February 10, 2008   Sign In |  About ebizQ |  Contact Us |  Join ebizQ Gold Club
Andre Yee
Andre Yee's Security Insider
An open dialogue about security and compliance for the enterprise.

« Internet Explorer Unsafe for Most of 2006? | Main | Ethical Hacking School in Session »

January 11, 2007
Adobe's Flaw Exposed

A number of security experts have recently reported on a major flaw in the Web browser plug-in for Adobe's Acrobat Reader program. The problem was first discovered by researchers Stefano Di Paola and Giorgio Fedon, who presented a paper on security issues related to Web 2.0 technologies such as AJAX (Asynchronous JavaScript and XML).

The issue centers around how Adobe Reader browser plugin can be made to execute JavaScript code on the client side. This code can then be the trigger for any number of malicious activities. A well written, detailed explanation plus code is available here at GnuCitizen.

The use of Javascript in cross site scripting is raising numerous headaches for security managers, especially with phishing attempts. By taking advantage of cross site scripting vulnerabilities, an attacker may launch malicious code referencing a URL that points to a carefully constructed phishing Web page. So for instance, when you're downloading a pdf report at your online broker's webpage, the attacker could take launch a script to throw up what looks like an official, legitimate request to validate your account number and password. That, my friends is what makes this so scary. The self righteous among us may have sneered in disdain at friends and family that fall for the unsophisticated phishing attempts. But this ability to perform highly contextualized phishing will fool any of us.

While you ponder about the possibility of that exposure, make sure you do this - download Acrobat 8.0 which fixes the vulnerability in the first place.

Posted by andreyee in Alerts/Warnings |Digg This|Add to del.icio.us

Trackback Pings

TrackBack URL for this entry:
http://www.ebizq.net/mt/mt-tb.cgi/1169

Comments Post a comment




Remember Me?

(you may use HTML tags for style)

We ask that you type your code (displayed below) in the text box.This code is an image that cannot be read by a machine. It prevents automated programs from submitting comments.


Code:



Most Recent ebizQ Blog Entries
ADVERTISEMENT
RSS Subscription

Blog Roll
This Work
Accountability:The opinions expressed in this blog are solely representative of the blog's author, and not of ebizQ

Subscribe to our Newsletters
ebizQ Weekly Gold Club Update
Live Webinar Updates
Updates from ebizQ Partners
ebizQ SOA Update
ebizQ BPM Update
ebizQ Security Update
ebizQ BI Update
ebizQ Open Source Software Update
Virtual Show Newsletter
Your E-mail Address:
BAM: The Killer App for CEP
Date: Feb 12, 2008
Time: 12:00 PM ET
(17:00 GMT)

I WANT TO ATTEND
Event Processing Market Pulse
Date: Feb 14, 2008
Time: 12:00 PM ET
(17:00 GMT)

I WANT TO ATTEND
Archived Webinars | Upcoming Webinars

Marketing Solutions | Feedback | About ebizQ | Unsubscribe | Privacy Policy | Site Map