Antivirus scanning update for WMF



I hung on to the last batch of 20 wmf exploit samples I had been working with for the purpose of testing my clamantivirus install against them to see when “full detection” of all 20 had been acheived. Last night, with version 1227 of the daily.cvd database, they were still detecting 8 out of the 20. Now, the signatures seem to have improved as with version 1228 of daily.cvd clamav detects all 20 as Exploit.WMF.Gen-3 FOUND


This improves the chances that those using squid with clamav scanning for web browsing have a better chance against it. That’s good news.

The bad news is that there’s been an update to the metasploit module for this exploit since those were created. Unfortunately Clamantivirus is now 0 for 20 with files from the new module. The metasploit update was reported to breeze pass current IDS signatures. Not good.

Related Posts

Blog Traffic Exchange Related Posts
  • Mozilla Firefox passes 80 million downloads According to the counter at spreadfirefox.com, Firefox has now surpassed 80 million downloads. (Well 80.1 million when I looked.) Version 1.0 of Mozilla Firefox was released ~9 months ago. That's a great (and impressive) number, but realistically there are a few things that it doesn't reflect. 1: multiple downloads by......
  • WMF exploit vs. Windows 98 again... If you've visited here in the last few days, you'll have noticed that I've been trying to test the WMF exploit against a Windows 98 Virtual machine since January 1st. I initially started out with a default install, which didn't work, (for the exploit), then added irfanview (didn't work), tried......
  • System patching 0-days and ancient-day vulnerabilities There's a good article at Michael Sutton's Blog which points out something that really makes sense and I think many people are aware of, but with all the buzz that a new previously undisclosed vulnerability has, we forget. The point is this, there are plenty of machines online vulnerable to......
Blog Traffic Exchange Related Websites
  • Why Choose The Best Web Browser For Online Security Web browser is the prime software to connect yourself to the world wide web. Now most of the companies are increasingly putting more and more services on their website and ask their customer to take active part online. Secured browser means keeping your computer free from the virus, spyware and......
  • The Complete Yachtmaster: Sailing, Seamanship, and Navigation for the Modern Yacht Skipper by Tom Cunliffe This week I am posting the book review early as Friday is a holiday. Happy 4th of July all! Although this book was written primarily for the UK market, there is still plenty of great advice for boaters around the world and it can easily be adapted for owners in......
  • These Wordpress Plugins May help Wordpress Plugins You May Need Image by teddy-rised via Flickr I have been asked many different times from new bloggers what plugins they should use. I think a big part of it comes down to personal taste.  While there are some essentials many of them are just add-on plugins......
PDF24    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site