Today I received information from one corporative user
> that installation of unofficial WMF patch (wmffix_hexblog13.exe)
> on Windows XP workstation causes to him network printing problems.
> The problem was solved via System Restore.

It would not surprise me.

GDI is used not only by the graphics on the screen, but also by the
printing subsystem. Escape() is commonly used by applications to pass
raw data (particularly *Postscript* data) through the driver, out
the port monitor, and off to a device.

Setting an abort procedure is something an application can do to
plant a callback for GDI to use to let the application regain
control during rendering (I think it's every 200 msec or so). Most
of the time the application returns "Keep going", but it can return
a "please cancel", perhaps in response to a user clicking same.

I could imagine an application actually *relying* on those callbacks
for some purpose, though I doubt it's good practice. In any case, I
can't speculate on the effects but can certainly imagine that it's
related to printer "stuff".

Steve (who writes printing system components)

---
Stephen J Friedl | Security Consultant | UNIX Wizard | +1 714 544-6561
www.unixwiz.net | Tustin, Calif. USA | Microsoft MVP | steve_at_unixwiz.net

http://seclists.org/lists/fulldisclosure/2006/Jan/0061.html
http://silverstr.ufies.org/blog/archives/000896.html
 
this might be why I had some trouble with a wireless modem...it was my new sprint 6700 whcih worked incredibly well then all of a sudden was hard to get working

I also thought it related to the patch, I did a system restore and my modem worked again

I have no idea if it was the patch and it doesn't seem as likely as a printer issue, since there aren't images or videos involved

I stopped worrying about the exploit becuase of my sandbox and let it stand exposed
 
It shouldn't matter anymore. Those who used the "unofficial patch" can now uninstall it completely, as suggested from the start, and install the official Microsoft one.

Melon
 
perris said:
this might be why I had some trouble with a wireless modem...it was my new sprint 6700 whcih worked incredibly well then all of a sudden was hard to get working

I also thought it related to the patch, I did a system restore and my modem worked again

I have no idea if it was the patch and it doesn't seem as likely as a printer issue, since there aren't images or videos involved

I stopped worrying about the exploit becuase of my sandbox and let it stand exposed

Could you install the patch again, on an unpatched machine, then if you once again have problems, run the un-installer instead of doing a system restore, and I would like to know if this makes a difference.

Fact is, according to "hackers" in the community, that Microsoft has done exactly what the unofficial patch did, except they did not require the extra code to work around, they just removed the command totally.

The only case where this can cause problems if the drivers that are in use for the printer are written with old 16 bit code in mind, Microsoft's patch will break those as well, since they have completely remove the command:

Users of Ilfak's temporary patch — which is no longer needed in the wake of Microsoft's early released official update — may rest easily. Ilfak reports that he checked-out Microsoft's new replacement GDI32.DLL . . . and it permanently does the same thing as his temporary patch: It simply revokes support for the age-old WMF "SETABORT" command from metafile processing.

http://www.grc.com/sn/notes-020.htm

This means that any users that were reporting problems, should be reporting problems after installing this patch, as they both do the same things.

Difference may be the fact that Windows can detect drivers whereas Ilfak's patch does not, but that IMHO would still leave a user open for attack if they downloaded drivers from a random place (Less likely to happen).

In this case i'd be very happy if I was proven wrong, and Microsoft did keep the old stuff around, just not for certain file types, as then they would break less software.


------

Just a simple note: On the school network we rolled out the unofficial patch the day it came out, and we have not had any problems with anything at all, that includes printing, graphic editing or anything one can imagine, the printing issues might be a totally unrelated cause. Keep me updated. (Official patch is being rolled out this weekend)
 
When all this started I presented my Super with the option of using the temp patch , we decieded to do something and not wait till next Tuesday, we have no problems from the over 100 stations I patched in our Plant.
 
Wow!!

On a side note to this,

I didn't even realize that this thread was a sticky. This is my first sticky here on this site, never had one before, even through previous iterations (ex-perience, etc,etc). I guess that I am pretty happy.

Thanks to whoever made it a sticky. Made my day.

Heeter
 
Heeter said:
Wow!!

On a side note to this,

I didn't even realize that this thread was a sticky. This is my first sticky here on this site, never had one before, even through previous iterations (ex-perience, etc,etc). I guess that I am pretty happy.

Thanks to whoever made it a sticky. Made my day.

Heeter
I did. Just wanted to make sure everyone was aware of the situation and taking appropriate precautions.
Hopefully, everyone's installed the official patch by now. :)
 
Well at work I will finish the MS patch next week no hurry now we are patched anyways lol
 
X-Istence said:
Could you install the patch again, on an unpatched machine, then if you once again have problems, run the un-installer instead of doing a system restore, and I would like to know if this makes a difference.

I couldn't do it on an unpatched machine because the entire 6700 has to be installed and the modem has to be set up with it

this includes going to support and downloading drivers that didn't make it to the install CD. I could try to find it on my hardrive and burn a CD to do it, but I believe I tossed those drivers

in other words, it would take me at least an hour, probably 3, then the issue is intermittent and might not show up for day

then I would have to be uninstalling everything from that persons box, and of course install the ms patch when I was done

this machine that had the issue already has the ms patch, so I would also be uninstalling that patch before installing the unofficial two patches, then I'd have to wait to see if the issue arose, because it didn't just jump up and yell when I installed the patch the first time...if it was the patch, which it looks like it was not

I do believe I've seen my issue on the internet...it was happening before the exploit or the patch, supposedly it's the mini SD card that causes conflicts.

this makes sense because I didn't actually start accessing the mini SD until right around the patch came out
 
Last edited:
Last edited:
Well we can't take a post and make it into a new thread (it's a limitation with vbulletin sadly).

chrpope: Could you please just copy paste your post into a new thread? It would get more attention and better help that way.
 
I moved it to the RAZR Drivers support thread.
 

Members online

Latest profile posts

Also Hi EP and people. I found this place again while looking through a oooollllllldddd backup. I have filled over 10TB and was looking at my collection of antiques. Any bids on the 500Mhz Win 95 fix?
Any of the SP crew still out there?
Xie wrote on Electronic Punk's profile.
Impressed you have kept this alive this long EP! So many sites have come and gone. :(

Just did some crude math and I apparently joined almost 18yrs ago, how is that possible???
hello peeps... is been some time since i last came here.
Electronic Punk wrote on Sazar's profile.
Rest in peace my friend, been trying to find you and finally did in the worst way imaginable.

Forum statistics

Threads
62,015
Messages
673,495
Members
5,624
Latest member
junebutlertd
Back