PDA

View Full Version : Attention Urgent Message for all Users!

Link to this page  Printable page

Posted by - wirewolf
Post date - 04-10-2007, 05:16 PM
Attention all users. I've just learned of a possible problem with Adobe Reader (http://www.adobe.com/products/acrobat/readstep2.html). I have disabled all of the p_d_f files in the Downloads Section and the uploading of p_d_f files to posts. The problem is NOT with the p_d_f files themselves, but with a vulnerability within Adobe and a hacker's possible injection of a cross site scripting java code. Please read these articles:
Adobe Reader flaws spook security experts (http://searchsecurity.techtarget.com/columnItem/0,294698,sid14_gci1237450,00.html)
Adobe to issue patches for Reader vulnerability (http://www.networkworld.com/news/2007/010507-adobe-to-issue-patches-for.html)

If you have the Adobe Plugin enabled in your browser, DISABLE it right away!!! This threat appears to affect all types of browsers, but mainly Firefox and Internet Explorer. Again, the threat is not with the site you are visiting or with an actual p_d_f file itself, but with a vulnerability with in Adobe Reader. This can be exploited with ANY site you visit that has p_d_f file links, not just the Forum and the wrong combination of Browser and Adobe.

Members', please do not place links to p_d_f files in any post. The hackers exploiting this Adobe vulnerability are scanning web pages looking for p_d_f file links. Once found, they wait for an innocent user to come along with just the right combination of browser and Adobe version. When found, the hacker uses cross-site scripting to gain access to that unsuspecting users' computer.

According to organizations like Secunia and The French Security Incident Response Team (FrSIRT), the best thing for users to do at this time, is to upgrade to Adobe 8.0.0 (http://www.adobe.com/products/acrobat/readstep2.html), where the vulnerability has been removed.

I have also learned of another problem for those using Microsoft Windows. This comes from - US-CERT - National Cyber Alert System:
Please read - Microsoft Windows Animated Cursor Vulnerability (http://www.us-cert.gov/cas/alerts/SA07-089A.html)

I will keep you updated with any new information regarding this issues.

Update: See post below.

John

PS, Ain't the Internet great? :userfriendly:

Background. One of our member's recently contacted me complaining that it took a while for the forum pages to load and that he had to wait for Adobe Reader to finish loading. There is no call from the forums server to preload Adobe Reader! After a little investigation, I informed him of the problem (as stated above). He removed the Adobe Plug-in, and upgraded to Adobe Version 8. He reported that this fixed the problem. Apparently his computer was not compromised.
If any user has experienced the same problem please upgrade to Adobe Version 8 and you may also want to upgrade your current browser. If you think your computer may have been compromised, perform a scan of your computer with a Anti-Virus program (make sure you have the latest virus definitions prior to doing the scan).

Posted by - wirewolf
Post date - 04-14-2007, 10:23 AM
An Update!

I've reconfigured the files to zip format for downloading.
1 - Joint clubs conference in New London, CT. (http://shipmodeling.net/vb_forum/thread3026.html)
2 - Modelling the New York Pilot Boat - Phantom (http://shipmodeling.net/vb_forum/downloads-file33.html)
3 - Articles on making of the Bluenose (http://shipmodeling.net/vb_forum/downloads-file32.html)

It still stands, please do not post any links to p_d_f files. If you have a p_d_f (s), compress it into a zip file first, then post or upload.

John

Posted by - captainpugwash
Post date - 04-14-2007, 02:14 PM
Cheers John. Thanks for the heads-up!

Posted by - wirewolf
Post date - 09-01-2007, 10:28 AM
Update! I've re-established pdf file downloads (for now, ChuckPassaro's Modelling the New York Pilot Boat - Phantom - all four parts (http://shipmodeling.net/vb_forum/downloads-category3.html)). You should still download the latest version of Adobe Reader however - Adobe Reader (http://www.adobe.com/products/acrobat/readstep2.html)
Cheers, John

Posted by - BobHill
Post date - 09-01-2007, 10:29 AM
John,
Specifically, Adobe has issued a security warning, concerning it's PDF Reader version 7.0 to 7.08 ONLY .. see: http://www.adobe.com/support/security/bulletins/apsb06-20.html

The correction is to download (free) from http://www.adobe.com/go/getreader/. And in any case, it's always best to download and use the latest PDF reader from Adobe when it's available. PDF documents are the most used and useful format for transporting information any where in the world, and if any company is up to being sure it's secure, it's Adobe.

Bob Hill
The Adobe Forum site is always the best source to check on their product reliabilities: http://www.adobe.com/support/forums/

Posted by - wirewolf
Post date - 09-01-2007, 11:06 AM
Thanks Bob. It's hard some times to stay up to date with the latest software.

BTW, that link - http://www.adobe.com/go/getreader/ re-directs to - http://www.adobe.com/products/acrobat/readstep2.html anyway. .....and if any company is up to being sure it's secure, it's Adobe.I know, Adobe has always been very responsible. I've got the new Reader version 8.1 Has some nice new features.
Cheers, John

Posted by - BillQ1947
Post date - 05-11-2010, 05:26 PM
Hi John;
I guess that this would be one of my first posts. I have Adobe 9.0 and AVG virus scan, both courtesy of the VA. If notifies me of anything that enters via emal or files. I have the voice operated computer, again courtesy of the VA.
I have noticed quite a bit of viruses on Pop Ups.
I will enter the information you posted onto my computer.
Thanks again.
Bill Q.

Posted by - BillQ1947
Post date - 05-18-2010, 01:44 PM
Thank You John for the heads up! As my previous post to you said, I have Adobe 9.0 and am very careful about what I uplaod and send.
Thanks again,