IT DRILLDOWN
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Social Responsibility's Strategic Benefits

December 15, 11:30 AM - 12:30 PM US/Eastern (GMT-5)

Join Ed Granger-Happ, CIO of Save the Children, for a discussion of how creating an organization that is socially responsible improves staffing, retention, leadership development and overall corporate health.

Working With and Communicating to Your Board of Directors

January 13, 2009, 4:00 PM - 5:00 PM US/Eastern (GMT-5)

CIO panelists who will share tips and experiences working with their boards: Twila Day of SYSCO; Jeff O'Hare, West Corp.; Marc West, formerly with H&R Block.

IT's Role in Growing Mid-Market Companies

January 14, 4:00 PM - 5:00 PM ET (GMT-5)

Mid-market Council members will share their companies' stories and challenges in driving or coping with growth. Panelists represent Veterinary Pet Insurance, Medicis Pharmaceutical, and Intrax Cultural Exchange.

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 
 

Attacks Aimed At Adobe Reader, Acrobat Flaws Intensify

 

February 11, 2008 — IDG News Service —

The flaws disclosed last week in Adobe System's Reader and Acrobat programs have been used to exploit computers since at least January via malicious banner advertisements, security analysts are reporting.

Adobe issued patches last Wednesday for Reader and Acrobat, but the company did not detail the flaws.

Problems with Adobe's software can potentially affect millions of PC users, since the company's software is widely used to read PDF (Portable Document Format) files. Most people regard PDFs as harmless.

"From our standpoint, it appears that this PDF-based attack has been quite successful, affecting many thousands of users throughout the world," wrote Hon Lau on Symantec's Security Response Weblog.

Greg McManus of iDefense Labs, the security arm of VeriSign, reported one of the vulnerabilities to Adobe in October, according to a post by the SANS Institute, a computer security organization.

Since hackers have been apparently using the Adobe flaws since January, it raises the question how they discovered the flaw.

Lau wrote that the "swiftness of the exploit appearing in the wild suggests that leaks had occurred."

However, it appears that the vulnerabilities in Reader and Acrobat were disclosed in a responsible way, Lau wrote.

The flaws in the programs allow a hacker to create a malicious PDF document. If opened by a victim, that document downloads a malicious Trojan that Symantec calls "Zonebac."

Zonebac was first detected in 2006. It shuts off a user's security software as well as downloads other bad software. The latest version also appears to taint search engine results, Lau wrote.

In January, iDefense noticed that the malicious PDF document was being delivered through malicious banner advertisements. Symantec's Lau wrote that it's not immediately clear how the PDF file is delivered, but that the banner ads could be redirecting people to other harmful Web sites with the file. Also, spam messages may be carrying the bad file as an attachment.

Malicious banner ads can be particularly dangerous since the ads can show up on legitimate Web sites. Online advertising companies have struggled to keep these ads off their networks. Sometimes, hackers will approach the networks with what is a legitimate ad and then substitute it for a malicious one. Many of those bad ads have exploited vulnerabilities in Adobe's Flash multimedia technology.

Adobe's Reader and Acrobat are designed to regularly look for updates, but users are advised to upgrade to the patched version, 8.1.2.

Copyright © 2008 IDG News Service. All rights reserved. IDG News Service is a trademark of International Data Group, Inc.
Loading...
 
 
CENTER OF EXCELLENCE
 
Infrastructure
» Outbound Email and Data Loss Prevention
This report shows the findings of a recent Proofpoint and Forrester Consulting study on e-mail security, data loss prevention, and includes statistics on electronic risks.
» A Modern Approach to On-Demand Email and Data Security
Learn how Proofpoint delivers a dedicated, hosted e-mail security solution that combines state-of-the-art anti-spam and virus control.
» A Proactive Approach to e-Discovery
Learn about the key e-discovery challenges facing legal and IT departments today and how businesses can develop an e-mail archiving strategy to deal with e-discovery requests.
» The Advantages of Identity Based Encryption
Download this paper to learn why e-mail encyrption is critical to an organization's overall security architecture and the advantages of identity-based encryption.
» Global Best Practices in Email Security, Privacy and Compliance
This whitepaper discusses the latest global regulations that impact the e-mail security policies and strategies of today's enterprises, universities and government organizations.
Center sponsored by

 
 
ABCs
 

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.

Over 25 tutorials on everything from business intelligence to virtualization.

 
 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Operational Excellence Is Key to Maximizing IT Investments

Quest Authentication and IBM Tivoli Identity Management

Get IDC's take on one company's foray into storage virtualization.

White Paper: Centralized Data Backup and Your WAN

White Paper: Accelerating the Next Phase of Virtualization

The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

Find out why IDC thinks virtualization is changing operating environments.

Explore the impact virtualization can have on your bottom-line.

Save with 0% Lease Offer on HP Servers and Storage

How RFID Improves Data Center Efficiency

Find out how to manage virtualization's risks and reap the rewards.

Conquer the realities of managing virtualization

Improve Web-Enabled SAP Performance

Gartner on Data Deduplication Cost Savings

Data Protection Options Explained

Webcast - "Into the Wild: Managing Laptops Outside the Office"

5 Steps to Successful IT Consolidation

High-performance computing is no longer just for Big Business

Leading university calls on Nokia for mobile unified communications.

Mobility is Growing: Survey Shows Why CIOs are Concerned

Learn what it takes to build a holistic digital collaboration platform

The ECM Paradox: Extending Local Flexibility to Strengthen Central Control

Customer Insight Yields Sales, Marketing Gains

7 Requirements of Data Loss Prevention

Put Enterprise Communications on Autopilot

Integrating ActiveRoles With IBM Tivoli Identity Manager 5.0

Quest Authentication Services: Simplify Identity Management

Data Protection: Challenges for the Traveling User

Learn how wide-area data services can help deliver the benefits of virtualization

Learn how companies are changing how they reach out to their most profitable customers.

Learn how to leverage virtualization for a 74% savings in TCO.

Find out how you can affordably consolidate applications with VMware.

ESG Research on Server and Storage Virtualization

Data Center ROI with RFID Asset Tracking

Get help navigating the management challenges of virtualization.

Narrow the gap between virtualization's benefits and the management risks.

Cash in on the promise of virtualization

Determine the ROI of Web Application Acceleration Managed Services

Achieve a 50:1 Data Deduplication Ratio

Remote Infrastructure Management - What Your Peers are Thinking

Complementary BI: The New Approach to Business Intelligence

Expand High-Performance Computing (HPC) Capabilities

Power the Platform of Choice for Virtualization in the Enterprise

Boost your top- and bottom- lines.

Unified Communications & Collaboration: Game-Changing Business Results

Best Intel Info for IT Pros/Intel Premier IT Professional Program: Stay up to date with roadmaps, technologies & best practices

Make Hidden Trends, Inter-Relationships and Influences Visible.

Improve delivery of product information to customers.

Prudential Financial Protects its Brand with Symantec

Mission Impossible: Building the Right Project Metrics