Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Foxit Reader update stops PDF attack

Adobe rival adds 'safe mode' to stymie embedded-malware attacks

Article comments

Foxit Software, the developer of a rival PDF viewer to Adobe's vulnerability-plagued Reader, released an update today that blocks some attacks with a "safe mode" that's switched on by default.

Foxit Reader 3.3 for Windows includes what Foxit dubbed "Trust Manager," which blocks all external commands that may be tucked into a PDF document. The new version is designed to stymie some common attack vectors that hackers use when they probe PCs for bugs in the PDF format, or in a viewer application.

"The Foxit Reader 3.3 enables users to allow or deny unauthorized actions and data transmission, including URL connection, attachment PDF actions, and JavaScript functions," the update's accompanying text explains.

Last week, several security companies warned of a major malware campaign that tried to dupe users into opening rigged PDFs that exploited an unpatched design flaw in the PDF format, one attackers could use to infect users of Adobe's and Foxit's software.

That flaw in the PDF specification's "/Launch" function was disclosed in late March by Belgium security researcher Didier Stevens, who demonstrated how he could abuse the feature to run malware embedded in a PDF document. He also reported he had figured out how to change Adobe Reader's warning to enhance the scam.

The attacks last week that exploited the /Launch flaw peaked on Friday, April 28, and have since dropped to nearly nothing, researchers at IBM Internet Security Systems' X-Force team said yesterday.

Foxit is alone in addressing the /Launch problem: Adobe has declined to answer questions on whether in-the-wild use of the function would prompt the company to update Reader and Acrobat. However, Brad Arkin, Adobe's head of security and privacy, has acknowledged that one possible solution would be to disable /Launch; currently, it's turned on by default.

PDF-based attacks are a major problem. According to recent tallies by antivirus vendor McAfee, PDF exploits were up more than eight-fold in 2009 compared to the year before, a trend that has continued thus far into 2010. Microsoft and Symantec have also noted a surge in exploits tucked into PDF documents.

Foxit 3.3's Trust Manager is switched on by default, said Eugene Xiong, the president of Foxit Software. But contrary to the text that accompanies the update, it does not disable all JavaScript, the scripting language that hackers have frequently used to exploit Adobe Reader vulnerabilities. "It doesn't disable JavaScript entirely," Xiong said. "It only partially disables JavaScript."

Among the JavaScript functions that Trust Manager strips away is one that lets a PDF execute another, non-PDF file, Xiong added.

Foxit 3.3 can be downloaded free-of-charge from the company's website.



Share:

More from Techworld

More relevant IT news

Comments



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *