Categorized | Security

Adobe Explains More of Reader X Protected Mode

sandbox.jpgAn entry in the Adobe Secure Software Engineering Team (ASSET) Blog expands on the company’s description of their sandboxing strategy for Adobe Reader X for Windows. Click here to read about the first entry in this series.

The focus of this entry is on Windows-specific features that make the sandbox possible. Any attempt to implement these capabilities on other operating systems would require a completely different approach. Going Windows-specific in this case makes perfect sense, since the real-world threats are basically all on Windows.

The approach follows the guidelines in the Practical Windows Sandboxing series by Microsoft’s David LeBlanc (part 1, part 2. part 3), as did Google’s Chrome web browser. Adobe goes on to thank LeBlanc and Nicolas Sylvain of the Google Chrome team for their help in building the sandbox.

I won’t go into the specific features. Read the Adobe blog for them. It is worth noting that Adobe considered one measure recommended by LeBlanc, that is running the application in a separate desktop, but decided not to use it as the changes to the Reader/Acrobat architecture would be too extensive. This limits the available attack mitigations some, especially with regard to screen scraping attacks, but not extensively.

It doesn’t go into the same level of detail, but below is a video from Adobe’s Brad Arkin in which he discusses Adobe’s security strategy in broad terms.

View full post on Security Watch

Related Posts

loverandme2011, professoressa sp0rcacciona si sp0glia nei banchi scuola per scommessa, Post a Message Spam Prevention Please enter the code shown above and click the Post Message button This additional step is required to help protect against message spam, allintext: post a message guest name message spam prevention please enter the code shown above and click the post message button this additional step is required to help protect against message spam enter code above, exploit win32 cve-2010-2568 gen, allintext:guest name message spam prevention please enter the code shown above and click the post message button this additional step is required to help protect against message spam enter code above, Post a Message Guest Name Message Spam Prevention Enter code above, allintextGuest Name Message Spam Prevention Please enter the code shown above and click the Post Message button This additional step is required to help protect against message spam Enter code above, allintext:post a message guest name message spam prevention please enter the code shown above and click the \post message\ button this additional step is required to help protect against message spam enter code above, allintext: guest name message spam prevention please enter the code shown above and click the \post message\ button this additional step is required to help protect against message spam enter code above, “Post a Message” “Please enter the code shown above and click the Post Message button ”, allintext:Post a Message Guest Name Message Spam Prevention Please enter the code shown above and click the Post Message button This additional step is required to help protect against message spam Enter code above, powered by vBulletin computer companies, powered by vBulletin at play, powered by vBulletin play, intext:Post a MessageGuest NameMessageSpam Prevention, powered by vBulletin girls playing, powered by vBulletin girl video, powered by vBulletin email, powered by vBulletin description of computer

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago