Syndicate

Syndicate content

Flattr


Flattr this

If you like this, you can use flattr. ;)

Imprint

About
eMail: wishinet at gmail . com
PGP ID: 0xCCCA5E74

Jabber: wishi@jabber.ccc.de

Tags for this post

Javascript, Acrobat, Linux and the Swine Flu

txttxt

JS and the Acrobat bring the Swine Flu to Linux


2D803207-F47D-42C0-846A-54DCE90C809A.jpg
Human or swine origin - in case of spammers that's now the question.



It seems to be a strange friendship: since JavaScript in Adobe's Acrobat Reader is common, targeted Office Malware attacks against it are everywhere. What's extraordinary dangerous here is, that especially unsophisticated users who just do their Office-stuff, are affected. - Not just the Administrator or any other IT person, that'll be far away to fix this.
Because of the Swine Flu spamming a successful spreading of this Malware seems to be very much likely. So no pandemic situation in the real world, but in IT?

These attacks are targeted to cause Data Leakage. Disclosure happens after the Exploits aren't useful any longer. That's now - nearly. I expect a Windows Exploit within the next two days appearing in the feeds.

SecurityFocus reports about the Acrobat Reader - but it just recently had another remote Exploit. Secunia's advisory links to the original ones from Packetstom:

http://packetstorm.linuxsecurity.com/0904-exploits/spell.txt
http://packetstorm.linuxsecurity.com/0904-exploits/getannots.txt

The solution is very dissatisfying: just don't open strange PDFs. Nevertheless this actually directly only affects Linux - be aware that it's highly likely to cause trouble in a Windows or Mac environment, too. That's just what I assume.

Updates:

  • an 0day for Acrobat Reader was sold on the black-market for 75 000 $. Source seems to be Matthew Watchinski from VRT. A reliebale source. So deactivate JS in your Readers now. Maybe that helps.
  • F-Secure has a new collection of targeted examples. Maybe Spammers are too lazy to alter their target-files.
  • you have made up the policies at your DLP, didn't you? Check them, now! Again ;).
  • nice article in Tech Harald.

Have fun,
wishi

Post new comment

The content of this field is kept private and will not be shown publicly.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Save the nature. Don't print this!


I provide textual exports for every blog entry. However let's save the nature together. The nature is everything around us. Every being should be respected. Save the nature - don't print too much.


Die Umgehung dieser Ausdrucksperre ist nach § 95a UrhG verboten!
Inhaltlich Verantwortlicher gemäß § 10 Absatz 3 MDStV: Marius Ciepluch - Anschrift via eMail. Die eMail Adresse entnehmen sie dem Impresseum dieser englischsprachigen Seite.
Aus Datenschutzgründen habe ich weder offiziellen noch behördlichen Schriftverkehr via eMail. Dazu ist die postalische, beim Dienstleister hinterlegte, Anschrift zu verwenden.

Datenerfassung

Es werden keine personenbezogenen Daten erfasst. Logdaten werden anonymisiert.