![]() |
#1 |
My True Self
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,126
Karma: 66242098
Join Date: Apr 2010
Location: Trantor, Galactic Center
Device: Galaxy Tab 2 7.0
|
Attack Riddles Adobe Reader
Interesting.
New Zero-Day Attack Riddles Adobe Reader "Adobe software is everywhere. It's even more ubiquitous than Windows, and perhaps even more vulnerable to hacker schemes. " "In an advisory posted on its website Wednesday, Adobe said essentially all versions of its Acrobat and Reader programs running on Windows, Macintosh and Unix-based machines have been exposed to a "critical vulnerability that could cause a crash and potentially allow an attacker to take control of the affected system." I have a couple of unexpected crashes. Make me wonder. "The dangerous code is being unleashed via PDF files that users are enticed to open by a phishing email offering courses from David Leadbetter, a world-renowned golf instructor. When the PDF file is opened, it downloads a hidden program that attacks the user's system." I should be safe. IF that is the only one out there. "While Microsoft (Nasdaq: MSFT) -- which is known for its "Patch Tuesday" regimen of issuing security fixes -- gets much more press about security issues, Adobe actually may be the victim of more attacks, Abrams suggested." Last edited by SameOldStory; 09-09-2010 at 05:26 PM. |
![]() |
![]() |
![]() |
#2 |
Kate
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,700
Karma: 3605799
Join Date: Mar 2009
Location: Oregon, United States
Device: MeeBook, Kobo Libra Colour
|
Never open attachments from people you don't know, or from people you *do* know unless you're expecting them to send you something.
|
![]() |
![]() |
Advert | |
|
![]() |
#3 |
Fanatic
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 555
Karma: 40032
Join Date: Oct 2008
Location: Boston :)
Device: Kindle, Kobo Aura H20, Pixel XL
|
Speaking of not opening suspicious attachments and pdf files.
"Here You Have" virus hit today..many corporations today. If you receive a message with this heading, do not open! Even if from someone you know. (Like many email viruses it will be sent from someone you know or has you in their address book). The emails with the subject "Here You Have" contain a link that encourages readers to click on a PDF document file. But rather than a PDF, the file contains a Windows script that transmits a virus and spams the entire contact list of the person who opened the file. A bit off-topic, but thought I would mention it. |
![]() |
![]() |
![]() |
#4 |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 11,230
Karma: 4651787
Join Date: Mar 2009
Device: Kindle, Kindle Fire, iPad, iPod Touch, Sony PRS-350
|
So is it good news that I only open all my emails on my iTouch now? I've noticed that I never read my emails on my laptop anymore.
|
![]() |
![]() |
![]() |
#5 |
Feral Underclass
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,622
Karma: 26821535
Join Date: Jan 2010
Location: Yorkshire, tha noz
Device: 2nd hand paperback
|
Foxit is better for PDF anyway.
|
![]() |
![]() |
Advert | |
|
![]() |
#6 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,230
Karma: 7145404
Join Date: Nov 2007
Location: Southern California
Device: Kindle Voyage & iPhone 7+
|
Not so Adobe-centric, just the vector of the day. Never open files from stangers, especially if they have SCR extension type, lol. Not that Adobe is blameless but every sophisticated OS or program has vulnerabilities.
|
![]() |
![]() |
![]() |
#7 |
Enthusiast
![]() Posts: 33
Karma: 22
Join Date: Aug 2010
Device: PRS-505
|
Doesn't matter if you open a suspicious file or not. All you have to do is go to a web page with a malicious PDF embedded in it (or the adverts). The player will automatically try to open it and the malware will install itself. Doesn't matter if you're running Firefox or IE either.
|
![]() |
![]() |
![]() |
#8 |
New York Editor
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 6,384
Karma: 16540415
Join Date: Aug 2007
Device: PalmTX, Pocket eDGe, Alcatel Fierce 4, RCA Viking Pro 10, Nexus 7
|
Adobe appears to be aware of it, if this is what is referred to:
http://www.adobe.com/support/securit...apsa10-02.html I couldn't find anything relating to the specific threat mentioned on Adobe's site. Nor could I find any on security vendor Secunia's list, or in the Gibson Research security forums at grc.com. You can see the current list of Adobe security advisories here: http://www.adobe.com/support/security/ I'm always a bit cynical when an announcement like this stems from a company that sells software designed to protect you from such things. I use Acrobat Reader here and haven't had problems. One thing I do do is set the Reader to open as a separate process, instead of installing as a plugin in the browser. This stems from problems a while back where Adobe Reader loaded in the browser as a plugin remained resident in memory even after you had closed the PDF and exited the browser. To do so, open Adobe Reader, select Edit/Preferences, and under Internet, uncheck Display PDF in browser It forces the Reader to launch as a separate process that does go away when you exit it. Adobe embeds a version of JavaScript in the Reader. You can turn that off by selecting JavaScript in Edit/Preferences and unchecking Enable Acrobat JavaScript Adobe Reader here is set to check for updates, so when Adobe issues a fix I'll get it automatically. Meanwhile, as others have mentioned, never open email attachments unless you know what they are and who they are from. They are a favorite method of delivering malicious content. I use a GMail account as my primary email, so attachments all stay on Google's servers, and never actually reach my machine unless I choose to download them. They get scanned by my A/V software if I do. ______ Dennis |
![]() |
![]() |
![]() |
#9 | |
My True Self
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,126
Karma: 66242098
Join Date: Apr 2010
Location: Trantor, Galactic Center
Device: Galaxy Tab 2 7.0
|
Quote:
My wife thinks that you get a virus from porn sites. I had an anti-virus program on her computer but for whatever reason it was turned off. One day she's pounding on her keyboard yelling that I had to get her a new computer, hers was too slow. Needless to say, I couldn't connect to, or download from, any anti-virus web sites. I downloaded one from my computer to a USB drive and installed it on her computer. It found more than 350 pieces of spyware, malware, and viruses. ![]() I now use the free version of Avast. It'll give you a pop-up when it detects a web page that tries to sneak something nasty into your computer. |
|
![]() |
![]() |
![]() |
#10 | ||
New York Editor
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 6,384
Karma: 16540415
Join Date: Aug 2007
Device: PalmTX, Pocket eDGe, Alcatel Fierce 4, RCA Viking Pro 10, Nexus 7
|
They aren't all virus ridden, but a number do host exploits of one sort or another. The most common attack vector is a claim you need a special codec to watch a video on the site. Download and install the codec, and you are pwned.
![]() Quote:
Quote:
I treat viruses and malware like diseases. Diseases enter a system though a vector, and the simplest way to avoid problems is to ward the vectors. I have some simple rules of thumb when using Windows: 1. Don't use Internet Explorer as your web browser. Just don't. Most spyware/malware targets IE, and bounces off if you use something else. 2. Keep Windows fully patched. Turn on auto-update to get critical security patches automatically, and apply them. 3. Turn off Windows default behavior of "Hide known file type extensions". In Windows Explorer, click Tools/Options. Click the View tab. Uncheck the "Hide extensions for known file types" box. Attackers use this to disguise malicious content. If it's turned on, you don't know that email attachment labelled "cute kitten picture.jpg" is really "cute kitten picture.jpg.exe, and clicking on it executes the program. 4. Run a good A/V software package, and keep the virus signatures updated. And on that line, viruses and spyware/malware are different kinds of threats. Do not assume protection software intended for one also protects against the other. 5. Run a firewall. There are an assortment of free firewall packages available for home users. If nothing else, make sure Windows Firewall is turned on. It does a decent job of stopping unauthorized outside access to your machine. Where it falls down is controlling outbound access from your machine. 6. Don't open attachments in email unless you are certain of where they are from and who sent them. (See #3 above for one reason why.) 7. Only download from known good sites that scan files on their end before making them available for DL. 8. Remember that the Internet is like a big city. It has bad neighborhoods you don't want to be in. Be aware of where you are and what you're doing. 9. See Rule 1. ![]() ______ Dennis Last edited by DMcCunney; 09-11-2010 at 02:17 AM. |
||
![]() |
![]() |
![]() |
#11 |
My True Self
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,126
Karma: 66242098
Join Date: Apr 2010
Location: Trantor, Galactic Center
Device: Galaxy Tab 2 7.0
|
I stopped using Norton a long time ago. Too much got by it. May be better today, but I'm no longer interested in it.
My favorite anti-virus software used to be McAfee. Until someone wrote a virus that turned it off. This was before it required a password to turn it off. That was a long time ago. Don't know if they still do that. "1. Don't use Internet Explorer as your web browser. Just don't. Most spyware/malware targets IE, and bounces if it you use something else." I think that most viruses get tested on the major anti-virus and web browsers before they get released. The win because so few people update their software, whatever it may be. I had a virus onetime because I was using an old version of Java. Live and learn. |
![]() |
![]() |
![]() |
#12 | ||||
New York Editor
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 6,384
Karma: 16540415
Join Date: Aug 2007
Device: PalmTX, Pocket eDGe, Alcatel Fierce 4, RCA Viking Pro 10, Nexus 7
|
Quote:
Quote:
See http://techcrunch.com/2010/08/19/int...llion-in-cash/ Quote:
Bad guys found ways to exploit security holes in Windows and IE to do "drive by installs" of rogue Active-X controls, that did not show any signs it was happening. You could get infected by visiting a compromised web site, and never know what happened till your machine started showing symptoms. Firefox got a lot of early users because it was more secure than IE. A good deal of that was simply not supporting Active-X controls as a security measure. (You can get an add-on that will let you run Active-X controls in Firefox, but it's a "not recommended, and you better know what you're doing!" exercise.) Google Chrome, Opera, and Safari also don't support Active-X, and are safer alternatives than IE. IE7 was supposed to be the big security push, and it's safer than IE6, but I still wouldn't call it secure. My preference is Firefox, with the NoScript add-on that blocks scripting activity unless the site is in a whitelist. Quote:
_______ Dennis |
||||
![]() |
![]() |
![]() |
#13 |
My True Self
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,126
Karma: 66242098
Join Date: Apr 2010
Location: Trantor, Galactic Center
Device: Galaxy Tab 2 7.0
|
Google Chrome version 6.0.472.55
Don't bet too much money on it being safer. Avast popped up to say that it had detected something while I was using Chrome Monday or Tuesday. I don't get it often enough not to care what it is, I just close out the tab. Is that a weekness of Chrome? Probably not, just Avast saying that something is there and I shopuld go away. As I said, the people that write the virus will write it, AND test it, against anything that's popular. With so many people absolutely, and insanely, hating MS Windows most of the viruses will be aimed there. Not that I'm paranoid, but I occasionally turn off "System Restore", and switch to "Safe Mode" before updating my anti-virus software. Then I'll scan in safe mode. Restart the computer and scan again. I'll do this if things seem strange. Mayby once a year in Windows XP, but only once in Windows 7. |
![]() |
![]() |
![]() |
#14 | ||||
New York Editor
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 6,384
Karma: 16540415
Join Date: Aug 2007
Device: PalmTX, Pocket eDGe, Alcatel Fierce 4, RCA Viking Pro 10, Nexus 7
|
Google Chrome us up to 7.0.517.0. You might wish to upgrade.
Quote:
Those aren't the only threats out there, and a safe browser is only one component of a layered defense. Quote:
Quote:
Microsoft Windows has the overwhelming share of the market, so it's where the overwhelming share of threats are directed. And bear in mind that viruses and spyware/malware are different kinds of threats. A/V software probably won't stop spyware/malware, and vice versa. Quote:
The last attempt at spyware/malware was a browser hijack attempt spawned by an auto-execute routine when opening a RAR file. It, too, was trivial to block. I believe it's simpler to not get infected than to clean up the mess once you have been. Since I've had no significant problems in several decades, I think I'm on the right track in terms of security. ______ Dennis |
||||
![]() |
![]() |
![]() |
#15 |
My True Self
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,126
Karma: 66242098
Join Date: Apr 2010
Location: Trantor, Galactic Center
Device: Galaxy Tab 2 7.0
|
"The last virus that bit was a Word Macro virus on a floppy from my then boss,"
Interestingly the company I work for actually puts, what is basically, a browser hijacker on our laptops. I can get rid of it, but every time we log on to the company's network it gets added back on to the laptop. What does it do? It makes our home page the companies main trashy web site. ![]() We're limited to what we can install on the laptops so the best way to get around it is with Google Chrome on a USB drive. But that's a nuisance so I just gave up. |
![]() |
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Why will Adobe not see my reader | surfingtroll | Sony Reader | 5 | 08-02-2009 03:08 PM |
My reader is trying to give me a heart attack... | Riocaz | Sony Reader | 16 | 04-07-2009 03:08 AM |
Adobe DE 1.5 and the Sony Reader | charlieperry | Sony Reader | 2 | 02-15-2008 07:56 AM |
Adobe reader? | fishcube | Sony Reader | 30 | 09-28-2007 11:12 AM |
iriver e-book reader powered by Adobe Reader LE, more photos | Alexander Turcic | News | 14 | 06-13-2007 01:23 AM |