The Portable Document Format ... PDF .... perhaps the most used way to share or distribute documents on internet ... its because it provides , portability , security and authoritativeness for documents , right ?? You might be surprised to read that , Acrobat Reader is perhaps the most downloaded and uses application among internet users ... reason ?? , because , its free , popular and ultra light .. ( err not by "weight" , by performance and resource consumption ) ...
Secure Computing’s Anti-Malware Research Labs spotted a new and yet unknown exploit toolkit which exclusively targets Adobe’s PDF format !!! This new toolkit targets only PDFs, no other exploits are used to leverage vulnerabilities. Typical functions like caching the already infected users are deployed by this toolkit on the sever-side. Whenever a malicious PDF exploit is successfully delivered, the victim’s IP address is remembered for a certain period of time. During this “ban time” the exploit is not delivered to that IP again, which is another burden for incident handling. Malware spreaders have put this kind of exploits to their arsenal of malicious weapons for a longer time already. The “Tibs” group of malware, for example, is known for planting malicious IFRAMEs onto infected legitimate web sites and having them refer back to their exploit servers. Dissecting the shellcode shows that the payload of the exploits tries to load more malware and the different number per exploit appears to be a kind of affilation ID to keep some statistics and track their different malware campaigns.
But , Secure Anti-Malware customers are protected since such PDF exploits are blocked proactively as “Script.Shellcode.Gen”!!! And don’t forget to not only patch the latested operating system and browser vulnerabilities, but also keep an eye on third-party browser plugins like Adobe Reader, Flash Player and QuickTime.
Better be carefull out there ....
Njoy ...
Friday, September 26, 2008
Beware of PDFs ???
Labels: internet, vulnerability
Subscribe to:
Post Comments (Atom)
Archive
-
▼
2008
(81)
-
▼
September
(18)
- Lyrics with Song ...
- Beware of PDFs ???
- Make the way for P4P .......
- MEWU - Scene 6 ... Want to replace FireFox ??
- (Un)Official Chrome for Linux !!!
- Find the Bots in your computer !!!
- MD5 ..... cross check the integrity ...
- Free AntiVirus for One Year !!!
- Top 10 Linux Distros !!!
- Useful Add-Ons for FireFox ...
- MEWU - Scene 5 ... Playing With Shark !?!?
- MEWU - Scene 4 ... GUI Firewall ..
- free PDF converter ....
- MEWU - Scene 3 ... Playing with DOCK
- China's Challenge to Intel !!!
- New browser from Google !!!
- MEWU - Scene 2 ... Need some Wine !!!
- Keep Track of your BandWidth ...
-
▼
September
(18)
Tags
- antivirus (5)
- cloud computing (3)
- computer (7)
- eyecandy (2)
- firefox (5)
- free (13)
- information (23)
- internet (59)
- linux (6)
- MEWU (9)
- My First Birthday.... (1)
- news (52)
- security (21)
- software (37)
- technology (27)
- ubuntu (12)
- vulnerability (22)
- windows (42)
- windows xp (4)
Creative Commons
Random Thoughts .... by Gaurang is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 United States License.
0 comments:
Post a Comment