Proactive IT security

Security center

Latest articles - Exploit analysis

Reflections on the PDF vulnerability

2010-04-22

Earlier this month we wrote about a vulnerability in the PDF specification that could be utilized to run malicious programs embedded in a PDF file. Proof-of-concept code was published, and it was expected that real-life malware that used this technique might appear soon.

more >>

Scary technique utilizing functionality in the PDF specification

2010-04-07

Exploitation of how applications handle files in the Portable Document Format (PDF) is one of the most used techniques to successfully create malicious software. Usually this is accomplished by utilizing vulnerabilities in the applications used to read PDF documents, like the very popular free program, Adobe Reader.

more >>

Aurora Attack - Zero day exploit in IE6

2010-02-04

Aurora attacks, which is known to be originated from china, is a major attack in the recent past which used an Internet explorer exploit code to attack companies like Google and Adobe and succeeded in stealing some intellectual properties.

more >>

Use-after-free vulnerability in Adobe

2010-02-02

Recently a new vulnerability has been discovered in Adobe Reader and Acrobat 9.2 and earlier versions (CVE-2009-4324). The vulnerability resides in Doc.media.newPlayer method. It’s a use-after-free vulnerability which can allow an attacker to execute arbitrary code.

more >>

Latest blog entries

Real world vs. Theory: 1 - 0

2010-09-03
In theory this should have been impossible: Cracking an encryption key, which is based on quantum cryptography. The rationale is that one cannot interfere with a quantum system without disturbing it i...
more >>

Who is connected to whom?

2010-08-30
I am currently working on a few presentations that I will give in the upcoming weeks. One of them will touch correlating data and actually is giving some interesting information. Using some older data...
more >>

DLL HiJacking… And now what?!?

2010-08-26
Lots have been written already about it, so I will keep it short on what it exactly involves. Basically, whenever an application wants to load a DLL, it can do that absolute (using a full pathname as...
more >>