Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Nasty PDF exploit runs wild
The Register ^ | Wednesday 24th October 2007 00:57 GMT | Dan Goodin

Posted on 10/23/2007 7:58:32 PM PDT by james500

A day after Adobe patched a serious security hole in its Reader and Acrobat programs, miscreants are flooding email inboxes with malware-tainted PDF files that try to remotely hijack vulnerable computers.

The malware, identified by Symantec researchers as Trojan.Pidief.A, is included in PDF files attached to a "fair number of emails," according to this blog entry. The spam typically targets specific businesses or organizations.

Adobe issued a patch for the vulnerability on Monday. The revelation of in-the-wild exploits underscores the importance of updating immediately. A patch for Reader is available here; an Acrobat update is available here.

Emails typically arrive bearing subjects such as "invoice," "statement" or "bill" and contain no text in the body. If the attached PDF is opened using a vulnerable version of Adobe software, the machine will execute code that lowers Windows security settings and installs a bevy of nasty malware, according to the SANS Internet Storm Center.

At least some of the spam comes courtesy of the Russian Business Network, a St. Petersburg-based service provider that offers bullet-proof hosting to criminals engaged in child pornography, identity theft and spam, according to Ken Dunham, director of global response at iSIGHT Partners. "The code and servers used in the attack are nearly identical to September 2006 Vector Markup Language (VML) zero-day attacks that took place one year ago," he wrote in an email.


TOPICS: Crime/Corruption; News/Current Events; Russia
KEYWORDS: adobe; computerhelp; computersecurity; pdf; pdfs
Navigation: use the links below to view more comments.
first 1-2021-4041-52 next last
the links in the article:

READER update

http://www.adobe.com/support/downloads/detail.jsp?ftpID=3806

ACROBAT update

http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows

1 posted on 10/23/2007 7:58:34 PM PDT by james500
[ Post Reply | Private Reply | View Replies]

To: james500

As usual, this malware does not attack Macs.


2 posted on 10/23/2007 8:02:42 PM PDT by docbnj
[ Post Reply | Private Reply | To 1 | View Replies]

To: james500
If the attached PDF is opened

Well, thar ya go.
3 posted on 10/23/2007 8:09:16 PM PDT by Thrownatbirth (.....when the sidewalks are safe for the little guy.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: james500

I use Foxit for PDF files. I wonder if it is vulnerable as well.


4 posted on 10/23/2007 8:17:10 PM PDT by Ghengis (Of course freedom is free. If it wasn't, it would be called expensivedom. ~Cindy Sheehan 11/11/06)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 2nd amendment mama

ping!


5 posted on 10/23/2007 8:29:05 PM PDT by basil (Support the Second Amendment--buy another gun today!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

ping


6 posted on 10/23/2007 8:30:35 PM PDT by Jet Jaguar (Who would the terrorists vote for?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Jet Jaguar

bump for work


7 posted on 10/23/2007 8:31:36 PM PDT by Robe (Rome did not create a great empire by talking, they did it by killing all those who opposed them)
[ Post Reply | Private Reply | To 6 | View Replies]

To: james500

This is for XP...NOT VISTA


8 posted on 10/23/2007 8:36:50 PM PDT by shield (A wise man's heart is at his RIGHT hand;but a fool's heart at his LEFT. Ecc 10:2)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ghengis
I use Foxit for PDF files. I wonder if it is vulnerable as well.

So do I.

I would tend to doubt that Foxit is vulnerable. It is merely an executable and does not install to the registry as does Adobe. But I could be wrong. The payload may not care what opens it.

9 posted on 10/23/2007 8:38:43 PM PDT by Bloody Sam Roberts (Jet noise. The Sound of Freedom. - Go Air Force!)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Bloody Sam Roberts

Why would anyone open any file from an unknown source?


10 posted on 10/23/2007 8:43:52 PM PDT by canadianally
[ Post Reply | Private Reply | To 9 | View Replies]

To: ShadowAce

Now, I know next to nothing about the OS security structure/model of the Windows OS(s), but why is this considered a flaw in Adobe, and not Windows?


11 posted on 10/23/2007 8:51:33 PM PDT by KayEyeDoubleDee (const Tag &referenceToConstTag)
[ Post Reply | Private Reply | To 1 | View Replies]

To: canadianally
Why would anyone open any file from an unknown source?

Well, there is that...yes.

But if your cat happened to jump on the mouse at just the right angle when the email message is open....it could happen.

12 posted on 10/23/2007 8:54:20 PM PDT by Bloody Sam Roberts (Jet noise. The Sound of Freedom. - Go Air Force!)
[ Post Reply | Private Reply | To 10 | View Replies]

To: docbnj
As usual, this malware does not attack Macs.

Because no one cares about attacking less than 10% of the marketplace. It's the same reason people like me don't develop software for them, it's not worth my time.
13 posted on 10/23/2007 8:59:44 PM PDT by TheZMan (Texas is no place for pansy-ass liberals. Ya'll move back to California er Mexico er somethin')
[ Post Reply | Private Reply | To 2 | View Replies]

To: TheZMan
Ouuh Ahh...Applause... Nice shot
14 posted on 10/23/2007 9:08:38 PM PDT by hatfieldmccoy (Satan has a new name and it is Islam)
[ Post Reply | Private Reply | To 13 | View Replies]

To: james500

“Hello, I sendo this invoice to you for your review”


15 posted on 10/23/2007 9:13:51 PM PDT by Rb ver. 2.0 (The WOT will end when pork products are weaponized)
[ Post Reply | Private Reply | To 1 | View Replies]

To: LibreOuMort; sionnsar

ping


16 posted on 10/23/2007 9:15:07 PM PDT by sionnsar (trad-anglican.faithweb.com |Iran Azadi| 5yst3m 0wn3d - it's N0t Y0ur5 (SONY) | UN: Useless Nations)
[ Post Reply | Private Reply | To 1 | View Replies]

To: james500
If the attached PDF is opened

I see. So the "malware" only attacks the computers of stupid people.

17 posted on 10/23/2007 9:17:08 PM PDT by montag813
[ Post Reply | Private Reply | To 1 | View Replies]

To: TheZMan

Oh c’mon— thats an extremely tired response as to why Apple has no viruses.....
You seen the latest earning reports over at Apple? You might want to rethink that not developing for Apple thing...
- also- if we have 10% market share, why not at least one virus in the wild? Not even asking for 10% ( Our fair share) of the viruses....
In any case, I’m certain writing for windows is a pretty good career path, what with all the productivity gains / anti-virus and anti spyware/adware assistance needed on that platform....


18 posted on 10/23/2007 9:18:17 PM PDT by humantech ("No one wants to live to see such evil times. Its what you do with the time you are given")
[ Post Reply | Private Reply | To 13 | View Replies]

To: TheZMan

Lessee, MS has 90% of the marketplace for applications written for windows. They have 25% of the marketplace for Mac. Given that software support costs for Mac have traditionally far less than that for windows, I would say that the software you write is either not wanted by Mac users or you are missing an opportunity which MS isn’t.

Personally, I have little use for MS, but I have never denied that they have a certain brilliance marketing-wise. They don’t ignore the Mac market. And it is not a lost leader for them, either.

Think about it.


19 posted on 10/23/2007 10:02:08 PM PDT by Frumious Bandersnatch
[ Post Reply | Private Reply | To 13 | View Replies]

To: humantech

Not much fun hacking around with stuff that won’t aggravate the “establishment” computer users up there in the corporate world. Why would the goofy little script-kiddies modify a virus that’s more likely to bust a highschool boyfriend’s fruit machine than to make it into the news?


20 posted on 10/23/2007 10:05:03 PM PDT by Fortyfied
[ Post Reply | Private Reply | To 18 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-52 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson