Author Topic: Did you already set the Javascript Blacklist for the recent 0-day?  (Read 5757 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Hi malware fighters,

The zero-day hole in Adobe Reader and Acrobat will not earlier be patched as the next patch round within three weeks' time and hackers now abuse it actively to infect systems. An out-of-band patch for this critical hole would have a negative impact, according to Adobe's Brad Arkin....

You can be protected here, for Adobe recommends customers follow the mitigation guidance below, utilizing the Adobe Reader and Acrobat JavaScript Blacklist Framework, until a patch is available.

http://kb2.adobe.com/cps/532/cpsid_53237.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Hermite15

  • Guest
Re: Did you already set the Javascript Blacklist for the recent 0-day?
« Reply #1 on: December 19, 2009, 08:52:26 PM »
Hi Polonus,

nice, wouldn't have checked that today, downloading the temporary fix now!  ;)

edit: I got secunia psi up and running and I had no warning, even a manual scan doesn't tell anything about Adobe  ::)
« Last Edit: December 19, 2009, 08:58:33 PM by Logos »

YoKenny

  • Guest
Re: Did you already set the Javascript Blacklist for the recent 0-day?
« Reply #2 on: December 19, 2009, 08:54:02 PM »
I don't install Adobe vulnerable stuff at all ;)

Omega40

  • Guest
Re: Did you already set the Javascript Blacklist for the recent 0-day?
« Reply #3 on: December 19, 2009, 08:59:08 PM »
Deleted Adobe Reader, I now use Foxit Reader.  ;D


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: Did you already set the Javascript Blacklist for the recent 0-day?
« Reply #4 on: December 19, 2009, 09:04:53 PM »
Hi logos,

We always have to be out on the alert, and what can psi secunia do if they have nothing to offer (well I have found the temporal fix it, they could have found it as well, I report to them..)

polonus
« Last Edit: December 19, 2009, 10:58:06 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Hermite15

  • Guest
Re: Did you already set the Javascript Blacklist for the recent 0-day?
« Reply #5 on: December 19, 2009, 11:29:54 PM »
after a reboot (and also after I applied the adobe registry fix), I got an alert from Secunia...but they say "no solution", so not aware of the temp fix.

Offline Omid Farhang

  • Frontend Developer
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1660
  • I wish I could write longer personal text!!
    • Homepage
Re: Did you already set the Javascript Blacklist for the recent 0-day?
« Reply #6 on: December 20, 2009, 12:05:04 AM »
I've installed Adobe Reader, but I don't use it, neither Foxit or...

since I use Google Chrome as the only browser I use, I've installed Google Document Ext, it would open my PDF links (Of course other kind documents too) in Google Document and if it don't, I would upload and open them in Google Document, so I believe I'm totally protected!! ;D
Twitter: OmidFarhangEn - OS: Manjaro KDE

Hermite15

  • Guest
Re: Did you already set the Javascript Blacklist for the recent 0-day?
« Reply #7 on: December 20, 2009, 12:13:44 AM »
LOL I discovered this extension for Chrome earlier today, but didn't install it, might give it a try.... But obviously you must be signed in to your google account to read a pdf then  ;D

Offline Omid Farhang

  • Frontend Developer
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1660
  • I wish I could write longer personal text!!
    • Homepage
Re: Did you already set the Javascript Blacklist for the recent 0-day?
« Reply #8 on: December 20, 2009, 12:27:52 AM »
LOL I discovered this extension for Chrome earlier today, but didn't install it, might give it a try.... But obviously you must be signed in to your google account to read a pdf then  ;D

no, you don't need to sign-in to just read a public document, I don't know! maybe you need! I've never signed out of my Google Account, because I use Google for everything ;D , Mail (even I check my Hotmail and yahoo and AOL inbox via Gmail!), Messenger (Linked my Yahoo and Hotmail to GoogleTalk via Jabber services!), my Phone number is via Google Voice, blogging, web site and and and...
Twitter: OmidFarhangEn - OS: Manjaro KDE

Alan Baxter

  • Guest
Re: Did you already set the Javascript Blacklist for the recent 0-day?
« Reply #9 on: December 20, 2009, 07:46:55 AM »
You can be protected here, for Adobe recommends customers follow the mitigation guidance below, utilizing the Adobe Reader and Acrobat JavaScript Blacklist Framework, until a patch is available.

http://kb2.adobe.com/cps/532/cpsid_53237.html

Done.  Thank you, polonus.

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: Did you already set the Javascript Blacklist for the recent 0-day?
« Reply #10 on: December 20, 2009, 09:48:33 AM »
Deleted Adobe Reader, I now use Foxit Reader.  ;D

same here :)
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM