On TechRepublic: 3 habits of highly ineffective employees
BNET Business Network:
BNET
TechRepublic
ZDNet

By Tom Krazit, News.com
Posted on ZDNet News: Jan 31, 2006 1:19:00 AM

A discussion forum Web site for fans of Advanced Micro Devices' chips was closed Monday after the discovery there of an exploit for Microsoft's Windows Meta File flaw.

Mikko Hypponen, chief research officer at F-Secure, posted an item on the company's blog Monday outlining a WMF exploit on the home page for AMD-sponsored discussion forums. The exploit has since been removed, AMD said.

AMD forums harbor WMF exploit

WMF exploits can trick users into viewing images or visiting Web sites that carry malicious software called Trojan horses. Once installed on a vulnerable PC, the software can allow an attacker to execute code on the system.

The forums were taken offline as soon as AMD learned of the exploit, said Drew Prairie, a spokesman for the Sunnyvale, Calif.-based chipmaker. The forums are maintained by another company that apparently failed to update its software in order to protect against the exploit, he said. Prairie was unaware of the name of the company, which is dealt with by AMD's staff in Europe.

The forums were back online late Monday afternoon. A poster started a thread on Saturday warning other forum users about the exploit. The discussions on the site usually center around building AMD-based PCs or bashing Intel, but visitors over the weekend got an unexpected lesson in Windows and Internet Explorer security techniques.

Microsoft was forced to issue an out-of-cycle patch in early January in response to the nasty WMF flaw, after originally planning to include the fix along with its usual monthly batch of patches. Windows users who downloaded that patch when it was distributed were protected if they visited the AMD discussion forum on Monday, Prairie said.

  • Talkback
  • Most Recent of 16 Talkback(s)
Look at the forum
it's a back and forth bash fest with 'don't touch my stuff' as I poke at yours kinda mentality, no matter the level of severity, it's across the board.... (Read the rest)
Posted by: Boot_Agnostic Posted on: 02/02/06 You are currently: Logged In | Log out
Wow! That's close! Grayson Peddie   | 01/30/06
You don't know the 1/2 of it... Wolfie2K3   | 01/31/06
Where are the shills? whisperycat   | 01/31/06
Look in the mirror!(nt) ShadeTree   | 01/31/06
I hate the smell of hypocrisy in the morning... wolf_z   | 01/31/06
Look at the forum Boot_Agnostic   | 02/02/06
you cant even spell waylander   | 01/31/06
misunderstanding nhac   | 01/31/06
Good question, no, excellent question... Nix_0S_Fan   | 01/31/06
Mike Cox? Yagotta B. Kidding   | 01/31/06
Right Real World   | 01/31/06
VERY true.. Wolfie2K3   | 01/31/06
Windows Security? b.d.hi   | 01/31/06
Huh! tsung   | 01/31/06
Couple options george_ou   | 01/31/06
You know it's a slow news day when Yensi717   | 01/31/06

What do you think?

advertisement
advertisement

The Green Enterprise

advertisement
Click Here