It is currently 05/18/24 1:33 pm

All times are UTC - 6 hours




  Page 1 of 1   [ 12 posts ]
Author Message
 Offline
 Post subject: WARNING re Adobe
PostPosted: 07/27/09 4:18 am • # 1 
User avatar
Administrator

Joined: 11/07/08
Posts: 42112
I'm hoping our resident tech gurus, FeatheredFish and Jab, will weigh in on this ~ I have and use Adobe ~ I do keep it updated ~ but this warning sounds ominous ~ if Adobe is installed but not opened/used, is it still at risk? ~ would I [and of course others who use Adobe] be better off uninstalling/not using it, at least for the time being? ~ if the answer to that is "yes", any suggestions for a replacement? ~ Sooz

Hackers may slip through hole found in Adobe tools
Updated 57m ago

Cybercriminals may have a clear path to spread mayhem on computers this week by taking advantage of a newly discovered vulnerability in Adobe's (ADBE) ubiquitous Flash video player and Acrobat Reader, the widely used tool for opening PDF documents.

Since early July, troublemakers have been e-mailing PDF files with corrupted Flash video clips and hacking into websites to implant them. These clips, when activated, enable attackers to quickly install malicious programs on the user's computer.

Criminals typically take control of PCs, turning them into obedient "bots." They can use bot networks to steal data, siphon cash from online financial accounts, spread spam and trigger promotions to sell fake anti-virus programs.

The number of attacks could soar this week as Adobe scrambles to develop an emergency patch by Friday. The company recently began issuing security patches once a quarter, with the next update scheduled on Sept. 8.

"The volume of cybercrime has been increasing, so we've stepped up our efforts to supply best-in-class security," says Rob Tarkoff, Adobe's senior vice president and general manager of business productivity.

But even that might not solve the problem. Adobe alerts computer users every seven days about software updates that can include security patches, but users often defer installing such updates.

As a result, "We may see a broad-scale explosion of attacks," says Paul Royal, a senior researcher at Purewire.

The security firm has already found a booby-trapped e-mail sent to a corporate executive.

Last week, another security firm, Finjan Software, found several dozen legitimate Web pages carrying poisoned Flash clips.

Tarkoff says Adobe is doing all it can.

"Every software product is a target," he says. The challenge is to find a way to keep offering new features without creating new security problems. "That's (the balance that) we're focused on striking."

That balancing act may grow more difficult as cybercriminals probe for more weaknesses in Adobe programs.

Some 43% of the 1,500 cyberattacks identified by security firm F-Secure in the first six months of 2009 were directed at Acrobat Reader, up from nearly 29% last year.

That puts Acrobat Reader ahead of Microsoft Word, targeted in 40% of this year's attacks.

"Adobe has become the victim of its own success," says Don Leatham, director of solutions and strategy at security firm Lumension.

"They've become a very juicy target, and they need to significantly increase their efforts to secure and stabilize their code."

http://www.usatoday.com/tech/news/compu ... kers_N.htm



Top
  
 Post subject: WARNING re Adobe
PostPosted: 07/27/09 4:36 am • # 2 
I keep saying it... the internet is a war zone and your computer is the prize. It's going to be hard for Adobe to get a handle on this because from what I've heard, they've either opened the PDF technology to "open source" or they're planning to do so soon.


Top
  
 Offline
 Post subject: WARNING re Adobe
PostPosted: 07/28/09 2:15 pm • # 3 
User avatar
Administrator

Joined: 04/05/09
Posts: 8047
Location: Tampa, Florida
[Adobe is suggesting] that users manually delete the file %ProgramFiles%\Adobe\Reader 9.0\Reader\authplay.dll, which is a library that Adobe Reader and Acrobat use to trigger embedded Flash and Shockwave videos.

Doing so might cause a crash when a user tries to launch a PDF document with an embedded video, though Adobe is indicating that this particular crash may not be an exploitable one.

The nature of Adobe's recommended workaround tells you almost everything you need to know about the exploit: It's another case where a maliciously crafted handoff between two interpreters triggers a crash in the one that's supposed to receive the proverbial baton. That crash leaves behind a situation where leftover code in the handoff can be executed without privilege.

It's a problem which may have existed for several days, though Adobe's security blog indicates the company had just gotten wind of the problem on Tuesday. What might have been holding the team up is another security problem, which Adobe currently rates as "moderate:" an active exploit of the Adobe Reader installer, where certain installation files may be replaced with malicious code. While the security team is already working on a fix for that problem, a fix for this newer "critical" issue may only be available by this time next Thursday.



Top
  
 Offline
 Post subject: WARNING re Adobe
PostPosted: 07/28/09 3:15 pm • # 4 
User avatar
Administrator

Joined: 11/07/08
Posts: 42112
Okay ~ I know you THINK that answer makes sense ~ and I'm sure it does to anyone "schooled" in computer-ese ~ then there's ME ~Image~ and you don't answer my original questions: if Adobe is installed but not opened/used, is it still at risk? ~ would I [and of course others who use Adobe] be better off uninstalling/not using it, at least for the time being? ~ if the answer to that is "yes", any suggestions for a replacement? ~

Sooz


Top
  
 Offline
 Post subject: WARNING re Adobe
PostPosted: 07/28/09 4:38 pm • # 5 
User avatar
Administrator

Joined: 04/05/09
Posts: 8047
Location: Tampa, Florida
No need to uninstall adobe. As long as you don't use until the fix is in, you're fine. Supposedly on thursday. Then, of course, someone would have to target you and your computer to send you a pdf with a script.
Stay away from suspicious websites and unsolicited email with attachments, as usual.
Don't be too paranoid. We always can run team viewer to fix if there is a problem once.


Top
  
 Offline
 Post subject: WARNING re Adobe
PostPosted: 07/29/09 1:35 am • # 6 
User avatar
Administrator

Joined: 04/05/09
Posts: 8047
Location: Tampa, Florida
Uhmm, just want to throw in another little tidbit...
I'll highlight the appropriate parts for the stubborn folks.

This critical vulnerability could allow an attacker who successfully exploits the vulnerability to take control of the affected system.

Note that this vulnerability is exclusive to Internet Explorer on Windows.

Installations of Flash Player for Firefox or other web browsers on Windows are not vulnerable.


Hey, looks like Shera's post design! Image


Btw, where's the Feathered One? Vacation? Tree-climbing in his kilt and got hung up on some tree limbs and can't get back down? Image



Last edited by jabra2 on 07/29/09 1:40 am, edited 1 time in total.

Top
  
 Offline
 Post subject: WARNING re Adobe
PostPosted: 07/29/09 2:37 am • # 7 
User avatar
Administrator

Joined: 11/07/08
Posts: 42112
FF sometimes disappears for a couple days ~ sound to you like anyone else we all know??? ~ Image

Sooz



Top
  
 Offline
 Post subject: WARNING re Adobe
PostPosted: 07/29/09 2:40 am • # 8 
User avatar
Administrator

Joined: 11/07/08
Posts: 42112

BTW, thanks for the info Jab ~ with all of the serious problems, how in the world did Windows and IE ever get to be the industry leader? ~ or maybe being the industry leader also set each up as a juicy target ~

Sooz



Top
  
 Offline
 Post subject: WARNING re Adobe
PostPosted: 07/29/09 3:51 am • # 9 
User avatar
Administrator

Joined: 04/05/09
Posts: 8047
Location: Tampa, Florida
sooz08 wrote:
FF sometimes disappears for a couple days ~ sound to you like anyone else we all know??? ~ Image

Sooz

Well, if he went hiking with that right wing hag from over there, he should be back soon, too. Image


Top
  
 Post subject: WARNING re Adobe
PostPosted: 07/29/09 6:22 am • # 10 
The best thing that could happen with Adobe Reader is that is go open source. Then it will have a global network of ninjas scanning the beta codes for backdoors and slamming them tight.

Windows and IE got so well established because of Microsofts aggressive marketing strategy/bullying/litigation/competitor buy-outs which ensured your computer came pre-installed with their products. You learned to use those products and people get nervous about changing.

I've had a bit of an enforced absence. I suppose it's ok to talk about it now.
There was a massive meteorite hurtling towards Earth which would have wiped out mankind and all the pretty fluffy things which occupy our little blue rock. Sooooooooo............................... [classified content redacted].

Phew! It was very close but hey, it's my sons 21st soon. Global devastation would have put a wee damper on that, so I had to do something I guess. Image


Top
  
 Offline
 Post subject: WARNING re Adobe
PostPosted: 07/29/09 1:57 pm • # 11 
User avatar
Editorialist

Joined: 05/23/09
Posts: 3185
Location: ontario canada
jabra2 wrote:
Uhmm, just want to throw in another little tidbit...
I'll highlight the appropriate parts for the stubborn folks.

This critical vulnerability could allow an attacker who successfully exploits the vulnerability to take control of the affected system.

Note that this vulnerability is exclusive to Internet Explorer on Windows.

Installations of Flash Player for Firefox or other web browsers on Windows are not vulnerable.


Hey, looks like Shera's post design! Image


Btw, where's the Feathered One? Vacation? Tree-climbing in his kilt and got hung up on some tree limbs and can't get back down? Image



ROFL--I'm working on him, but he still thinks it's going to be too much trouble. You crazy non-conformists...


Top
  
 Offline
 Post subject: WARNING re Adobe
PostPosted: 07/29/09 1:59 pm • # 12 
User avatar
Editorialist

Joined: 05/23/09
Posts: 3185
Location: ontario canada
Thanks for saving the world again, oh masked one...


Top
  
Display posts from previous:  Sort by  

  Page 1 of 1   [ 12 posts ] New Topic Add Reply

All times are UTC - 6 hours



Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
© Voices or Choices.
All rights reserved.