« WMF Exploit Unofficial Patch | Main | WMF Exploit Official Microsoft Patch Available »

Wednesday, January 04, 2006

WMF Exploits via Email, Part 2

The latest email using the WMF exploit purports to come from Yale University. If the link within the email is clicked then the exploit launches. This evil site also attempts to exploit flaws found in older versions of Firefox - another reason to upgrade to the latest Firefox. Unless you are protected as previously outlined (here, here, here and here) you are screwed! Welcome to the Internet! Sheesh. Please add the following entries to your ever expanding hosts file:

  • playtimepiano[dot]home[dot]comcast[dot]net
  • 86[dot]135[dot]149[dot]130 # UDP
  • 140[dot]198[dot]35[dot]85:8080 # IRC
  • 24[dot]116[dot]12[dot]59:8080 # IRC
  • 140[dot]198[dot]165[dot]185:8080 # IRC
  • 129[dot]93[dot]51[dot]80:8080 # IRC
  • 70[dot]136[dot]88[dot]76:8080 # IRC

Please note that [dot] (above) should be replaced with .