Skip navigation

Monthly Archives: February 2008

I found this video from Sunbelt on Trojan DNS Changers. It’s about 5 minutes and pretty telling for those tht don’t believe the the "hype" about internet dangers. In all fairness, the version Alex is using doesn’t appear to be current, but the concept is still applicable.

Trojan DNS Changer video from alex eckelberry on Vimeo

Another vulnerability was disclosed in Acrobat Reader v8.x. a few days ago:
http://www.adobe.com/support/security/advisories/apsa08-01.html

This vulnerability is now being exploited on the web (and probably by email very soon). It’s being loaded from a web page. The exploit code is in a file called 1.pdf and contains a variant of the zonebac virus (Trojan). None of the common/leading/popular AV products are detecting it. A handler at ISC ran it through virus total:
http://www.virustotal.com/analisis/372ecd6435eb0bd66b8dbd1c1ef4b4b9]1.pdf virustotal

Adobe suggests that users of v8.x upgrade to v8.1.2. Users of v7.x have to wait for a patch (this sucks, since it always becomes back burner status for them).

85.17.221.2 is a site where it’s found. The IP belongs to LeaseWeb which is in the Netherlands. Because the lack of attention to the vulnerability, it won’t take much for this to become huge; specially considering the lack of attention by AV companies. The only public reports have been in Italian.