OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[Dailydave] JBIG falls without JavaScript

From: dave (daveimmunityinc.com)
Date: Tue Mar 03 2009 - 13:06:40 CST


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Downloadable here, for those of you with CANVAS Early Update Subscriptions:
http://www.immunityinc.com/ceu-index.shtml

So things like this are harder than they look - Pablo and Kostya had to
work quite a bit on reliability every step of the way. But the Acrobat
JBIG exploit now works nicely without any JavaScript heap spray.

For those of you with the exploit that was caught in the wild, how
reliable is that one? What versions of Acrobat Reader does it work on?

- -dave
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkmtf8AACgkQtehAhL0gheoN+ACfcEPl1ADGcc9ouGVhgeR46qFe
dl8AniOrku/5H/WfNMug95zN4LwS7XIt
=CE+o
-----END PGP SIGNATURE-----
_______________________________________________
Dailydave mailing list
Dailydavelists.immunitysec.com
http://lists.immunitysec.com/mailman/listinfo/dailydave