Reply to comment
Newsletter Sign-up
Newsletter Sign-up
Security news and analysis with expert opinion and perspective from the Threatpost editors.
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.


The second screenshot on the register article makes the bug guessable. The control must whitelist *.adobe.com, then he uses the obvious open redirector on feeds.adobe.com to 302 to his exploit.
looking at the download page and you just need a page that has this (didnt test)
<object id="GetActiveX" classid="clsid:E2883E8F-472F-4fb0-9522-AC9BF37916A7"
Where file.txt is formatted like this http://get.adobe.com/reader/webservices/dlm/?itemid=Reader_9.3_English_UK_for_Windows
Checksum is just the MD5 of that exe, so you can just replace it. You need to click the security bar and agree you want it to run, and it's only installed transiently. I guess I agree with Adobe: not the end of the world. Any user who will clicky that will agree to the "install control" warning as well and already has bonzibuddy.ocx