11/12/2008
Security reserachers have a contact problem with ADOBE
PDF attacks are the future for the moment because people trust PDF's so much there are even enterprises where they aren't scanned by the antivirus because it made too many false positives and you know 'work has to go faster' and 'what could be wrong with a PDF?" (not with the PDF with the javascript behind it)
So take you have a POC for a new attack scheme (some are already coming to light in my sick mind) or for a new vulerability (I doubt they have a penetration and attack test running against their software) where do I go with it to Adobe.
There is no security team or security blog to speak off, so this is to no avail.
or could it be this
software review ? http://sjw2.adobe.com/AdobeUserGroup/review.asp although it seems to be more for publishers
It is not in the partner section https://www.adobe.com/cfusion/partnerportal/index.cfm although you could say that you provide a solution :)
There are community experts, although it seems to be more tuned to product specific solutions. http://www.adobe.com/communities/experts/faq.html
There are a lot of forums also http://www.adobe.com/support/forums/ so lets look at the one for Acrobat reader http://www.adobeforums.com/webx/.ee6b2e6/ there are some postings about security but nothing that goes deep enough to say that it is security focused or helping in that way.
Adobe should understand that with the javascript functions behind the PDF of SWF files there is a whole lot of new possibilities that are popping up. So many that I don't know where to start. Because javascript is god for the developer who likes to do many big things with only a few lines of code. There is hardly something more powerful with so few lines of code (and cross platform).
Maybe they need a doomlike virus before they understand that they have to act ?
Meanwhile KILL JAVASCRIPT in your PDF files. (see below how to do it)
By the way does anyone know of a free software with which you can control and manage the updates and configuration of your pdf readers on a network ? Good ideas will be republished. THis is an urgent necessity.
09:16 | Permalink | Comments (3) | Email this
|
|
del.icio.us
|
|
Digg |
Facebook




Comments
correctie http://www.adobe.com/support/security/alertus.html
They do have a contact form on their website and it's available through the Send Feedback link on their main page.
Secunia PSI is a good tool to do what you're looking for and it also has a corporate (not free) version, that provides centralized management.
Posted by: Wim Remes | 11/12/2008
Respond to this commentIf this were my problem to solve.... I'd put a comment in a post on the Adobe PSIRT blog. http://blogs.adobe.com/psirt/
Posted by: David Kennedy | 11/14/2008
Respond to this commentIf this were my problem to solve.... I'd post a comment on the Adobe PSIRT blog: http://blogs.adobe.com/psirt/
Posted by: David Kennedy | 11/14/2008
Respond to this commentPost a comment