3 ms·
If it's as they describe they did have a 0-day used on them. The email attachments, which were excel spreadsheets with an embedded flash exploit apparently were
by trotsky 16y ago
If it's as they describe they did have a 0-day used on them. The email attachments, which were excel spreadsheets with an embedded flash exploit apparently were the source of the 0-day report documented in CVE-2011-0609 and published on Mar 14. The RSA attack was reported on Mar 17.
https://www.adobe.com/support/security/advisories/apsa11-01.html https://www.adobe.com/support/security/advisories/apsa11-01....
While there is definitely something to be said for what you're saying about "omg, email attack" the other side of the coin is that spearphishing is the most popular/common attack vector because it works.
- chair6 16y agoI was thinking 'in external facing system/service' while I was typing 0-day but yes, you're right. Agreed on the spearphishing point.
- mryall 16y agoIt's a good reminder that with ubiquity comes an increased focus on security. I'm much more conscious of the security problems with Flash after a lot of recent news about it. However, it isn't necessarily because it's any less secure than other applications, just that it's ubiquitous and therefore a more likely avenue of attack.