Adobe Acrobat vulnerable again

February 23rd, 2009 1 Comment »

Another serious vulnerability in Adobe Acrobat is making its way around the Internet.  So far testing has confirmed  the vulnerability in Adobe Acrobat 8.1.0, 8.1.1, 8.1.2, 8.1.3, and 9.0.0.  This affects the latest version of both 8.x and 9.x versions of Adobe Acrobat.  Although the exploit is not JavaScript based, it is trigger via JavaScript, so for now disabling JavaScript will help mitigate this threat.  Adobe has acknowledge the vulnerability and has plans on releasing a patch around March 11th.

For now, if you want to disable JavaScript in Adobe Acrobat, you can go into the Edit menu and select preferences.   Under preferences you will see a JavaScript option group, from there you can un-check the box to disable JavaScript.

This can also be disabled via the registry or a GPO under HKEY_CURRENT_USER

Adobe Acrobat Reader:

Software\Adobe\Acrobat Reader\x.0\JSPrefs
Adobe Acrobat:

Software\Adobe\Adobe Acrobat\x.0\JSPrefs
Changing DWORD “bEnableJS” to zero will disable JavaScript.
Tags: , , , , , , ,

Author: Christopher

(No Ratings Yet)
Loading ... Loading ...

FAA employee data compromised

February 15th, 2009 No Comments »

Federal Adviation Administrion (FAA) recently fell victim to another malicious hacker attack.  This time two servers were compromised resulting in the exposure of personal data for 45,0000 employees and retirees.    The second server contained encrypted medical records which are believed to be safe.

FAA spokespersons confirm this attack had no reach to Air Traffic Control systems.

“These government systems should be the best in the world and apparently they are able to be compromised,” said Waters, an FAA contracts attorney.

Tags: , ,

Author: Christopher

(No Ratings Yet)
Loading ... Loading ...