Zero day hole in Adobe Reader and Acrobat
#1
Posted 20 February 2009 - 02:23 PM
For a successful attack to occur, the victim has to open a specially crafted PDF file. According to the Shadowserver Foundation, an association of several security specialists that monitor botnets, malware and phishing activities, users can prevent the hole from being exploited by disabling JavaScript in Adobe Reader and Acrobat. To do this, untick the "Enable Acrobat JavaScript" box in the Edit/Preferences/JavaScript menu.
http://www.h-online.com/security/Zero-day-...t--/news/112687
#2
Posted 20 February 2009 - 04:07 PM
Mainer, on Feb 20 2009, 09:23 AM, said:
For a successful attack to occur, the victim has to open a specially crafted PDF file. According to the Shadowserver Foundation, an association of several security specialists that monitor botnets, malware and phishing activities, users can prevent the hole from being exploited by disabling JavaScript in Adobe Reader and Acrobat. To do this, untick the "Enable Acrobat JavaScript" box in the Edit/Preferences/JavaScript menu.
http://www.h-online.com/security/Zero-day-...t--/news/112687
A low level threat right now, I cannot believe Adobe is not reacting as well as they could!! Ever wonder why?
I suggest not to se adobe and try foxitsoftwares Foxit reader.
Foxit reader HERE
#3
Posted 26 February 2009 - 12:58 AM
Quote
Having installed Foxit a number of times, I really didn't question the first Foxit acceptance (assuming I was allowing the Foxit Reader). After further review, one should un-check BOTH the Foxit Toolbar and the Ask default.
That's a pretty sleazy install, IMO, but not as bad as I initially thought (an install continuing despite the user declining it). It's still bad, though, IMO.
Also, be aware that the Foxit install will drop an ebay icon on your desktop and (I noticed yesterday) in your quick start toolbar.
This was substantiated by Seti and quoted in the above-referenced blog post.
As a means of enticing the user to continue with the installation of the toolbar, Microsoft MVP "HappyAndyK" reported at WinVistaClub, Applications which foist the Ask Toolbar
Quote
#4
Posted 26 February 2009 - 01:45 AM
Quote
Why another PDF reader?
Sumatra has a minimalistic design. Simplicity has a higher priority than a lot of features.
It's small and starts up very fast.
It's designed for portable use: it's just one file with no external dependencies so you can easily run it from external USB drive.
#5
Posted 26 February 2009 - 05:58 PM
Corrine, on Feb 25 2009, 07:58 PM, said:
Quote
Having installed Foxit a number of times, I really didn't question the first Foxit acceptance (assuming I was allowing the Foxit Reader). After further review, one should un-check BOTH the Foxit Toolbar and the Ask default.
That's a pretty sleazy install, IMO, but not as bad as I initially thought (an install continuing despite the user declining it). It's still bad, though, IMO.
Also, be aware that the Foxit install will drop an ebay icon on your desktop and (I noticed yesterday) in your quick start toolbar.
This was substantiated by Seti and quoted in the above-referenced blog post.
As a means of enticing the user to continue with the installation of the toolbar, Microsoft MVP "HappyAndyK" reported at WinVistaClub, Applications which foist the Ask Toolbar
Quote
WOW! I am dumb founded!
The Ebay one I was aware of and had the same happen to me as the quote says.
I was not aware foxit toolbar was Ask toolbar.
I have just got off the phone with them and They are suggesting using the msi for no install of toolbar.
Thank you so much for this Corrine, I did not know this.
Um how do I know that I have this Beast now?
Donna I really appreciate you efforts!
I am embarrassed to say the the ask tool bar thread was never reallyof myinterest due to the fact i hates toolbars anyhow.
This post has been edited by Remus Dei: 26 February 2009 - 06:03 PM
#6
Posted 26 February 2009 - 09:31 PM
http://www.foxitsoft...down_reader.htm
Or go here to get PDF-XChange Viewer - Portable v.2.04102 21 Feb, 2009 5.46Mb that has nothing added to it.
http://www.pdfxviewe...ownloads/users/
#7
Posted 27 February 2009 - 02:27 AM
#8
Posted 05 March 2009 - 02:58 PM
Quote
http://demo.foxitsoftware.com/project/cust...***=e3UwdHdyNn0=
Please let me know if you have any further questions.
--
Best Regards,
Matt H.
Foxit Customer Service
Foxit Software Company
This post has been edited by Remus Dei: 05 March 2009 - 02:59 PM
#9
Posted 05 March 2009 - 06:34 PM
Remus Dei, on Mar 5 2009, 06:58 AM, said:
Quote
http://demo.foxitsoftware.com/project/cust...***=e3UwdHdyNn0=
Please let me know if you have any further questions.
--
Best Regards,
Matt H.
Foxit Customer Service
Foxit Software Company
You trust it? LhhwGTp-FoxitReader_Setup is the file and Size:3039.25KB.
This post has been edited by hewee: 05 March 2009 - 06:37 PM
#10
Posted 06 March 2009 - 03:39 PM
#11
Posted 06 March 2009 - 04:41 PM

Help
















