Thursday, May 14, 2009

Foxit Reader Goes from Bad to Worse

Several months ago, I reported that people looking to Foxit Reader as a substitute to Adobe Reader had discovered the Ask Toolbar included as a pre-checked, opt-out option.

As illustrated by Paperghost in Why I Flushed Foxit, it appears that by the time the option is presented to accept or decline the Ask toolbar, it has already been installed!

If you are looking for an alternative to Adobe Reader, I suggest one of the open source programs available from http://pdfreaders.org/. In the event you are still using Adobe Reader, be sure to get the latest update.




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Google currently falls short

In a carefully documented report, Ben Edelman, a well known and respected security expert, reveals how Google and its partners
  • intercede to divert traffic that would have reached advertisers' sites directly -- without advertisers incurring any advertising expense.
  • pass the traffic back to the advertisers users were trying to reach -- but only after collecting pay-per-click advertising fees.
Also demonstrated is what appears to be conveniently overlooking Google's "Software Principles" requirements for their WhenU and IAC partners.

See how
  • WhenU Covers Advertisers' Sites with Advertisers' Own Google Ads
  • IAC's SmileyCentral Grab Advertisers' Organic Traffic to Show Google Ads
  • Typosquatting: Cmcast.com, MediaLogik, and Thousands More Intercept Users' Misspellings to Show Google Ads
  • Google Chrome Suggestions Divert Users from Direct Navigation to Search
in How Google and Its Partners Inflate Measured Conversion Rates and Inflate Advertisers' Costs.




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, May 12, 2009

Critical Update: Adobe Reader and Acrobat

Adobe has released an update to the critical vulnerability in both Adobe Reader 9.1 and Acrobat 9.1 as well as earlier versions. The vulnerability, described below as CVE-2009-1492, would cause the application to crash and could potentially allow an attacker to take control of the affected system.

A second vulnerability, identified as CVE-2009-1493, which affects Adobe Reader for UNIX is also addressed.

It is strongly recommended that the appropriate update be installed as soon as possible!

Adobe Reader Updates:

Windows: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows.

Macintosh: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Macintosh.

UNIX: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Unix.

Acrobat Updates:

Windows:

Macintosh:


CVE-2009-1492:
The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.
CVE-2009-1493:
The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 8.1.4 and 9.1 on Linux allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.
Reference: APSB09-06 Security Updates available for Adobe Reader and Acrobat




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...