PC Review


Reply
Thread Tools Rate Thread

CVE-2009-0927, P.O.C.?

 
 
Catter
Guest
Posts: n/a
 
      9th Apr 2010
I just accidentally run pdf file CVE-2009-0927.pdf, from CVE-2009-0927 pack,
when antivirus was disabled.
Although this pack marked as exploit and technical report note, I'm not
sure, can it contain link to real malware or virus when exploit executed?
pdf size is124KB

http://www.coromputer.net/CVE-2009-0927_package.zip

 
Reply With Quote
 
 
 
 
Tom Willett
Guest
Posts: n/a
 
      9th Apr 2010
You think anyone would be foolish enough to click on the link you posted?

"Catter" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
:I just accidentally run pdf file CVE-2009-0927.pdf, from CVE-2009-0927
pack,
: when antivirus was disabled.
: Although this pack marked as exploit and technical report note, I'm not
: sure, can it contain link to real malware or virus when exploit executed?
: pdf size is124KB
:
:


 
Reply With Quote
 
Catter
Guest
Posts: n/a
 
      9th Apr 2010

"Tom Willett" <(E-Mail Removed)> wrote in message
news:elK9PK%(E-Mail Removed)...
> You think anyone would be foolish enough to click on the link you posted?
>
> "Catter" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
> :I just accidentally run pdf file CVE-2009-0927.pdf, from CVE-2009-0927
> pack,
> : when antivirus was disabled.
> : Although this pack marked as exploit and technical report note, I'm not
> : sure, can it contain link to real malware or virus when exploit
> executed?
> : pdf size is124KB
> :
> :
>

---------------
if you afraid click on link, how do you use Internet at all?

 
Reply With Quote
 
Tom Willett
Guest
Posts: n/a
 
      9th Apr 2010


: ---------------
: if you afraid click on link, how do you use Internet at all?

You really don't get it, do you? No wonder you get malware.
:


 
Reply With Quote
 
Michael
Guest
Posts: n/a
 
      9th Apr 2010
"Catter" <(E-Mail Removed)> wrote in message
news:eXn4Am#(E-Mail Removed)...
>
> "Tom Willett" <(E-Mail Removed)> wrote in message
> news:elK9PK%(E-Mail Removed)...
>> You think anyone would be foolish enough to click on the link you posted?
>>
>> "Catter" <(E-Mail Removed)> wrote in message
>> news:(E-Mail Removed)...
>> :I just accidentally run pdf file CVE-2009-0927.pdf, from CVE-2009-0927
>> pack,
>> : when antivirus was disabled.
>> : Although this pack marked as exploit and technical report note, I'm not
>> : sure, can it contain link to real malware or virus when exploit
>> executed?
>> : pdf size is124KB
>> :
>> :
>>

> ---------------
> if you afraid click on link, how do you use Internet at all?


You posted a link to a file that may be a virus. You do the math, moron!
--


"Don't pick a fight with an old man.
If he is too old to fight, he'll just kill you."


 
Reply With Quote
 
Elmo
Guest
Posts: n/a
 
      9th Apr 2010
Michael wrote:
> "Catter" <(E-Mail Removed)> wrote in message
> news:eXn4Am#(E-Mail Removed)...
>>
>> "Tom Willett" <(E-Mail Removed)> wrote in message
>> news:elK9PK%(E-Mail Removed)...
>>> You think anyone would be foolish enough to click on the link you
>>> posted?
>>>
>>> "Catter" <(E-Mail Removed)> wrote in message
>>> news:(E-Mail Removed)...
>>> :I just accidentally run pdf file CVE-2009-0927.pdf, from CVE-2009-0927
>>> pack,
>>> : when antivirus was disabled.
>>> : Although this pack marked as exploit and technical report note, I'm
>>> not
>>> : sure, can it contain link to real malware or virus when exploit
>>> executed?
>>> : pdf size is124KB
>>> :
>>> :
>>>

>> ---------------
>> if you afraid click on link, how do you use Internet at all?

>
> You posted a link to a file that may be a virus. You do the math, moron!


No, he posted a link to a file that _contained_ a virus (or some type of
malware). Or at least that's how Avast! saw it. Since it was a .zip
file, I thought I'd click it, and just not unzip the file.. Avast!
caught it before the "page" loaded.

--
Joe =o)
 
Reply With Quote
 
Michael
Guest
Posts: n/a
 
      9th Apr 2010

"Elmo" <(E-Mail Removed)> wrote in message
news:#4GvMV$(E-Mail Removed)...
> Michael wrote:
>> "Catter" <(E-Mail Removed)> wrote in message
>> news:eXn4Am#(E-Mail Removed)...
>>>
>>> "Tom Willett" <(E-Mail Removed)> wrote in message
>>> news:elK9PK%(E-Mail Removed)...
>>>> You think anyone would be foolish enough to click on the link you
>>>> posted?
>>>>
>>>> "Catter" <(E-Mail Removed)> wrote in message
>>>> news:(E-Mail Removed)...
>>>> :I just accidentally run pdf file CVE-2009-0927.pdf, from CVE-2009-0927
>>>> pack,
>>>> : when antivirus was disabled.
>>>> : Although this pack marked as exploit and technical report note, I'm
>>>> not
>>>> : sure, can it contain link to real malware or virus when exploit
>>>> executed?
>>>> : pdf size is124KB
>>>> :
>>>> :
>>>>
>>> ---------------
>>> if you afraid click on link, how do you use Internet at all?

>>
>> You posted a link to a file that may be a virus. You do the math, moron!

>
> No, he posted a link to a file that _contained_ a virus (or some type of
> malware). Or at least that's how Avast! saw it. Since it was a .zip
> file, I thought I'd click it, and just not unzip the file.. Avast!
> caught it before the "page" loaded.
>
> --
> Joe =o)


....and your point is?
--


"Don't pick a fight with an old man.
If he is too old to fight, he'll just kill you."


 
Reply With Quote
 
T Shadow
Guest
Posts: n/a
 
      9th Apr 2010
"Elmo" <(E-Mail Removed)> wrote in message
news:%234GvMV$(E-Mail Removed)...
> Michael wrote:
>> "Catter" <(E-Mail Removed)> wrote in message
>> news:eXn4Am#(E-Mail Removed)...
>>>
>>> "Tom Willett" <(E-Mail Removed)> wrote in message
>>> news:elK9PK%(E-Mail Removed)...
>>>> You think anyone would be foolish enough to click on the link you
>>>> posted?
>>>>
>>>> "Catter" <(E-Mail Removed)> wrote in message
>>>> news:(E-Mail Removed)...
>>>> :I just accidentally run pdf file CVE-2009-0927.pdf, from CVE-2009-0927
>>>> pack,
>>>> : when antivirus was disabled.
>>>> : Although this pack marked as exploit and technical report note, I'm
>>>> not
>>>> : sure, can it contain link to real malware or virus when exploit
>>>> executed?
>>>> : pdf size is124KB
>>>> :
>>>> :
>>>>
>>> ---------------
>>> if you afraid click on link, how do you use Internet at all?

>>
>> You posted a link to a file that may be a virus. You do the math, moron!

>
> No, he posted a link to a file that _contained_ a virus (or some type of
> malware). Or at least that's how Avast! saw it. Since it was a .zip
> file, I thought I'd click it, and just not unzip the file.. Avast!
> caught it before the "page" loaded.
>
> --
> Joe =o)



"In all the excitement I can't remember, did I shoot five, or six? You've
got one question to ask yourself, do you feel lucky, punk? Well, ...


 
Reply With Quote
 
Elmo
Guest
Posts: n/a
 
      10th Apr 2010

T Shadow wrote:
> "Elmo" <(E-Mail Removed)> wrote in message
> news:%234GvMV$(E-Mail Removed)...
>> Michael wrote:
>>> "Catter" <(E-Mail Removed)> wrote in message
>>> news:eXn4Am#(E-Mail Removed)...
>>>> "Tom Willett" <(E-Mail Removed)> wrote in message
>>>> news:elK9PK%(E-Mail Removed)...
>>>>> You think anyone would be foolish enough to click on the link you
>>>>> posted?
>>>>>
>>>>> "Catter" <(E-Mail Removed)> wrote in message
>>>>> news:(E-Mail Removed)...
>>>>> :I just accidentally run pdf file CVE-2009-0927.pdf, from CVE-2009-0927
>>>>> pack,
>>>>> : when antivirus was disabled.
>>>>> : Although this pack marked as exploit and technical report note, I'm
>>>>> not
>>>>> : sure, can it contain link to real malware or virus when exploit
>>>>> executed?
>>>>> : pdf size is124KB
>>>>> :
>>>>> :
>>>>>
>>>> ---------------
>>>> if you afraid click on link, how do you use Internet at all?
>>> You posted a link to a file that may be a virus. You do the math, moron!

>> No, he posted a link to a file that _contained_ a virus (or some type of
>> malware). Or at least that's how Avast! saw it. Since it was a .zip
>> file, I thought I'd click it, and just not unzip the file.. Avast!
>> caught it before the "page" loaded.
>>
>> --
>> Joe =o)

>
>
> "In all the excitement I can't remember, did I shoot five, or six? You've
> got one question to ask yourself, do you feel lucky, punk? Well, ...


Agreed, that was pretty risky.. I won't do that again. I noticed that
after I clicked the link, my download folder had an empty .zip file PLUS
an external file. I just didn't see how a .zip file could be dangerous
unless files were actually extracted and executed, but I seem to
remember reading in a Trend Micro newsletter about a couple of new
exploits, and I suspect this was one of them.

--
Joe =o)
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
convert 13.11.2009 general to 13/11/2009 date, how to xppuser Microsoft Excel Worksheet Functions 1 13th Jan 2010 01:21 PM
How do I create a June 2009 doc. from a 2009 calendar template? socalviking Microsoft Word Document Management 1 30th May 2009 08:50 PM
How to find & replace all dates eg 3.19.2009 with 3-19-2009, ect? fofficecommunityk Microsoft Word New Users 3 17th Feb 2009 07:49 PM
Format Dates: Sunday, Feb 1, 2009 to Saturday, Feb 7, 2009 ryguy7272 Microsoft Access 4 8th Feb 2009 01:04 AM
How create 365 labels for 2009? Example: Monday, Jan. 4, 2009 callmark1 Microsoft Excel Misc 0 28th Dec 2008 06:17 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 07:15 AM.