Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 05-30-2009, 07:49 AM   #1
Brad Mitchell
Confirmed User
 
Brad Mitchell's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: Southfield, MI
Posts: 9,812
:stop Adobe product exploits on your local computer can compromise your servers

I have just sent this to all of our customers and wanted to bring the exploit to the whole community's attention as this is something that can affect everyone at all hosts. Best wishes to all and enjoy your weekend.



Dear Clients,

We have caught something early and fortunately, for 99% of you, this will likely mean that you have not been a victim yet. To give this scenario perspective, in the last week we have identified approximately 3 clients where in the final analysis it was determined this exploit of client side software has been the culprit.

If you are not running the most recently patched versions of Adobe Acrobat and Adobe Flash Player you are at risk for compromising your web sites. A recently discovered vulnerability in this software which runs locally on your computer can lead to malware stealing your FTP credentials with the potential for much more. This poses a significant security risk to your server and web sites, leading to attackers using client FTP credentials to deface web sites and insert malicious code which can exploit things further. Below is a description of the risk from the United States Computer Emergency Readiness Team.

Here are two quick links to update your versions:
http://get.adobe.com/flashplayer/
http://get.adobe.com/reader/

Lastly, please be sure that you are up to date with good antivirus software on your local computer. If you discover by surfing any of your web sites that they have been affected, please enter a support ticket and our team can help to mitigate any damage done and issue new FTP/other credentials. It is crucial that your local software and virus protection be up to date and this unexpected exploit of everyday software is a lesson to everybody about just how fragile things truly can be.

---------------------------------------------------------------------
Information as published on: http://www.us-cert.gov/current/

Gumblar Malware Exploit Circulating
added May 18, 2009 at 12:47 pm

US-CERT is aware of public reports of a malware exploit circulating. This is a drive-by-download exploit with multiple stages and is being referred to as Gumblar. The first stage of this exploit attempts to compromise legitimate websites by injecting malicious code into them. Reports indicate that these website infections occur primarily through stolen FTP credentials but may also be compromised through poor configuration settings, vulnerable web applications, etc. The second stage of this exploit occurs when users visit a website compromised by Gumblar. Users who visit these compromised websites and have not applied updates for known PDF and Flash Player vulnerabilities may become infected with malware. This malware may be used by attackers to monitor network traffic and obtain sensitive information, including FTP and login credentials, that can be used to conduct further exploits. Additionally, this malware may also redirect Google search results for the infected user.

US-CERT encourages users and administrators to apply software updates in a timely manner and use up-to-date antivirus software to help mitigate the risks.

US-CERT will provide additional information as it becomes available.
---------------------------------------------------------------------


Sincerely,

Brad Mitchell, CEO
MojoHost
888-345-MOJO Toll Free
248-233-2045 International
ICQ #56950199
__________________
President at MojoHost | brad at mojohost dot com | Skype MojoHostBrad
71 industry awards for hosting and professional excellence since 1999
Brad Mitchell is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 07:59 AM   #2
SeanLEE
Confirmed User
 
SeanLEE's Avatar
 
Join Date: Feb 2006
Location: Miami, FL
Posts: 1,556
My computer crashes ten times a day- flash.ocx internet explorer issue

Ive tried and tried and tried- but cant stop it.

I thought it was google virusing the IE browser to compete with Chrome-

But now Im not sure.

Nonetheless- Im about to switch back to my Mac pro-
__________________
I spammed in threads!
SeanLEE is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 08:01 AM   #3
Diomed
Converting like it's 1999
 
Diomed's Avatar
 
Industry Role:
Join Date: Jan 2009
Location: The South
Posts: 6,167
I have been fucked up by that adobe one like 10 times now,

I think I have it again.
__________________
10 years of experience in:

CHAT SALES - PAID TRAFFIC - CONVERSION - CREATIVES - CONSULTATION
Diomed is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 08:03 AM   #4
Tat2Jr
Confirmed User
 
Tat2Jr's Avatar
 
Join Date: Feb 2001
Location: Sunny California
Posts: 4,882
First thing to do is get RID of Adobe Reader altogether. Their time between finding a vulnerability and patching it is unacceptable. Use Foxit instead. MUCH more secure, and MUCH faster.

http://www.foxitsoftware.com/pdf/reader/
__________________
NICHE MONEY >> Ass WorshipPantiesSolo TeenPantyhose
Serving up exclusive fetish sites since 1997!
Tat2Jr is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 08:13 AM   #5
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
I've been "saved" from the exploits because I have my browser set up to NOT embed pdfs... instead I get a dialog asking what I'd like to do with XXX.pdf (save, load with default application).

I've loaded at least 3 sites which invoked this dialog, so if it wasn't for that I probably would have been infected.

I think it's time to try something else, foxit looks good...
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 08:37 AM   #6
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
Adobe reader uninstalled
Foxit installed (gee, talk about prechecked cross sales :D )
Adobe flash uninstalled
Latest version installed

I'm set. :D
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 11:06 AM   #7
Grapesoda
So Fucking Banned
 
Industry Role:
Join Date: Jul 2003
Location: Montana
Posts: 46,238
Quote:
Originally Posted by SeanLEE View Post
My computer crashes ten times a day- flash.ocx internet explorer issue

Ive tried and tried and tried- but cant stop it.

I thought it was google virusing the IE browser to compete with Chrome-

But now Im not sure.

Nonetheless- Im about to switch back to my Mac pro-
I have the same bullshit with flash...adobe crashes out another computer that I don't use on-line randomly as well
Grapesoda is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 11:11 AM   #8
Grapesoda
So Fucking Banned
 
Industry Role:
Join Date: Jul 2003
Location: Montana
Posts: 46,238
Quote:
Originally Posted by Tat2Jr View Post
First thing to do is get RID of Adobe Reader altogether. Their time between finding a vulnerability and patching it is unacceptable. Use Foxit instead. MUCH more secure, and MUCH faster.

http://www.foxitsoftware.com/pdf/reader/
man you are a life saver!! now is there another way to use flash without adobe?
Grapesoda is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 11:15 AM   #9
Robbie
Leaner, Meaner, Faster
 
Robbie's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: Vegas
Posts: 20,959
Thanks for the info Brad
__________________
-Robbie
ClaudiaMarie.Com
Robbie is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 12:25 PM   #10
Brad Mitchell
Confirmed User
 
Brad Mitchell's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: Southfield, MI
Posts: 9,812
Quote:
Originally Posted by Robbie View Post
Thanks for the info Brad
Sure thing!

Everyone else, great suggestions on product alternatives, etc, keep it coming for the greater good.

Cheers,

Brad
__________________
President at MojoHost | brad at mojohost dot com | Skype MojoHostBrad
71 industry awards for hosting and professional excellence since 1999
Brad Mitchell is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 12:27 PM   #11
Agent 488
Registered User
 
Industry Role:
Join Date: Feb 2006
Posts: 22,511
adobe is gay.
Agent 488 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 12:52 PM   #12
Ethersync
Confirmed User
 
Ethersync's Avatar
 
Join Date: Mar 2008
Location: London, Saint-Tropez, Bermuda, Moscow
Posts: 5,289
Thanks....
Ethersync is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 01:12 PM   #13
mynameisjim
Confirmed User
 
mynameisjim's Avatar
 
Join Date: Aug 2007
Posts: 2,985
I visited a very popular adult company and they were infected, it loaded a PDF by itself and I got infected. Had to dump the HDD.

I'll never use acrobat again. I'm stuck with flash but Adobe is pretty slow on the patching.
__________________
jim (at) amateursconvert . com Amateurs Convert
mynameisjim is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 01:17 PM   #14
u-Bob
there's no $$$ in porn
 
u-Bob's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
thnx, but already removed Acrobat 3 weeks ago when it wouldn't let me install the security updates without the install cd.... :/
u-Bob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2009, 03:54 PM   #15
Tat2Jr
Confirmed User
 
Tat2Jr's Avatar
 
Join Date: Feb 2001
Location: Sunny California
Posts: 4,882
Quote:
Originally Posted by bm bradley View Post
man you are a life saver!! now is there another way to use flash without adobe?
Not that I've heard of. You can use an extension in Firefox called "No Script" that will block all flash until you whitelist it. It also protects against clickjacking (and is the only thing so far that does).
__________________
NICHE MONEY >> Ass WorshipPantiesSolo TeenPantyhose
Serving up exclusive fetish sites since 1997!
Tat2Jr is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-31-2009, 08:07 AM   #16
Brad Mitchell
Confirmed User
 
Brad Mitchell's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: Southfield, MI
Posts: 9,812
Bump for the uninformed..

Brad
__________________
President at MojoHost | brad at mojohost dot com | Skype MojoHostBrad
71 industry awards for hosting and professional excellence since 1999
Brad Mitchell is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-31-2009, 09:24 AM   #17
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Hmm this explain why some trojan site loads pdf when opening.So that means i would be infected if i didnt used foxit.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-31-2009, 09:54 AM   #18
AmeliaG
Too lazy to set a custom title
 
AmeliaG's Avatar
 
Join Date: Jan 2003
Location: Los Angeles
Posts: 10,568
Wow, that is creepy.
__________________
GFY Hall of Famer

AltStar Hall of Famer




Blue Blood's SpookyCash.com

Babe photography portfolio
AmeliaG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-31-2009, 11:45 AM   #19
budz
Disruptive Innovator
 
budz's Avatar
 
Industry Role:
Join Date: Sep 2003
Location: Vegas
Posts: 4,230
<3 noscript

noscript.net
__________________
C:\Code\
C:\Code\Run\
budz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-31-2009, 11:52 AM   #20
digifan
The Profiler
 
digifan's Avatar
 
Industry Role:
Join Date: Oct 2002
Location: ICQ 76281726 and I'm female
Posts: 14,618
Quote:
Originally Posted by Brad Mitchell View Post
Bump for the uninformed..

Brad
Thanks Brad! I have stopped using Adobe Reader long ago btw, I do not need it at all.

Another bizump.
__________________
[email protected]
Webair Rocks
digifan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.