Indigo Rose Software

Professional Software Development Tools

 
Results 1 to 4 of 4
  1. #1
    Corey is offline Indigo Rose Staff Alumni
    Join Date
    Aug 2002
    Posts
    9,746

    The final word on the Windows Metafile (WMF) vulnerability

    It's now pretty clear that the ability to execute code in WMF graphics files was intentional - but we may never know why it's there. Steve wraps up the subject, lays a few myths to rest, explains why Windows 95/98/Me are not vulnerable, and offers a tool to detect the hole in all versions of Windows, including the WINE emulator for Linux.
    http://thisweekintech.com/sn23

  2. #2
    Join Date
    Feb 2001
    Location
    Indigo Rose Software
    Posts
    2,728
    The vulnerability probably wasn't intentional...the feature that permits it was put there on purpose, but the evidence indicates that it wasn't put there for any malicious intent.

    It's worth keeping in mind that the WMF format is over 14 years old...

    For a good explanation see Mark Russinovich's blog post (in fact it's linked from the page you posted).

    http://www.sysinternals.com/Blog/

    Note: I think Mark Russinovich understands the guts of Windows better than most people at Microsoft.

    From his concluding statement:

    A secret backdoor would probably have been noticed by the WINE group, and given a choice of believing there was malicious intent or poor design behind this implementation, I’ll pick poor design. After all, there are plenty of such examples all throughout the Windows API, especially in the part of the API that has its roots in Windows 3.1. The bottom line is that I'm convinced that this behavior, while intentional, is not a secret backdoor.
    Last edited by Lorne; 01-24-2006 at 10:27 AM.
    --[[ Indigo Rose Software Developer ]]

  3. #3
    Join Date
    Mar 2005
    Location
    WA 'wait a while' - Australia
    Posts
    872
    I'm with you Lorne,

    the fact that MS released updates across the OSs, in quick response,
    suggests no real clandestine purpose of the backdoor..

    whenever an OS visits 'windows update' and interacts, although encrypted,
    this info is stored at MS's end. The 'Genuine Advantage' technology suggests
    this quite openly really ?
    Last edited by Eagle; 01-24-2006 at 10:40 AM.

  4. #4
    Corey is offline Indigo Rose Staff Alumni
    Join Date
    Aug 2002
    Posts
    9,746
    It's worth keeping in mind that the WMF format is over 14 years old...
    Definitely puts it in perspective.

Similar Threads

  1. INFO: JET and MDAC (Complete) Runtime Notes
    By Desmond in forum Setup Factory 6.0 Knowledge Base
    Replies: 0
    Last Post: 11-28-2003, 08:35 AM
  2. INFO: JET 4.0 SP7-SP8 Runtime Notes
    By Desmond in forum Setup Factory 6.0 Knowledge Base
    Replies: 0
    Last Post: 11-28-2003, 08:34 AM
  3. INFO: Setup Factory and the Windows Installer
    By Support in forum Setup Factory 6.0 Knowledge Base
    Replies: 0
    Last Post: 10-22-2002, 10:38 AM
  4. HOWTO: Install Files to the Windows Directory
    By Support in forum Setup Factory 6.0 Knowledge Base
    Replies: 0
    Last Post: 09-18-2002, 02:33 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts