Ditch the malware magnet
A sysadmin battles his nemesis
Sysadmin blog It is no secret that I have little use for endpoint anti-malware protection apps. In my experience they are all, regardless of vendor, virtually worthless. A well written piece of modern endpoint anti-malware will briefly inform you that you have been infected right before it commits seppuku and vanishes, leaving you to deal with the malware and all the little friends it downloaded.
The best way to deal with malware, of course, is not to get infected in the first place. This means learning to manage application vulnerabilities.
I point the zombie-infested malware-ridden finger of ultimate shame at Adobe. Adobe is my personal nemesis. When I go to work tomorrow there are three computers from clients waiting for me, each of them pwned by a flash ads on Facebook. There are another two that, from what I can determine, were hit by infected PDFs.
Similar to Microsoft Office, the near universal distribution of Adobe’s Flash and Reader products makes them prime targets. The easiest way to avoid the risk is to not install either product, but this is impossible for most internet users. I’m going to deal with the risk of Adobe Reader right away, and we’ll leave coping with Flash until next time.
Of course, the best way to deal with the myriad vulnerabilities in Adobe Reader is simply to replace it with an alternative.
Foxit of course is the most popular Reader replacement, but it comes with a warning: as Foxit has worked hard to reproduce the abilities of Adobe Reader, so too has it reproduced many of its vulnerabilities. If you install Foxit Reader, take the time to defang it before using it.
PDF-XChange Viewer is probably the second most popular Reader alternative. Like Foxit, it is a feature-rich replacement for Reader that carries some vulnerabilities with it, thanks to its attempts to be compatible with Reader. Take time to review its security settings.
Cool PDF Reader is a dead simple PDF reader with no fancy features. I have not heard of any exploits for this piece of software, and I would be surprised if any PDFs designed to exploit Adobe Reader were to tip this application over. It doesn’t have the feature list of Adobe Reader, Foxit or PDF-XChange, but from a security standpoint that’s a Good Thing.
Sumatra PDF, like Cool PDF Reader, is a minimalist PDF reader. There is no fancy anything; it just views PDFs.
Regardless of which PDF application you choose, avoid Adobe: it simply isn’t worth the risk to keep this malware magnet around. ®