On The Insider: Gerard Butler Joins Aniston in Mexico
BNET Business Network:
BNET
TechRepublic
ZDNet

September 24th, 2008

Researchers discover PDF exploit packs

Posted by Ryan Naraine @ 9:50 am

Categories: Adobe, Arbitrary Code Execution, Botnets, Browsers, Data theft, Exploit code, Flash, Hackers, Malware, Patch Watch, Pen testing, Punditocracy, Responsible disclosure, Vulnerability research, Web 2.0, Zero-day attacks

Tags: Adobe PDF, Malware, Exploit, Spyware, Adware & Malware, Cyberthreats, Security, Ryan Naraine

PDF exploit kit circulating on InternetIf you still need a reason to patch that installation of Adobe Reader, pay close attention to this discovery by Secure Computing’s anti-malware research labs.

The group has stumbled upon an exploit pack that exclusively targets PDF vulnerabilities, exposing millions of Windows desktops to malicious hacker attacks.

Secure Computing warns:

This new toolkit targets only PDFs, no other exploits are used to leverage vulnerabilities. Typical functions like caching the already infected users are deployed by this toolkit on the sever-side. Whenever a malicious PDF exploit is successfully delivered, the victim’s IP address is remembered for a certain period of time. During this “ban time” the exploit is not delivered to that IP again, which is another burden for incident handling.

Other existing toolkits have also been enhanced with PDF exploits lately. For example we spotted the “El Fiesta” toolkit to have also added exploits for the Portable Document Format.

[ SEE: Flash attack may as well have been zero-day ]

Unpatched third-party desktop applications are a big, big part of the malware epidemic on the Windows platform.  As we learned during that Adobe Flash attack earlier this year, end users are very slow to apply these patches, giving the bad guys a huge opening for targeted, localized malware attacks.

I can’t recommend Secunia’s PSI (personal software inspector) highly enough.   Please patch now.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 3 Talkback(s)
Unfortunately, the US Government Disagrees
Imagine the Anti-Trust issues if Microsoft had the ability to patch multiple vendor's products in the monthly patch cycle! Remember the setting of kill-bits is only a courtesy for the vendor and customers according to Microsoft.... (Read the rest)
Posted by: TelcoChuck Posted on: 09/25/08 You are currently: a Guest | | Terms of Use
.....  Linux User 147560 | 09/24/08
Unfortunately, the US Government Disagrees  TelcoChuck | 09/25/08
RE: Researchers discover PDF exploit packs  jjharriss | 09/24/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here