4 ms·
Obviously I can't speak to your situation specifically, but it is very common these days for people to have malware that was installed through an exploit that t
by trotsky 16y ago
Obviously I can't speak to your situation specifically, but it is very common these days for people to have malware that was installed through an exploit that they've never detected - indeed it can be very difficult to detect a lot of modern malware without in memory analysis and skilled forensics. Signature tools and things like malware bytes are extremely hit and miss. OS X and linux are even worse off (at least with standard configurations) once something has done a remote code execution and gotten a privesc.
Poll a few people who do security work and ask them if they have acrobat or flash or the jdk installed at all, or running on pages by default. You'll hear about the same thing.
Even 5 years ago was a very different world as far as threats go.
I'd strongly suggest using an alternate PDF reader (apple, google, evince, sumatra) and using flashblock.
- Qz 16y agoI got nailed by some Whitesmoke Translator malware that seemed to re-appear every time Acrobat updated. I eventually just wiped my HD and upgraded to windows 7 which I had been putting off for a while. Nothing like a good virus to convince you it's time to wipe your HD.
- sp_ 16y agoWithout wanting to go into more details, I work a job that makes me see and analyze more Adobe vulnerabilities than anybody else outside of Adobe. Having said that, I run both Flash and Adobe Reader (and Foxit for dubious stuff) on my normal machine. The number of 0-days exploited in the wild is not actually that big (I'd like to see stats here but I am not aware of any) and the odds of being hit by an 0-day exploit is really low. When people get owned through Adobe exploits, it is because they are not updating regularly.
- trotsky 16y agoI definitely agree with you that when (most) people get owned it's because they're not updating regularly - and I don't want to discount your opinion at all as clearly you're in a position to know the risks. But (as I'm sure you know) Adobe does have 0-days quite often and can take weeks to distribute a patch. The sep 14 cve-2010-2883 drop for example was being exploited seemingly quite widely by ~sep 20, and Adobe didn't push a patch until Oct 4. That's a pretty big window to be open to a drive by iframe vuln. Also, doesn't adobe updater take 7 or 14 days between update checks? It used to, at least. The thing about not running them at all (or on opt-in) is it also mitigates some of the danger in update lagging. It seems a majority of the time when I touch someone else's computer they have an adobe product that's out of date and being actively exploited (on the internet) - even if they appear to try to keep up to date with the patches.