Adobe alert

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • soup
    Just Trying To Help
    • Nov 2005
    • 7524

    Adobe alert

    Anybody who uses Adobe reader should check into this further & not just go by what I put here. A friend put me on to this.

    Hackers have been exploiting a critical bug in Adobe Reader, the popular PDF-viewing software, for at least nine days, researchers said Friday, but a patch may not be ready for another three weeks.

    "We reported this to Adobe on Feb. 12," said Kevin Haley, a director in Symantec Corp.'s security response group. "That was the same day that we had a sample of the exploit."

    Attacks have been spotted in Asia, primarily in Japan, said Haley, as well as in a few other countries. But their small number led him to characterize them as "targeted," meaning the victims had been specially selected.

    "But this [bug] is not hard to exploit," he added, indicating that Symantec expects the attacks to spread.

    So does Andrew Storms, director of security operations at nCircle Network Security Inc. "If the history of Adobe Reader vulnerabilities shows us anything, it's probably just a number of days before this takes off," Storms said.

    In a security advisory released yesterday, Adobe acknowledged the bug and the ongoing attacks, and said that both Reader and Acrobat, an advanced PDF-creation and edit application, are vulnerable. Versions 7, 8 and 9 of both programs, and on all platforms, contain the flaw, the company confirmed. Adobe Reader, by far the more popular of the two applications, is available for Windows, Mac OS X and Linux.

    Adobe plans to patch Reader 9 and Acrobat 9 -- the most current versions -- by March 11, and will then follow with fixes for Reader/Acrobat 8 and Reader/Acrobat 7, in that order. It did not spell out a timetable for updates to Versions 7 and 8, however.

    In the meantime, both Haley and Storms expect hackers to take advantage of the bug, possibly by integrating new attack code into the multistrike exploit kits that are frequently used by cybercriminals to launch attacks against users who are duped into visiting malicious Web sites. "There's no reason to think that that won't happen," he said. "Reader is a very popular application."

    The in-the-wild attacks trigger the bug with a Trojan horse that Symantec has pegged "Pidief.e," which then installs several additional components to open a backdoor on the compromised computer. That backdoor can later be used to inject additional malware into the machine.

    Attacks could be initiated by spam messages that trick users into clicking through to a malicious site, or by packing exploit code in a file attachment.

    Although neither Adobe nor Symantec provided details of the vulnerability, the Shadowserver.org site posted a partial analysis that claimed the bug was in a non-JavaScript function call.

    "I had completely expected that this would be yet another JavaScript vulnerability in Reader," said Storms, who has blasted Adobe in the past for what he has called an "epidemic" of JavaScript bugs.

    Shadowserver.org's write-up recommended that users disable JavaScript in Reader and Acrobat because, although the flaw is not in that code, turning off the feature helps protect against the current exploit. "The exploit can be effectively mitigated by disabling JavaScript," said Shadowserver. "In this scenario, Adobe [Reader] will still crash, but the required heap spray will not occur and code execution is not possible."

    Storms had no better advice, but wondered if that would be enough. "What do we do in the meantime, between now and March 11, when Adobe patches this?" he asked. "Is the [disabling JavaScript] mitigation a good step or the only step? Without a look at the exploit, we can't be sure."

    To disable JavaScript in Adobe Reader, Windows users should select "Preferences" from the Edit menu, then click on "JavaScript" in the ensuing list and uncheck the box marked "Enable Acrobat JavaScript." Mac users will find Preferences under the "Adobe Reader" menu.

    Adobe Reader and Acrobat are no strangers to exploits. Last November, attackers jumped on a just-patched vulnerability in Reader 8.1.3 within days.

    There is also this article.



    But this is what my friend got in mail.

    must be a bigger problem than this report > because the mail I rec'd from europe was in large red block letter get it off your machine.
    Last edited by UncasMS; 22 Feb 2009, 07:03 AM.

  • Abuilder
    Digital Video Enthusiast
    Digital Video Enthusiast
    • Oct 2006
    • 347

    #2
    I guess I'm safe. I'm still running Adobe reader 5 or PDF reader free when in doubt.
    Last edited by Abuilder; 22 Feb 2009, 07:06 AM.
    They tried to Assimilate me and failed!

    Comment

    • PurpleDemon
      Digital Video Expert
      Digital Video Expert
      • Mar 2006
      • 716

      #3
      I wonder if foxit reader would be a safe alternative until this is fixed.

      Or just don't open pdf's from untrusted sources until March 11

      Comment

      • UncasMS
        Super Moderator
        • Nov 2001
        • 9047

        #4
        i can recommend FOXIT pdf reader - an excellent freeware

        Comment

        • soup
          Just Trying To Help
          • Nov 2005
          • 7524

          #5
          Originally Posted by UncasMS
          i can recommend FOXIT pdf reader - an excellent freeware
          I can second that.

          Comment

          • gonwk
            Lord of Digital Video
            Lord of Digital Video
            • Dec 2005
            • 1500

            #6
            Yeah guys,

            Don't open your Bank Staement and Stuff in PDF mode online ... I have heard and forget where I read it ... but I am definitely Staying Away from it for a foreseen future.

            THANKS Soup ... for brining it to everyone's attention.

            @ UnCasMS ...

            Q1: What version are you on FoxIt are you on?

            Q2: And did you get for FREE because you did the "Triple Play" or what?

            G!

            Comment

            • UncasMS
              Super Moderator
              • Nov 2001
              • 9047

              #7
              you can find the free version just about anywhere

              it works more than fine for me - much faster than adobe

              Comment

              • soup
                Just Trying To Help
                • Nov 2005
                • 7524

                #8
                @ gonwk, you are welcome. Foxit can be found lots of places & the following.

                Sorry, the page you requested could not be found.

                Comment

                • MilesAhead
                  Eclectician
                  • Nov 2006
                  • 2615

                  #9
                  Plus you can get the lean & mean 2.0 version at oldversions.com
                  I just put in on my Vista64 and it seems to work fine. Doesn't have browser embedding but it downloads and opens externally. Does the job.

                  Comment

                  • soup
                    Just Trying To Help
                    • Nov 2005
                    • 7524

                    #10
                    I use it on XP64 with no problems.

                    Comment

                    • gonwk
                      Lord of Digital Video
                      Lord of Digital Video
                      • Dec 2005
                      • 1500

                      #11
                      Hi guys,

                      YOU PEOPLE are the BEST!

                      Thanks UnCasMS.

                      Soup & Miles ... Thanks for the download sites.

                      G!

                      Comment

                      • doctorhardware
                        Lord of Digital Video
                        Lord of Digital Video
                        • Dec 2006
                        • 1907

                        #12
                        I have foxit also, it has a nice small footprint, where as Adobe is so bloated.
                        Star Baby Girl, Born March,1997 Died June 30th 2007 6:35 PM.

                        Comment

                        • UncasMS
                          Super Moderator
                          • Nov 2001
                          • 9047

                          #13
                          and it even let's you add/edit annotations, which i doubt the (freeware) reader will do

                          Comment

                          • atifsh
                            Lord of Digital Video
                            Lord of Digital Video
                            • May 2003
                            • 1534

                            #14
                            Adobe finally releases critical Adobe patches zero-day Reader flaw
                            Seems like as soon you buy somehing, v. 2 comes out 1.5 times as fast!..!

                            Comment

                            • gonwk
                              Lord of Digital Video
                              Lord of Digital Video
                              • Dec 2005
                              • 1500

                              #15
                              Hi folks,

                              BTW ... I plum forgot about this Post and the ALERT Soup put out ... my Memory is going folks ... anyway ...

                              My 8 months old laptop came with Adobe 8 ... in my wisdom I opened up a pdf file and I happen to be online so the darn Adobe Acrobat Reader asked me if I want to update from 8.x to 8.xxx something else .. I said yes and it updated A-OK ... then I thought why not update to the latest 9.1.0 version ...

                              Once I did that Adobe without asking me installed "Adobe AIR" and "Adobe.com" and I don't particularly like 9.1.0 look over my old one.

                              Q1: Does 9.1.0 have the Security Problem fixed!?!?

                              Q2: What version of Adobe Acrobat Reader is Safest? 7.0, 8.0, 8.1.3, or what?

                              Q3: Any Recommendation to my delimma?

                              THANKS,

                              G!

                              Comment

                              Working...