Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Temporary solution for Adobe bug

Notifications for Security Updates, as well as News and Information from across the web - mostly security minded.

Update Contributors: Members of the Malware Removal University.

Regular Members: Our Regular Members are invited to start and/or participate in all other topics. Join in and share the news that's important to you.

Temporary solution for Adobe bug

Unread postby Sludge3000 » April 8th, 2010, 4:26 am

The attack was first demonstrated last week by researcher Didier Stevens. By misusing a feature contained in the PDF specification, his proof-of-concept attack showed how hackers could embed a malicious payload in a document and trick Adobe's Reader and Acrobat applications - as well as the competing FoxIT Reader - into executing it.

In the meantime, users who have no need for the automatic launch feature (and we're guessing this is 90 percent or more of them) can mitigate the threat by modifying their Reader or Acrobat preferences. To do this, go to Edit > Preferences and click on Trust Manager in the left pane. Then, uncheck the box for "Allow opening of non-PDF file attachments with external applications."


Full story @ The Register
User avatar
Sludge3000
Regular Member
 
Posts: 695
Joined: April 15th, 2009, 3:47 pm
Location: Somewhere fluffy
Advertisement
Register to Remove

Re: Temporary solution for Adobe bug

Unread postby Sludge3000 » April 16th, 2010, 4:10 am

UPDATE - Bug now being abused in the wild.

Criminals behind the notorious Zeus crimeware package have begun exploiting an unpatched hole in the widely used portable document format to install malware on end user computers.

The booby-trapped PDF documents arrive in emails that purport to contain a billing invoice, according to a post from M86 Security Labs. If the user opens the documents and clicks through a series of dialog boxes, PDF readers from Adobe will execute a file that makes the PC a part of a botnet (The FoxIT reader will automatically save the malicious file on the user's hard drive.)


Full story @ The Register

Blog post @ m86 security
User avatar
Sludge3000
Regular Member
 
Posts: 695
Joined: April 15th, 2009, 3:47 pm
Location: Somewhere fluffy


Return to News Desk



Who is online

Users browsing this forum: No registered users and 30 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware