New Acrobat 0 day exploit!

Chiefcrowe

Diamond Member
Sep 15, 2008
5,055
198
116
Here is the link to the security bulletin which tells you about it.

The workaround is to disable JavaScript within Adobe Acrobat, you can do this by unchecking "Enable Acrobat JavaScript"
under menu Edit => Preferences => JavaScript.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Originally posted by: RedSquirrel
Why would a pdf file have javascript, or capabilities for javascript anyway?

Because js is the new hotness. Everything needs to be js enabled!
 

Red Squirrel

No Lifer
May 24, 2003
70,166
13,573
126
www.anyf.ca
Originally posted by: n0cmonkey
Originally posted by: RedSquirrel
Why would a pdf file have javascript, or capabilities for javascript anyway?

Because js is the new hotness. Everything needs to be js enabled!

Lol it's true, and it's really sad tbh. I have noscript, and like 90% of websites don't work until I enable js. What's up with that? Can't people code normal html/css anymore? It's not the cool thing to do now or what? lol
 

MrChad

Lifer
Aug 22, 2001
13,507
3
81
Originally posted by: RedSquirrel
Lol it's true, and it's really sad tbh. I have noscript, and like 90% of websites don't work until I enable js. What's up with that? Can't people code normal html/css anymore? It's not the cool thing to do now or what? lol

When used properly, JavaScript can increase a site's usability substantially over static HTML and CSS.

That said, many sites use JavaScript for the sake of JavaScript (see: Web 2.0).
 

MrChad

Lifer
Aug 22, 2001
13,507
3
81
Originally posted by: RedSquirrel
Why would a pdf file have javascript, or capabilities for javascript anyway?

Adobe has a number of enterprise server-side products that use the PDF format and Adobe Reader for workflow and forms automation. These are the typical applications for scripting a PDF file.
 

Raincity

Diamond Member
Feb 17, 2000
4,477
12
81
Somehow I got rooted two weeks ago by this exploit through Foxit reader. I am not sure if I was browsing while logged in as admin but this was first me for. I don?t stray off the beaten path as far as internet sites go so this exploit must have come from a legitimate site.
 

Chiefcrowe

Diamond Member
Sep 15, 2008
5,055
198
116
that is scary! do you normally use your machine under an admin account?


Originally posted by: Raincity
Somehow I got rooted two weeks ago by this exploit through Foxit reader. I am not sure if I was browsing while logged in as admin but this was first me for. I don?t stray off the beaten path as far as internet sites go so this exploit must have come from a legitimate site.

 

Raincity

Diamond Member
Feb 17, 2000
4,477
12
81
Originally posted by: Chiefcrowe
that is scary! do you normally use your machine under an admin account?


Originally posted by: Raincity
Somehow I got rooted two weeks ago by this exploit through Foxit reader. I am not sure if I was browsing while logged in as admin but this was first me for. I don?t stray off the beaten path as far as internet sites go so this exploit must have come from a legitimate site.

No I run a SU account for matainance and LUA for everthing else. Running XP PRO SP-3 fully patched. All apps patched accorrding to Secunia advisor. DEP is enabled also. digeste.dll was the payload, a UPX packed trojan that got by Kaspersky 8.
The tip off was my machine was just crawling. Found Foxit sucking up lots of memory and there was no pdf files open at the time. Rebooted the machine and checked processes again to see a strange dll attached to each process. I shut down and then booted up the Kaspersky rescue cd and ran a scan and found the root kit. Luckliy I did a backup two day before it happend. Nuked both drives in my system. At that point I did not even trust my Acronis images to reinstall.
 

Chiefcrowe

Diamond Member
Sep 15, 2008
5,055
198
116
thanks for the reply.. these viruses are getting sneakier and sneakier these days!