Go Back   Technology Questions > Software Questions > Operating System Questions > Windows XP

Windows XP Discuss the Microsoft Windows XP Operating System

Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 02-22-2007, 02:31 AM
janedough250164@dontsendhotmail.com
Tablet PC Guest
 
Posts: n/a
Any way to tell if wmv file contains executable code?

I was just reading that information inherent in a wmv file can execute
other files (see below). Is there any way to determine if there's code in
a wmv file before opening it with WM Player or Media Player Classic (or
another program)?








http://www.geocities.com/ResearchTri.../eng/safe.html


> There is also an issue regarding Windows Media Player, which under some

environments may allow any media file which is opened by Windows Media
Player to execute some local files (depending on their extensions, but
including some executable extensions) as long as the name and path of the
file are given in that media file. The issue, has to do with the ability of
..wmv files to refer to an Internet address (the accurate term should be URL
rather than "Internet address"). This address can also be a location of a
local file in the computer. In such a case, the wmv file can instruct
Windows Media Player to execute a local executable file, as long as the
location and name of the file are given in the .wmv file. As you should
already know, the WMV file may have any extension as long as it is opened
by Windows Media Player. There is a way to block an exploitation of this
security hole, and it involves tweaking the registry keys. The instruction
is relevant to Internet Explorer versions 4 and above. It has to do with
disabling the "Download unsigned ActiveX controls", in the "My Computer"
security zone.
>
> We shall not give here full explanation, but only comment that this

activity is done with the help of components from Internet Explorer. The
needed tweaking is to use a registry editor, and in the following
> registry key:
> HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings\Zones\0
> to change the value of the "1004" entry to contain a DWORD value of 3.
> ("HKCU" stands for HKEY_CURRENT_USER).


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

 
Old 02-22-2007, 02:31 AM
Xploder HD Movie Player for PS3. Manage, convert and transfer media files between the PC and PS3.
  #2 (permalink)  
Old 02-22-2007, 02:31 AM
geothermal
Tablet PC Guest
 
Posts: n/a
Re: Any way to tell if wmv file contains executable code?

On Feb 22, 2:16 am, janedough250...@dontsendhotmail.com wrote:
> I was just reading that information inherent in a wmv file can execute
> other files (see below). Is there any way to determine if there's code in
> a wmv file before opening it with WM Player or Media Player Classic (or
> another program)?


Read this thread:

http://www-gatago.com/comp/security/misc/16265498.html

cheers,

geothermal


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #3 (permalink)  
Old 02-22-2007, 05:46 AM
MAP
Tablet PC Guest
 
Posts: n/a
Re: Any way to tell if wmv file contains executable code?

janedough250164@dontsendhotmail.com wrote:
> I was just reading that information inherent in a wmv file can execute
> other files (see below). Is there any way to determine if there's
> code in a wmv file before opening it with WM Player or Media Player
> Classic (or another program)?
>
>
>
>
>
>
>
>
> http://www.geocities.com/ResearchTri.../eng/safe.html
>
>
>> There is also an issue regarding Windows Media Player, which under
>> some

> environments may allow any media file which is opened by Windows Media
> Player to execute some local files (depending on their extensions, but
> including some executable extensions) as long as the name and path of
> the file are given in that media file. The issue, has to do with the
> ability of .wmv files to refer to an Internet address (the accurate
> term should be URL rather than "Internet address"). This address can
> also be a location of a local file in the computer. In such a case,
> the wmv file can instruct Windows Media Player to execute a local
> executable file, as long as the location and name of the file are
> given in the .wmv file. As you should already know, the WMV file may
> have any extension as long as it is opened by Windows Media Player.
> There is a way to block an exploitation of this security hole, and it
> involves tweaking the registry keys. The instruction is relevant to
> Internet Explorer versions 4 and above. It has to do with disabling
> the "Download unsigned ActiveX controls", in the "My Computer"
> security zone.
>>
>> We shall not give here full explanation, but only comment that this

> activity is done with the help of components from Internet Explorer.
> The needed tweaking is to use a registry editor, and in the following
>> registry key:
>> HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet
>> Settings\Zones\0 to change the value of the "1004" entry to contain
>> a DWORD value of 3. ("HKCU" stands for HKEY_CURRENT_USER).


That's what a good anti-virus program is for. (or process guard or the paid
version of kiero) Note the link you provided is nearly 5 years old.

--
Mike Pawlak


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #4 (permalink)  
Old 02-22-2007, 02:01 PM
David H. Lipman
Tablet PC Guest
 
Posts: n/a
Re: Any way to tell if wmv file contains executable code?

From: <janedough250164@dontsendhotmail.com>

| I was just reading that information inherent in a wmv file can execute
| other files (see below). Is there any way to determine if there's code in
| a wmv file before opening it with WM Player or Media Player Classic (or
| another program)?
|
| http://www.geocities.com/ResearchTri.../eng/safe.html
|
>> There is also an issue regarding Windows Media Player, which under some

| environments may allow any media file which is opened by Windows Media
| Player to execute some local files (depending on their extensions, but
| including some executable extensions) as long as the name and path of the
| file are given in that media file. The issue, has to do with the ability of
| .wmv files to refer to an Internet address (the accurate term should be URL
| rather than "Internet address"). This address can also be a location of a
| local file in the computer. In such a case, the wmv file can instruct
| Windows Media Player to execute a local executable file, as long as the
| location and name of the file are given in the .wmv file. As you should
| already know, the WMV file may have any extension as long as it is opened
| by Windows Media Player. There is a way to block an exploitation of this
| security hole, and it involves tweaking the registry keys. The instruction
| is relevant to Internet Explorer versions 4 and above. It has to do with
| disabling the "Download unsigned ActiveX controls", in the "My Computer"
| security zone.
>>
>> We shall not give here full explanation, but only comment that this

| activity is done with the help of components from Internet Explorer. The
| needed tweaking is to use a registry editor, and in the following
>> registry key:
>> HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings\Zones\0
>> to change the value of the "1004" entry to contain a DWORD value of 3.
>> ("HKCU" stands for HKEY_CURRENT_USER).


As Mike indicated that is what Anti Virus softqwasre is for. If you don't scann all file
types then make sure WMV files are scanned.

Any file can be named anyrhing and can still be used via the registry even if the file
extension is not a executable file. However, you have more to worry about a Wimad Trojan
where the WMV explots the Windows Media Player DRM to download and install malware. A
tactic the Zango/180Solutions is well known for.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Lost File Transfer Code jde1345 Windows Vista 0 02-13-2007 10:01 AM
Leaked Windows 2000 Source Code File fake@yahmoo.com Desktop Computers 0 02-06-2007 05:00 PM
Watch an executable file? weeniejeff@gmail.com Windows XP 0 01-14-2007 02:46 PM
Time Executable - Windows XP Ollakal Windows XP 6 01-04-2007 05:22 AM
Executable files problem Dual Windows Vista 3 01-01-2007 09:54 PM


All times are GMT -8. The time now is 02:47 AM.


2003 - 2008 All Rights Reserved. Technology Questions

SEO by vBSEO 3.1.0