Saturday, February 21, 2009

Mitigating the Adobe zero day

Reports of the Adobe Acrobat zero day exploit should not be shrugged off.

However, mitigating this exploit may be a bit bewildering due to lack of information.

Our friend John LaCour has posted a quick fix. However, this involves disabling Javascript in Acrobat, which for some enterprises is unacceptable.
Not a good situation. If you can�t disable Javascript in PDFs, then your next best answer relying on your endpoint solution and begging your users to be careful with PDFs from unknown parties.

Prayer is also a good thing to throw into the mix. Can�t hurt.

Alex Eckelberry

PS: I should mention that you can always get a snort rule for it.

No comments:

Post a Comment