PDA

View Full Version : Windows no longer the target?



MAGGIO
08-06-2009, 09:15
Sum up: Make sure to update your office, adobe, and Flash player today from the manufactures website.

If you are a criminal and you want to break into a network a common attack method is to exploit a hole in software that exists on most computers, has its fair share of holes and isn't automatically updated.
In 2002, that would have been Windows. Today, it's likely to be Adobe Reader or Flash Player, whose shares of vulnerabilities and exploits are on the rise while Microsoft's is falling.

Nearly half of targeted attacks exploit holes in Acrobat Reader, which is used to read PDF (portable document format) files, according to F-Secure. Meanwhile, the number of PDF files used in dangerous Web drive-by attacks jumped from 128 during the first three and a half months of last year to more than 2,300 during that time this year, the company said.
In addition, there are more and more Zero-Day holes, vulnerabilities that are public before a patch is available. Like sitting ducks, users of affected software are left wide open to attack until a fix is available.

There have been Zero-Day exploits for the Flash Player (http://forums.nation-wars.com/8301-27080_3-10294212-245.html) plug-in, used for viewing rich media like videos and interactive charts on Web sites. And in one case this spring (http://forums.nation-wars.com/8301-1009_3-10229070-83.html), a Zero-Day hole in Adobe Reader spurred security experts to recommend that users disable JavaScript.
One security researcher at Black Hat last week, who asked to remain anonymous, said: "As a result of the number of Zero-Day attacks on PDFs this year, large banks hate Adobe."

MAGGIO
08-06-2009, 09:17
On fathersday weekend, I was asked to update my flash player to an HD version...stupidly i did it from a non manufacturer website (not adobe).

I got a virus so bad that I spent 8hrs trying to fix it before it was so bad that I had to just do a fresh install (which for me on this computer takes 6hrs due to software).

Minimus
08-07-2009, 19:08
Probably all the porn surfing didn't help.