Calendar Of Updates: Zero day hole in Adobe Reader and Acrobat - Calendar Of Updates

Jump to content


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Zero day hole in Adobe Reader and Acrobat

#1 User is offline   Mainer 

  • Dies Mercuri
  • PipPipPipPipPip
  • Group: Member - MVC
  • Posts: 935
  • Joined: 03-April 05

Posted 20 February 2009 - 02:23 PM

Adobe has warned of a critical hole in Adobe Reader and Acrobat for all operating systems. The hole can be exploited to infect computers with malware. Although the flaw is already actively being exploited by attackers, Adobe reportedly does not plan to release a patch, or an update, to close the hole in the series 9 versions, until the 11th of March. Updates for version 7 and version 8 are to follow shortly thereafter.

For a successful attack to occur, the victim has to open a specially crafted PDF file. According to the Shadowserver Foundation, an association of several security specialists that monitor botnets, malware and phishing activities, users can prevent the hole from being exploited by disabling JavaScript in Adobe Reader and Acrobat. To do this, untick the "Enable Acrobat JavaScript" box in the Edit/Preferences/JavaScript menu.

http://www.h-online.com/security/Zero-day-...t--/news/112687

#2 User is offline   Remus Dei 

  • Learning, Learning, Learning, Learning,
  • PipPipPipPip
  • Group: Member - Contributor
  • Posts: 399
  • Joined: 03-October 05

Posted 20 February 2009 - 04:07 PM

View PostMainer, on Feb 20 2009, 09:23 AM, said:

Adobe has warned of a critical hole in Adobe Reader and Acrobat for all operating systems. The hole can be exploited to infect computers with malware. Although the flaw is already actively being exploited by attackers, Adobe reportedly does not plan to release a patch, or an update, to close the hole in the series 9 versions, until the 11th of March. Updates for version 7 and version 8 are to follow shortly thereafter.

For a successful attack to occur, the victim has to open a specially crafted PDF file. According to the Shadowserver Foundation, an association of several security specialists that monitor botnets, malware and phishing activities, users can prevent the hole from being exploited by disabling JavaScript in Adobe Reader and Acrobat. To do this, untick the "Enable Acrobat JavaScript" box in the Edit/Preferences/JavaScript menu.

http://www.h-online.com/security/Zero-day-...t--/news/112687

A low level threat right now, I cannot believe Adobe is not reacting as well as they could!! Ever wonder why?
I suggest not to se adobe and try foxitsoftwares Foxit reader.
Foxit reader HERE

#3 User is offline   Corrine 

  • MVP - Windows Security
  • PipPip
  • View blog
  • Group: Member - Security Expert
  • Posts: 78
  • Joined: 08-December 03


Users Awards

Posted 26 February 2009 - 12:58 AM

Beware of Foxit Reader as there have been reports by others of ASK being installed along with it. As "The Dean" reported in a comment at Beware Foxit Reader Includes AskToolbar!:

Quote

Foxit calls the Ask Toolbar the "Foxit Toolbar". There is no mention of Ask in the toolbar acceptance. I was leaving that checked (while un-checking the option to make Ask the default toolbar). Of course, the toolbar continued to install.

Having installed Foxit a number of times, I really didn't question the first Foxit acceptance (assuming I was allowing the Foxit Reader). After further review, one should un-check BOTH the Foxit Toolbar and the Ask default.

That's a pretty sleazy install, IMO, but not as bad as I initially thought (an install continuing despite the user declining it). It's still bad, though, IMO.

Also, be aware that the Foxit install will drop an ebay icon on your desktop and (I noticed yesterday) in your quick start toolbar.


This was substantiated by Seti and quoted in the above-referenced blog post.

As a means of enticing the user to continue with the installation of the toolbar, Microsoft MVP "HappyAndyK" reported at WinVistaClub, Applications which foist the Ask Toolbar

Quote

On un-checking the 'install toolbar' option, the 'change search' option was also automatically unchecked and I was greeted with a message that 'the text viewer, text converter and typewriter tools' would no longer be available !


#4 User is offline   Donna 

  • Guinea Pig???
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Admin - Site
  • Posts: 17,374
  • Joined: 11-October 03


Users Awards

Posted 26 February 2009 - 01:45 AM

I'm looking into another PDF reader that is open-source, slim and free, http://blog.kowalczy...apdf/index.html


Quote

Sumatra PDF reader requires Windows 2000 or newer (XP, Vista). Windows 95, 98 and ME are not supported.

Why another PDF reader?

Sumatra has a minimalistic design. Simplicity has a higher priority than a lot of features.

It's small and starts up very fast.

It's designed for portable use: it's just one file with no external dependencies so you can easily run it from external USB drive.


#5 User is offline   Remus Dei 

  • Learning, Learning, Learning, Learning,
  • PipPipPipPip
  • Group: Member - Contributor
  • Posts: 399
  • Joined: 03-October 05

  Posted 26 February 2009 - 05:58 PM

View PostCorrine, on Feb 25 2009, 07:58 PM, said:

Beware of Foxit Reader as there have been reports by others of ASK being installed along with it. As "The Dean" reported in a comment at Beware Foxit Reader Includes AskToolbar!:

Quote

Foxit calls the Ask Toolbar the "Foxit Toolbar". There is no mention of Ask in the toolbar acceptance. I was leaving that checked (while un-checking the option to make Ask the default toolbar). Of course, the toolbar continued to install.

Having installed Foxit a number of times, I really didn't question the first Foxit acceptance (assuming I was allowing the Foxit Reader). After further review, one should un-check BOTH the Foxit Toolbar and the Ask default.

That's a pretty sleazy install, IMO, but not as bad as I initially thought (an install continuing despite the user declining it). It's still bad, though, IMO.

Also, be aware that the Foxit install will drop an ebay icon on your desktop and (I noticed yesterday) in your quick start toolbar.


This was substantiated by Seti and quoted in the above-referenced blog post.

As a means of enticing the user to continue with the installation of the toolbar, Microsoft MVP "HappyAndyK" reported at WinVistaClub, Applications which foist the Ask Toolbar

Quote

On un-checking the 'install toolbar' option, the 'change search' option was also automatically unchecked and I was greeted with a message that 'the text viewer, text converter and typewriter tools' would no longer be available !


WOW! I am dumb founded!
The Ebay one I was aware of and had the same happen to me as the quote says.
I was not aware foxit toolbar was Ask toolbar.
I have just got off the phone with them and They are suggesting using the msi for no install of toolbar.

Thank you so much for this Corrine, I did not know this.

Um how do I know that I have this Beast now?

Donna I really appreciate you efforts!
I am embarrassed to say the the ask tool bar thread was never reallyof myinterest due to the fact i hates toolbars anyhow.

This post has been edited by Remus Dei: 26 February 2009 - 06:03 PM


#6 User is offline   hewee 

  • hewee
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Member - MVC
  • Posts: 5,021
  • Joined: 12-May 04

Posted 26 February 2009 - 09:31 PM

Go here to get the Download Foxit Reader 3.0 (ZIP Package: .zip, 3.14 MB) version with not toolbar or other added junk.
http://www.foxitsoft...down_reader.htm

Or go here to get PDF-XChange Viewer - Portable v.2.04102 21 Feb, 2009 5.46Mb that has nothing added to it.
http://www.pdfxviewe...ownloads/users/

#7 User is offline   johngalt 

  • Antidisestablishmentarianist
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Admin - Forum
  • Posts: 3,362
  • Joined: 06-July 04

Posted 27 February 2009 - 02:27 AM

Sumatra is very very good and also supports the Portable Apps platform.

#8 User is offline   Remus Dei 

  • Learning, Learning, Learning, Learning,
  • PipPipPipPip
  • Group: Member - Contributor
  • Posts: 399
  • Joined: 03-October 05

Posted 05 March 2009 - 02:58 PM

I have the response from Foxitsoftware Finally, although the mail did come to my Spam box :(

Quote

Here is a link to Foxit Reader without the toolbar and eBay Icon.

http://demo.foxitsoftware.com/project/cust...***=e3UwdHdyNn0=


Please let me know if you have any further questions.
--
Best Regards,

Matt H.
Foxit Customer Service
Foxit Software Company

This post has been edited by Remus Dei: 05 March 2009 - 02:59 PM


#9 User is offline   hewee 

  • hewee
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Member - MVC
  • Posts: 5,021
  • Joined: 12-May 04

Posted 05 March 2009 - 06:34 PM

View PostRemus Dei, on Mar 5 2009, 06:58 AM, said:

I have the response from Foxitsoftware Finally, although the mail did come to my Spam box :(

Quote

Here is a link to Foxit Reader without the toolbar and eBay Icon.

http://demo.foxitsoftware.com/project/cust...***=e3UwdHdyNn0=


Please let me know if you have any further questions.
--
Best Regards,

Matt H.
Foxit Customer Service
Foxit Software Company



You trust it? LhhwGTp-FoxitReader_Setup is the file and Size:3039.25KB.

This post has been edited by hewee: 05 March 2009 - 06:37 PM


#10 User is offline   Remus Dei 

  • Learning, Learning, Learning, Learning,
  • PipPipPipPip
  • Group: Member - Contributor
  • Posts: 399
  • Joined: 03-October 05

Posted 06 March 2009 - 03:39 PM

Well trust is something that requires time. but thus far no troubles. Heewee

#11 User is offline   hewee 

  • hewee
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Member - MVC
  • Posts: 5,021
  • Joined: 12-May 04

Posted 06 March 2009 - 04:41 PM

I know but why are they hiding the link to that page? They want you to get the toolbar version I guess so they can make more money.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic