Security [CENTRAL] Forum - SCforum.info
08. February 2012., 20:37:26 *
Welcome, Guest. Please login or register.

Login with username, password and session length
Help Niamh

Custom Search
News: Zemana AntiLogger - 50 licenses Giveaway !!!
 
  Home Help Chess Links Login Register   *

SCforum.info





Members
Total Members: 11206
Latest: chillalmd
Stats
Total Posts: 14792
Total Topics: 4146
Online Today: 2077
Online Ever: 51419
(01. January 2010., 10:27:49)

SCF UnSpam

Friend of WOT


SCF Feedburner

SCF Facebook

SCF Twitter

Welcome to SCforum.info - Security [CENTRAL] Forum, a home of the SCF Community devoted to provide Computer related News, Alerts, Downloads and FREE Help in such a way that even the novice computer user can understand.

Getting started using our community is extremely easy, check the two steps below:

Step 1: Create an account by clicking here and wait for approval from Administrator. It's completely free with no hidden strings attached.

Step 2: If you have a computer problem and need some help, or just want to take part in opened discussions, simply browse Forum. Once you *Register an account, you can quickly post your questions and comments.

(*Registered Members get: free support, also, they can communicate privately with other members via PM, removal of this message, see fewer ads and much more...)






Pages: 1
  Print  
Author Topic: Hackers love to exploit PDF bugs, says researcher (CVE-2010-0188)  (Read 1639 times)
0 Members and 1 Guest are viewing this topic.
Samker
SCF Administrator
*****

KARMA: 76
Gender: Male
Location: Europe
Posts: 4789


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« on: 11. March 2010., 07:56:36 »



Last month's Adobe Reader vulnerability now under attack, says F-Secure and Microsoft.


Hackers adore Adobe Reader, and have pushed it into first place as the software most often exploited in targeted attacks, a Finnish security company said today.

Helsinki-based F-Secure also urged users to update to the newest version of Reader to protect themselves against new attacks taking advantage of a vulnerability patched just three weeks ago.

According to F-Secure, 61% of the nearly 900 targeted attacks it's tracked in the first two months of 2010 exploited a vulnerability in Reader, Adobe's popular PDF viewer: http://www.f-secure.com/weblog/archives/00001903.html
By comparison, Microsoft's Word was exploited in just 24% of the attacks, and bugs in its Excel spreadsheet and PowerPoint presentation maker were leveraged only a combined 14% of the time.

Reader's slice of the targeted attack "market" climbed from 29% in 2008 to almost 50% last year, but at its pace so far this year, exploits aimed at Adobe's software are on track to account for nearly two out of every three attacks.

Microsoft's portion of targeted attack exploits, meanwhile, has steadily declined. Last year, for example, Word, Excel and PowerPoint exploits accounted for approximately 51% of attacks aimed at specific individuals or organizations. In 2008, exploits of those three Microsoft Office applications made up 71% of all targeted attacks.

Word, Excel and PowerPoint accounted for only 39% of all attacks so far this year, F-Secure said.

Targeted attacks can be disastrous to victimized companies and organizations. Google, for instance, was one of scores of Western corporations hit late last year and early this year by targeted attacks thought to originate from China. In Google's case, the attacks, which exploited a then-unpatched bug in Internet Explorer 6 (IE6), made off with company secrets. Intel was also attacked in January, but the chip maker has denied any connection between what hit its network and the Google-China attacks.

Earlier this week, the U.S. Federal Deposit Insurance Corporation (FDIC) said that hackers stole more than $120 million in just three months from small businesses' banking accounts, in some cases using malware carried by targeted attacks.

Adobe said it wasn't surprised at F-Secure's data. "Given the relative ubiquity and cross-platform reach of many of our products, Adobe has attracted -- and will likely continue to attract -- increasing attention from attackers," said spokeswoman Wiebke Lips in an e-mail.

She also urged users to update to the newest versions of Reader and other Adobe products. "The majority of attacks we are seeing are exploiting software installations that are not up-to-date on the latest security updates," she said.

F-Secure and Microsoft echoed Lips' recommendation, as both have discovered in-the-wild attacks exploiting a vulnerability Adobe patched less than a month ago: http://blogs.technet.com/mmpc/archive/2010/03/08/cve-2010-0188-patched-adobe-reader-vulnerability-is-actively-exploited-in-the-wild.aspx

On Feb. 16, Adobe issued an emergency update for Reader and Acrobat to patch a pair of flaws, including one tagged as CVE-2010-0188 in the Common Vulnerabilities and Exposures (CVE) database. Microsoft reported that bug to Adobe via its Microsoft Vulnerability Research Program (MSVR), where the company's security researchers submit flaws they find in third-party software to the programs' makers.

F-Secure's claim that Reader leads the exploit pack isn't the first time that a security company has awarded Adobe dubious honors. Last month, ScanSafe of San Bruno, Calif. said that malicious PDF files comprised 80% of all exploits at the end of last year.

The most up-to-date editions of Adobe Reader, 9.3.1 and 8.2.1, can be downloaded using links on Adobe's security site: http://www.adobe.com/support/security/bulletins/apsb10-07.html

(CW)
Logged

Security [CENTRAL] Forum - SCforum.info
« on: 11. March 2010., 07:56:36 »



 Logged
fotis100
SCF Member
**

KARMA: 2
Gender: Male
Age: 40
Location: GREECE
Posts: 29



« Reply #1 on: 12. March 2010., 10:00:19 »

thanks for your information. have a nice day BiH Smiley
Logged
laurent
SCF Member
**

KARMA: 0
Posts: 28


« Reply #2 on: 14. March 2010., 18:14:42 »

Instead of using Adobe Acrobat Reader which is a resource/memory hog,why not use foxit reader,a light alternative which should not be a very tempting target for malware.

link www.foxitsoftware.com/pdf/reader/
Logged
Pages: 1
  Print  
 
Jump to:  

Enter your email address to receive daily email with 'SCforum.info - Security CENTRAL Forum' newest content:

Terms of Use | Privacy Policy | Advertising
Powered by MySQL Powered by PHP Powered by SMF | SMF © 2011, Simple Machines
TinyPortal © Bloc
Valid XHTML 1.0! Valid CSS!


Google visited last this page 06. February 2012., 09:17:00