Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -2 articles for you...
83

Adobe Reader: Unpatched Flaw Exposes Users to ZeuS Bot Threat

According to several reports by anti-virus vendors, criminals have attempted to exploit an unpatched hole in Adobe Reader disclosed about two weeks ago to infect Windows PCs. The relevant malware includes the particularly dangerous ZeuS bot. The specially crafted documents are apparently sent to users as email attachments.. The "Launch Actions/Launch File" function in Adobe Reader allows the execution of scripts or EXE files embedded in PDFs. Although Adobe Reader asks users to agree to the execution of the file, this dialogue can be designed in such a way that users have no idea they may be allowing an infection in to their systems. Sophos have posted a demo which tries to persuade users to click an OK button on their blog. A report from M86Security describes a PDF document that tries to install the ZeuS bot. When opened, the document tries to save a further PDF document which contains the actual malware. The documents are probably nested in an attempt to trick virus scanners. Interestingly, Reader opens a user dialogue before saving the file, but Foxit automatically saves the file without requesting confirmation. The current version of Foxit at least opens a dialogue when trying to start the bot that is hidden in the PDF The link for this article located at H Security is no longer available. . Intrusive efforts to take advantage of a vulnerability in Microsoft Word allow cybercriminals to run code, such as Dridex malware, through DOCX documents.. Adobe Reader Exploit, Malware Threats, PDF Security Risks. . LinuxSecurity.com Team

Calendar 2 Apr 16, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Exploring Malicious Code Spreading Through PDF Exploits

Security researcher Jeremy Conway says he has discovered a way to spread malicious code across PDF documents on a victim's computer. The attack leverages a flaw in the way the PDF file format works, adding malicious data to legitimate PDF files that could then be used to attack anyone who opens them.. Conway, a product manager with NitroSecurity, had already developed a technique for injecting the malicious commands into PDFs. But his attack only worked when there was some other malicious program on the system that added the code. That all changed last week, when researcher Didier Stevens showed how a PDF document could be altered to run an executable file on a victim's computer. "When I saw Didier's hack, it was the first time I could do it from completely inside the PDF," Conway said. Hackers have known for some time that PDF readers could be manipulated in this way, but Stevens' attack showed how one reader -- Foxit Reader -- could launch the executable without even notifying the user. Foxit has now patched this bug, but the underlying flaw in the PDF standard can't be fixed without changing the PDF standard itself. The link for this article located at Computer World is no longer available. . Conway, a product manager with NitroSecurity, had already developed a technique for injecting the ma. security, researcher, jeremy, conway, spread, malicious, across. . LinuxSecurity.com Team

Calendar 2 Apr 08, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Investigating Risks And Exploits Associated With Adobe Reader PDFs

A security researcher has demonstrated a mechanism that exploits PDF files without taking advantage of any particular vulnerabilities. Didier Stevens' proof of concept exploit relies on running an executable embedded in a PDF file - something that ought to be blocked - by launching a command that ultimately runs an executable.. In the case of Adobe Reader, such attempted launches generate a pop-up dialog box asking users if they want to proceed. However, this is not necessarily a major hurdle because Stevens was also able to manipulate the text displayed by the pop-up in a way that might easily fool most users. "With Adobe Reader, the only thing preventing execution is a warning," Stevens explains. "Disabling JavaScript will not prevent this, and patching Adobe Reader isn The link for this article located at The Register UK is no longer available. . Discover how a cybersecurity analyst altered PDF documents, which were free from flaws, to sway user decisions in Adobe Acrobat.. PDF Threats, Security Exploits, Adobe Reader Risks, Malware Mechanisms, User Awareness. . LinuxSecurity.com Team

Calendar 2 Apr 06, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here