<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tekblog &#187; adobe</title>
	<atom:link href="http://tekblog.teksquisite.com/tag/adobe/feed/" rel="self" type="application/rss+xml" />
	<link>http://tekblog.teksquisite.com</link>
	<description>Tackling Technology One Byte At A Time!</description>
	<lastBuildDate>Mon, 26 Jul 2010 13:30:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>More on the Adobe PDF Eploit&#8230;</title>
		<link>http://tekblog.teksquisite.com/2009/02/24/more-on-the-adobe-pdf-eploit/</link>
		<comments>http://tekblog.teksquisite.com/2009/02/24/more-on-the-adobe-pdf-eploit/#comments</comments>
		<pubDate>Wed, 25 Feb 2009 01:31:32 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[eploit]]></category>

		<guid isPermaLink="false">http://www.teksquisite.com/blog/?p=244</guid>
		<description><![CDATA[You will want to read up at SOPHOS to see how to protect yourself until the application is patched. PDF exploit &#8211; proactive detection confirmed Check out this registry tweak described on the US-CERT notification. likebot_bgcolor = ''; likebot_url = 'http://www.teksquisite.com/blog/?p=244'; likebot_type = 'horizontal_thumbs';]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F02%2F24%2Fmore-on-the-adobe-pdf-eploit%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F02%2F24%2Fmore-on-the-adobe-pdf-eploit%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p>You will want to read up at SOPHOS to see how to protect yourself until the application is patched.</p>
<h1><a href="http://www.teksquisite.com/blog/wp-content/uploads/2009/02/adobe-logo.jpg"><img class="alignnone size-thumbnail wp-image-245" title="adobe-logo" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/02/adobe-logo-150x150.jpg" alt="" width="150" height="150" /></a><a title="POF Eploit - proactive detection confirmed" href="http://www.sophos.com/security/blog/2009/02/3267.html" target="_blank">PDF exploit &#8211; proactive detection confirmed</a></h1>
<h1></h1>
<h1>Check out this registry tweak described on the <a href="http://www.us-cert.gov/cas/techalerts/TA09-051A.html">US-CERT notification</a>.</h1>
<div style="float:left; margin-left:10px;">	
			<a class="LikeBotButton" />
				<script type="text/javascript">
					likebot_bgcolor = '';
					likebot_url = 'http://www.teksquisite.com/blog/?p=244';
					likebot_type = 'horizontal_thumbs';
				</script>
				<script src="http://i.likebot.com/button.js" type="text/javascript"></script>
			</a>
			
			</div>]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2009/02/24/more-on-the-adobe-pdf-eploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disable JavaScript in Adobe Reader</title>
		<link>http://tekblog.teksquisite.com/2009/02/19/disable-javascript-in-adobe-reader/</link>
		<comments>http://tekblog.teksquisite.com/2009/02/19/disable-javascript-in-adobe-reader/#comments</comments>
		<pubDate>Fri, 20 Feb 2009 03:05:05 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[reader]]></category>
		<category><![CDATA[shadowserver]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.teksquisite.com/blog/?p=239</guid>
		<description><![CDATA[It appears that there is something in the wild that the guys over at Shadowserver are very concerned about.  The versions of reader that are affected are 8.x to 9.x.  To disable JavaScript in in your reader select EDIT from the main menu, then select PREFERENCES and click on JavaScript and uncheck enable Acrobat JavaScript. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F02%2F19%2Fdisable-javascript-in-adobe-reader%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F02%2F19%2Fdisable-javascript-in-adobe-reader%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.teksquisite.com/blog/wp-content/uploads/2009/02/ar9.jpg"><img class="alignnone size-thumbnail wp-image-240" title="ar9" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/02/ar9-150x150.jpg" alt="" width="150" height="150" /></a>It appears that there is something <em>in the wild</em> that the guys over at <a title="Shadowserver" href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219" target="_blank">Shadowserver</a> are very concerned about.  The versions of reader that are affected are 8.x to 9.x.  To disable JavaScript in in your reader select <strong>EDIT </strong>from the main menu, then select <strong>PREFERENCES </strong>and click on<strong> JavaScript </strong>and <span style="text-decoration: underline;">uncheck</span> <em>enable Acrobat JavaScript. </em></p>
<p>Shadowserver also believes that Symantec has provided protection against a possible dubbed Trojan.Pidief.E  since February 12.  Peek over at <a title="Shadowserver" href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219" target="_blank">Shadowserver</a> to get the latest news regarding this threat.</p>
<p><strong>Updates from Shadowserver on Friday, February 20, 2009:</strong></p>
<p>More information for you on this and Sophos protection &#8211; since Feb 7th 2009</p>
<p>Sophos detection is Troj/PDFJs-U with exploit aliases of Exploit.Win32.Pdfief.acv and Exploit.JS/Mult.BC<br />
Writeup located here:<br />
<a title="http://www.sophos.com/security/analyses/viruses-and-spyware/trojpdfjsu.html" href="http://www.sophos.com/security/analyses/viruses-and-spyware/trojpdfjsu.html" target="_blank">http://www.sophos.com/security/analyses/viruses-and-spyware/trojpdfjsu.html<br />
</a><br />
There is also a closely related shell code type attack Sophos calls Troj/PDFJs-I with protection since Dec 8 2008 Sophos write-up located here:<br />
<a title="http://www.sophos.com/security/analyses/viruses-and-spyware/trojpdfjsi.html" href="http://www.sophos.com/security/analyses/viruses-and-spyware/trojpdfjsi.html" target="_blank">http://www.sophos.com/security/analyses/viruses-and-spyware/trojpdfjsi.html</a></p>
<p><strong>&#8212;&#8212;&#8212;Updates Late Friday:</strong></p>
<p>I have more news for you as an update to this rapidly developing Adobe exploit issue:<br />
Clam AV sig is called Exploit.PDF-23 so we have another vendor on board with this exploit that now has protection.</p>
<p>Also Snort has a new ruleset to detect attacks targeting this vulnerability.  Go here:<br />
<a title="http://www.snort.org/vrt/advisories/vrt-rules-2009-02-20.html" href="http://www.snort.org/vrt/advisories/vrt-rules-2009-02-20.html" target="_blank">http://www.snort.org/vrt/advisories/vrt-rules-2009-02-20.html</a></p>
<p>Sourcefire just released a good blog with details on the workings of the exploit and how a heap spray could be used across multiple versions of the reader.  Go here:</p>
<p><a title="http://vrt-sourcefire.blogspot.com/2009/02/have-nice-weekend-pdf-love.html" href="http://vrt-sourcefire.blogspot.com/2009/02/have-nice-weekend-pdf-love.html" target="_blank">http://vrt-sourcefire.blogspot.com/2009/02/have-nice-weekend-pdf-love.html</a></p>
<p>Thanks goes to Dave from Shadowserver for providing info &amp; updates on this!</p>
<div style="float:left; margin-left:10px;">	
			<a class="LikeBotButton" />
				<script type="text/javascript">
					likebot_bgcolor = '';
					likebot_url = 'http://www.teksquisite.com/blog/?p=239';
					likebot_type = 'horizontal_thumbs';
				</script>
				<script src="http://i.likebot.com/button.js" type="text/javascript"></script>
			</a>
			
			</div>]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2009/02/19/disable-javascript-in-adobe-reader/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
