Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Applications > PDF drive-by exploit

PDF drive-by exploit
Thread Tools
Mac Enthusiast
Join Date: Feb 2005
Status: Offline
Reply With Quote
Feb 15, 2009, 09:15 PM
 
Funny, at the moment the top several threads deal with various Adobe issues...

Anyway, over the past year or two there have been a few PDF vulnerabilities which have apparently been fixed with Adobe Reader 9.0

I was browsing a site the other day and all of a sudden the page loaded the Adobe Reader plugin in Safari and started to load a PDF. The PDF appeared to be blank.

I have the url, is there a place that I can submit it AND find out what it was doing and if I was actually attacked?

I know that posts about Mac hacks/viruses tend to get dismissed or mocked, but if there is any thing I can do to figure out what was going on I would be appreciative.

This was on 10.4.11 PPC with Safari 3.2.1 and Adobe Reader 9.0
Everything is fully patched as far as I can tell.
     
Clinically Insane
Join Date: Jun 2001
Location: planning a comeback !
Status: Offline
Reply With Quote
Feb 15, 2009, 09:25 PM
 
I just googled a bit and couldn't find anything about PDF exploits for OS X.

Does anyone have some links about real exploits happening in the wild ?

-t
     
Mac Enthusiast
Join Date: Feb 2005
Status: Offline
Reply With Quote
Feb 15, 2009, 09:53 PM
 
The Adobe security advisories (scroll down a bit for Adobe Reader OS X) all mention MacOS X as potentially vulnerable.

It does seem like I should be alright since I am using version 9.0, although I would be interested in identifying the specific exploit which was attempted.
     
Moderator
Join Date: Apr 2001
Location: Wasilla, Alaska
Status: Offline
Reply With Quote
Feb 15, 2009, 10:10 PM
 
Can someone explain to me why anyone would use adobe reader any more?
     
Clinically Insane
Join Date: Jun 2001
Location: planning a comeback !
Status: Offline
Reply With Quote
Feb 16, 2009, 12:13 AM
 
Originally Posted by AKcrab View Post
Can someone explain to me why anyone would use adobe reader any more?
Dunno. I certainly haven't used it in ages.

-t
     
Mac Enthusiast
Join Date: Feb 2005
Status: Offline
Reply With Quote
Feb 16, 2009, 01:06 AM
 
Originally Posted by AKcrab View Post
Can someone explain to me why anyone would use adobe reader any more?
PDF functions on Tiger are not as advanced as with Leopard.

There are many types of PDF's that Preview can't handle on 10.4.x

Example:
Want to apply for a political appointment in the new administration?
     
JKT
Professional Poster
Join Date: Jan 2002
Location: London, UK
Status: Offline
Reply With Quote
Feb 16, 2009, 05:20 AM
 
Originally Posted by AKcrab View Post
Can someone explain to me why anyone would use adobe reader any more?
Some of us need to be able to use and support more than the PDF 1.5 spec (it is currently PDF 1.9 iirc) and Preview is a long way behind the curve in this regard, even in Leopard. E.g. embedded 3D, films or slideshows are not supported by Preview. Also, Preview has many problems with the display of PDF mark-up so, alas, Adobe Reader is still very much required.

It is worth saying that version 9.0 or Reader is a huge improvement over prior ones on OS X, so using Reader isn't anywhere near as bad as it used to be.
     
Clinically Insane
Join Date: Jun 2001
Location: planning a comeback !
Status: Offline
Reply With Quote
Feb 16, 2009, 09:24 AM
 
Originally Posted by JKT View Post
E.g. embedded 3D, films or slideshows
It's that kind of stupid crap that makes me *not* support Adobe Acrobar Reader.

Who the heck needs 3D, films or slideshows in PDFs ?
There are much better formats to be used for that purpose.

-t
     
JKT
Professional Poster
Join Date: Jan 2002
Location: London, UK
Status: Offline
Reply With Quote
Feb 16, 2009, 09:39 AM
 
Originally Posted by turtle777 View Post
It's that kind of stupid crap that makes me *not* support Adobe Acrobar Reader.

Who the heck needs 3D, films or slideshows in PDFs ?
There are much better formats to be used for that purpose.
Academics do and, no, it isn't just stupid crap that it is being used for. The information can be delivered in other formats but none is as convenient or universal or as easy to create and use.
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 04:26 PM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2