Showing posts with label exploit. Show all posts
Showing posts with label exploit. Show all posts

Monday, May 10, 2010

Updated Foxit Reader Blocks "Launch" Issue

Foxit Software has released a new version of their PDF viewer software. Foxit Reader 3.3 contains "Trust Manager" that blocks all external commands that may be tucked into a PDF document. The update is a response to reported malware campaigns abusing unfixed "/Launch" flaw.

Source

Friday, February 20, 2009

Buffer Overflow Issue In Adobe Reader And Acrobat - No Patch Available Yet

Adobe warns about a critical vulnerability in Adobe Reader 9 & Acrobat and earlier versions. The found vulnerability would cause the application to crash and could potentially allow an attacker to take control of the affected system. The issue is being exploited already.

There's no update released to patch the vulnerability yet. "Adobe expects to make available an update for Adobe Reader 9 and Acrobat 9 by March 11th, 2009. Updates for Adobe Reader 8 and Acrobat 8 will follow soon after, with Adobe Reader 7 and Acrobat 7 updates to follow."

While waiting for the fix users should keep their antivirus programs up-to-date and avoid opening files from dubious sources.

Adobe's security advisory on the issue can be found here.

Wednesday, January 28, 2009

Downadup Worm Taking Advantage of Universal Plug And Play

Downadup aka Conficker worm is at the moment a hot topic in computer security. This parasite has infected systems all over the world using a variety of methods to spread itself. One of these is a remote procedure call (RPC) exploit against the MS08-067 vulnerability. Using the vulnerability, the worm injects shellcode that connects back to the infecting machine. This is known as a back-connect. The back-connect works via HTTP on a randomly selected port and the infecting machine responds to incoming requests by providing the entire worm file. The shellcode receives this file and executes it on the remote host, causing it to then become infected.

Nowadays, many users have routers and other gateway devices that by default prevent external computers from connecting their home systems in addition to using network address translation (NAT). Normally that makes back-connect establishing fail and that way protect against Downadup infection.

However, this worm is a sneaky one and tries to bypass the issue by taking advantage of Universal Plug and Play (UPnP) protocol. Eric Chien describes in Symantec Security Response Blog entry how that is done.

Wednesday, August 20, 2008

China Netcom DNS Cache Poisoning

Websense® Security Labs™ ThreatSeeker™ Network has detected that the DNS cache on the default DNS server used by the customers of China Netcom (CNC) has been poisoned. When China Netcom customers mistype and enter an invalid domain name, the poisoned DNS server directs the visitor's browser to a page that contains malicious code.

When users mistype a domain name they are sometimes directed by their ISPs to a placeholder Web site with generic advertisements. In the case of CNC its customers are directed to a web site under the control of an attacker. Malicious sites contain an iframe with malicious code that attempts to exploit RealPlayer, MS06-014, MS Snapshot Viewer and Adobe Flash player vulnerabilities.