Massive security Hole in Windows & Adobe
Moderator: Thanas
Massive security Hole in Windows & Adobe
Haven't seen this posted, but since I need to deal with fallout from shit like this at work, might as well spread the word:
http://www.theregister.co.uk/2007/10/26 ... x_windows/
Basically, patch your Adobe Reader to v8.1.1 and be on your toes after that. Even then, you might get hosed. Machines that get infected by the Adobe PDF vulnerability or through the Windows one tend to become spam servers spewing out maliciously constructed PDFs to spread the infection.
http://www.theregister.co.uk/2007/10/26 ... x_windows/
Basically, patch your Adobe Reader to v8.1.1 and be on your toes after that. Even then, you might get hosed. Machines that get infected by the Adobe PDF vulnerability or through the Windows one tend to become spam servers spewing out maliciously constructed PDFs to spread the infection.
Warwolf Urban Combat Specialist
Why is it so goddamned hard to get little assholes like you to admit it when you fuck up? Is it pride? What gives you the right to have any pride?
–Darth Wong to vivftp
GOP message? Why don't they just come out of the closet: FASCISTS R' US –Patrick Degan
The GOP has a problem with anyone coming out of the closet. –18-till-I-die
Why is it so goddamned hard to get little assholes like you to admit it when you fuck up? Is it pride? What gives you the right to have any pride?
–Darth Wong to vivftp
GOP message? Why don't they just come out of the closet: FASCISTS R' US –Patrick Degan
The GOP has a problem with anyone coming out of the closet. –18-till-I-die
- Einhander Sn0m4n
- Insane Railgunner
- Posts: 18630
- Joined: 2002-10-01 05:51am
- Location: Louisiana... or Dagobah. You know, where Yoda lives.
Feel free to consider this post trolling, but I use Foxit for my PDF needs. Adobe's too bloaty for my tastes (why I switched in the first place), and this PDF spam sploit is even more reason to use anything else.
- Ace Pace
- Hardware Lover
- Posts: 8456
- Joined: 2002-07-07 03:04am
- Location: Wasting time instead of money
- Contact:
Cavet, some of us need Adobe because Foxit doesn't fully deal with some complex PDF with many layers, or some stuff doesn't render properly. I've had to deal with such PDFs quite abit, and others(such as Zod) also had.Einhander Sn0m4n wrote:Feel free to consider this post trolling, but I use Foxit for my PDF needs. Adobe's too bloaty for my tastes (why I switched in the first place), and this PDF spam sploit is even more reason to use anything else.
Brotherhood of the Bear | HAB | Mess | SDnet archivist |
It should be noted that even though Adobe 8.0 had a vulnerability, the deepr issue is still in Windows XP itself and how it passes information to 3rd party programs, so even without Adobe Reader, you can get fucked by this problem. IE7 is one of the programs affected. So until MS fixes it, any PDF on the net is a potential landmine.
Fun fact regarding the malware that infects your machine through this exploit: It has anti-AV capabilities. I don't know just how many security software suites it can hamper, but it can avoid detection by F-Secure except by indirect means (the outgoing PDF spam is noticed, but its cause is not) and it can terminate F-Secure virusscan prematurely. No idea what it does with Norton and the other big name AV software.
So this is not something you really want to risk unless you like nuking and reinstalling your computer.
Fun fact regarding the malware that infects your machine through this exploit: It has anti-AV capabilities. I don't know just how many security software suites it can hamper, but it can avoid detection by F-Secure except by indirect means (the outgoing PDF spam is noticed, but its cause is not) and it can terminate F-Secure virusscan prematurely. No idea what it does with Norton and the other big name AV software.
So this is not something you really want to risk unless you like nuking and reinstalling your computer.
Warwolf Urban Combat Specialist
Why is it so goddamned hard to get little assholes like you to admit it when you fuck up? Is it pride? What gives you the right to have any pride?
–Darth Wong to vivftp
GOP message? Why don't they just come out of the closet: FASCISTS R' US –Patrick Degan
The GOP has a problem with anyone coming out of the closet. –18-till-I-die
Why is it so goddamned hard to get little assholes like you to admit it when you fuck up? Is it pride? What gives you the right to have any pride?
–Darth Wong to vivftp
GOP message? Why don't they just come out of the closet: FASCISTS R' US –Patrick Degan
The GOP has a problem with anyone coming out of the closet. –18-till-I-die
I've found that most third-party PDF viewers (including Leopard's Preview, which far better performing than Adobe's own software and my preferred viewer) completely screw up when opening complex PDFs; specifically, encrypted ones locked to a user name and password that use a web server to authenticate. They seem to only work with Adobe's product.Einhander Sn0m4n wrote:Feel free to consider this post trolling, but I use Foxit for my PDF needs. Adobe's too bloaty for my tastes (why I switched in the first place), and this PDF spam sploit is even more reason to use anything else.
I installed Adobe's viewer but didn't set it as default so I never see it unless I need it.
I'm just glad I'm on a Mac and don't have to worry about this. Still, I'm sure I'll be fixing it at work.
Ah crap. I just know SOMEONE will download this at work and infect half the network and I'll be stuck with cleanup duty, reformatting machines one at a time.Fun fact regarding the malware that infects your machine through this exploit: It has anti-AV capabilities. I don't know just how many security software suites it can hamper, but it can avoid detection by F-Secure except by indirect means (the outgoing PDF spam is noticed, but its cause is not) and it can terminate F-Secure virusscan prematurely. No idea what it does with Norton and the other big name AV software.
So this is not something you really want to risk unless you like nuking and reinstalling your computer.
- Guardsman Bass
- Cowardly Codfish
- Posts: 9281
- Joined: 2002-07-07 12:01am
- Location: Beneath the Deepest Sea
Is there any way to get around its potential ability to shut off virus scans? Can you run a better diagnostic in safe mode?
“It is possible to commit no mistakes and still lose. That is not a weakness. That is life.”
-Jean-Luc Picard
"Men are afraid that women will laugh at them. Women are afraid that men will kill them."
-Margaret Atwood
-Jean-Luc Picard
"Men are afraid that women will laugh at them. Women are afraid that men will kill them."
-Margaret Atwood
- His Divine Shadow
- Commence Primary Ignition
- Posts: 12791
- Joined: 2002-07-03 07:22am
- Location: Finland, west coast
- InnocentBystander
- The Russian Circus
- Posts: 3466
- Joined: 2004-04-10 06:05am
- Location: Just across the mighty Hudson
Unfortunately, evince seems to leak prodigious amounts of memory, and doesn't render PDFs as well (letters seem misaligned). I use it as the default though since it does load substantially faster.RThurmont wrote:This causes me to appreciate Evince and XPDF more vigourously. That said, it is indeed a disturbing problem, in that the PDF was generally viewed as one of the last "safe" formats for sending data.
ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer
George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor