AJAXify your Wordpress

Learn how I ajaxified my wordpress blog with these few steps...

SBS Show!

Listen to the latest episode of the SBS Show, Dave Sobel talks about process management...

Vladville Newsletter!

Looking for a more focused, exclusive insight into the world of SMB tech & business? Sign up for my newsletter!

WMF workaround
Posted: 2:14 pm
December 29th, 2005
Post a comment
Security, Web 2.0

Figured I'd post the update to this panic that started yesterday and at least try to help a few of you out there that may not be protected by the likes of ExchangeDefender or competent IT staff. If you're worried about WMF exploit infecting your system try to unassociate the WMF files so they cannot be automatically opened by Internet Explorer: Un-register the Windows Picture and Fax Viewer (Shimgvw.dll)

1. Click Start, click Run, type "regsvr32 -u %windir%/system32/shimgvw.dll" (without the quotation marks), and then click OK. 2. A dialog box appears to confirm that the un-registration process has succeeded. Click OK to close the dialog box.

Then check with your system admin and ask if they have restricted WMF flow (through the mail server), how up-to-date is your virus protection, what kind of content/network filtering is in place. There is always Firefox… Slight update. I'm just read an email from Michael Curley alluding to what I've said above about unassociating the filetype:

"Although blocking wmf extensions at the proxy is a good idea, it should be noted that a wmf can present itself as a .png or a .gif or a .anything, and windows can still read the metadata on the file and treat it as a .wmf."

In practical IT security (which is quite different from the idiots that write security books and have no business experience whatsoever) where you have to consider business practices, user experience / education and all the other factors in implementing a good and efficient security plan one size does not fit all. You have to implement as many layers you can to protect yourself. That is, use antivirus. Use a firewall. Use a proxy/content filter. Use everything you can tag onto your mail server to stop direct contact. Use content permission software to block where users are going. It cannot be a shotgun implementation.

8 Comments

Bob |

Never miss an opportunity to talk about the ExchangeDefender huh?



Amy |

The ExchangeDefender, you say? ;)



CharlesM |

Pick on it all you want, we haven’t had a single thing get on our network since ExchangeDefender was put in.



Vlad |

Hey, thats my bread and butter, of course I’m going to pimp it any chance I get.



happyfunboy |

yeah…how dare you advertise the product that pays your bills on your free blog that is chock-full of free information that tons of other folks use to do their jobs, which pay them money, for free.

btw…does anyone know that vladville is free?



amanda |

Amen Chris. Vlad needs to push his stuff more, I can’t believe how much stuff he does for free and no advertising, no banners, nothing.

Slap some sense into him. If you live to help others you should have others be aware what keeps you alive.



Vlad |

Wow, someone actually knows the almighty HappyFunBoy by his real name? Another show fan! :)
I appreciate your support guys, really, I know its not a big deal but I need to pay for a wedding now so Vlad needs to rake in some extra smallbiz cash :p)



brian |

Hey, promote away brother! We’re a customer already and you should be screaming it from the rooftops.

Never be ashamed to talk about your business. I think nearly everyone here will agree that you’re one of the most intelligent people around, I don’t see a reason for you not to mention it.

For the love of god, this is your site!!! Spam away man!



Leave a Reply






 

Categories

 

Archives

 

About

Divider Divider