ICANN/GNSO GNSO Email List Archives

[ga]


<<< Chronological Index >>>    <<< Thread Index >>>

[ga] PDF Exploits On the Rise

  • To: Ga <ga@xxxxxxxxxxxxxx>, ICANN Policy staff <policy-staff@xxxxxxxxx>
  • Subject: [ga] PDF Exploits On the Rise
  • From: "Jeffrey A. Williams" <jwkckid1@xxxxxxxxxxxxx>
  • Date: Tue, 23 Sep 2008 02:18:59 -0700

All,

  Perhaps the following should be given some serious consideration
by ICANN's staff and the SSAC, see:

Our research some two years ago came to these conclusions
which were briefly wrtiien up in Computerworld at the time.
I am a bit surprised that yet again these exposiers need to
be revisted.  Additionally .DOC format is similarly an easy
hack as well, and we for some time no longer use either
format, no will download either and recomend same.

Further see:
According to the TrustedSource Blog, malware authors
 http://www.trustedsource.org/blog/153/Rise-Of-The-PDF-Exploits
increasingly target PDF files as an infection vector. Keep your browser
plugins updated. From the article: "The Portable Document Format (PDF)
isone of the file formats of choice commonly used in today's
enterprises, since it's widely deployed across different operating 
systems. But on a down-side this format has also known vulnerabilites 
which are exploited in the wild. Secure Computing's Anti-Malware 
Research Labs spotted a new and yet unknown exploit toolkit which 
exclusively targets Adobe's PDF
format."

Regards,

Spokesman for INEGroup LLA. - (Over 281k members/stakeholders strong!)
"Obedience of the law is the greatest freedom" -
   Abraham Lincoln

"Credit should go with the performance of duty and not with what is
very often the accident of glory" - Theodore Roosevelt

"If the probability be called P; the injury, L; and the burden, B;
liability depends upon whether B is less than L multiplied by
P: i.e., whether B is less than PL."
United States v. Carroll Towing  (159 F.2d 169 [2d Cir. 1947]
===============================================================
Updated 1/26/04
CSO/DIR. Internet Network Eng. SR. Eng. Network data security IDNS.
div. of Information Network Eng.  INEG. INC.
ABA member in good standing member ID 01257402 E-Mail
jwkckid1@xxxxxxxxxxxxx
My Phone: 214-244-4827



<<< Chronological Index >>>    <<< Thread Index >>>