<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Secure yourself from the recent PDF exploits by disabling JavaScript</title>
	<atom:link href="http://insecureweb.com/javascript/secure-yourselffrom-the-recent-pdf-exploits-by-disabling-javascript/feed/" rel="self" type="application/rss+xml" />
	<link>http://insecureweb.com/javascript/secure-yourselffrom-the-recent-pdf-exploits-by-disabling-javascript/</link>
	<description>Insight into web application security</description>
	<lastBuildDate>Wed, 16 Dec 2009 01:02:49 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Zero-Day Malware Drops Payloads Signed with a Forged Microsoft Certificate &#171; Webroot Threat Blog</title>
		<link>http://insecureweb.com/javascript/secure-yourselffrom-the-recent-pdf-exploits-by-disabling-javascript/comment-page-1/#comment-68</link>
		<dc:creator>Zero-Day Malware Drops Payloads Signed with a Forged Microsoft Certificate &#171; Webroot Threat Blog</dc:creator>
		<pubDate>Wed, 16 Dec 2009 01:02:49 +0000</pubDate>
		<guid isPermaLink="false">http://insecureweb.com/?p=85#comment-68</guid>
		<description>[...] the meantime, until Adobe issues updates for Acrobat and/or Reader, you may wish to follow these instructions to disable Javascript within those [...]</description>
		<content:encoded><![CDATA[<p>[...] the meantime, until Adobe issues updates for Acrobat and/or Reader, you may wish to follow these instructions to disable Javascript within those [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sean</title>
		<link>http://insecureweb.com/javascript/secure-yourselffrom-the-recent-pdf-exploits-by-disabling-javascript/comment-page-1/#comment-67</link>
		<dc:creator>Sean</dc:creator>
		<pubDate>Tue, 15 Dec 2009 15:58:24 +0000</pubDate>
		<guid isPermaLink="false">http://insecureweb.com/?p=85#comment-67</guid>
		<description>Thanks for the registry file and for including all current versions, I use PolicyMaker here and this makes it really simple to push the registry updates. Adobe&#039;s security on this javascript stuff is just cheesecloth. Why we need yet another webpage when actually we need a secure way of passing documents eludes me at the moment.</description>
		<content:encoded><![CDATA[<p>Thanks for the registry file and for including all current versions, I use PolicyMaker here and this makes it really simple to push the registry updates. Adobe&#8217;s security on this javascript stuff is just cheesecloth. Why we need yet another webpage when actually we need a secure way of passing documents eludes me at the moment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bryan Migliorisi</title>
		<link>http://insecureweb.com/javascript/secure-yourselffrom-the-recent-pdf-exploits-by-disabling-javascript/comment-page-1/#comment-52</link>
		<dc:creator>Bryan Migliorisi</dc:creator>
		<pubDate>Fri, 01 May 2009 03:34:16 +0000</pubDate>
		<guid isPermaLink="false">http://insecureweb.com/?p=85#comment-52</guid>
		<description>@leftystrat Thanks :)  You can also try FoxIt which is another free PDF reader for Windows.

http://www.foxitsoftware.com/pdf/reader/</description>
		<content:encoded><![CDATA[<p>@leftystrat Thanks <img src='http://insecureweb.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />   You can also try FoxIt which is another free PDF reader for Windows.</p>
<p><a href="http://www.foxitsoftware.com/pdf/reader/" rel="nofollow">http://www.foxitsoftware.com/pdf/reader/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: leftystrat</title>
		<link>http://insecureweb.com/javascript/secure-yourselffrom-the-recent-pdf-exploits-by-disabling-javascript/comment-page-1/#comment-51</link>
		<dc:creator>leftystrat</dc:creator>
		<pubDate>Fri, 24 Apr 2009 22:29:23 +0000</pubDate>
		<guid isPermaLink="false">http://insecureweb.com/?p=85#comment-51</guid>
		<description>I read yesterday that people are starting to recommend using alternatives to Acrobat.  I avoid Adobe wherever possible personally but get stuck with it sometimes at work.  Sumatra is a free reader app for Windows that works quite well (and doesn&#039;t phone home).  Linux generally comes with its own.  

It has been my experience that very little good comes from javascript in a browser.  Now I have to worry about it in Acrobat too.

Bravo on the GPO/registry file!</description>
		<content:encoded><![CDATA[<p>I read yesterday that people are starting to recommend using alternatives to Acrobat.  I avoid Adobe wherever possible personally but get stuck with it sometimes at work.  Sumatra is a free reader app for Windows that works quite well (and doesn&#8217;t phone home).  Linux generally comes with its own.  </p>
<p>It has been my experience that very little good comes from javascript in a browser.  Now I have to worry about it in Acrobat too.</p>
<p>Bravo on the GPO/registry file!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bryan Migliorisi</title>
		<link>http://insecureweb.com/javascript/secure-yourselffrom-the-recent-pdf-exploits-by-disabling-javascript/comment-page-1/#comment-13</link>
		<dc:creator>Bryan Migliorisi</dc:creator>
		<pubDate>Mon, 23 Feb 2009 21:20:39 +0000</pubDate>
		<guid isPermaLink="false">http://insecureweb.com/?p=85#comment-13</guid>
		<description>@Blood

Thanks.  Unfortunately, in many environments where you manage more than a few machines, its very difficult to know which versions of any software is installed.  Plus, its good measure to lock things down preemptively.</description>
		<content:encoded><![CDATA[<p>@Blood</p>
<p>Thanks.  Unfortunately, in many environments where you manage more than a few machines, its very difficult to know which versions of any software is installed.  Plus, its good measure to lock things down preemptively.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blood</title>
		<link>http://insecureweb.com/javascript/secure-yourselffrom-the-recent-pdf-exploits-by-disabling-javascript/comment-page-1/#comment-12</link>
		<dc:creator>Blood</dc:creator>
		<pubDate>Mon, 23 Feb 2009 21:13:54 +0000</pubDate>
		<guid isPermaLink="false">http://insecureweb.com/?p=85#comment-12</guid>
		<description>So long as your copy is up-to-date you should be OK

http://www.avertlabs.com/research/blog/index.php/2008/02/11/another-adobe-pdf-exploit-in-the-wild/</description>
		<content:encoded><![CDATA[<p>So long as your copy is up-to-date you should be OK</p>
<p><a href="http://www.avertlabs.com/research/blog/index.php/2008/02/11/another-adobe-pdf-exploit-in-the-wild/" rel="nofollow">http://www.avertlabs.com/research/blog/index.php/2008/02/11/another-adobe-pdf-exploit-in-the-wild/</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
