<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title>www.ritlabs.com [Topic: The Bat! vs WMF exploit: are we vulnerable?]</title>
		<link>http://www.ritlabs.com</link>
		<description>New posts in The Bat! vs WMF exploit: are we vulnerable? of  forum at www.ritlabs.com [www.ritlabs.com]</description>
		<language>en</language>
		<docs>http://backend.userland.com/rss2</docs>
		<lastBuildDateTag>Fri, 06 Jan 2006 18:40:56 +0200</lastBuildDateTag>		<item>
			<title>The Bat! vs WMF exploit: are we vulnerable?</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic2344/message9621/">The Bat! vs WMF exploit: are we vulnerable?</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Microsoft has just released a fix for the WMF problem. The fix is available via Windows Update. <br />
			<i>06 January 2006 18:40:56, <a href="http://www.ritlabs.com/en/forums/">Maxim Masiutin</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic2344/message9621/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic2344/message9621/</guid>
			<pubDate>Fri, 06 Jan 2006 18:40:56 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>The Bat! vs WMF exploit: are we vulnerable?</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic2344/message9589/">The Bat! vs WMF exploit: are we vulnerable?</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			While MS is working on the patch, you can use The Bat! 3.64.03 which does not display WMF using the internal image viewer. You can download this version from <noindex><a href="http://www.ritlabs.com/download/files/the_bat/beta/tbb36403.rar" target="_blank" rel="nofollow">http://www.ritlabs.com/download/files/the_bat/beta/tbb36403.rar</a></noindex> <br />
			<i>05 January 2006 06:20:48, <a href="http://www.ritlabs.com/en/forums/">Maxim Masiutin</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic2344/message9589/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic2344/message9589/</guid>
			<pubDate>Thu, 05 Jan 2006 06:20:48 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>The Bat! vs WMF exploit: are we vulnerable?</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic2344/message9579/">The Bat! vs WMF exploit: are we vulnerable?</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br />Hope M$ will roll the hotfix soon<br />=============<br /><br />Let's hope so. Today my virus s/w (F-Prot) issued a new release to address this issue and I've also disabled Admin privaleges, though this plays havoc with my True Image scheduled backups. Still it's something.<br /><br /> <br />
			<i>04 January 2006 16:08:41, <a href="http://www.ritlabs.com/en/forums/">Alan</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic2344/message9579/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic2344/message9579/</guid>
			<pubDate>Wed, 04 Jan 2006 16:08:41 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>The Bat! vs WMF exploit: are we vulnerable?</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic2344/message9575/">The Bat! vs WMF exploit: are we vulnerable?</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			BTW, it was asked many times to disable images in the Bat! completely...<br /><br />Yes, v3 has an option to start showing an HTML message as plain text, but the IMAGE tab is still there.<br /> <br />
			<i>04 January 2006 12:34:16, <a href="http://www.ritlabs.com/en/forums/">n.a. n.a.</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic2344/message9575/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic2344/message9575/</guid>
			<pubDate>Wed, 04 Jan 2006 12:34:16 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>The Bat! vs WMF exploit: are we vulnerable?</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic2344/message9574/">The Bat! vs WMF exploit: are we vulnerable?</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			With this hack installed ZA goes crazy - it starts blocking the things it never blocked before, even those already marked as "Allowed"...<br /><br />I did try that hack three times - unless I uninstall it I can't even switch the keyboard layout - Cyrillc|Latin. (Among other glitches)<br /><br />Hope M$ will roll the hotfix soon. There are leaks, the new, fixed, GDI32.DLL is out there... I wish I could find it...<br /> <br />
			<i>04 January 2006 12:30:07, <a href="http://www.ritlabs.com/en/forums/">n.a. n.a.</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic2344/message9574/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic2344/message9574/</guid>
			<pubDate>Wed, 04 Jan 2006 12:30:07 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>The Bat! vs WMF exploit: are we vulnerable?</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic2344/message9572/">The Bat! vs WMF exploit: are we vulnerable?</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /> Till next tuesday when M$ has promised it's hotfix we may all be doomed.<br /><br />(The Ilfak's patch breaks ZoneAlarm on my system) <br />=============<br /><br />I've just said to my wife before seeing your posting that I'm seriously considering pulling the internet plug until next Tuesday.<br /><br />Edit: seems we are worse off than OE. In OE people are being advise to set OE to only display plain text. I can see no way to do that in The Bat (v2). I was about to upgrade to v3. Maybe it's time to look at Thunderbird.<br /><br />Edit 2: Just been to the <noindex><a href="http://forums.mozillazine.org/viewtopic.php?t=361062&amp;postdays=0&amp;postorder=asc&amp;postsperpage=15&amp;start=15" target="_blank" rel="nofollow">Thunderbird Forum</a></noindex> where it mentions a Thunderbird option to stop images being downloaded:<br />Tools-Options-Advanced-Privacy-"Block Loading of Remote Images in Mail Messages". <br /><br />Do we not need something similar in The Bat! It would be nice to get some feedback from The Bat! developers.<br /><br />Edit 2 End.<br /><br /><br />Thanks for the note about Ilfak's patch breaking ZoneAlarm. I have ZA. What happened exactly to ZA and what version of ZA are you on?<br /><br />Alan <br />
			<i>04 January 2006 10:34:38, <a href="http://www.ritlabs.com/en/forums/">Alan</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic2344/message9572/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic2344/message9572/</guid>
			<pubDate>Wed, 04 Jan 2006 10:34:38 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>The Bat! vs WMF exploit: are we vulnerable?</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic2344/message9571/">The Bat! vs WMF exploit: are we vulnerable?</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			This is strange that the Developer Team has not yet commented on the raging WMF exploit...<br /><br />Till next tuesday when M$ has promised it's hotfix we may all be doomed.<br /><br />(The <b>Ilfak</b>'s patch breaks ZoneAlarm on my system)<br /> <br />
			<i>04 January 2006 10:20:22, <a href="http://www.ritlabs.com/en/forums/">n.a. n.a.</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic2344/message9571/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic2344/message9571/</guid>
			<pubDate>Wed, 04 Jan 2006 10:20:22 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>The Bat! vs WMF exploit: are we vulnerable?</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic2344/message9570/">The Bat! vs WMF exploit: are we vulnerable?</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /> Since the Bat! has an image preview - I'd like to hear from the developers that in no way the Bat! will depend on external code to handle any images (SVG mainly) in the mail. <br />=============<br /><br />I just sent myself a test wmf file and The Bat! displayed it in the image tab, next to a text tab. I would suspect that if The Bat! has already rendered the image when creating the tab, then it is too late and even ignoring the tab will not stop infection. &nbsp;<img src="http://www.ritlabs.com/bitrix/images/main/smiles/5/icon_sad.gif" border="0" data-code=":(" data-definition="SD" alt=":(" style="width:16px;height:16px;" title="" class="bx-smile" /> <br /><br />I have written on this <noindex><a href="http://www.dslreports.com/forum/remark,15115819~days=9999~start=620" target="_blank" rel="nofollow">Broadband Security Forum</a></noindex> where I have made some experiments with creating a wmf file and then renaming it to a jpg file. Windows (98 & XP) & IE (5.5 & 6) ignores the jpg, identifies the file as a wmf and displays it.<br /><br />Alan<br />Edit: Should have said: I'm using v 2.04.7 of The Bat!<br /> <br />
			<i>04 January 2006 10:02:16, <a href="http://www.ritlabs.com/en/forums/">Alan</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic2344/message9570/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic2344/message9570/</guid>
			<pubDate>Wed, 04 Jan 2006 10:02:16 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>The Bat! vs WMF exploit: are we vulnerable?</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic2344/message9533/">The Bat! vs WMF exploit: are we vulnerable?</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			This exploit is really nasty one. It does not need to be run to activate.<br />Windows Meta File is handled by the OS.<br />Since the Bat! has an image preview - I'd like to hear from the developers that in no way the Bat! will depend on external code to handle any images (SVG mainly) in the mail.<br /> <br />
			<i>31 December 2005 06:25:34, <a href="http://www.ritlabs.com/en/forums/">n.a. n.a.</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic2344/message9533/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic2344/message9533/</guid>
			<pubDate>Sat, 31 Dec 2005 06:25:34 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>The Bat! vs WMF exploit: are we vulnerable?</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic2344/message9525/">The Bat! vs WMF exploit: are we vulnerable?</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			No. TB doesn't execute anything, so unless you open the file yourself it won't be used. <br />
			<i>30 December 2005 16:42:43, <a href="http://www.ritlabs.com/en/forums/">Roelof Otten</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic2344/message9525/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic2344/message9525/</guid>
			<pubDate>Fri, 30 Dec 2005 16:42:43 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>The Bat! vs WMF exploit: are we vulnerable?</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic2344/message9507/">The Bat! vs WMF exploit: are we vulnerable?</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Is it deadly to receive an attached WMF-file with the Bat! ?<br /> <br />
			<i>30 December 2005 08:10:04, <a href="http://www.ritlabs.com/en/forums/">n.a. n.a.</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic2344/message9507/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic2344/message9507/</guid>
			<pubDate>Fri, 30 Dec 2005 08:10:04 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
	</channel>
</rss>
