Banner
donkdown

Who Is Chatting

Chatroom is empty

Chat Now

Account Login

MANDATORY: Former NeverWinPoker users, please click HERE to reset your password



Poker Blog

02/03/2012
Glimmer of Hope
Comments: 5
by chinamaniac
01/31/2012
They Just Grab it Part 2
Comments: 1
by chinamaniac
01/12/2012
Little Comeback
Comments: 3
by chinamaniac

Micon's Hot Tweets

BryanMicon: RT @qsdaddy1: @BryanMicon @GoldfarbLOL @painlesswon @BrandonGerson I'm on team "cute little schmeckle" FTW
BryanMicon: I need maximum internet love for @GoldfarbLOL 12 handed for the Suzie McBain Orleans Sanatarium Open event. @painlesswon @BrandonGerson
BryanMicon: glglgl to my little schmekel @GoldfarbLOL in the Sanitarium Open @painlesswon is birding hard plz update frequently
BryanMicon: Yup, wondered into the Orleans. @GoldfarbLOL http://t.co/SyLLHtT3
BryanMicon: headshot @DonkDown radio coming soon: @McEvoy_Tom to get real with us about FTP and it's owners - stay tuned
Banner
Banner
Banner


Search This Topic:
Jump to:  


Post new topic Reply to topic  [ 7 posts ] 
Major Security Breach in iPhone/iPad 
Author Message

http://www.huffingtonpost.com/2010/08/03/apple-security-breach-cou_n_669481.html

Quote:
Opening a manipulated website or a PDF file could allow criminals to spy on passwords, planners, photos, text messages, e-mails and even listen in to phone conversations, the agency said in a statement.


Wed Aug 04, 2010 11:55 am
Online
DD InfoSec Oyabun
User avatar

Profile
Degen Index: 59
Joined: 04 Feb 2007
Posts: 7978
not to minimize this but people i know who are pretty zealous about ITSec simply refuse to have any adobe projects whatsoever on their phones or computers. which is to say, yeah this is egregious, but there are sooo many other super exploitable issues with pdfs as well.

_________________
Wiz' Fruity Pebbles Poetry Contest Runner-Up, probably.
<Ripptyde64> anyway I just wanted to give you some props for your posts....you really have a unique way with words and as a fellow writer I am humbled
<Ripptyde64> lol I just like your style. there are so many useless and moronic poster on these forums and you are vastly superior in quality, form and content.

╭∩╮(︶︿︶)╭∩╮


Wed Aug 04, 2010 12:09 pm
DD Whale
User avatar

Profile
Degen Index: 28
Joined: 22 May 2008
Posts: 3237
sonatine wrote:
not to minimize this but people i know who are pretty zealous about ITSec simply refuse to have any adobe projects whatsoever on their phones or computers. which is to say, yeah this is egregious, but there are sooo many other super exploitable issues with pdfs as well.


I never understood why there are so many exploits for pdf files. Can you explain in lay person terms why this is?

_________________
micon wrote:

1) I CREATED THIS, DON'T FUCKING FORGET THAT
.


Wed Aug 04, 2010 12:28 pm
DD Piranha

Profile
Degen Index: 13
Joined: 30 Apr 2010
Posts: 835
betcheckbet wrote:
sonatine wrote:
not to minimize this but people i know who are pretty zealous about ITSec simply refuse to have any adobe projects whatsoever on their phones or computers. which is to say, yeah this is egregious, but there are sooo many other super exploitable issues with pdfs as well.


I never understood why there are so many exploits for pdf files. Can you explain in lay person terms why this is?


You asked basically the same question I was going to! Anyone who is an expert in this, would love to have some input....


Wed Aug 04, 2010 12:57 pm
DD Old School

Profile
Degen Index: -3
Joined: 03 May 2005
Posts: 8081
Adobe Reader (what most of us use to read .pdf's) has JavaScript enabled by default. JavaScript allows access to not only objects within the application that it's using (Reader in this case), but also allows access to other objects within a computer. If malicious code is hidden within the JavaScript, it can compromise the system. Pretty standard mal-ware technique but only recently exploited on Adobe.

_________________
408mike wrote:
The male scrotum is incredibly sensitive and should be handled with the utmost of care.


Wed Aug 04, 2010 1:10 pm
Online
DD InfoSec Oyabun
User avatar

Profile
Degen Index: 59
Joined: 04 Feb 2007
Posts: 7978
hugh_chardon wrote:
Adobe Reader (what most of us use to read .pdf's) has JavaScript enabled by default. JavaScript allows access to not only objects within the application that it's using (Reader in this case), but also allows access to other objects within a computer. If malicious code is hidden within the JavaScript, it can compromise the system. Pretty standard mal-ware technique but only recently exploited on Adobe.



this is a big problem but the reality is, its more of a symptom than the core issue.

with regards to why Adobe is the new Microsoft for product vulnerability, it really boils down to decisions made with regards to department management. around 2005, adobe started to outsource its management to india, like, *hardcore*. adobe had outsourced a lot of code dev to india and it was decided that they wanted to continue the trend with regards to cutting cost overhead in the project management/department management vectors. not long thereafter, these indian department heads started to prune their departments of coders from san francisco, san jose, portland, who had been with adobe for ages or had been aquired through the macromedia merger. these coders were replaced with rent-a-coders from, you guessed it, india.

on top of all this, adobe didnt really have a security department as of 2005. they had simply chopped up various components of ITSec (network, application, platform) and made various departments responsible for maintaining the most appropriate facets. eg the network team ran the firewall, the systems admins looked for platform issues, so on.

predictably, this did not work out. they had their hands full with other shit, and security was absolutely ridiculous because of it. they had managed to deploy and maintain a *highly* architected SOX compliant environment which helped sandbox any incidents really well, but their rep took a fucking mauling. exploitable cgis on their websites, XSS attacks on their forums, etc.

anyway, around 2007, they finally formed an actual security department, however they were tasked almost completely with responding to security notifications. in essence, they were a PR wing. they responded to emails and opened tickets with developers.

so why so many problems still?

because adobe cant afford to audit its code, in so many words. adobes stock dropped by something like 50% between 2004 and 2006, it performed a hugely expensive acquisition of macromedia, ostensibly to aquire its mobile flash platform, and then proceeded to either mis-market it or grossly overestimate the need for it in the first place. so basically no one can afford to pay someone competent to audit literally hundreds of thousands of lines of code *for each product*.

and even if they could, the indian managers would surely outsource the job to the same fucking indian developers who probably introduced the bugs in the first place.

so basically thats why adobe chugs an ugly dick these days, security wise.

*jazzhands*

_________________
Wiz' Fruity Pebbles Poetry Contest Runner-Up, probably.
<Ripptyde64> anyway I just wanted to give you some props for your posts....you really have a unique way with words and as a fellow writer I am humbled
<Ripptyde64> lol I just like your style. there are so many useless and moronic poster on these forums and you are vastly superior in quality, form and content.

╭∩╮(︶︿︶)╭∩╮


Wed Aug 04, 2010 1:53 pm
DD Photoshop Diva
User avatar

Profile
Degen Index: 60
Joined: 10 Jan 2010
Posts: 1463
Awesome laydown of the story, godatine.

So if I just never open a PDF on my iPhone, am I safe?

_________________
neverheeb wrote:
Most nerves in the body are located in the butthole which is why so many people are gay.


Wed Aug 04, 2010 2:32 pm
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 


Users browsing this topic: No registered users and 1 guest


Similar Topics

 Topics  Forum  Author  Replies
lifeproof iphone cases Shooting Off DRL453
Mon Jan 23, 2012 8:42 pm
2
Wireless network security Anti-Hacker Information Warfare Forum tomfmason
Wed Jan 18, 2012 6:55 pm
3
WTF is wrong with Hero poker?? MAJOR TILT VENT!!! Shooting Off pokeremtdj
Thu Jan 12, 2012 5:07 am
47
HOF Baseball fan escapes security Shooting Off muck ficon
Sat Nov 05, 2011 6:28 am
4
TSA Employee Takes Bribe to Move Passengers to Front of Airport Security Line Shooting Off Anonymous
Wed Sep 14, 2011 4:23 pm
6

Search for:
Jump to:  

Poker Blog | Poker Forum | Contact Us | Advertise | Sitemap
Copyright © 2009-2011 Donkdown.com