Adobe reader vulnerability demo [Anatomy of an Attack online]
Sign in to YouTube
Sign in with your Google Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to like SophosLabs's video.
Sign in to YouTube
Sign in with your Google Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to dislike SophosLabs's video.
Sign in to YouTube
Sign in with your Google Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to add SophosLabs's video to your playlist.
Published on Jun 19, 2012
Here's a demo on how a vulnerability in Adobe Reader allowed random content to be downloaded from the internet.
Find a live Anatomy of an Attack event near you: http://bit.ly/LxLwm4
-
Category
-
License
Standard YouTube License
Loading...
Loading...
Loading...
The interactive transcript could not be loaded.
Loading...
Loading...
Ratings have been disabled for this video.
Rating is available when the video has been rented.
This feature is not available right now. Please try again later.
Loading...
-
1:04:37
Stuxnet decoder Ralph Langner speaks about Stuxnetby Dawidh2011Featured
17,369
-
4:18
iFrame drive-by attack demo [Anatomy of Attack online]by SophosLabs
22,099 views
-
4:00
Stuxnet/Windows shortcut zero-day explained [Anatomy of an Attack online]by SophosLabs
19,011 views
-
4:59
Fake Anti-Virus live demo [Anatomy of an Attack online]by SophosLabs
7,700 views
-
2:38
Server-side polymorphism demo [Anatomy of an Attack online]by SophosLabs
3,342 views
-
4:37
Adobe Reader X/XI zero-day flaw found by Group-IBby GroupIB
29,674 views
-
18:54
Step-byStep SQL Injection Attack (HQ)by Lemuel Botha
96,942 views
-
4:37
The latest breed of hackers/cybercriminals [Anatomy of an Attack online]by SophosLabs
4,338 views
-
6:21
Adobe Reader Xby ARGYLEtech
15,047 views
-
6:00
How blackhat SEO and Fake Anti-Virus work - Sophos demoby SophosLabs
26,502 views
-
10:05
Ethical Hacking - Client-side attack - InfoSec Instituteby InfoSecInstitute
4,147 views
-
3:51
How to choose a strong password - simple tips for better securityby SophosLabs
140,053 views
-
7:28
iFrame Injection - Malicious Code Executionby Chintan Gurjar
1,762 views
-
3:17
How to perform a DOS-DDOS attackby Martino Jones
15,961 views
-
9:28
The Moral of the Hackby SophosLabs
2,269 views
-
7:19
WordPress Hacked - Mass IFrame Injection Attack 2by Allen Underwood
2,428 views
-
5:35
How to Create a Digital Signature in Adobe Acrobat Readerby communitytutorials
30,882 views
-
3:19
Facebook worm: Teacher nearly killed this boy attack spreads virallyby SophosLabs
93,811 views
-
3:04
The Blackhole Exploit Kitby SophosLabs
5,707 views
-
4:12
Exploit sur site WEB : vulnérabilité JAVA et Adobe Readerby MaK MaK
20,002 views
- Loading more suggestions...
All Comments (8)
MrPhilippos96 10 months ago
@S3b1Videos It didn't warn the user because the malware is digitally signed(certificated).
@SamKeupoN Yes,the buffer overflow itself is caused by a strcat API call on a
"custom"-size stack variable
Sign in to YouTube
Sign in to YouTube
SamKeupoN 11 months ago
My guess is that it uses a buffer overflow allowing code injection. The download is actually done by the injected code.
Sign in to YouTube
Sign in to YouTube
TheHouseOfWaffles 11 months ago
Why would Adobe Reader download another file when it crashes, and how would it know to where to get it? If a PDF file is corrupt or not an actual PDF at all, shouldn't Adobe Reader simply say, "This is not a PDF file, so I can't open it," then do nothing else? As far as I know, Adobe Reader isn't one those applications which take a plain-text-based malicious script file masquerading as something else like a JPEG, determine it's a script file and not the supposed file type, then runs the script.
Sign in to YouTube
Sign in to YouTube
notta3d 11 months ago
Damn Leadbetter!
Sign in to YouTube
Sign in to YouTube
S3b1Videos 11 months ago
But how did the exploit creator calculate the return adress if ASLR is enabled? Why Windows didn't warn the user of an stack execution or an overwritten variable?
Sign in to YouTube
Sign in to YouTube
mp3talon 1 year ago
i think he is canadian
Sign in to YouTube
Sign in to YouTube
pilebaina 1 year ago
Ok we have an American here...
Sign in to YouTube
Sign in to YouTube