On mySimon: ifrogz Soft Touch Lux Case for iPhone 3g
BNET Business Network:
BNET
TechRepublic
ZDNet

August 5th, 2008

Adobe: Beware of fake Flash downloads

Posted by Ryan Naraine @ 4:26 am

Categories: Adobe, Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Data theft, Facebook, Flash, Malware, Microsoft, Passwords, Patch Watch, Pen testing, Social Networking Applications, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research, Web 2.0

Tags: Adobe Systems Inc., Macromedia Flash Player, Adobe Flash, Microsoft Windows, Tools & Techniques, Spyware, Adware & Malware, Cyberthreats, Security, Viruses And Worms, Operating Systems

Beware of fake Flash downloadsAmidst confirmed reports that malicious hackers are starting to use fake Flash Player downloads as social engineering lures for malware, Adobe has issued a call-to-arms for users to validate installers before downloading software updates.

The company’s notice comes on the heels of malware attacks on Facebook, MySpace and Twitter that attempt to trick Windows users into installing a Flash Player update that turns out to be a malicious executable.

Some golden advice from Adobe’s advisory:

First off, do not download Flash Player from a site other than adobe.com –  you can find the link for downloading Flash Player here. This goes for any piece of software (Reader, Windows Media Player, QuickTime, etc.) – if you get a notice to update, it’s not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious.

Second, all Adobe software for Windows is signed with a digital certificate that is validated by Windows when you install our software. The Publisher will always be ‘Adobe Systems, Incorporated’, and you can verify this when you double-click the installer, or by right-clicking on the installer, selecting ‘Properties’, and going to the ‘Digital Signatures’ tab.

For Flash Player in particular, computer users can use this page to verify what version of Flash Player is installed, and what the current version of Flash Player is for your operating system. The most recent version of Flash Player version is 9.0.124.0.

Adobe Flash is arguably the most widely deployed software in the world.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 27 Talkback(s)
RE: Adobe: Beware of fake Flash downloads
This is NOT new, it has been around since 2001 and was even posted about in 2003. It was used along with an activeX control which allowed a flash movie to take control of a pc. Here is a segment fro... (Read the rest)
Posted by: dinosoft@... Posted on: 09/25/08 You are currently: a Guest | | Terms of Use
Judicious editing  Palmetto | 08/05/08
Next, leave computer turned off  waecaidr@... | 08/05/08
"Flash is used to deliver a lot of the content webizens want. "  bmerc | 08/06/08
You forgot...  DonRupertBitByte | 08/05/08
RE: Judicious Editing  bfilipiak@... | 08/05/08
Do Not Download Flash Player??  KeithAu001 | 08/06/08
Use Adobe to update  sjbinaz | 08/07/08
RE: Adobe: Beware of fake Flash downloads  Gis Bun | 08/05/08
Flash Player 10.0  Greenknight_z | 08/06/08
Beta 10  Ross Snowden | 08/06/08
Flash Player 10 ?????  KeithAu001 | 08/06/08
Gee, they say that as though your average...  JohnMcGrew@... | 08/05/08
RE: Adobe: Beware of fake Flash downloads  tsudhonimh | 08/05/08
RE: Adobe: Beware of fake Flash downloads  Ross Snowden | 08/05/08
Same Problem  duane@... | 08/05/08
Then you gotta problem!...  JCitizen | 08/05/08
Nevermind I see there is a new one..  JCitizen | 08/08/08
Beta Build  Greenknight_z | 08/06/08
RE: Adobe: Beware of fake Flash downloads  Dusterman | 08/05/08
What about the Adobe auto-updater??  techboy_z | 08/05/08
Not really an issue  dazweeja | 08/05/08
RE: Adobe: Beware of fake Flash downloads  Update victim | 08/05/08
RE: Adobe: Beware of fake Flash downloads  quimkaos@... | 08/06/08
Remedy?  Lynnally | 08/21/08
RE: Adobe: Beware of fake Flash downloads  blonddove1@... | 08/08/08
RE: Adobe: Make those Flash pages a HTTPS  JoeRJr | 08/13/08
RE: Adobe: Beware of fake Flash downloads  dinosoft@... | 09/25/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here