4 ms·
The article is a little unclear - do I have to open a word doc, or is a TIFF embedded in a web page itself enough to cause infection? This may not be the place
by GioM 13y ago
The article is a little unclear - do I have to open a word doc, or is a TIFF embedded in a web page itself enough to cause infection? This may not be the place, but I could really use an opinion right now... I'm running firefox with noscript on Win7/64 and have Word 2007 installed on the system. I hit a suspect page last night, noscript blocked a number of objects, and at no point did I open a word doc, but... it was a link masquerading as am imgur link, that bounced me off at least two redirects (one of which was a .ir domain) before landing me on a spammy-looking blog.
So, I guess the question is, how paranoid should I be? MSE, malwarebytes, and GMER all show nothing (as one would expect if it was a zero-day), but going full scorched earth and doing a system wipe on both my drives would be a huge inconvenience right now. I feel like wiping the whole damn thing on principle, but you can't wipe everything every single time you get spooked.
PS: I did some testing, and it doesn't appear that firefox can display a tif file - it prompts for an external program (photoshop, in my case) and there's no application defined for the content type tiff in the firefox preferences.
Opinions appreciated. Thanks in advance.
- FiloSottile 13y agoI think that a random spammy site is not going to afford burning such a zero-day. There is much lower-hanging fruit for them, and your system does not look like their target "difficulty level". That said with a level of paranoia like yours (that I'm not critiquing) I'm not really sure Windows is the best choice first of all.
- tanzam75 13y ago> I'm running firefox with noscript on Win7/64 and have Word 2007 installed on the system. ... at no point did I open a word doc ... So, I guess the question is, how paranoid should I be? Security advisory 2896666 covers only Windows Vista and Server 2008. Since you were browsing on Windows 7, you are not affected. It further states that you can be attacked if you open an email or file. You say that you did not open any Word documents. That's a start. But did you open any files at all in Microsoft Office? Outlook emails, Excel spreadsheets, Powerpoint presentations, etc.? If not, then you are not affected. At least, you're not affected by the current version of the attack.
- deleted 13y ago[deleted]
- yuhong 13y agoAFAIK most of the time these kinds of attacks are delivered via email attachments sent to specific targets.