MaldivianDigital® :: Forum

Go Back   MaldivianDigital® :: Forum > Site Related > Announcements & News

Announcements & News For announcements of what's happening with the Maldiviandigital.com forum and important news.

 
 
LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 30-05-2008, 08:20 PM
ahmedvisham's Avatar
AhmedVisham®
 
Join Date: May 2007
Location: where do you want me to live????
Posts: 2,136
Thanks: 2,158
Thanked 2,474 Times in 805 Posts
Rep Power: 145
ahmedvisham has a reputation beyond repute ahmedvisham has a reputation beyond repute ahmedvisham has a reputation beyond repute ahmedvisham has a reputation beyond repute ahmedvisham has a reputation beyond repute ahmedvisham has a reputation beyond repute ahmedvisham has a reputation beyond repute ahmedvisham has a reputation beyond repute ahmedvisham has a reputation beyond repute ahmedvisham has a reputation beyond repute ahmedvisham has a reputation beyond repute
new_ Symantec backtracks on Flash hack warning

After warning earlier this week that hackers were exploiting an unpatched bug in Adobe's Flash Player software, Symantec has backtracked, saying the flaw is "very similar" to another vulnerability patched last month.

Symantec's initial warning described a disturbing threat - a previously unknown and unpatched flaw that was being exploited on tens of thousands of web pages. The flaw allowed attackers to install unauthorised software on a victim's machine and was being used to install botnet programs and password-logging software, Symantec said.

Now Symantec believes that the bug was previously known and patched by Adobe on 8 April, said Ben Greenbaum, a senior research manager with Symantec Security Response. However, the Linux version of Adobe's standalone Flash Player, version 9.0.124, is vulnerable to the attack.

On Tuesday Symantec researchers said that the attack worked on Linux and that it caused Flash Player to crash on Windows XP, so they reasoned that they had a new bug that was just not working properly on the Windows platform, possibly due to a programming error by the hackers. "We thought it was a problem with the exploit," he said.

Now Symantec believes that the vulnerability was simply not properly patched in this one version of Adobe's software, Greenbaum said.

That means that Windows and Mac OS X users with the latest updates are not vulnerable, and even Linux users who are running the latest Flash Player plugin inside their browser, rather than as standalone software, are safe. However, Windows XP users running the older Flash Player, version 9.0.115, are vulnerable to the attack, Greenbaum said.

This kind of missed security assessment is rare, but it does happen from time to time, said Matt Richard, director of VeriSign's iDefense Rapid Response Team.

"It looks like they just jumped the gun and put it out a little bit too early without doing all the homework," he said of Symantec. "When we did our testing in the lab, the latest version completely fixes the issue: No crashes, no exploits, no nothing."'

IBM's Internet Security Systems (ISS), which is credited with discovering the Flash Player bug, echoed Richard's analysis. "Several reports have stated that a zero-day Flash vulnerability is being exploited through several Chinese hacker websites," ISS wrote in its advisory on the flaw. "All of the samples X-Force has seen target the vulnerability disclosed in this Advisory."

In a note on its website, Symantec said that it was working with Adobe to figure things out.

An Adobe spokesman said Wednesday that his company was "still trying to get to the bottom of this," but expected to have an update by around noon Pacific time on Wednesday.
__________________



Reply With Quote
The Following 2 Users Say Thank You to ahmedvisham For This Useful Post:
AngelEye (04-06-2008), mvdig (30-05-2008)
To Advertise Us
 

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump