Banner
donkdown

Who Is Chatting

Chatroom is empty

Chat Now

Account Login

MANDATORY: Former NeverWinPoker users, please click HERE to reset your password



Banner
Banner
Banner

Micon's Hot Tweets

BryanMicon: RT @stealthmunk: Made sickest call of my life in a crazy .6-1.2 btc hand on @SealsWithClubs poker. Games are crazy! Come play! Better than any US site by far
BryanMicon: RT @50cent RT @Lloydbanks cuz go head switch yo style up and if they hate then let 'em hate and watch the money pile up
BryanMicon: Seriously! Go to the orleans by the high limit slots and play @SealsWithClubs free!! http://t.co/YWv5idWV
BryanMicon: No seriously - I just put $14 in to buy like an hour of time on the kiosk by the high limit slots - GO PLAY IT FREE - just fire the acct
BryanMicon: This public internet station I just loaded at Orleans has a burner @SealsWithClubs acct. with 200 chips - go play it!! http://t.co/6tj3hmD2


Search This Topic:
Jump to:  


Post new topic Reply to topic  [ 4 posts ] 
In the Fuckup Olympics, there is Adobe and there is everyone 
Author Message
DD InfoSec Oyabun
User avatar

Profile
Degen Index: 55
Joined: 04 Feb 2007
Posts: 8622
Jesus Christ, where to begin?

This is going to be a long thread but let me get the important points out of the way.

There was a recent Security Threat Watchlist poll on a well trafficked Information Security site, prompting security admins to vote for what was going to be the biggest security nightmares of 2010.

#1 Adobe

#2 Adobe

Adobe's Acrobat & Flash took top two slots.

And yes, you read that right; Adobe Acrobat. As in PDFs.

Little known fact about PDFs; Adobe originally designed them to be a *replacement* for HTML. The original vision was to have entire websites posted online in PDF format. A heady ambition, that. But if you look closely, you can see the functionality is all there; hyperlinks, image imbedding, as long as you have Acrobat installed as a browser plugin, you can basically navigate a well architected PDF document exactly like it was a website. There are even some functions that you cant have in a website, such as digital signatures when "signing" forms, certain math abstractions are capable within the PDF platform itself, so on and so forth.

So it might not surprise you to find out that you can embed Javascript in PDFs.

What you might very well be surprised to find out, however, is that Javascript is enabled by default in Acrobat.

Why is this a problem, you ask?

Lets ask Google:

Results 1 - 10 of about 1,300,000 for javascript security exploit. (0.32 seconds)

Javascript is one of the most easily abused vectors for websites in history. In fact, one of the primary reasons why Google ends up blacklisting sites is because of malicious javascript being detected.

So it came as some shock to the security community when someone discovered that a PDF sent to an obscure government email address around December 1 passed all the anti-virus scanners with flying colors, but still managed to download and install malware when opened in Acrobat.

Discreet alarms were raised. Adobe was notified and a public announcement was made, warning everyone that Javascript was enabled by default in Acrobat and PDFs were being used to perform targetted attacks.

And this is where things get really, *really* fucked up.

A few days before Christmas, Adobe released a press statement acknowledging the issue.

And then, it sent all its dev teams home for the holidays.

Stop and read that again; Adobe understood the threat, publicly acknowledged its existence, and knowing full well that one of the most ubiquitous computer file formats in existence could be manipulated to attack fully patched computers, sent their programmers home to celebrate their holidays without releasing a patch.

Their advice was to disable Javascript but the original public disclosure announcement indicates quite clearly that this isnt even an effective prophylactic measure!

Now Adobe are saying we can all expect a patch "in the coming weeks".

And in the meantime, all anyone can do is block PDFs at their mail servers and firewalls.

Which is happening all over hell and gone, right now.

The general assumption as it stands is that 2010 is the year that *all* Adobe products get blacklisted on all Corporate and Government IT deployments.

I will be outlining some of the nightmare scenarios that have made Flash a dirty word as well in coming posts, I need to take a long hot shower first tho.

_________________
Wiz' Fruity Pebbles Poetry Contest Runner-Up, probably.
<Ripptyde64> anyway I just wanted to give you some props for your posts....you really have a unique way with words and as a fellow writer I am humbled
<Ripptyde64> lol I just like your style. there are so many useless and moronic poster on these forums and you are vastly superior in quality, form and content.
<BB92> lol i have tits
╭∩╮(︶︿︶)╭∩╮


Tue Dec 29, 2009 1:27 pm
Online
DD Mushroom Stamping Mod
User avatar

Profile
Degen Index: 37
Joined: 23 Feb 2005
Posts: 13623
I believe that .pdfs were how the Chinese government got into Google.cn and viewed the header, but supposedly not the contents, of emails related to Chinese civil rights activists- prompting Google to announce they're leaving China. The cool thing is that apparently Google's security team hacked into a server used by the attackers and discovered the other 20 major US companies that had been attacked.


Sun Jan 17, 2010 2:26 pm
DD InfoSec Oyabun
User avatar

Profile
Degen Index: 55
Joined: 04 Feb 2007
Posts: 8622
DirtyB wrote:
I believe that .pdfs were how the Chinese government got into Google.cn and viewed the header, but supposedly not the contents, of emails related to Chinese civil rights activists- prompting Google to announce they're leaving China. The cool thing is that apparently Google's security team hacked into a server used by the attackers and discovered the other 20 major US companies that had been attacked.


I have some semi-conflicting details on Project Aurora (the targetted PDF attacks) and whether or not it actually had anything to do with the google hacks (plural). Aurora definitely was responsible for the Adobe intrusion however.

Im waiting for confirmation on some of the background regarding the activist/google hacks, there are some discrepancies in the public info that make no sense to me at this point.

For example, the activist email hacks had nothing to do with google.cn. They were perpetrated almost a year ago IIRC and were simple phishing attacks against known activists.

Also google originally implied that proprietary code had been compromised from the google.cn office based attacks, a detail thats been scrubbed completely from all PR since.

So it sounds like Google is in full PR/Spin mode here and trying to leverage the event in an effort to undo the damage their compliance with Chinese law had on their public image here.

_________________
Wiz' Fruity Pebbles Poetry Contest Runner-Up, probably.
<Ripptyde64> anyway I just wanted to give you some props for your posts....you really have a unique way with words and as a fellow writer I am humbled
<Ripptyde64> lol I just like your style. there are so many useless and moronic poster on these forums and you are vastly superior in quality, form and content.
<BB92> lol i have tits
╭∩╮(︶︿︶)╭∩╮


Tue Jan 19, 2010 6:17 pm
Site Admin
User avatar

Profile
Degen Index: 19
Joined: 08 May 2004
Posts: 13770
god damn this forum is a great idea.

_________________
-/\/\icon

Serving the degenerate poker community since 2004. Technology solved smoking! Click here to go e-cig - it feels almost exactly like smoking and delivers the nicotine that your degen ass craves.


Tue Jan 26, 2010 6:02 pm
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 


Users browsing this topic: No registered users and 1 guest


Similar Topics

 Topics  Forum  Author  Replies
Phil Hellmuth's sister is Special Olympics Champion!! Shooting Off DJ_Chaps
Fri Jul 23, 2010 6:27 pm
10
Help me with my Adobe Flash problem Shooting Off DanDruff
Fri May 21, 2010 7:43 pm
7
***Official Canada Breaks All Time Record - Wins Olympics ** Shooting Off chipcounter
Sun Feb 28, 2010 9:53 pm
23
DD 2010 WINTER OLYMPICS THREAD Shooting Off vegas1369
Wed Feb 17, 2010 8:29 pm
35
Brock Lesnar = fuckup roid casualty Shooting Off sonatine
Sat Nov 21, 2009 11:47 pm
4

Search for:
Jump to:  

Poker Blog | Poker Forum | Contact Us | Advertise | Sitemap
Copyright © 2009-2011 Donkdown.com LLC