Adobe Acrobat Reader Collab getIcon通杀漏洞
evil_pdf.py在以下系统测试通过:
Windows XP SP3 英文版/法文版
Windows 2003 SP2 英文版
Adobe 应用程序版本:
Adobe Reader 9.0.0/8.1.2 英文版/法文版
测试对象:
单独PDF文件、火狐FireFox3.0.13和IE7嵌入式PDF
#!/usr/bin/env python
#
# *** Acrobat Reader – Collab getIcon universal exploiter ***
# evil_pdf.py, tested on Operating Systems:
# Windows XP SP3 English/French
# Windows 2003 SP2 English
# with Application versions:
# Adobe Reader 9.0.0/8.1.2 English/French
# Test methods:
# Standalone PDF, embedded PDF in Firefox 3.0.13 and Internet Explorer 7
# 24/06/2009 – Created by Ivan Rodriguez Almuina (kralor). All rights reserved.
# [Coromputer] raised from the ashes.
#
http://www.coromputer.net/CVE-2009-0927_package.zip
back: http://milw0rm.com/sploits/2009-CVE-2009-0927_package.zip
# milw0rm.com [2009-09-03]
转载请尊重版权,出处:秋天博客,零点空间 本文链接: http://www.cfresh.net/web-security/95


@alzn
据说它们的内核都是相同的,你分析的很对,与其说是技术的失败,不如说是营销策略的失败。