• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

New Adobe Zero-Day Exploit

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
According to researchers at Trend Micro, there is a new zero-day exploit targeting Adobe Reader that drops a backdoor onto your computer. To put it another way, if your soap was made by Adobe, don't bend over to pick it up in the shower. :eek:

Based on our findings, the shellcode (that was heap sprayed) jumps to another shellcode inside the .PDF file. The said shellcode then extracts and executes a malicious file detected by Trend Micro as BKDR_PROTUX.BD. The said backdoor is also embedded in the .PDF file and not the usual file downloaded from the Web. Protux variants are known for their ability to provide unrestricted user-level access to a malicious user.
 
Last edited:
Foxit FTW. I've stopped using as many Adobe products as I can.

Does Foxit still have trouble with fill-able forms? I tried it a few years back but ended up going back to Adobe Reader simply because Foxit didn't like some tax documents.

Of course, if Foxit was 100% feature compatible with all PDFs, then chances are we'll be back to square one with all the vulnerabilities and bloat of Adobe Reader.
 
Protux? Sounds like a rabid, foaming-at-the-mouth linux fanboi wrote that... :confused:
 
Why am I not surprised.... Adobe really need to get their act together....

I ditched adobe reader for foxit years ago and I haven't looked back... and if I could, I would drop flash in a heart beat...

ATM I use flashblock and noscript to only allow the flash content I want.
 
Foxit FTW. I've stopped using as many Adobe products as I can.

My question is , where does one have to go to pickup this exploit, or does it just meander around the internet looking for a host. If it is at respectable websites that are suppose to be trustworthy then that is where the attention should be brought to, and if its at the sites where we can expect to receive it, then we have to, do diligence.
 
To put it anohter way, if your soap was made by Adobe, don't bend over to pick it up in the shower.

that should really go onto a newsprint :D

Why am I not surprised.... Adobe really need to get their act together....

I ditched adobe reader for foxit years ago and I haven't looked back... and if I could, I would drop flash in a heart beat...

ATM I use flashblock and noscript to only allow the flash content I want. [/quote[

i dont know, its just everything is getting complicated, thousand of lines of code, its not like adobe really wanted that to happen imo :) , we could ditch everything and get back to the text only version of the web , that would probably leave us exploit free. I reckon its much more important, if an exploit is found, a patch should be out in a few days to a week..

if everyone used foxit in the near future, i wont be surprised if there would come a time where an exploit will be brought about that will affect the reader too.
 
I don't doubt that even Foxit is susceptible to exploits and malicious code. I switched to Foxit because it isn't bloated or slow like Adobe reader. Of course adhering to safe web surfing and not just downloading any PDF file we come across would greatly reduce the chance of infection.
 
exploits shouldnt happen in products like this, Adobe needs better QA on their products since they seem to have these exploits more frequently lately.

i blame it on lazy coders, or upper management pushing out products too dam fast!
 
I've become very leery of Adobe over the years. I started listening to Steve Gibson's "Security Now" podcast and he fingers them as one of the major offenders. Besides all this kind of crap, Adobe has a separate class of cookies their products keep that are hard to get at and most people don't even realize exist. Websites are moving to these cookies because users can easily control web browser cookies nowadays. Sucks.
 
Meh, I dropped Foxit for Adobe Reader Lite and found it much faster and compatible.

Anyway, MSE is up to date. ;)
Posted via [H] Mobile Device
 
I use Sumatra PDF for my PDF needs. It's lightweight, fast, and portable, although it's only good as a reader. Adobe's shit is so hideously bloated, slow and poorly-designed that it makes my head spin just thinking about it. I'd have nothing of theirs gracing my precious computer if it wasn't for the fact that they are unfortunately the industry standard for most fields they have products in.
 
Adobe reader is an absolute piece of crap. i mean why does it not let you control w out of tabs? and why doesn't it allow you to turn off your computer if any PDF tabs are open?
 
Back
Top