iThome online | iThome Blog | iThome周刊訂閱

載入中...

richardsuma

IT邦初學者
3級

Flash爆零時差攻擊, Symantec已澄清那不是"零時差攻擊

"Symantec: Sorry, Flash Player attack not a zero day"
http://www.zdnet.com.au/news/security/soa/Symantec-Sorry-Flash-Player-attack-not-a-zero-day/0,130061744,339289430,00.htm

收藏到:發佈到twitter       
分享時間:2008-06-13 10:09:06
更新1次,最後更新:2008-06-13 11:54:59
分享內容(
14

Symantec: Sorry, Flash Player attack not a zero day
Liam Tung, ZDNet.com.au

29 May 2008 03:14 PM

Tags: adobe, flash, flaw, nishad herath, security, symantec, zero day, ibm

After suspecting a zero day exploit was being used to attack the latest version of Flash Player (9.0.124.0), Symantec says the call was a mistake — it was an exploit for versions 9.0.115.0 and prior.

Yesterday it was feared that hackers were using a malicious ShockWave Flash file which Symantec researchers thought was a zero day exploit for the latest version of Flash Player.

Symantec, however, shied away from confirming that it was a zero day exploit, as it appears to be designed for a flaw which Adobe patched in April, prior to it being publicly disclosed by an IBM security researcher.

"Originally this issue was believed to be unpatched and unknown, but further technical analysis has revealed that it is the previously reported Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability (BID 28695), discovered by Mark Dowd of IBM," Symantec reported on its ThreatCon page today.

Adobe has also confirmed the exploit is not new. "This exploit does NOT appear to include a new, unpatched vulnerability as has been reported elsewhere — customers with Flash Player 9.0.124.0 should not be vulnerable to this exploit," it states on its Product Security Incident Response Team site.

The CEO of security consultancy Novologica, Nishad Herath, who yesterday acquired a sample of the exploit, told ZDNet.com.au today that the error appears to have been caused by a reference in the malicious SWF file to the new version of Flash Player.

"Actually [the code] does have references to the latest version of Flash, but it is not exploiting a new zero day — it is exploiting the old patched vulnerability," he said.

"It means Adobe patched the flaw properly, but Symantec has made a mistake... The exploit writer had made a reference to a SWF file with the name 9.0.124.0.swf, so it may just be that they were planning to add something to that exploit that may work on the new version in the future, should a zero day vulnerability be released… They might have been attempting to make this code base future-proof, but it's of no real relevance [to the exploit]," said Herath.

Adobe recommends updating Flash Player to the latest version since older versions are vulnerable to the exploit which Symantec discovered yesterday.

Flash爆零時差攻擊, Symantec已澄清那不是"零時差攻擊
xzjiang( IT邦初學者7級 )
2008-06-13 11:30:58
「Symantec: Sorry, Flash Player attack not a zero day」
正確文章網址如下:
Symantec: Sorry, Flash Player attack not a zero day

[-隱藏]

回應 xzjiang

richardsuma 說:

謝謝指正!

2008-06-13 11:35:03

jerry640( IT邦初學者1級 )
2008-06-13 16:13:24
用道歉的方式聲明,也讓原本adobe的漏洞因小口水戰轉移了焦點~
jjw( IT邦初學者1級 )
2008-06-19 23:55:55
謝謝分享
iT邦守護神
davistai( IT邦好手1級 )
2008-06-20 11:32:06
可學一下怎麼用英文寫類似的聲明稿^^

回應

請填寫您的回應,長度限為1,000個字,回應不計點數,也不限使用次數



 

檢舉違規

違規事項:

*補充檢舉理由(可省略),字數不可超過100字

推薦

推薦理由:


*給回答者的鼓勵(可不填),字數不可超過100字

熱門標籤

 ad   aspireone   eee   epson   excel   firefox   freenas   google   hp   it   linux   microsoft   moss   msnlib   msnsdk   msn機器人   office   outlook   powerpoint   pro   server   solaris   sql   sun   ubuntu   usb   ux   vista   windows   xp   伺服器控制項   備份   免費軟體   好康妹   學習   工作   微軟   投影機   文書處理   有話大聲說   活動   綠色聰明採購大公開   職場   資訊安全   輸入法   鐵人賽   鐵殼心文化搖籃   防毒軟體   防火牆   2003 

free counters