<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New BackDoor Attacks Using PDF Documents</title>
	<atom:link href="http://blogs.mcafee.com/mcafee-labs/2009/02/19/new-backdoor-attacks-using-pdf-documents/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com/mcafee-labs/new-backdoor-attacks-using-pdf-documents</link>
	<description></description>
	<lastBuildDate>Tue, 29 Nov 2011 07:51:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Asheerq</title>
		<link>http://blogs.mcafee.com/mcafee-labs/new-backdoor-attacks-using-pdf-documents/comment-page-1#comment-22534</link>
		<dc:creator>Asheerq</dc:creator>
		<pubDate>Mon, 06 Apr 2009 03:37:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=806#comment-22534</guid>
		<description>i thinx  adobe update it now
thanx dear</description>
		<content:encoded><![CDATA[<p>i thinx  adobe update it now<br />
thanx dear</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LouNaTech</title>
		<link>http://blogs.mcafee.com/mcafee-labs/new-backdoor-attacks-using-pdf-documents/comment-page-1#comment-22532</link>
		<dc:creator>LouNaTech</dc:creator>
		<pubDate>Wed, 11 Mar 2009 17:41:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=806#comment-22532</guid>
		<description>Adobe&#039;s Patch Is Released for Acrobat Reader 8.x &amp; 9.x

Adobe recommends Adobe Reader users update to Adobe Reader 9.1, available here:
http://get.adobe.com/reader/

Acrobat 9

Adobe recommends Acrobat 9 Standard and Acrobat 9 Pro users on Windows update to Acrobat 9.1, available at the following URLs:
http://www.adobe.com/support/downloads/detail.jsp?ftpID=4375
http://www.adobe.com/support/downloads/detail.jsp?ftpID=4382

Adobe recommends Acrobat 9 Pro Extended users on Windows update to Acrobat 9.1, available here:
http://www.adobe.com/support/downloads/detail.jsp?ftpID=4381

Adobe recommends Acrobat 9 Pro users on Macintosh update to Acrobat 9.1, available here:
http://www.adobe.com/support/downloads/detail.jsp?ftpID=4374

 Still no talk of the vulnerability of Acrobat 6.x</description>
		<content:encoded><![CDATA[<p>Adobe&#8217;s Patch Is Released for Acrobat Reader 8.x &amp; 9.x</p>
<p>Adobe recommends Adobe Reader users update to Adobe Reader 9.1, available here:<br />
http://get.adobe.com/reader/</p>
<p>Acrobat 9</p>
<p>Adobe recommends Acrobat 9 Standard and Acrobat 9 Pro users on Windows update to Acrobat 9.1, available at the following URLs:<br />
http://www.adobe.com/support/downloads/detail.jsp?ftpID=4375<br />
http://www.adobe.com/support/downloads/detail.jsp?ftpID=4382</p>
<p>Adobe recommends Acrobat 9 Pro Extended users on Windows update to Acrobat 9.1, available here:<br />
http://www.adobe.com/support/downloads/detail.jsp?ftpID=4381</p>
<p>Adobe recommends Acrobat 9 Pro users on Macintosh update to Acrobat 9.1, available here:<br />
http://www.adobe.com/support/downloads/detail.jsp?ftpID=4374</p>
<p> Still no talk of the vulnerability of Acrobat 6.x</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Y</title>
		<link>http://blogs.mcafee.com/mcafee-labs/new-backdoor-attacks-using-pdf-documents/comment-page-1#comment-22531</link>
		<dc:creator>Daniel Y</dc:creator>
		<pubDate>Mon, 02 Mar 2009 22:41:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=806#comment-22531</guid>
		<description>There are a few new PoC at milworm that do not appear to be detected by VirusScan using the most recent DAT release.  I&#039;ve submitted some samples to AVERT in hope that an updated DAT will come out soon.  According to http://secunia.com/blog/44/, they created some samples that proof disabling javascript in Acrobat/Reader does not mitigate the risk.  VirusScan buffer overflow protection may help for users running Internet Explorer, but not firefox users.</description>
		<content:encoded><![CDATA[<p>There are a few new PoC at milworm that do not appear to be detected by VirusScan using the most recent DAT release.  I&#8217;ve submitted some samples to AVERT in hope that an updated DAT will come out soon.  According to http://secunia.com/blog/44/, they created some samples that proof disabling javascript in Acrobat/Reader does not mitigate the risk.  VirusScan buffer overflow protection may help for users running Internet Explorer, but not firefox users.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe Blough</title>
		<link>http://blogs.mcafee.com/mcafee-labs/new-backdoor-attacks-using-pdf-documents/comment-page-1#comment-22529</link>
		<dc:creator>Joe Blough</dc:creator>
		<pubDate>Thu, 26 Feb 2009 14:37:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=806#comment-22529</guid>
		<description>There is exploit code (in the form of a perl script) at milworm.  The script will generate a pdf file that contains the exploit.  As of last night, 2 out of 39 AV programs on virustotal detect the milworm file as a threat.  When tested on acrobat 6 running on Windows 98, acrobat displays a message that the file is corrupt and can&#039;t be read.  It does not crash.  I take that as an indication that Acrobat 6 is not vulnerable to the exploit.  Windows-98 wins again over NT-based OS&#039;s.</description>
		<content:encoded><![CDATA[<p>There is exploit code (in the form of a perl script) at milworm.  The script will generate a pdf file that contains the exploit.  As of last night, 2 out of 39 AV programs on virustotal detect the milworm file as a threat.  When tested on acrobat 6 running on Windows 98, acrobat displays a message that the file is corrupt and can&#8217;t be read.  It does not crash.  I take that as an indication that Acrobat 6 is not vulnerable to the exploit.  Windows-98 wins again over NT-based OS&#8217;s.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Johnno</title>
		<link>http://blogs.mcafee.com/mcafee-labs/new-backdoor-attacks-using-pdf-documents/comment-page-1#comment-22528</link>
		<dc:creator>Johnno</dc:creator>
		<pubDate>Wed, 25 Feb 2009 15:36:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=806#comment-22528</guid>
		<description>Disabling Javascript may not help at all. I&#039;ve noticed if you launch a &quot;javascript&quot; enabled PDF, it just keeps bugging you to turn it back on... Great fix for a corporate environment where users will agree to anything quickly if it&#039;ll stop them being bugged!</description>
		<content:encoded><![CDATA[<p>Disabling Javascript may not help at all. I&#8217;ve noticed if you launch a &#8220;javascript&#8221; enabled PDF, it just keeps bugging you to turn it back on&#8230; Great fix for a corporate environment where users will agree to anything quickly if it&#8217;ll stop them being bugged!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Addus</title>
		<link>http://blogs.mcafee.com/mcafee-labs/new-backdoor-attacks-using-pdf-documents/comment-page-1#comment-22527</link>
		<dc:creator>Addus</dc:creator>
		<pubDate>Mon, 23 Feb 2009 16:54:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=806#comment-22527</guid>
		<description>Will Mcafee be releasing a HIPS signature for this?  If so when is it planning on being released?</description>
		<content:encoded><![CDATA[<p>Will Mcafee be releasing a HIPS signature for this?  If so when is it planning on being released?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Addus</title>
		<link>http://blogs.mcafee.com/mcafee-labs/new-backdoor-attacks-using-pdf-documents/comment-page-1#comment-22526</link>
		<dc:creator>Addus</dc:creator>
		<pubDate>Mon, 23 Feb 2009 16:53:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=806#comment-22526</guid>
		<description>The CERT advisory states that disabling javascript in acrobat reader &quot;may&quot; prevent exploitation. What does &quot;may&quot; mean?  Also if users have stripped down rights what would this do to the impact of exploit?</description>
		<content:encoded><![CDATA[<p>The CERT advisory states that disabling javascript in acrobat reader &#8220;may&#8221; prevent exploitation. What does &#8220;may&#8221; mean?  Also if users have stripped down rights what would this do to the impact of exploit?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Geok Meng Ong</title>
		<link>http://blogs.mcafee.com/mcafee-labs/new-backdoor-attacks-using-pdf-documents/comment-page-1#comment-22523</link>
		<dc:creator>Geok Meng Ong</dc:creator>
		<pubDate>Mon, 23 Feb 2009 01:38:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=806#comment-22523</guid>
		<description>Larry, the vulnerability used by Conficker was exploited in the wild as a 0-day before the out-of-cycle patch was released, more notable by Spy-Agent.da.
http://www.labs.com/research/blog/index.php/2008/10/24/first-glimpse-into-ms08-067-exploits-in-the-wild/</description>
		<content:encoded><![CDATA[<p>Larry, the vulnerability used by Conficker was exploited in the wild as a 0-day before the out-of-cycle patch was released, more notable by Spy-Agent.da.<br />
http://www.labs.com/research/blog/index.php/2008/10/24/first-glimpse-into-ms08-067-exploits-in-the-wild/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe Blough</title>
		<link>http://blogs.mcafee.com/mcafee-labs/new-backdoor-attacks-using-pdf-documents/comment-page-1#comment-22519</link>
		<dc:creator>Joe Blough</dc:creator>
		<pubDate>Sat, 21 Feb 2009 20:56:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=806#comment-22519</guid>
		<description>Can anyone confirm (or can anyone post a reference) that Acrobat version 6 is, or is not, affected by this exploit or has this vulnerability?  Is there any example code available for vulnerability testing?</description>
		<content:encoded><![CDATA[<p>Can anyone confirm (or can anyone post a reference) that Acrobat version 6 is, or is not, affected by this exploit or has this vulnerability?  Is there any example code available for vulnerability testing?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larry Seltzer</title>
		<link>http://blogs.mcafee.com/mcafee-labs/new-backdoor-attacks-using-pdf-documents/comment-page-1#comment-22508</link>
		<dc:creator>Larry Seltzer</dc:creator>
		<pubDate>Fri, 20 Feb 2009 11:16:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=806#comment-22508</guid>
		<description>Conficker wasn&#039;t a zero-day.</description>
		<content:encoded><![CDATA[<p>Conficker wasn&#8217;t a zero-day.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

