Is this feature included?

Bug reports and enhancement requests
Post Reply
luntrus
Senior Member
Posts: 237
Joined: Sat Mar 21, 2009 6:29 pm

Is this feature included?

Post by luntrus »

Hi forum friends,
The zero-day hole in Adobe Reader and Acrobat will not earlier be patched as the next patch round within three weeks' time (that is in the coming new year) and hackers now already abuse it actively to infect systems.
An out-of-band patch for this critical hole would have a negative impact, according to Adobe's Brad Arkin....

You can be protected here, for Adobe recommends customers follow the mitigation guidance below, utilizing the Adobe Reader and Acrobat JavaScript Blacklist Framework, until a patch is available.

Windows: For end-users on Windows, download the compressed file from here: http://download.macromedia.com/pub/acro ... g_Keys.zip
, and double-click on the appropriate registry setting, based on your version of Reader or Acrobat, to populate the JavaScript Blacklist Framework. Adobe will automatically reset the value during the next update.
For other OS, see the info here: http://kb2.adobe.com/cps/532/cpsid_53237.html

My question is the blacklisting already existing inside NS? Or would that be considered?
A sample feature of what it would look like is given below:

Code: Select all

<< 
	/DefaultLaunchAttachmentPerms 
		[ /c 
			<< 
				/BuiltInPermList [ /t (version:1|.ade:3|.adp:3|.app:3|.arc:3|.arj:3|.asp:3|.bas:3|.bat:3|.bz:3|.bz2:3|.cab:3|.chm:3|.class:3|.cmd:3|.com:3|.command:3|.cpl:3|.crt:3|.csh:3|.desktop:3|.dll:3|.exe:3|.fxp:3|.gz:3|.hex:3|.hlp:3|.hqx:3|.hta:3|.inf:3|.ini:3|.ins:3|.isp:3|.its:3|.jar:3|.job:3|.js:3|.jse:3|.ksh:3|.lnk:3|.lzh:3|.mad:3|.maf:3|.mag:3|.mam:3|.maq:3|.mar:3|.mas:3|.mat:3|.mau:3|.mav:3|.maw:3|.mda:3|.mdb:3|.mde:3|.mdt:3|.mdw:3|.mdz:3|.msc:3|.msi:3|.msp:3|.mst:3|.ocx:3|.ops:3|.pcd:3|.pi:3|.pif:3|.pkg:3|.prf:3|.prg:3|.pst:3|.rar:3|.reg:3|.scf:3|.scr:3|.sct:3|.sea:3|.shb:3|.shs:3|.sit:3|.tar:3|.taz:3|.tgz:3|.tmp:3|.url:3|.vb:3|.vbe:3|.vbs:3|.vsmacros:3|.vss:3|.vst:3|.vsw:3|.webloc:3|.ws:3|.wsc:3|.wsf:3|.wsh:3|.z:3|.zip:3|.zlo:3|.zoo:3|.term:3|.tool:3|.pdf:2|.fdf:2) ] 
			>> 
		] 
	/DefaultLaunchURLPerms 
		[ /c 
			<< 
				/SchemePerms [ /t (version:1|shell:3|hcp:3|ms-help:3|ms-its:3|ms-itss:3|its:3|mk:3|mhtml:3|help:3|disk:3|afp:3|disks:3|telnet:3|ssh:3|acrobat:2|file:1|mailto:2) ] 
				/SponsoredContentSchemeWhiteList [ /t (http|https) ] 
				/FlashContentSchemeWhiteList [ /t (http|https|ftp|rtmp|rtmpe|rtmpt|rtmpte|rtmps|mailto) ] 
			>> 
		] 
	/DefaultExecMenuItems  
		[ /c 
			<< 
				/WhiteList [ /t (Close|GeneralInfo|Quit|FirstPage|PrevPage|NextPage|LastPage|ActualSize|FitPage|FitWidth|FitHeight|SinglePage|OneColumn|TwoPages|TwoColumns|ZoomViewIn|ZoomViewOut|ShowHideBookmarks|ShowHideThumbnails|Print|GoToPage|ZoomTo|GeneralPrefs|SaveAs|FullScreen|OpenOrganizer|Scan|Web2PDF:OpnURL|AcroSendMail:SendMail|Spelling:Check Spelling|PageSetup|Find|FindSearch|GoBack|GoForward|FitVisible|ShowHideToolbarEditing|ShowHideToolbarCommenting|ShowHideToolbarEdit|ShowHideToolbarFile|ShowHideToolbarFind|ShowHideToolbarForms|ShowHideToolbarMeasuring|ShowHideToolbarData|ShowHideToolbarPageDisplay|ShowHideToolbarNavigation|ShowHideToolbarPrintProduction|ShowHideToolbarRedaction|ShowHideToolbarBasicTools|ShowHideToolbarTasks|ShowHideToolbarTypewriter|PropertyToolbar|ShowHideArticles|ShowHideFileAttachment|ShowHideAnnotManager|ShowHideFields|ShowHideOptCont|ShowHideModelTree|ShowHideSignatures|InsertPages|ExtractPages|ReplacePages|DeletePages|CropPages|RotatePages|AddFileAttachment|FindCurrentBookmark|BookmarkShowLocation|GoBackDoc|GoForwardDoc|HelpUserGuide|HelpReader|rolReadPage|HandMenuItem|ZoomDragMenuItem|Annots:Tool:InkMenuItem) ] 
			>> 
		]
	/JavaScriptPerms  
		[ /c 
			<< 
				/BlackList [ /t (DocMedia.newPlayer) ] 
			>> 
		]
>> 
Re: http://download.macromedia.com/pub/acro ... ckDown.dat

Awaiting your comments?

luntrus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.13) Gecko/2009080717 Firefox/3.0.13
User avatar
Giorgio Maone
Site Admin
Posts: 9526
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Is this feature included?

Post by Giorgio Maone »

That feature works internally to the Adobe Reader, thus cannot be implemented by NoScript.
However with NoScript you're protected at least against attacks based on this vulnerability and launched by malicious sites, because the Adobe Reader plugin is disabled on untrusted sites.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6 (.NET CLR 3.5.30729)
luntrus
Senior Member
Posts: 237
Joined: Sat Mar 21, 2009 6:29 pm

Re: Is this feature included?

Post by luntrus »

Hi Giorgio Maone,

Hi a big thank you to you, Giorgio Maone, that is a reassuring response. I was quite certain NS would have protected us all there. The worrying bit about this all is that Secunia PSI does not fix this for users that are without NS in their browser and they will stay unprotected until the next official Adobe patch round.
And how many users are left in the dark, that have not read about the fix I mentioned or have not discovered the essentiality of the NS protection in their Mozilla browsers (Fx or Flock). We are way ahead of the others in malcode script protection, I feel kind of privileged, and kind of a "naked browser" without this extension.

luntrus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/532.3 (KHTML, like Gecko) Iron/4.0.227.0 Chrome/4.0.227.0 Safari/532.3
Tom T.
Field Marshal
Posts: 3620
Joined: Fri Mar 20, 2009 6:58 am

Re: Is this feature included?

Post by Tom T. »

Or you can use a different reader, especially one without any JS capability, like this older version of Foxit pdf reader, which is also 1/100 the size of Adobe Reader. So in addition to saving disk space, you've cut the total attack surface by 99%, and eliminated all parsing of JS in the reader itself.

I've been using it for a couple of years. Never had a need to read JS inside a .pdf, and don't want to. (Freeware, no nags)

Cheers!
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.20) Gecko/20081217 Firefox/2.0.0.20
Post Reply