Malware Using Hacked Adobe Certificates
Adobe has just released a statement that one of its build servers has been compromised and attackers have used it to sign their malware with Adobe certificates. Due to how Windows 7 UAC works an attacker could sign their malware with this Adobe certificate and gain instant privilege escalation. Even with UAC on Max (as is the default for Vista) the attackers have a legitimate certificate, which will make convincing a user that it’s a legitimate application much easier. Certain policies that rely on digital signatures to secure systems will also fail here – for example some policies restrict execution to signed programs.
There are two malicious samples found. One seems to steal password hashes from the operating system and the other works as an ISAPI Filter (in other words it filters your HTTP requests and then acts based on those requests). No further details are given for the two malicious entries. The malware is likely part of a sophisticated and targeted attack – not something the average user will run across.
Adobe has stated that it is working with security vendors and that a current fix would be to add the MD5 hashes of the malware to your Software Restriction Policies. Adding the certificates to ‘Untrusted Certificates’ would also potentially work but it would also block legitimate Adobe products.
The investigation into the compromise of the build server is ongoing. No source code has been stolen or tampered with. It seems that a build server was not configured properly and it’s as simple as that.
You can read more about this straight from Adobe. (Here)
And honestly, kudos to Adobe for putting this out there. This isn’t us reading about it weeks later and Adobe trying to cover it (which is surprisingly common with these things) but they owned up, said a server was misconfigured, and as far as I can tell they’re doing everything right. So often a website gets hacked and all they do is play damage control with the press or try to cover it up. Adobe’s certificate got hacked and they’ve responded well.
I think that’s really a testament to how Adobe has changed. Flash isn’t the security hole it once was – it’s not amazing but they’ve made significant improvements both to the security (ASLR, Sandboxing) and performance (multithreaded video decoding, GPU accelerated, etc). The same goes for Adobe Reader. So good for them for owning up and taking the right steps to fix their mistakes yet again.
blog comments powered by Disqus