Slashdot Mirror


Attackers Infect Ads With Old Adobe Vulnerability

thethibs writes "eWeek is reporting that just as everyone is buzzing about the latest Adobe vulnerability, someone poisoned ads hosted by Ziff-Davis with an older Adobe exploit (affecting versions 8.12 and earlier, and long since patched). Z-D fixed the problem less than 24 hours after its first appearance. The interesting bit of this is that a bunch of people probably got hit with the old Trojan when they browsed to a story about the new one."

26 of 70 comments (clear)

  1. Adobe what? by Anonymous Coward · · Score: 5, Informative

    While it's fairly evident that they're talking about Adobe Reader, nowhere in the summary does it state which Adobe product this affects. Adobe is a company, not a product, even if it's not called Adobe Acrobat anymore!

    1. Re:Adobe what? by RPoet · · Score: 2, Interesting

      I find that most people who just say "Adobe" mean Adobe Photoshop. Apparently this guy meant Adobe Acrobat Reader. I suspected perhaps he meant Adobe Flash Player. Oh well.

      --
      "Oppression and harassment is a small price to pay to live in the land of the free." -- Montgomery Burns.
  2. another good reason...... by Nossie · · Score: 4, Interesting

    to run scripts selectively ....

    Which I do, and with no script the way I have... *shrugs* the little extra hassle is worth all the benefits!

    1. Re:another good reason...... by Anonymous Coward · · Score: 4, Insightful

      Yeah, because people like you (running noscript) are so likely to be running a 2-years-old version of Reader.

    2. Re:another good reason...... by iztehsux · · Score: 3, Informative

      Agreed. NoScript isn't a bad option. You could also fix up your hosts file to strip out the banner ads using a list like the one at [http://www.mvps.org/winhelp2002/hosts.txt" or even better, just use Lynx!

    3. Re:another good reason...... by Phroggy · · Score: 5, Informative

      Blocking scripts isn't guaranteed to protect you from this kind of attack, since the article specifically mentioned that the attack used iframes. Loading a PDF into an iframe can be done with no scripting; this will either trigger a file download or will invoke the Adobe Reader plug-in (or whatever other plug-in your browser is configured to use to display PDF files).

      However, if the iframe is inserted into the DOM by a script (not uncommon with advertisements these days), then yeah, blocking scripts would prevent it.

      Of course, I imagine the attempt to install a rogue application would trigger a UAC prompt on VIsta, protecting anyone on that platform who isn't a moron.

      --
      $x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
      $x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
    4. Re:another good reason...... by Spy+der+Mann · · Score: 4, Informative

      Blocking scripts isn't guaranteed to protect you from this kind of attack, since the article specifically mentioned that the attack used iframes.

      Let me remind you that NoScript (TM) not only protects you from scripts. It also protects you from clickjacking (iframes or not), in-iframe browsing, embedded objects and other nuisances.

      With noscript installed, the only way I could be hit with malicious code would be through an html or css buffer overflow vulnerability - and that's why I keep my distro up to date.

    5. Re:another good reason...... by Anonymous Coward · · Score: 4, Informative

      Noscript blocks iframes, but not default enabled. You have to drill through preferences, which I do anyway, but some might not.
      Perhaps it's time to default-enable security enhancing features and if it BREAKS something, turn them off selectively, instead of the converse.
      Or is it more work to click through a menu than to reformat and reinstall because you got hosed?

    6. Re:another good reason...... by Akzo · · Score: 5, Insightful

      Unless the malicious code was placed on any one of the authors sites or another trusted site.

      --
      Sig is for Signature, so you don't have to manually sign every post.
    7. Re:another good reason...... by ion.simon.c · · Score: 3, Informative

      Heh. If they're anything like *me*, they won't be running *any* Adobe software at all. :D

    8. Re:another good reason...... by hairyfeet · · Score: 2, Informative

      That is why I use Adblock Plus WITH Noscript. Some may think it is overkill, but with Adblock Plus and Noscript I don't have to worry about nastiness like this, as anything one doesn't catch the other will.

      --
      ACs don't waste your time replying, your posts are never seen by me.
  3. So what exactly happened? by Phroggy · · Score: 4, Interesting

    So what servers were actually compromised by hackers? According to the article, Stephen Wellman, director of community and content for Ziff Davis Enterprise, says no ZD web sites were compromised and it "was not our fault." Whose fault was it? Does ZD use a third-party advertising service? If so, does anyone else use that same advertising service? If ZD runs its own ad servers, how is this not ZD's fault?

    --
    $x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
    $x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
    1. Re:So what exactly happened? by Phroggy · · Score: 4, Insightful

      I loaded eweek in Firefox, and adblock stopped ads from Doubleclick, Googlesyndication, and Atdmt.com. I'm guess it came from the last one.

      These are huge advertisers (atdmt.com is Microsoft, and you probably know that Google bought DoubleClick). Was one of them hacked? If so, what does this have to do with ZD at all?

      --
      $x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
      $x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
    2. Re:So what exactly happened? by NJRoadfan · · Score: 2, Informative

      I've always wondered how so many machines were getting hit with the Vundo trojan even though the user was only browsing "safe" websites in Firefox. Its likely because many of the major ad providers are running "poisoned" ads. Ad-block Plus is surprisingly effective against this one attack vector.

  4. Work computers by Sporkinum · · Score: 2, Funny

    Our computers at work will probably get trashed from this. They only use Adobe reader, some old unpatched version, and only IE without any adblocking. Microsoft shop don't you know.

    --
    "He's lost in a 'floyd hole"
    1. Re:Work computers by Ilgaz · · Score: 2, Insightful

      I understand the resistance to upgrade a major version (9) but if one, especially a company doesn't apply a free update to same major version, that system is not managed and should be taken off the internet.

      As far as I know Adobe uses the ultra paranoid microsoft installer on Windows and it has excellent admin options like rollback and deployment.

      Old computer isn't an excuse, they are being real lazy. I mean one should use advantages of the platform if they are stuck with it.

  5. Documents are not applications by Gothmolly · · Score: 5, Insightful

    If a "document" wants to _do_ anything, then it is not a document, and should be given the same trust as other programs. The Microsoftification of the world must stop.

    --
    I want to delete my account but Slashdot doesn't allow it.
    1. Re:Documents are not applications by Gadget_Guy · · Score: 3, Insightful

      Microsoft predates this with their stupid decision to have macros in Word 6.0 back in 1993. The first time that I read about that feature (that the macros could be saved in the document) I said that it would get used for making a virus. It actually took a surprisingly long time for the first virus to be released.

      I imagine that there must have been some similar "feature" in spreadsheets before that.

    2. Re:Documents are not applications by artor3 · · Score: 4, Funny

      ... rather than improperly blaming Microsoft

      Woah, woah, woah.... just where do you think you are?

    3. Re:Documents are not applications by mcrbids · · Score: 3, Interesting

      You mean, like when a text file starts behaving like a program? What about simple text files with '#! /bin/sh' on the first line?

      Unix had it right: everything is a file. Period. Programs, data ports, IP connections, shell scripts. All files. simple, human-understandable permissions. This isn't anything to do with Microsoft, it's just the natural order of developers scratching their itch.

      --
      I have no problem with your religion until you decide it's reason to deprive others of the truth.
  6. The company is vulnerable? by ThrowAwaySociety · · Score: 2, Funny

    I see no mention in the summary of a specific product. Since I'm not going to RTFA, should I just assume that, since I don't own Adobe stock, I'm not affected?

  7. Don't use AR. If you must use AR, turn of JS. by bcrowell · · Score: 4, Insightful

    Don't have anonymous sex with strangers in bath-houses. Or if you must have anonymous sex with strangers in bath-houses use a condom. This has been a public service message.

    In other words, don't use AR. Use Evince (on Linux) or Sumatra PDF (Windows). If you must use AR, go to Edit, Preferences, JavaScript, and uncheck "Enable Acrobat JavaScript".

    No, none of this has much to do with PDF's merits as a file format. Embedding JS in PDF was a mistake. The mistake won't hurt you if you take these elementary precautions.

  8. Re:Interesting by andy.ruddock · · Score: 2, Informative

    The ads, as served from Ziff-Davis, performed redirects to a third-party site. It was this third-party site which was hosting the malicious pdf files. They probably escaped automatic checking in this manner.
    Any advertiser is going to want a click to end up as a vist to their site, one way or another - and once there it's out of Ziff-Davis' hands.

    --
    God: An invisible friend for grown-ups.
  9. I got hit by a very similar one by Anonymous Coward · · Score: 3, Informative

    I got hit before the weekend by a very similar one, but not exactly the same.

    Browsing with fully patched FF & WinXP. But yeah, I have the little puppy updater from Adobe disabled (because it tries to shit everywhere). Why can't people make an updater that is just an updater and doesn't try to sneak in other shit?

    Anyways, I was looking for some guitar cases, and a pop-under showed up (apparently this is another problem that can not be fixed a 100%...), and then a crash message saying "~.exe" had crashed. You try to google ~.exe, and see what you find...

    Okay, so I realize this is not good and bring up task manager and see a task named "4.pr". Fuck, this is really not good.

    So I unplug, go to another machine and figure some stuff out. There's two files in the c: root directory: p3.bat and 4.pr. Looks like also some rogue version of wdmaud.sys.

    Looks like the crash caused the trojan to not install successfully, but still, this is the first time in my > 20 years messing with computers that I got p0wned.

    So I'm mad as hell, and sure, I'm stupid. I know FF loads certain plugins automagically (which is something I really don't like) but I didn't really think of it loading AR... Normally I download PDFs first. As a matter of fact, I DON'T WANT to use AR as a plugin.

    In any case, I've decided a couple of things:
    - I will never install Acrobat Reader again. I will advise anyone that listens to do the same. Either find an alternative, or just forget about viewing the content. It can't be that important.
    - For other plugins, especially those that are hard to do without like Flash, I will search for Open Source alternatives.
    - VMs. I never liked VMs, but it seems like there's no way around it. I'm thinking three VMs: one for crazy browsing, one for the normal stuff (eBay/slashdot) and one for sensitive stuff (banks/paypal). The big advantage is that you can snapshot them, so that if one gets hit, you aren't immediately dead in the water. Instead you fire up the old snapshot.
    - Again review what can be done to have a reasonable browsing experience while having plugins disabled by default.
    - All (remotely) sensitive data goes on a truecrypt drive that automatically dismounts. I've been using it for really sensitive data and it works great.

    But the other thing I have to say though: PLEASE Firefox developers, have a mode that does NOT load any plugins, but displays their content as an empty square first. Then if you want to see it, I can click on it or something. Maybe noscript is the thing; last time I looked it was too tedious to use. Maybe now I'll feel differently.

    btw. Just for shits an grins, you should look at what plugins are installed for Firefox: Tools->Add-ons->Plugins tab. I was surprised to say the least.

  10. Word macros arent really the problem. by TiggertheMad · · Score: 3, Insightful

    Its the decision to allow the macro script do other things outside of a word doc that is the problem.

    Who cares if accountants have macros that autosum three pages of figures. I just want to punch the idiot who thought that its ok to have a macro alter/save files other than the active file, or connect to outside data sources (e.g. teh intarwebz) without a big freaking' popup asking for a manual confirmation.

    What probably happened is some clever punk thought it would be smart to just tie it to the VBScript engine, and let anything happen, rather than developing a special macro language for office.

    --

    HA! I just wasted some of your bandwidth with a frivolous sig!
  11. This explains those random PDFs on my desktop by Spatial · · Score: 2, Interesting

    I have PDFs set to automatically download to my desktop in FF, since the Adobe plugin has a habit of crashing and it's very slow.

    It seems that I was fortunate. I never opened them since I didn't know where they came from, they went straight to the bin.