Home News Latest Security News Q&A: Sandbox for Adobe Reader

Q&A: Sandbox for Adobe Reader

Didier Stevens is an IT security consultant well-known for his research into malicious PDF files. Since Adobe announced a sandbox for Adobe Reader, it was a perfect opportunity to hear his opinion on the subject. What are the pros and cons of Adobe's sandboxing approach? I believe it is good enough to block most malicious PDF files found in the wild for the moment. I've my doubts about some lesser-known PoCs, but that needs to be tested once Adobe releases its software. A major con is that...


for the moment, it's a write-sandbox. Only "write" operation are sandboxed, to prevent system alteration by malware. However, unrestricted reading is allowed in this first phase. Therefore it is possible to write info-stealing shellcode and let that happily run in the sandbox and exfiltrate all your secrets.


Is this the "magic bullet" that's going to solve most Adobe Reader security woes?

No, and Adobe acknowledges this. Phishing attacks is one example they gave that won't be mitigated by the sandbox.

Is it possible for the Protected Mode to introduce new issues for end users?

It could. The Broker Process has to be very reliable. If I can mislead the Broker Process, it will give we access.

Think of the bug in the blacklisting function for the /Launch action. Extension .EXE is blacklisted, but using extension .EXE" allows me to bypass this process. If there are similar bugs in the Broker Process, researchers will soon find them. Also, the Broker Process also has to fail gracefully. If it goes down (for example due to an attack), the mechanism has to fail closed: deny all access.


Read Full Article

GSO
Written on Wednesday, 21 July 2010 22:00 by GSO

Viewed 72 times so far.
Like this? Tweet it to your followers!

Latest articles from GSO

Latest 'tweets' from GovernmentSecurity


 

Information Security Resources

Latest Articles

Security Log Management Tips

News image

The security log for Windows is full of great information, but unless you know how to control, manage, and analyze the information, it is going to take you much longer ...

GSO | Thursday, 26 August 2010 | Hits: 107

Read more

GFI LANguard - Voted WindowSecurity.com

Winner in the Patch Management Category of Readers’ Choice Awards: GFI LANguard August 25, 2010 - GFI LANguard was selected the winner in the Patch Management category of the WindowSecurity.com Readers’ Choice Awards. Ecora Patch Manager and ...

GSO | Wednesday, 25 August 2010 | Hits: 84

Read more

Product Review: ObserveIT

News image

Product: ObserveIT Remote Access Auditor Product Homepage:click here When dealing with a security issue or compliance audit, your server logs are often the most important asset you have ...

GSO | Wednesday, 18 August 2010 | Hits: 147

Read more

Latest News

Labor Day phishing warning

News image

Due to the upcoming Labor Day holiday, consumers are at high risk for targeted phishing attacks due to the preponderance of online retail sales events over the holiday weekend. Amidst ...

GSO | Friday, 3 September 2010 | Hits: 1

Read more

User's opinions on malware infectio

News image

A recently concluded online survey organized by SC Magazine and Symantec has resulted is some curious and some expected results. When asked to give their opinion on which is the ...

GSO | Thursday, 2 September 2010 | Hits: 11

Read more

Google Code hosting malware-spreading pr

News image

Google Code's project hosting feature has occasionally been used by malicious individuals for storing and spreading malware. Zscaler pointed out yesterday that even though Google claims that any project ...

GSO | Thursday, 2 September 2010 | Hits: 16

Read more

Latest Blogs

Welcome

Welcome to GovernmentSecurity.org Network security articles and hacking prevention resources for the government and general public. Covering all aspects of Computer Hacking, including tutorials and exploit do...

Stephen | Friday, 30 April 2010 | Hits: 1185

Read more

Main Site Alternate Colors

As many of you have noticed we recently launched a new design after receiving many complaints about ...

Stephen | Tuesday, 19 January 2010 | Hits: 1460

Read more

We have launched the new GovernmentSecur

News image

We decided to launch the new site, though we have not completed all the planned fe...

GSO | Saturday, 10 October 2009 | Hits: 3553

Read more

Syndicate





Member Login



Other Links

Latest Exploits