For users of Adobe Acrobat Reader (of any version or patch level today - safety hint):
Since it has been attacked so much recently (via its ability to place javascripting into its .pdf document format, & javascript that bears truly "ill will")?
Well, update to the latest/greatest version... HOWEVER, if you don't trust that, as I do not, FULLY?
(I say this, & simply because browser makers have been trying that left & right since "time immemorial" online, & more of those types of attacks pop up of differing nature that evades new patches vs. it, keep popping up regardless of the patches!)
Plus, like I had stated earlier in this guide?
I suggested turning off using javascript for EVERY SITE online, in your webbrowser (& only keep it for ones that demand it (or, become useless w/out it, like many shopping &/or banking sites - this lessens the possibility of being poisoned by bad adbanner OR site code & also lessens the attack surface area + limits the possibles to the sites you left javascript on for, ONLY))??
Try this FOR ADOBE ACROBAT READER ALSO:
TURN OFF JAVASCRIPT USAGE IN ADOBE ACROBAT READER!
Simply to be safe vs. attacks in it that are javascript-based in nature!
----
Use Adobe Acrobat's EDIT menu
PREFERENCES submenu
Javascript section (in left-hand side column of options)
& uncheck "Enable Acrobat Javascript" in the right-hand side option for that.
----
What boggles MY mind, moreso in webbrowsers &/or email programs though (as far as javascript is concerned)? Browser makers are working on speeding up its processing, first, rather than securing its weak/exploitable DOM (document object model) behind it.
Speeding up javascript in webbrowser programs, for example?
WELL - That's only speeding up how FAST you can be infected by misuse of javascript then, really, & this is all (not good!).
(AND, anyone reading here now can simply take a read over @ SECUNIA.COM &/or SECURITYFOCUS.COM & see that a GOOD 95% of today's attacks are hitting users via the indiscriminate use of javascript (misuse of it) on every website they go to).
----
Imo @ least, but, one based on the data in this guide (plus that from security websites I noted above)?
Javascript should be turned off by DEFAULT in a webbrowser!
Why??
Well, because most times, if a site needs it???
The site errs out & signals the user javascript is required. Turn it on @ that point, IF you absolutely NEED it to be running (& only then, for useful tasks you wish to perform online, such as data access like you see on shopping &/or banking websites)
I mean, hey: Even adbanners have been abused this way & proofs of that abound in this guide no less.
In fact, when I noted this over @ slashdot?
I was "modded down" for it, & just for telling the truth to javascript (& other scripting languages) developers... just for telling the truth! Boggles the mind. Secure that DOM behind javascript first, for security, AND ONLY THEN, work on speeding it up afterwards. That's not how it's being done though, unfortunately.
----
10 Forces Guiding the Future of Scripting:
http://developers.slashdot.org/comme...1&cid=25362703
----
Another bonus (for speed this time though, not security), also exists in turning off javascript processing in webbrowsers: Speed.
I.E.-> You're not using CPU cycles processing scripts that you probably don't actively directly use, yourself (such as ARE needed on e-commerce/shopping + banking websites, where you DO need it mostly to do actual useful tasks), & you're also not "hauling in" data from other servers (slowing you down even moreso, if not compromising your system (such as have been seen the past 4++ yrs. now or so, in bad adbanners that house javascript misuse)) that you don't really need, or want, around on your webpages you view...
APK
P.S.=> That assures you are "bullet-proofed" vs. Adobe Acrobat malware/bad javascript containing contaminated .pdf documents via bogus javascript in them for exploiting you online today!
NOW - the only hassle here is that SOMETIMES, there is so much javascript in them, ADOBE MAY "nag" a lot about it, & should have a feature to turn that off (imo @ least)...
So, evidence as to WHY one should do this to Adobe Acrobat Reader (until it's patched vs. this type of thing):
Critical Vulnerability In Adobe Reader:
http://it.slashdot.org/article.pl?sid=08/11/05/2042211
(Dated 11/06/2008, 8 months after I noted this here no less - if/when Adobe secures THIS particular exploit in their program? Turning off javascript processing (enabled by DEFAULT in that program no less, mind you) can help protect vs. other exploits like this one, in the future, that misuse javascript)...
----
Turning off javascript in this program, & also webbrowsers + email programs simply assures you that you are "bullet-proofed" vs. Adobe Acrobat malware/bad javascript containing contaminated .pdf documents via bogus javascript in them for exploiting you online today!
NOW - the only hassle here is that SOMETIMES, there is so much javascript in them, ADOBE MAY "nag" a lot about it, & should have a feature to turn that off (imo @ least)... apk