ABXZone Computer  Forums



Welcome to the ABXZone Computer Forums forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.
Why not Register and remove some of the ads from The ABXZone
Reply
 
LinkBack Thread Tools Display Modes
Old 09-22-2007, 09:47 PM   #1
Grab Life By The Balls
 
SRTDodge05's Avatar
 
Join Date: Jan 2003
Location: Michigan
Posts: 7,691
Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

A security researcher and self-described hacker known as "pdp" claims he has found a critical exploit in Adobe's Acrobat software that can compromise many Windows PCs simply by viewing a maliciously-crafted PDF file. The flaw affects both Windows XP SP2 and Windows 2003; Windows Vista, OS X, and Linux users are unaffected.

The bug affects Acrobat Reader, versions 8.1, 8.0, and 7, either when run in stand-alone mode or embedded inside a web page. Some work-alike PDF readers, such as the svelte Foxit Reader, are also affected but in a lesser manner: they display a confirmation dialog before the exploit is allowed to run.
The exploit uses a flaw in Adobe's scripting language to automatically run an executable program—the discoverer tested this by harmlessly running Calculator and Notepad in a video on his site. Yet, as noted, the exploit could be used to run any program, including a trojan or virus or a scripted attack. The malware in question would have to have already been downloaded onto the victim's computer, but this could be accomplished in various ways, including putting the executable inside a .ZIP file that includes the original PDF, or linking to a remote executable (the latter option would still trigger a warning by the operating system, however).

Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits
(Offline)   Reply With Quote
Old 09-22-2007, 10:07 PM   #2
Registered User
 
Join Date: Apr 2006
Posts: 339
Re: Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

I'm still using Acrobat 5.1, best version ever.
__________________
OS Microsoft Windows XP Professional SP2 CPU Intel Core 2 Duo E6600 3.0 GHz (Conroe)
Motherboard ASUS P5B-E RAM 2 GB Kingston DDR2-667 4-4-4-12 Dual Channel
Video NVIDIA GeForce 7950 GT PCI-E 512 MB Audio SoundMAX HD Audio

OS Microsoft Windows XP Professional SP2 CPU Intel Pentium 4 3.0 GHz with HT (Northwood)
Motherboard ASUS P4P800 Deluxe RAM 1 GB Kingston DDR400 3-3-3-8 Dual Channel
Video NVIDIA GeForce 7600 GT AGP 256 MB Audio SoundMAX Digital Audio

OS Microsoft Windows XP Professional SP2 CPU Intel Pentium III 1.0 GHz (Coppermine)
Motherboard ASUS P3V4X RAM 256 MB Kingston PC133 2-2-2-6
Video NVIDIA GeForce2 MX400 AGP 64 MB Audio Creative Sound Blaster Live!
(Offline)   Reply With Quote
Old 09-23-2007, 09:11 AM   #3
XJ.
Registered User
 
XJ.'s Avatar
 
Join Date: Apr 2002
Location: NH, USA
Posts: 5,715
Re: Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

I use Foxit, just because AA is such a target (and slow).
(Offline)   Reply With Quote
Old 09-23-2007, 10:31 AM   #4
Sleuth
 
Cogar's Avatar
 
Join Date: Dec 2002
Location: It varies, but usually within 100 feet of a keyboard.
Posts: 7,090
Re: Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

Thank you for the warning. It's getting so you cannot trust anyone anymore.
(Offline)   Reply With Quote
Old 09-23-2007, 04:01 PM   #5
Grab Life By The Balls
 
SRTDodge05's Avatar
 
Join Date: Jan 2003
Location: Michigan
Posts: 7,691
Re: Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

MS needs to comeout with a pdf program.
(Offline)   Reply With Quote
Old 09-23-2007, 10:23 PM   #6
You can run.....
 
3 of 7's Avatar
 
Join Date: Feb 2004
Posts: 4,558
Re: Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

Quote:
Originally Posted by SRTDodge05 View Post
MS needs to comeout with a pdf program.
I don't see it happening.. They could never compete with Foxit and it's free....
They'll probably buy Foxit and bloat it up and make it not work like they did with Giant software..

Come to think of it, I have no idea at all why anyone would even consider using Acrobat reader anymore, with Foxit out there..
(Offline)   Reply With Quote
Old 09-24-2007, 12:52 AM   #7
C1eaner
 
bajo's Avatar
 
Join Date: Feb 2001
Location: TX, USA
Posts: 17,107
Talking Re: Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

Well, just switched back to AR 5.1 !
__________________
USA "I won't be wronged, I won't be insulted, and I won't be laid a hand on. I don't do these things to other people, and I require the same from them." Duke (The Shootist)

Gigabyte_AGP_LGA775, PentiumD960_dual core 3.6GHz, SapphireHD3850_AGP512MB_DDR2, WD RaptorX 150GB SATA_clearTop_16MB + Seagate 1TB SATA_32MB, CorsairDominator 2GB 8500_1066MHz, Dell 24" 2408WFP *AGP +DVIx2 +HDMI +DisplayPort +USB2x4, XPproSP3
Inspiron9400 17"uxga CentrinoC2duoT7600_2.39GHz_685MHz 4GB Micron6400@800_675_400MHz GeForceGo7900GSMobileForce_M6Enhanced_256MB 2x200GbSATA_7200rpm_16MBcache Vista hp, VistaP6001SP1
(Offline)   Reply With Quote
Old 09-24-2007, 08:17 AM   #8
Grab Life By The Balls
 
SRTDodge05's Avatar
 
Join Date: Jan 2003
Location: Michigan
Posts: 7,691
Re: Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

Quote:
Originally Posted by 3 of 7 View Post
I don't see it happening.. They could never compete with Foxit and it's free....
They'll probably buy Foxit and bloat it up and make it not work like they did with Giant software..

Come to think of it, I have no idea at all why anyone would even consider using Acrobat reader anymore, with Foxit out there..
Acrobat reader is the only pdf viewer i use.
(Offline)   Reply With Quote
Old 09-24-2007, 08:24 AM   #9
You can run.....
 
3 of 7's Avatar
 
Join Date: Feb 2004
Posts: 4,558
Re: Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

Quote:
Originally Posted by SRTDodge05 View Post
Acrobat reader is the only pdf viewer i use.
Have you tried Foxit?

Foxit Software
(Offline)   Reply With Quote
Old 09-24-2007, 08:28 AM   #10
Grab Life By The Balls
 
SRTDodge05's Avatar
 
Join Date: Jan 2003
Location: Michigan
Posts: 7,691
Re: Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

Quote:
Originally Posted by 3 of 7 View Post
Have you tried Foxit?

Foxit Software
No, i never heard of it before.
(Offline)   Reply With Quote
Old 09-24-2007, 08:30 AM   #11
You can run.....
 
3 of 7's Avatar
 
Join Date: Feb 2004
Posts: 4,558
Re: Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

Give it a try, I think you'll be surprised..
(Offline)   Reply With Quote
Old 09-24-2007, 08:35 AM   #12
Grab Life By The Balls
 
SRTDodge05's Avatar
 
Join Date: Jan 2003
Location: Michigan
Posts: 7,691
Re: Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

I'll have to give it a try, ill add it to my list of things to do.
(Offline)   Reply With Quote
Old 09-24-2007, 07:01 PM   #13
Registered User
 
Join Date: Apr 2006
Posts: 339
Re: Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

Quote:
Originally Posted by bajo View Post
Well, just switched back to AR 5.1 !
5.1 FTW
__________________
OS Microsoft Windows XP Professional SP2 CPU Intel Core 2 Duo E6600 3.0 GHz (Conroe)
Motherboard ASUS P5B-E RAM 2 GB Kingston DDR2-667 4-4-4-12 Dual Channel
Video NVIDIA GeForce 7950 GT PCI-E 512 MB Audio SoundMAX HD Audio

OS Microsoft Windows XP Professional SP2 CPU Intel Pentium 4 3.0 GHz with HT (Northwood)
Motherboard ASUS P4P800 Deluxe RAM 1 GB Kingston DDR400 3-3-3-8 Dual Channel
Video NVIDIA GeForce 7600 GT AGP 256 MB Audio SoundMAX Digital Audio

OS Microsoft Windows XP Professional SP2 CPU Intel Pentium III 1.0 GHz (Coppermine)
Motherboard ASUS P3V4X RAM 256 MB Kingston PC133 2-2-2-6
Video NVIDIA GeForce2 MX400 AGP 64 MB Audio Creative Sound Blaster Live!
(Offline)   Reply With Quote
Old 09-24-2007, 07:03 PM   #14
C1eaner
 
bajo's Avatar
 
Join Date: Feb 2001
Location: TX, USA
Posts: 17,107
Re: Critical Acrobat Reader security flaw exposes Windows to arbitrary exploits

__________________
USA "I won't be wronged, I won't be insulted, and I won't be laid a hand on. I don't do these things to other people, and I require the same from them." Duke (The Shootist)

Gigabyte_AGP_LGA775, PentiumD960_dual core 3.6GHz, SapphireHD3850_AGP512MB_DDR2, WD RaptorX 150GB SATA_clearTop_16MB + Seagate 1TB SATA_32MB, CorsairDominator 2GB 8500_1066MHz, Dell 24" 2408WFP *AGP +DVIx2 +HDMI +DisplayPort +USB2x4, XPproSP3
Inspiron9400 17"uxga CentrinoC2duoT7600_2.39GHz_685MHz 4GB Micron6400@800_675_400MHz GeForceGo7900GSMobileForce_M6Enhanced_256MB 2x200GbSATA_7200rpm_16MBcache Vista hp, VistaP6001SP1
(Offline)   Reply With Quote
Old 09-24-2007, 09:33 PM   #15
Where to next?
 
traveler's Avatar
 
Join Date: May 2001
Location: South Florida
Posts: 17,496
- - - - - - - no auto parrot here - - - - - - -

Quote:
Originally Posted by JMerrick View Post
I'm still using Acrobat 5.1, best version ever.

I'm currently using v.6. Should I switch back?


(Online)   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.1
vBulletin Skin developed by: vBStyles.com