Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-20-2011, 01:45 PM
Bear Bottoms
Guest
 
Posts: n/a
Default Adobe Reader X can't be trusted yet

"Adobe reader X limitations:

Protected Mode will not prevent unauthorized read access to the file
system or registry.
Protected Mode will not restrict network access.
Protected Mode will not prevent reading or writing to the clip board.

Given these limitations, attackers that exploit these “protected” components
will still be able to stay resident in memory and perform damaging activities
such as:

Read and exfiltrate data from the registry and/or user’s file system
Attack other machines and devices on the network
Use Reader as a stepping stone to execute other exploits against the host
system including exploits against kernel services

While Adobe’s Protected Mode is a step in the right direction for mitigating
risk of Adobe Reader, it still leaves significant residual risk on the table
for cyber adversaries to exploit.

http://www.invincea.com/blog/2010/11...der-x-sandbox/

--
Bear Bottoms, security consultant
http://bearware.info

Reply With Quote
  #2 (permalink)  
Old 08-21-2011, 01:21 PM
Virus Guy
Guest
 
Posts: n/a
Default Re: Adobe Reader X can't be trusted yet

Bear Bottoms wrote:

> "Adobe reader X limitations:


> While Adobe’s Protected Mode is a step in the right direction for
> mitigating risk of Adobe Reader, it still leaves significant
> residual risk on the table for cyber adversaries to exploit.


Acrobat reader 6.0x is still able to open the vast majority of PDF files
that I throw at it, and it also seems to be particularly incapable of
correctly executing many, most or all of the PDF exploits that have
emerged over the past 3 years - at least on win-9x/me systems.

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
adobe reader for blackberry uk.telecom.mobile 5 05-19-2010 11:44 AM
Mobile Adobe Acrobat Reader? uncle_vito alt.cellular.verizon 2 02-15-2007 12:36 AM


All times are GMT. The time now is 08:11 AM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45