 mysec Premium join:2005-11-29
2 edits | reply to Stem Bolt Re: Torrentreactor breach serves potent exploit
Note that this exploit is following the trend of packaging both browser and plugin exploits, hoping to catch something unpatched.
The browser exploit is for IE6 (MDAC, MS06-014) and Microsoft Office Snapshot Viewer which works on IE6 and I think IE7.
Both of these have been long since patched.
The plugin exploits are for Adobe Acrobat Reader and Adobe Shockwave, and of course, will work in any browser.
These require a vulnerable verision of the application and plugins enabled.
Pretty typical stuff these days.
Hopefully everyone is aware of how to protect against this, but I still mention it to people just to be sure.
---- rich |