Skip to content

Biting the hand that feeds IT

The Register ®

Security:


Related Whitepapers

Comments on ‘New strain of Gozi Trojan prowls the net’

Variant of SSL-sniffing malware unleashed in nasty PDF attack

Published Friday 26th October 2007 03:18 GMT

« Back to article page

Be thankful 

By Jesus Puncher
Posted Friday 26th October 2007 05:50 GMT
Thumb Up

Well lets thank those ru55ians for helping the rest of us develop more robust document formats and advancing the field of virus protection.

How lovely of them, and how happy it makes me, being always able to look forward to a fresh round of software updating. Another fine and happy day for us all.

God / Alaa / Spaghetti-Monster bless their cotton socks.

Here we go again 

By uncle sjohie
Posted Friday 26th October 2007 06:25 GMT
Unhappy

Even PDF's aren't safe anymore, now what?

Reader update through group policy 

By Matt Dodds
Posted Friday 26th October 2007 08:36 GMT
Unhappy

Having to update Acrobat/Reader on Windows wouldn't be such a PITA if Adobe were to provide an MSI installation/upgrade package which you could roll out through Group Policy.

I tried to create such a thing using Symantec Packager and it failed miserably.

Oh well, only 20 desktops with 8.x here... oh, and where's the patch for 7.x?

Any word on Foxit's reader 

By Anonymous Coward
Posted Friday 26th October 2007 09:33 GMT

I don't normally use the Adobe reader because it has become incredibly bloated, only when looking at proofs. Instead I use the Foxit reader, so I'm interested if that has the same problem - probably not.

That is, of course, when I use Windows, which is about 5% of the time..

@ Jesus Puncher 

By Andy Worth
Posted Friday 26th October 2007 09:44 GMT

Spaghetti Monster? Has someone been reading into Pastafarianism then?

Viruses lol? 

By Anonymous Coward
Posted Friday 26th October 2007 10:02 GMT
Gates Horns

It's all a conspiracy to get you to download Adobe malware! Don't bother updating - the jews are out to get us!

who's idea was this 

By Anonymous Coward
Posted Friday 26th October 2007 10:13 GMT
Paris Hilton

"The program uses Winsock2, advanced functionality that allows it to snoop on traffic even when it is protected in Secure Socket Layer sessions."

Now with even more features and convenient to use API.Gozi the amazing banking information stealing worm Microsoft XPsp1 XPsp2 Vista.Adobe Acrobat reader required. Wheres their website I would like to buy it and give it to all my friends.

Bugger 

By Chris
Posted Friday 26th October 2007 10:37 GMT
Unhappy

I upgraded from AR 7 to AR 8 and after a couple of weeks went back to 7 again. Version 8.x is really frustrating to use, with floating search boxes and multiple windows, while in 7 it's all self-contained. Looks like I'll have to put up with it :-( I tried Foxit but the fonts didn't look as clean, and since I spend half the day looking at pdfs, that mattered.

@Chris 

By Anonymous Coward
Posted Friday 26th October 2007 15:25 GMT

??? Acrobat Reader 8 is a vast improvement over Acrobat Reader 7 precisely because AR8 DOESN'T have a floating search box. In AR8, the search box is on the tool bar across the top. I've finally replaced Foxit on my home machine with Acrobat Reader 8, because it's user interface is so much better.

Adobe 8 issues 

By Mike Chesmore
Posted Monday 29th October 2007 13:46 GMT

While Adobe has had a really bad reputation in the past, Adobe 8 is a vast improvement over previous versions. I am very pleased with it overall. I have rolled Adobe out to 6000 + users in the forms of 6, 7 and now 8. If you are having trouble loading Adobe 8, you need to download the Adobe 8 MSI creator, it is free and really easy to use. I have created hundreds of MSI's with all the major tools out there and this one is as good as any of the paid for ones. I saw a comment about deploying it via AD, you absolutely can use AD to deploy it. The largest complaint we had with it were that "it looks different". Well it is different, things change, software changes, sorry but we still can't use Windows 3.11 even though Vista looks different. Move on... I am still not a huge Adobe fan largely due to their past history but the new stuff seems much much better.

Mike

Clarifications 

By Dr. Vesselin Bontchev
Posted Wednesday 31st October 2007 10:06 GMT
Boffin

uncle sjohie: PDF files have never been safe. They are written in the PostScript language. Lots of nasty things can be written in this language - even viruses. Also, they allow JavaScript contents. Finally, there is at least one virus infecting PDF files and spreading from them (albeit only if you have the full Acrobat - not just the Reader).

Matt Dodds: The exploit is actually in Internet Explorer 7 on Windows XP machines - the Acrobat Reader is just the vector, which has the "nice" added capability of executing embedded URLs automatically. Version 7.x is not vulnerable and you don't need to update non-WinXP machines.

Anonymous Coward: Foxit is "vulnerable" (in the sense that it can be used as an attack vector) too - the only difference is that there you'll have to be convinced to click on an URL in the PDF file, while with Acrobat the malware runs by just opening the PDF file. Other applications (Firefox, Skype, mIRC, Miranda and countless others) can similarly be attack vectors. The root of the problem is in IE7 on WinXP machines. Microsoft has yet to patch that. Once they do, the problem will disappear.

whitepaper title

Solution Brief: Reduce Energy Costs

Energy consumption has become a big issue. Dramatically increase server utilization and significantly reduce energy costs through Virtualization..
whitepaper title

Server Consolidation and Containment

This paper discusses how consolidation and containment solutions with a virtual infrastructure meet the challenges of server sprawl and underutilization..

Top 20 storiesAll The Week’s HeadlinesArchiveSearch