Banner
donkdown

Who Is Chatting

Chatroom is empty

Chat Now

Account Login

MANDATORY: Former NeverWinPoker users, please click HERE to reset your password



Banner
Banner
Banner

Micon's Hot Tweets

BryanMicon: RT @stealthmunk: Made sickest call of my life in a crazy .6-1.2 btc hand on @SealsWithClubs poker. Games are crazy! Come play! Better than any US site by far
BryanMicon: RT @50cent RT @Lloydbanks cuz go head switch yo style up and if they hate then let 'em hate and watch the money pile up
BryanMicon: Seriously! Go to the orleans by the high limit slots and play @SealsWithClubs free!! http://t.co/YWv5idWV
BryanMicon: No seriously - I just put $14 in to buy like an hour of time on the kiosk by the high limit slots - GO PLAY IT FREE - just fire the acct
BryanMicon: This public internet station I just loaded at Orleans has a burner @SealsWithClubs acct. with 200 chips - go play it!! http://t.co/6tj3hmD2


Search This Topic:
Jump to:  


Post new topic Reply to topic  [ 7 posts ] 
Major Security Breach in iPhone/iPad 
Author Message

http://www.huffingtonpost.com/2010/08/03/apple-security-breach-cou_n_669481.html

Quote:
Opening a manipulated website or a PDF file could allow criminals to spy on passwords, planners, photos, text messages, e-mails and even listen in to phone conversations, the agency said in a statement.


Wed Aug 04, 2010 11:55 am
DD InfoSec Oyabun
User avatar

Profile
Degen Index: 55
Joined: 04 Feb 2007
Posts: 8622
not to minimize this but people i know who are pretty zealous about ITSec simply refuse to have any adobe projects whatsoever on their phones or computers. which is to say, yeah this is egregious, but there are sooo many other super exploitable issues with pdfs as well.

_________________
Wiz' Fruity Pebbles Poetry Contest Runner-Up, probably.
<Ripptyde64> anyway I just wanted to give you some props for your posts....you really have a unique way with words and as a fellow writer I am humbled
<Ripptyde64> lol I just like your style. there are so many useless and moronic poster on these forums and you are vastly superior in quality, form and content.
<BB92> lol i have tits
╭∩╮(︶︿︶)╭∩╮


Wed Aug 04, 2010 12:09 pm
DD Whale
User avatar

Profile
Degen Index: 30
Joined: 22 May 2008
Posts: 3366
sonatine wrote:
not to minimize this but people i know who are pretty zealous about ITSec simply refuse to have any adobe projects whatsoever on their phones or computers. which is to say, yeah this is egregious, but there are sooo many other super exploitable issues with pdfs as well.


I never understood why there are so many exploits for pdf files. Can you explain in lay person terms why this is?

_________________
micon wrote:

1) I CREATED THIS, DON'T FUCKING FORGET THAT
.


Wed Aug 04, 2010 12:28 pm
DD Piranha

Profile
Degen Index: 13
Joined: 30 Apr 2010
Posts: 835
betcheckbet wrote:
sonatine wrote:
not to minimize this but people i know who are pretty zealous about ITSec simply refuse to have any adobe projects whatsoever on their phones or computers. which is to say, yeah this is egregious, but there are sooo many other super exploitable issues with pdfs as well.


I never understood why there are so many exploits for pdf files. Can you explain in lay person terms why this is?


You asked basically the same question I was going to! Anyone who is an expert in this, would love to have some input....


Wed Aug 04, 2010 12:57 pm
DD Old School

Profile
Degen Index: -4
Joined: 03 May 2005
Posts: 8085
Adobe Reader (what most of us use to read .pdf's) has JavaScript enabled by default. JavaScript allows access to not only objects within the application that it's using (Reader in this case), but also allows access to other objects within a computer. If malicious code is hidden within the JavaScript, it can compromise the system. Pretty standard mal-ware technique but only recently exploited on Adobe.

_________________
408mike wrote:
The male scrotum is incredibly sensitive and should be handled with the utmost of care.


Wed Aug 04, 2010 1:10 pm
DD InfoSec Oyabun
User avatar

Profile
Degen Index: 55
Joined: 04 Feb 2007
Posts: 8622
hugh_chardon wrote:
Adobe Reader (what most of us use to read .pdf's) has JavaScript enabled by default. JavaScript allows access to not only objects within the application that it's using (Reader in this case), but also allows access to other objects within a computer. If malicious code is hidden within the JavaScript, it can compromise the system. Pretty standard mal-ware technique but only recently exploited on Adobe.



this is a big problem but the reality is, its more of a symptom than the core issue.

with regards to why Adobe is the new Microsoft for product vulnerability, it really boils down to decisions made with regards to department management. around 2005, adobe started to outsource its management to india, like, *hardcore*. adobe had outsourced a lot of code dev to india and it was decided that they wanted to continue the trend with regards to cutting cost overhead in the project management/department management vectors. not long thereafter, these indian department heads started to prune their departments of coders from san francisco, san jose, portland, who had been with adobe for ages or had been aquired through the macromedia merger. these coders were replaced with rent-a-coders from, you guessed it, india.

on top of all this, adobe didnt really have a security department as of 2005. they had simply chopped up various components of ITSec (network, application, platform) and made various departments responsible for maintaining the most appropriate facets. eg the network team ran the firewall, the systems admins looked for platform issues, so on.

predictably, this did not work out. they had their hands full with other shit, and security was absolutely ridiculous because of it. they had managed to deploy and maintain a *highly* architected SOX compliant environment which helped sandbox any incidents really well, but their rep took a fucking mauling. exploitable cgis on their websites, XSS attacks on their forums, etc.

anyway, around 2007, they finally formed an actual security department, however they were tasked almost completely with responding to security notifications. in essence, they were a PR wing. they responded to emails and opened tickets with developers.

so why so many problems still?

because adobe cant afford to audit its code, in so many words. adobes stock dropped by something like 50% between 2004 and 2006, it performed a hugely expensive acquisition of macromedia, ostensibly to aquire its mobile flash platform, and then proceeded to either mis-market it or grossly overestimate the need for it in the first place. so basically no one can afford to pay someone competent to audit literally hundreds of thousands of lines of code *for each product*.

and even if they could, the indian managers would surely outsource the job to the same fucking indian developers who probably introduced the bugs in the first place.

so basically thats why adobe chugs an ugly dick these days, security wise.

*jazzhands*

_________________
Wiz' Fruity Pebbles Poetry Contest Runner-Up, probably.
<Ripptyde64> anyway I just wanted to give you some props for your posts....you really have a unique way with words and as a fellow writer I am humbled
<Ripptyde64> lol I just like your style. there are so many useless and moronic poster on these forums and you are vastly superior in quality, form and content.
<BB92> lol i have tits
╭∩╮(︶︿︶)╭∩╮


Wed Aug 04, 2010 1:53 pm
DD Photoshop Diva
User avatar

Profile
Degen Index: 60
Joined: 10 Jan 2010
Posts: 1463
Awesome laydown of the story, godatine.

So if I just never open a PDF on my iPhone, am I safe?

_________________
neverheeb wrote:
Most nerves in the body are located in the butthole which is why so many people are gay.


Wed Aug 04, 2010 2:32 pm
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 


Users browsing this topic: No registered users and 1 guest


Similar Topics

 Topics  Forum  Author  Replies
What's the best iphone 4S case? Shooting Off Goodpoop
Wed Feb 29, 2012 2:16 pm
8
WTF is wrong with Hero poker?? MAJOR TILT VENT!!! Shooting Off pokeremtdj
Tue Feb 14, 2012 8:14 pm
49
iphone/training site question Shooting Off Fergie72
Sun Feb 12, 2012 7:31 am
2
lifeproof iphone cases Shooting Off DRL453
Mon Jan 23, 2012 8:42 pm
2
Wireless network security Anti-Hacker Information Warfare Forum tomfmason
Wed Jan 18, 2012 6:55 pm
3

Search for:
Jump to:  

Poker Blog | Poker Forum | Contact Us | Advertise | Sitemap
Copyright © 2009-2011 Donkdown.com LLC