Sunday, October 11, 2009

Article Blog #7: Taking the backdoor into Adobe

Adobe exploit puts backdoor on computers

A new exploit has been discovered, and the affected software company is scrambling to code a patch. This time the company is Adobe, and the products in question are Adobe Reader and Adobe Acrobat. The security flaw is exploited when a malicious hacker sends the victim a PDF file containing javascript-based malware. The trojan horse creates a backdoor into the victim's computer, which the hacker can use to gain access. This is a zero day attack, meaning that the exploits started on the same day Adobe became aware of the security flaw. The term "zero day" attack comes from the practice of starting numbering at zero in computer science, a practice readers are sure to be familiar with. This is the fourth zero-day attack involving malicious code contained in PDF files this year.

This latest attack is a good reminder to the computer-using public. The Internet has enabled us to do many things that we once could not, and has made everyday tasks and communication far easier. But with that convenience comes the ever present threat of viruses and hackers. This attack uses a .pdf file as a trojan horse. The success of the attack depends on the victim trusting that the attacker is being honest and sending them a safe file. Unfortunately, such attacks have become common. There will always be people who can be fooled by hackers on the Internet, so security issues become a race between software vendors to close holes and hackers to exploit them. And no matter how quickly vendors work, some users will fall prey to malware before security patches can be issued. So it is in the users' best interests to learn about the software they depend on, and about the potential security exploits. This knowledge would give those who understand it the ability to better protect themselves from the threat of hacking.

Additional Sources:
New Adobe Reader, Acrobat Vulnerability Comes Under Attack
Hackers exploit this year's fourth PDF zero-day
Zero day attack

No comments:

Post a Comment