Xkcd Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 20 April 2010

Adobe Reader and Internet Explorer: Most Attacked

Posted on 17:05 by Unknown
One key to protecting your computer (and the data on which you depend) is to limit the attack surface. The fewer avenues for compromise you have, the better chance you stand of being passed over for a more inviting target.

If you're seeking the opposite approach - to become a flaming honeypot of vulnerability - run Microsoft's Internet Explorer and Adobe Reader. 

InSecurity Complex notes:
A hole in Microsoft's Windows SMB2 (Server Message Block) protocol was the most attacked vulnerability last year, followed by holes in Adobe Reader and Flash Player, Internet Explorer 7, and Windows MPEG2 ActiveX Control, according to a Symantec report to be released on Tuesday.
I stopped running both products ages ago, mostly due to the number of zero-day exploits that ran rampant in the wild targeting these two software gems. It's bad enough when you need to scramble to deploy patches before the bad guys reverse-engineer them to create and launch exploit code. It's a whole other nightmare when the attacks begin before the public, and often the software maker, are aware of the vulnerabilities.
Of Web-based attacks, suspicious PDF file downloads was the top method, representing nearly half of such attacks, followed by six attacks on IE, one targeting Adobe SWF (Shockwave Flash), and two targeting MPEG2 ActiveX Controls, the Symantec Global Internet Security Threat Report found.

Nearly half! And I can remember when people moved from Word documents to PDF files because they were seen as more secure. In fact, many companies explicitly blocked Word docs at the gateways but allowed PDF files to drive right inside.

Now, that's not to say that there aren't other products with more announced vulnerabilities than these two, because there are. But the perfect storm might be the combination of frequent flaws, plodding response by the software makers, and product saturation. IE and Reader are heavily used by home and enterprise users, and historically both user types have been slow as molasses to patch and/or upgrade their vulnerable Adobe installs, to the point where Adobe recently announced plans to automatically apply updates in the background without user notification or interaction.

If you don't want your car stolen, do some research into which are the most stolen vehicles and then don't buy one of those. If you want to keep your computer and data safe, look at the most frequently attacked programs and then don't install them. Pick something else that gives you a fighting chance.


Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in exploit, vulnerability | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • SMBC - Ass Acne
    Saturday Morning Breakfast Cereal
  • The Shame
    Oh, McRib. You are one saucy bitch.
  • Sharron Angle - All Fringe, All The Time
    The highlight of Harry Reid's political career must be that joyous moment when Sharron Angle won the Republican primary and become Reid...
  • Mad World
  • Maslow's Hierarchy of Robot Needs
    Via lunchbreath's photostream on flickr
  • Rain, rain, go away...
    Ugh. More rain. It's been so wet the last few weeks that I'm suffering from a bad case of trench-house. Back to you, Chet.
  • (no title)
    Hi. You may not remember me, but I am Kevin's son. As you may know, we have been coping with the loss of my mom, and it is very difficul...
  • Steve Jobs
    There's been a lot of talk since Jobs died about his passion for thinking differently, and how the "crazy ones" are actually t...
  • Goodnight iPad
  • Adobe Flash Player Update Fixes 32 Security Flaws
    It should tell you something that Adobe's latest Flash Player update, released in response to ongoing exploits of a particular vulnerabi...

Categories

  • activism
  • Adobe
  • advertising
  • Afghanistan
  • aging
  • airlines
  • Apple
  • Arizona
  • art
  • banking
  • Barack Obama
  • Barbie
  • blog
  • Bobblespeak Translation
  • business
  • charity
  • childhood
  • CNN
  • Colbert
  • Columbus
  • comic
  • commentary
  • compassion
  • computers
  • conservatives
  • crime
  • cyber security
  • DADT
  • data protection
  • David Letterman
  • death
  • democracy
  • dogs
  • Ebert
  • economy
  • education
  • EFF
  • energy
  • England
  • environment
  • evolution
  • exploit
  • Facebook
  • faith
  • feminism
  • finance
  • flowchart
  • food
  • football
  • Fox
  • fraud
  • gadget
  • gadgets
  • Gawker
  • gay
  • geek
  • Glenn Beck
  • Google
  • government
  • GraphJam
  • guns
  • hacking
  • history
  • holiday
  • humor
  • information security
  • iPhone
  • Japanese
  • Java
  • John Hodgman
  • Jon Stewart
  • journalism
  • law enforcement
  • legal
  • life
  • lunchbreath
  • mainstream media
  • malware
  • McCain
  • McDonald's
  • media
  • medicine
  • merchandise
  • Metasploit
  • Microsoft
  • military
  • movie
  • movies
  • MSNBC
  • Muppets
  • music
  • nature
  • New Orleans
  • news
  • newspapers
  • NFL
  • NY Times
  • Obama
  • odd
  • Oddly Specific
  • Ohio
  • Olbermann
  • parenting
  • Paul Krugman
  • pets
  • philosophy
  • photo
  • piracy
  • poetry
  • politics
  • prank
  • privacy
  • protest
  • psychology
  • Rachel Maddow
  • racism
  • radio
  • religion
  • Republicans
  • right-wing
  • robots
  • Sarah Palin
  • sarcasm
  • satire
  • Saturday Morning Breakfast Cereal
  • science
  • security
  • Seinfeld
  • sexism
  • sexy
  • SMBC
  • social networking
  • socialism
  • sports
  • Star Trek
  • Star Wars
  • Steelers
  • Stephen Colbert
  • Taibbi
  • taxes
  • tea bagging
  • technology
  • television
  • terrorism
  • The Daily Show
  • the internet
  • The Onion
  • threats
  • toys
  • veteran
  • video
  • video game
  • vulnerability
  • Wal Mart
  • xkcd.com

Blog Archive

  • ►  2013 (1)
    • ►  March (1)
  • ►  2011 (23)
    • ►  November (1)
    • ►  October (4)
    • ►  September (5)
    • ►  April (4)
    • ►  March (5)
    • ►  February (3)
    • ►  January (1)
  • ▼  2010 (476)
    • ►  December (8)
    • ►  November (7)
    • ►  October (24)
    • ►  September (10)
    • ►  August (28)
    • ►  July (44)
    • ►  June (83)
    • ►  May (147)
    • ▼  April (125)
      • John Hiatt - Feels Like Rain
      • Michael Moore on Immigration and Goldman Sachs
      • Porn Stars Decry Piracy
      • Give Mom The Gift of Masturbation for Mother's Day
      • Don't Boycott AriZona Iced Tea!
      • Religious Reminder for Immigration Zealots
      • Hayseed Dixie - 'Walk This Way'
      • The Fart-Catching Blanket
      • Offshore Drilling - A Political Lesson
      • The Art of Eating Sunflower Seeds
      • Beware of Fake Anti-Virus Software
      • Spock Does The Shocker
      • Arizona According to the Daily Show
      • Bluegrass Cover - 'American Idiot'
      • Republicans Fold on Financial Reform Filibuster
      • Steve Stivers Sign Seen From Space
      • Lego Rage
      • Shitty Deal - The Highlight Reel
      • How I Met Your Motherboard
      • Bob Evans Gravy Machine
      • HDTV
      • Cornbread Red Covers Green Day's 'Boulevard of Bro...
      • Hysterical Costco Prank
      • KFC Double Down Chart - How Many DDs in Your Lunch...
      • Man Hides From Cops in Vat of Poo
      • 'The Simpsons' Supports South Park
      • Teacher Fail
      • Old Jews Telling Jokes - Fruit Store
      • Dumbpiphany
      • Honeywagon Covers Rolling Stones 'Wild Horses'
      • Stomach Cake
      • Boycott Arizona
      • Stephen Colbert on Arizona's Immigration Law
      • Save Stephen Baldwin
      • If Tea Baggers Were Black
      • Pat Boone - 'Paradise City'
      • Walmart Robble Robble
      • Somail Pirates Are Subsidiary of Goldman Sachs
      • Who Needs Border Patrol When The Shoes Are The Clues?
      • 100 Year Old Virginia Gets An iPad
      • More Cowbell
      • ABC and Fox Hate Fat Chicks
      • Blippers Sharing Bites Them In The Butt
      • Hayseed Dixie - Ace of Spades
      • Lou Dobbs Chic
      • This is Spinal Tape
      • Solutions to Problems That Aren't Really Problems
      • Opt Out of Facebook's 'Instant Personalization'
      • Perspective
      • Economists and Bible Talk
      • "Bitches Ain't Shit" Ben Folds Covers Dr Dre
      • You Stay Classy, Ohio Republicans!
      • Video - Drugs and Flip Flops Don't Mix
      • Venn Diagram - Prime Time TV in 2010
      • What's With All The Anal Sex Studies?
      • Arizona - Home of the Looneys
      • Yee Haw - Encounters with Random Southerners
      • Drill, Baby, Drill, Y'all
      • Jonathan Coulton - Baby Got Back
      • It's My Tea Party, and I'll Cry If I Want To
      • Jon Stewart and Bernie Goldberg Dance
      • Shut Up, Gun Lovers
      • David Lee Roth - Bluegrass Version of 'Jump'
      • Steakhouse XT™ Burger Did Me Wrong
      • The DudeGyver
      • Adobe Reader and Internet Explorer: Most Attacked
      • Creepy Robot Mouth Goes Nom Nom Nom
      • A Real Man for Congress
      • Sarah Palin - Leading the American Taliban
      • Adam Savage's Speech to the Harvard Humanist Society
      • Colbert - Sunday Morning Fact-Checking
      • Politics and Poker - Wingers Go 'All In' With Righ...
      • If Ancient People Had Modern Science
      • Rachel Maddow's Rules for Living
      • John Hodgman Solves The Pedophile Priest Problem
      • Rachel Maddow Calls 'Neener Neener" on David Koch
      • Password Story Confusion
      • Toothache Guy
      • Mike Rowe Reads Tiger Woods Sexy Text Messages
      • Green Eggs and Hamlet
      • Mike Huckabee Dances As Fast As He Can
      • "We've Got Company!"
      • Crazy Dog Man
      • Man Rides Exploding Airbag
      • Victoria Jackson Sings to Tea Party Faithful
      • Graph: Teabagger Concerns
      • Old School Handset for iPad
      • Jesus Plays Chinese Whispers
      • MSNBC Uses Puppets to Explain Financial Crisis
      • Johnny Cash - Rusty Cage
      • Jizz - The Nail Polish To Match Your Necklace
      • Republicans and Leukemia Team Up to Repeal HCR
      • Hate Government and Taxes?
      • Olive Garden Cheese Constipation
      • The IRS - Modern Day Robin Hood or Jackbooted Thug?
      • Against All Enemies, Foreign and Domestic
      • Laptops - We Need More Laptops
      • Worked Like A Dog Today
      • Jon Voight is Crazy as a Shithouse Rat
      • Microsoft Security Bulletin for April 2010
Powered by Blogger.

About Me

Unknown
View my complete profile