Clicky

Pages

Showing posts with label CVE-2010-0188. Show all posts
Showing posts with label CVE-2010-0188. Show all posts

Wednesday, December 15, 2010

Dec 15 CVE-2010-3333 DOC, CVE-2010-0188 PDF Health Tips Collection from jackey870@yahoo.com.tw

Common Vulnerabilities and Exposures (CVE)number

CVE-2010-3333 Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability." .

CVE-2010-0188 Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.  (LibTIFF exploit)

  General File Information

CVE-2010-3333

File      ATT78214.doc
MD5   C31341DF029E6DC2804BA2F97DB7BAF7
SHA1  518ca81280f5bcf7ce98a6a262ac7d74ca261faf
File size :  1066411 bytes
Type:  DOC
Distribution: Email attachment 

CVE-2010-3333

File      ATT27390.doc
MD5   b4e256982947b3c68aaa84545b61c9b1
SHA1  8a6aacaf1a3a741a4c0cf707dcc70ffaa9442fee
File size :  1066411 bytes
Type:  DOC
Distribution: Email attachment 

CVE-2010-0188

File ....pdf
MD5   92db03a6d1db9a9012ccc7bd9b45ed7a
SHA1  b92dd18baf2dc041062b1e862db05a4d097a2411

File size :  232743 bytes
Type:  PDF
Distribution: Email attachment


Wednesday, August 11, 2010

Aug 3 CVE-2010-0188 PDF Asian Regionalism and US Policy

CVE-2010-0188 Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors


UPDATE August 11,2010 Many thanks to binjo (@binjo), xanda (@xanda), Matthew de Carteret (@lordparody) and Tyler M from Vicheck.ca for additional information/analysis of the attachment


Download  126939c66f62baaa0784d4e7f5b4d973 Asian_Regionalism_and_US_Policy  and all the files listed below as a password protected archive (please contact me for the password if you need it)



From: XXXXXXXX [mailto:XXXXXXXXXXX@yahoo.com]
Sent: Tuesday, August 03, 2010 8:18 AM
To: XXXXXXXXXXXX
Subject: Asian Regionalism and US Policy

Dear All,

Recently I read an excellent article.

Maybe you are interested in it.

FYI.

Best,
XXXXXX

 File Asian_Regionalism_and_US_Policy.p received on 2010.08.05 05:00:51 (UTC)
http://www.virustotal.com/analisis/d4323260646038181015f91cc83fc310b9f4901bb2c187cc5580ff15ae798737-1280984451
Result: 7/41 (17.08%)
Authentium    5.2.0.5    2010.08.05    JS/CVE-0188
BitDefender    7.2    2010.08.05    Exploit.PDF-JS.Gen
F-Prot    4.6.1.107    2010.08.05    JS/CVE-0188
F-Secure    9.0.15370.0    2010.08.05    Exploit.PDF-JS.Gen
GData    21    2010.08.05    Exploit.PDF-JS.Gen
Microsoft    1.6004    2010.08.04    Exploit:Win32/Pdfjsc.gen!B
nProtect    2010-08-04.01    2010.08.04    Exploit.PDF-JS.Gen
Additional information
File size: 168331 bytes
MD5...: 126939c66f62baaa0784d4e7f5b4d973

Headers
Received: from [173.244.197.210] by web120020.mail.ne1.yahoo.com via HTTP; Tue, 03 Aug 2010 05:17:59 PDT
X-Mailer: YahooMailClassic/11.2.4 YahooMailWebService/0.8.105.279950
Date: Tue, 3 Aug 2010 05:17:59 -0700
From: "XXXXXXXXXXX"
Subject: Asian Regionalism and US Policy
To: XXXXXXXXXXX
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="0-1610185150-1280837879=:30394"

Tor
Hostname:    anonymizer2.torservers.net
ISP:    Hosting Services
Organization:    Hosting Services
Proxy:    Confirmed proxy server. (Read about proxy servers)
State/Region:    Utah
City:    Providence

=============
 Test on WinXP XP 2 Adobe 8 and 9.3.0

Created files
%tmp%\1.dat
File: 1.dat
Size: 168331
MD5:  126939C66F62BAAA0784D4E7F5B4D973 (same as the PDF itself)
%tmp%\A9R3302.tmp
File A9R3302.tmp
Size: 358
MD5:  AD395DBE5B8E5005CF87EC6B0958AB09
%tmp%\jackjon.exe
File: jackjon.exe
Size: 0
MD5:  D41D8CD98F00B204E9800998ECF8427E





Thursday, July 29, 2010

Jul 29 CVE-2010-0188 PDF Defense New Thinks


CVE-2010-0188 Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors



Download  5e0e5951ca4626a891344e38e0085d58 Defense_Attache.pdf  as a password protected archive (please contact me for the password if you need it)





From: Gillian Medina [mailto:gillianmedina@hotmail.com]
Sent: Thursday, July 29, 2010 4:31 AM
To: randolph.strong@us.army.mil
Subject: Defense New Thinks

Defense New Thinks 


  File Defense_Attache.pdf received on 2010.08.02 03:25:36 (UTC)
http://www.virustotal.com/analisis/c6a606ebb758ed5f7e552019d656dab7cda723617819f583ceef797cfc9cfbf5-1280719536
Result: 11/42 (26.2%)
Antiy-AVL    2.0.3.7    2010.08.02    Exploit/Win32.Pidief
Avast    4.8.1351.0    2010.08.02    PDF:CVE-2010-0188
Avast5    5.0.332.0    2010.08.02    PDF:CVE-2010-0188
DrWeb    5.0.2.03300    2010.08.02    Exploit.PDF.1046
eTrust-Vet    36.1.7753    2010.07.31    PDF/CVE-2010-0188!exploit
GData    21    2010.08.02    PDF:CVE-2010-0188
Ikarus    T3.1.1.84.0    2010.08.02    Exploit.Win32.Pidief
Kaspersky    7.0.0.125    2010.08.02    Exploit.Win32.Pidief.dci
McAfee-GW-Edition    2010.1    2010.08.01    Heuristic.BehavesLike.PDF.Suspicious.L
NOD32    5331    2010.08.01    a variant of PDF/CVE-2010-0188
Sophos    4.56.0    2010.08.02    Troj/PDFJs-II
Additional information
File size: 73708 bytes
MD5...: 5e0e5951ca4626a891344e38e0085d58


Headers
Received: from SNT133-W12 ([65.55.90.71]) by snt0-omc2-s32.snt0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);
     Thu, 29 Jul 2010 01:31:18 -0700
Message-ID:
Return-Path: gillianmedina@hotmail.com
Content-Type: multipart/mixed;
    boundary="_e55064e7-b368-4f85-ab6f-7c8fd62fce86_"
X-Originating-IP: [113.225.75.65]
From: Gillian Medina
To:
Subject: Defense New Thinks
Date: Thu, 29 Jul 2010 01:31:18 -0700
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 29 Jul 2010 08:31:18.0425 (UTC) FILETIME=[6A87E890:01CB2EF8]

Hostname:    113.225.75.65
ISP:    China Unicom Liaoning province network
Organization:    China Unicom Liaoning province network
Type:    Broadband
Assignment:    Static IP
State/Region:    Liaoning
City:    Shenyang

This IP is on many blacklists http://www.robtex.com/ip/113.225.75.65.html#blacklists


Wednesday, July 7, 2010

Jul 7 CVE-2010-0188 PDF Britain intelligence service started analysis of the spy radio

CVE-2010-0188 Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors

The message attachment name says "Britain intelligence service started analysis of the spy radio". Then the body says "internal info".
While it can lure in a few readers, I'd say it is a very inane attempt to get into the targeted attack business. In general, I have not seen any high quality (zero day-low detection) or well designed targeted messages that would be clearly originating in Russia (not to say they don't exist). If you did see any convincing targeted attacks that were or looked like they were from Russia and they are as good as these, please let me know. I have a few more editorial comments regarding espionage in general and targeted attacks in particular, but I should probably leave them out and let you have fun with the attachment. Let me know if you find anything extra interesting inside (M).


Download  bfa67a03fd7d88b9b7ebeb5cae3cd95aac as a password protected archive (please contact me for the password if you need it)




 -----Original Message-----
From: usadog@mail.ru [mailto:usadog@mail.ru]
Sent: Wednesday, July 07, 2010 5:56 AM
To: aa@minprom.gov.ru
Subject: Britan razvedka mi5 vstupila v rassledovanie racci shpiona

vnutr.infa.


 File Britan_razvedka_mi5_vstupila_v_ra  received on 2010.07.07 17:10:19 (UTC)
http://www.virustotal.com/analisis/d788e52e6999e1a162d04ebc9d211f1c1d6ca41636a97709b058d44ba2f70829-1278522619
Result: 15/41 (36.59%)
AntiVir     8.2.4.10     2010.07.07     EXP/Pidief.529300
Authentium     5.2.0.5     2010.07.07     JS/Pdfka.AD
Avast     4.8.1351.0     2010.07.07     PDF:CVE-2010-0188
Avast5     5.0.332.0     2010.07.07     PDF:CVE-2010-0188
BitDefender     7.2     2010.07.07     Exploit.TIFF.Gen
eTrust-Vet     36.1.7690     2010.07.07     PDF/Pidief.RV
F-Prot     4.6.1.107     2010.07.07     JS/Pdfka.AD
F-Secure     9.0.15370.0     2010.07.07     Exploit.TIFF.Gen
McAfee     5.400.0.1158     2010.07.07     Exploit-PDF.q.gen!stream
McAfee-GW-Edition     2010.1     2010.07.05     Heuristic.BehavesLike.PDF.Suspicious.O
PCTools     7.0.3.5     2010.07.07     Trojan.Pidief
Sophos     4.54.0     2010.07.07     Troj/PDFJs-II
Symantec     20101.1.0.89     2010.07.07     Trojan.Pidief.I
VirusBuster     5.0.27.0     2010.07.06     Exploit.JS.Pdfka.T
Additional information
File size: 531530 bytes
MD5   : bfa67a03fd7d88b9b7ebeb5cae3cd95a

Thursday, July 1, 2010

Jul 01 CVE-2010-0188 PDF phone calls from imxjih@limousinehire.za.net

CVE-2010-0188 Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors


Download PhoneCalls.pdf a38a70821c62be2996ac1c28575f2fd2  ac as a password protected archive (please contact me for the password if you need it)


-----Original Message-----
From: james [mailto:imxjih@limousinehire.za.net]
Sent: Thursday, July 01, 2010 6:18 PM
To: XXXXXXXXXXXXXXX
Cc: XXXXXXXXXX XXXXXXXXXXXXX XXXXXXXXXXXXX
Subject: phone calls

Hey man..

Remember all those long distance phone calls we made.
Well I got my telephone bill and WOW.
Please help me and look at the bill see which calls where yours ok..


 File PhoneCalls.pdf received on 2010.07.04 03:49:02 (UTC)
http://www.virustotal.com/analisis/61c1eb84397b0f4459e73b6e91ef2fc768d14967ea1a7ef5bf712464d7ce0869-1278215342
Result: 18/41 (43.91%)
a-squared    5.0.0.31    2010.07.03    Exploit.Win32.Pidief!IK
AntiVir    8.2.4.2    2010.07.02    EXP/Pidief.haa
Avast    4.8.1351.0    2010.07.03    PDF:CVE-2010-0188
Avast5    5.0.332.0    2010.07.03    PDF:CVE-2010-0188
BitDefender    7.2    2010.07.04    Exploit.TIFF.Gen
eTrust-Vet    36.1.7684    2010.07.03    PDF/CVE-2010-0188!exploit
F-Secure    9.0.15370.0    2010.07.03    Exploit.TIFF.Gen
GData    21    2010.07.04    Exploit.TIFF.Gen
Ikarus    T3.1.1.84.0    2010.07.03    Exploit.Win32.Pidief
Kaspersky    7.0.0.125    2010.07.04    Exploit.Win32.Pidief.dci
McAfee    5.400.0.1158    2010.07.04    Exploit-PDF.pp!stream
McAfee-GW-Edition    2010.1    2010.07.02    Exploit-PDF.pp!stream
Microsoft    1.5902    2010.07.03    Exploit:Win32/Pdfjsc.gen!B
PCTools    7.0.3.5    2010.07.02    Trojan.Pidief
Sophos    4.54.0    2010.07.03    Troj/PDFJs-II
Symantec    20101.1.0.89    2010.07.04    Trojan.Pidief.I
TrendMicro    9.120.0.1004    2010.07.04    TROJ_PDFJSC.AR
TrendMicro-HouseCall    9.120.0.1004    2010.07.04    TROJ_PDFJSC.AR
Additional information
File size: 2616 bytes
MD5...: a38a70821c62be2996ac1c28575f2fd2

Headers
 Received: from 201-34-210-6.gnace703.dsl.brasiltelecom.net.br (HELO 201-34-210-6.gnace703.dsl.brasiltelecom.net.br) (201.34.210.6)
  by XXXXXXXXXXXXXXXXXXXXXXXXXXX
Date: Thu, 1 Jul 2010 19:17:31 -0300
Message-ID: <000e01cb196b$32fcbb50$00426d68@uryqmxukq>
From: james
To:
CC: XXXXXXXXXXXX
Subject: phone calls
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------4016D0ETO0O036L"

Hostname:    201-34-210-6.gnace703.dsl.brasiltelecom.net.br
ISP:    Brasil Telecom S/A - Filial Distrito Federal
Organization:    Brasil Telecom S/A - Filial Distrito Federal
Type:    Broadband
Assignment:    Dynamic IP
Country:    Brazil
State/Region:    Goias




Monday, June 7, 2010

CVE-2010-0188 + CVE-2009-4324 PDF The information you want from tibetstudent@gmail.com



Download 46bd79357c01e68715adf4f63d6a0c6d address book.pdf and 1d539bba6ef0a7c02a40f6bd5a2d5590 data.pdf as a password protected archive (contact me if you need the password)



From: Mr.Wong [mailto:tibetstudent@gmail.com]
Sent: Monday, June 07, 2010 4:52 AM
To: XXXXXXXXXXXXXXXX
Subject: The information you want

Sorry after a long time to think of it.  This is the analysis of last outstanding issues and their contacts  that  you want. Why  your mailbox always  bounce ? Please check if the mailbox is  full .

CVE-2009-4324
 File Address_Book.pdf received on 2010.06.28 04:29:57 (UTC)
http://www.virustotal.com/analisis/21ebe23b16213eb37575c90a9e07e35792d3707c007e7c8236a44b7723da9e60-1277699397
Result: 12/40 (30%)
a-squared    5.0.0.30    2010.06.28    Exploit.PDF-JS!IK
Avast    4.8.1351.0    2010.06.27    JS:Pdfka-gen
Avast5    5.0.332.0    2010.06.27    JS:Pdfka-gen
BitDefender    7.2    2010.06.28    Exploit.PDF-JS.Gen
eSafe    7.0.17.0    2010.06.27    Win32.Pidief.H
F-Secure    9.0.15370.0    2010.06.28    Exploit.PDF-JS.Gen
GData    21    2010.06.28    Exploit.PDF-JS.Gen
Ikarus    T3.1.1.84.0    2010.06.28    Exploit.PDF-JS
McAfee-GW-Edition    2010.1    2010.06.27    Heuristic.BehavesLike.Exploit.PDF.CodeExec.EBEO
nProtect    2010-06-27.02    2010.06.27    Exploit.PDF-JS.Gen
PCTools    7.0.3.5    2010.06.28    Trojan.Pidief
Symantec    20101.1.0.89    2010.06.28    Trojan.Pidief.H
Additional information
File size: 327857 bytes
MD5...: 46bd79357c01e68715adf4f63d6a0c6d

CVE-2010-0188 (PDF Exploit base64 shellcode in TIFF - generated with metasploit)
http://www.virustotal.com/analisis/88b6a2bb9d866f12ff5a5c56cacd2bd1add406f4aa01f40ccefb715e134e71ff-1277699645
File Data.pdf received on 2010.06.28 04:34:05 (UTC)
Result: 17/41 (41.47%)
a-squared    5.0.0.30    2010.06.28    Trojan.Script!IK
AhnLab-V3    2010.06.27.01    2010.06.27    PDF/Exploit
Antiy-AVL    2.0.3.7    2010.06.25    Exploit/Win32.Pidief
Authentium    5.2.0.5    2010.06.27    PDF/Expl.HS
Avast    4.8.1351.0    2010.06.27    PDF:CVE-2010-0188
Avast5    5.0.332.0    2010.06.27    PDF:CVE-2010-0188
BitDefender    7.2    2010.06.28    Trojan.Script.435196
eSafe    7.0.17.0    2010.06.27    Win32.Pidief.H
eTrust-Vet    36.1.7668    2010.06.25    PDF/Pidief.QS
F-Prot    4.6.1.107    2010.06.27    JS/Crypted.DT
F-Secure    9.0.15370.0    2010.06.28    Trojan.Script.435196
GData    21    2010.06.28    Trojan.Script.435196
Ikarus    T3.1.1.84.0    2010.06.28    Trojan.Script

PCTools    7.0.3.5    2010.06.28    Trojan.Pidief
Sophos    4.54.0    2010.06.28    Troj/PDFJs-JI
Symantec    20101.1.0.89    2010.06.28    Trojan.Pidief.H
VirusBuster    5.0.27.0    2010.06.27    Exploit.PDFDrop.A
Additional information
File size: 926302 bytes
MD5...: 1d539bba6ef0a7c02a40f6bd5a2d5590



Friday, May 14, 2010

Phoenix 2.0 Exploit kit

I normally do not post exploit packs, even partial but I am posting it in this case as it appears to be the source of the java files analyzed by InReverse.  Read this for more details and Java analysis.
The other possibility is the Crimepack. Let me know if there are others, I may post them too.


 Download  Phoenix2.zip as a password protected archive (contact me if you need the password)

   

List of included files


AdgredY.java    11895    416ff21ed3ddb4ce5665a4917964c5ce
all.js    5167    9432b83d52fc325f5bda83d58598e825  -- All listed except newplayer cve-2009-4324
deie.html    15097    a88f45102b57595d6c7b1cf2c2b4b241  --
flash.as    2746    718803346bbbed11e934c63af99c4a9f
ie.html    14939    1c8bd04644942a0f1832844ee4b44e63
newplayer.js    2595    a2344d3a54f26ae863011323a0973ac8
newplayer cve-2009-4324


Filename MD5 File Size   Extension
flash.swfC643C2B8E901E52C14A8D6CE8096E3271,645swf
all.pdf66BDB0DC68294890E359E91F1EF18D9E2,677
pdf
allv7.pdfB948321DE93582951598F3BDDDCC57352,465pdf
collab.pdfEF68F7B0018EDA2C149EF92EAAA666E22,012 CVE-2007-5659 pdf
geticon.pdf1ED11F0EEE47135067F36E73FD5E889E2,003 CVE-2009-0927pdf
libtiff.pdfE1E581CC0D817A808DC33CEB230F91B43,514 CVE-2010-0188pdf
newplayer.pdf37F28E5BE542AD2E32DA19EE5C44967C1,975 CVE-2009-4324pdf
printf.pdfAF680ECCA07B3294553F672F785545881,907 CVE-2008-2992pdf
index.jsB07E39D831F8EA3F8BCD84DCC9A60FFF14,272js
des.jar98F5ACDB21E8B8116FE5C7B4BA17D0E98,539jar
ie.html30C1A7B87C419A1427932773642FEEE714,929 CVE-2009-3867 html
index.html9939596B9BA5ECD4EE5FD648171EF01C14,462html
vistaie7.htmlE8888E4EDA75F6CE016A5FBA9BE02FA314,415html
vistan7ie8.html6D11908E6CCC01B14ED0097561853F868,747html
vistan7other.html3E4B94ED2A6ED5F7FF42165BB165A46B13,734html
xpie7.htmlEDE58120D8C76212E458898B348D2B8014,420html
xpie8.htmlA18CCEEE89E13B137C77F88688668CED8,714html
xpother.html355A809F8B5BDE1E511C628DD75CD87114,129html

Flash exploits are

CVE-2009-1869
CVE-2007-0071

PDF exploits
 CVE-2007-5659
 CVE-2009-0927
 CVE-2010-0188
 CVE-2009-4324
 CVE-2008-2992

Internet Explorer Exploits
CVE-2009-0806

Java Exploits
CVE-2009-3867
CVE-2008-5353

Let me know if i missed any

Java exploit GetSoundBank Read inReverse Ratsoul's posts for more information here or on their new blog here 
Also, see some malware links with this exploit here





deie.html
MDAC exploit

 Flashloader - using object and embed for different browsers. Read this article for more details http://borodin.livejournal.com/10471.html


Actionscript

IE 2010-0806




Tuesday, May 11, 2010

May 11 CVE-2010-0188 PDF Call the Ministry of Defense from hiw11111@gmail.com

Download ATT73189.pdf aaeed3399e542e4ba881f27adabaf31f ac as a password protected archive (please contact me for the password if you need it)

Details ATT73189.pdf aaeed3399e542e4ba881f27adabaf31f 

From: yiwei huang [mailto: hiw11111@gmail.com]Sent: Tuesday, May 11, 2010 9:06 PMTo: XXXXXXSubject: Call the Ministry of DefenseSuch as the subject

-Coast Guard Department of Planning by Wei HuangTEL: 02-22399201 # 266137FAX: 02-22392936Wenshan District, Taipei City 296, Sec Xinglong



File ATT73189.pdf received on 2010.05.12 12:35:03 (UTC)
Result: 7/41 (17.08%)
Authentium    5.2.0.5    2010.05.12    JS/Pdfka.AD
Avast    4.8.1351.0    2010.05.12    PDF:CVE-2010-0188
Avast5    5.0.332.0    2010.05.12    PDF:CVE-2010-0188
ClamAV    0.96.0.3-git    2010.05.12    Suspect.PDF.ObfuscatedJS
GData    21    2010.05.12    PDF:CVE-2010-0188
IMicrosoft    1.5703    2010.05.12    Exploit:Win32/Pdfjsc.FI
Sophos    4.53.0    2010.05.12    Troj/PDFJs-II
Additional information
File size: 446746 bytes
MD5...: aaeed3399e542e4ba881f27adabaf31f

:CVE-2010-0188


Monday, May 10, 2010

May 9 CVE-2010-0188 PDF Concept Paper.pdf from global.faruk@gmail.com

Download Concept_Paper.pdf  c06ef052db6710fd632952cc14917d84  ac as a password protected archive (please contact me for the password if you need it)
Nothing new or special in this one except the text of the message appears to be stolen from a real message or is a very good fake. This sender sent a message before http://contagiodump.blogspot.com/2010/04/apr-2-cve-2009-0927-cve-2007-5659-pdf.htmlDetection is as low as it was a month ago, not much improvement on this CVE (M)


Details Concept_Paper.pdf c06ef052db6710fd632952cc14917d84 
File Concept_Paper.pdf received on 2010.05.10 11:14:19 (UTC)
http://www.virustotal.com/analisis/e3366fd2b4ff485840c147ea2eb811e793616a5a8bb2e1abfb4d37a03e53d774-1273490059
Result: 6/41 (14.64%)
Authentium    5.2.0.5    2010.05.10    JS/CVE20100
Avast    4.8.1351.0    2010.05.09    PDF:CVE-2010-0188
Avast5    5.0.332.0    2010.05.09    PDF:CVE-2010-0188
GData    21    2010.05.10    PDF:CVE-2010-0188
eTrust-Vet    35.2.7477    2010.05.10    PDF/CVE-2010-0188!exploit
Sophos    4.53.0    2010.05.10    Troj/PDFJs-II
Additional information
File size: 172952 bytes
MD5...: c06ef052db6710fd632952cc14917d84








From: 呂參謀 [mailto:global.faruk@gmail.com]
Sent: Sunday, May 09, 2010 9:30 PM
To: XXXXXXXXXXXXXXXXXXXXXX
Subject: Fwd: ASEM Cooperation on Capacity Building of Disaster Relief


---------- Forwarded message ----------
From: Alan D. Romberg
Date: 2010/5/7 20:11
Subject: RE: Yang's bio. doc
To: Andrew Nien-Dzu Yang
Cc: 毛 毛


Dear Andrew –

Although I am going to be away (in Korea) next week, I want to get out an invitation to your talk so people will mark it on their calendars.

I am attaching a draft for your approval. I am assuming that, since you are giving a similar talk “on the record” at Harvard, your talk at Stimson will also be “on the record.” But if you want to tell all of your most closely-held secrets to our audience (while only giving fluff to Steve’s group at Harvard), I’m happy to make it off the record or at least “not for attribution.” Let me know.

Please let me have your feedback on the invitation text.

While the invitations are generally issued electronically, they are also printed up. So I may need to cut back a bit on the bio stuff to make it fit on one page, but I hope not. But I wanted to make you aware of that. However, I didn’t want to take more time to fiddle with formatting now before sending it to you (and LtCol Mao) for your OK.

Thanks. Looking forward to seeing you.

Best.

Alan


Thursday, May 6, 2010

May 6 CVE-2010-0188 PDF birthday briefing series from spoofed jjsung@ntu.edu.tw

Download  d80eb21cfe8ad1a710c8652b13f8b7 ATT59802.pdf ac as a password protected archive (please contact me for the password if you need it)



Virustotal
 File ATT59802.pdf received on 2010.05.06 18:49:42 (UTC)
Result: 6/41 (14.64%)
Avast    4.8.1351.0    2010.05.06    PDF:CVE-2010-0188
Avast5    5.0.332.0    2010.05.06    PDF:CVE-2010-0188
eTrust-Vet    35.2.7471    2010.05.06    PDF/CVE-2010-0188!exploit
Kaspersky    7.0.0.125    2010.05.06    Exploit.Win32.Pidief.dch
Sophos    4.53.0    2010.05.06    Troj/PDFJs-II
Additional information
File size: 106855 bytes6
MD5...: d80eb21cfe8ad1a710c8652b13f8b7ac


 

-----Original Message-----
From: jjsung@ntu.edu.tw [mailto:jjsung@ntu.edu.tw]
Sent: 2010-05-06 10:34 AM
To: XXXXXXXXXXXX
Subject: 蔡政文教授七十華誕系列活動簡報

XXXXXXXXXXXXX

今年適逢我國政治學界耆老、臺大政治學系名譽教授、國策顧問、國家政策研究基金會執行長蔡政文教授七秩華誕,為祝賀蔡教授七秩榮慶,及表達國內政治學同道景仰之意,籌委會特別規劃系列活動,以玆慶賀。
一、蔡政文教授七十華誕學術論文研討會
謹訂於今年5月29、30兩日假台大社科院國際會議廳舉辦「全球、兩岸、臺灣—蔡政文教授七十華誕學術論文研討會」,此次研討會主題訂為「全球、兩岸、臺灣」,也正呼應馬總統「壯大臺灣、連結兩岸、布局全球」的整體大戰略,歡迎蔡教授的門生故舊與知交友好踴躍賜稿外,亦請政治學先進與同道惠賜宏文,共襄盛舉。
二、大陸地區賀壽團來訪
為擴大參與並推動兩岸學術交流,探討「壯大臺灣、連結兩岸、布局全球」之當前國家發展方針,藉此加速大陸民主化之進程,同時邀集與蔡老師有深厚情誼的江蘇省海峽兩岸關係研究會、中國社科院台灣研究所等重要涉台智庫組團來臺祝賀,共襄盛舉。與會大陸學者除參與論文研討會外,會後並安排大陸學者南下參訪政經建設。
來臺賀壽團名單:
江蘇省海峽兩岸關係研究會:路進明副會長暨夫人
台研所:朱副所長衛東、田主任賀民、高劍副主任、柳英助理研究員、汪助理研究員曙申、陳助理研究員詠江等六人
南京大學:張永桃副校長(中國政治學會副會長)、張鳳陽院長
三、蔡政文教授七十華誕祝壽晚宴
預定於99年5月29日(星期六)晚上六點舉行,晚宴席設上海鄉村首都店。
蔡老師自民國63年指導學生林嘉誠撰寫〈大衛‧伊士頓之政治理論〉碩士論文起,截至99年4月底,指導學生共計有25位博士、98位碩士。
蔡老師的每位指導學生,畢業後都能謹遵師訓,在工作崗位上有傑出的表現,未曾辜負老師的嚴格訓練。
蔡老師的門生、故舊、同事、部屬都期盼能躬逢其盛,為蔡老師舉辦一場祝壽晚宴,以表達心中的感謝與祝福!

----------------------------------------------------------------------
若有任何垂詢事項,請洽:
籌委會總幹事  宋紀均
電話:0932-322-687;傳真:(02) 2367-9708;
電子信箱:jjsung@ntu.edu.tw
----- Original Message -----From: jjsung@ntu.edu.tw [mailto: jjsung@ntu.edu.tw]Sent: 2010-05-06 10:34 AMTo: XXXXXXSubject: Professor Cai Zhengwen 70 birthday briefing seriesXXXX Hello:This year marks the country's political circles and seniors, National Taiwan University political science professor emeritus, national policy advisor to the National Policy Research Foundation, Professor Cai Zhengwen Seventieth Birthday, Professor Zhu Hecai seven to rank Rongqing, and expression of admiration of fellow domestic politics means , the PC series of special planning activities to celebrate hereby.First, Professor Cai Zhengwen 70 birthday academic seminarTo be held May 29-30 this year, a two-day leave held at National Taiwan University International Conference Hall, Academy of Social Sciences, "global, cross-strait, Taiwan - 70 birthday of Professor Cai Zhengwen academic seminar", the theme of the seminar as a "global, cross-strait , Taiwan ", are also echoed President Ma of" strengthening Taiwan, connecting both sides of the layout of the world, "the overall grand strategy, welcomed Professor Cai friendly and enthusiastic disciple old friends and fraternity grant the draft, but also advanced and fellow political science please give Wang Hui Wen, join the festivities.Second, the mainland delegation's visit Birthday GreetingsTo expand the participation and promote cross-strait academic exchanges, of "strengthening Taiwan, connecting both sides of the layout of the world" in the current national development policy to accelerate the democratization process in mainland China, and invited Tsai has a profound friendship with the Jiangsu Province-Strait Relations Research Council, the Chinese Academy of Social Sciences Institute of Taiwan Studies, and other important Taiwan-related think tanks to organize groups to congratulate the endeavor. In addition to participating scholars from mainland China to participate thesis seminars will be arranged after visiting mainland scholars south political and economic development.Taiwan Yoshihisa group list:Jiangsu Province of cross-strait relations will be: Way into the next vice chairman and his wifeTaiwan Research Institute: Deputy Director Zhu Weidong, landowner Renhe Min, Gao Jian, deputy director, Liu Ying, an assistant researcher, assistant researcher Wang Shu Shen, Yong Jiang Dengliu Ren Chen, an assistant researcherNanjing: Zhang Tao, Vice President (Vice President of Chinese Political Science Association), Zhang Fengyang DeanThird, Professor Cai Zhengwen 70 birthday birthday dinnerScheduled for 5 月 29 日 99 (星期六) 18:00 held a dinner I set up shop in Shanghai Rural capital.Tsai guide students from the Republic of China Lin Chia-cheng 63 years to write master's thesis on, at 99 years by the end of April, guiding students to a total of 25 doctoral, 98 master's degree.Tsai's guide for each student upon graduation can Jinzun teacher training, in the workplace have outstanding performance, did not live up to the rigorous training of teachers.Tsai's disciple, and old friends, colleagues, subordinates all look forward to critical keepers, to host a birthday dinner Tsai, to express their thanks and best wishes!-------------------------------------------------- --------------------If you have any inquiries matters, please contact:Director-General of the Preparatory Committee of Song Ji areTel :0932-322-687; Fax: (02) 2367-9708;E-mail: jjsung@ntu.edu.tw

 Headers
Received: from wmail1.cc.ntu.edu.tw (HELO wmail1.cc.ntu.edu.tw) (140.112.2.161)
  by XXXXXXXwith DHE-RSA-AES256-SHA encrypted SMTP; 6 May 2010 14:33:45 -0000
Received: from localhost (localhost [127.0.0.1])
    by wmail1.cc.ntu.edu.tw (Postfix) with ESMTP id 9DABE35E841
    for XXXXXXXXX; Thu,  6 May 2010 22:33:42 +0800 (CST)
Received: from 218.94.121.180 ([218.94.121.180]) by wmail1.cc.ntu.edu.tw
 (Horde Framework) with HTTP; Thu, 06 May 2010 22:33:42 +0800
Message-ID: <20100506223342.59074hzo2e1mojly@wmail1.cc.ntu.edu.tw>
Date: Thu, 6 May 2010 22:33:42 +0800
Disposition-Notification-To: jjsung@ntu.edu.tw
From: jjsung@ntu.edu.tw




Hostname:    218.94.121.180
ISP:    Data Communication Division
Organization:    CHINANET jiangsu province network
Country:    China cn flag
State/Region:    Beijing
City:    Beijing

Wednesday, May 5, 2010

May 5 CVE-2010-0188 PDF 2010-05-06 Asian Pacific Security stuff from samuelberger19@yahoo.com


Download  0999aef064dc91d68d48df3d7c1482e4  Assessing_the_Asian_Balance.pdf as a password protected archive (please contact me for the password if you need it)

Details 0999aef064dc91d68d48df3d7c1482e4 Assessing_the_Asian_Balance.pdf


http://www.virustotal.com/analisis/20e241ba72b751ea9b5b46617d27c6572f98dc216140ed002f30d2a169f16ee2-1273171733
File Assessing_the_Asian_Balance.pdf received on 2010.05.06 18:48:53 (UTC)
Result: 6/41 (14.64%)
Avast    4.8.1351.0    2010.05.06    PDF:CVE-2010-0188
Avast5    5.0.332.0    2010.05.06    PDF:CVE-2010-0188
eTrust-Vet    35.2.7471    2010.05.06    PDF/CVE-2010-0188!exploit
GData    21    2010.05.06    PDF:CVE-2010-0188
Kaspersky    7.0.0.125    2010.05.06    Exploit.Win32.Pidief.dch
Additional information
File size: 124874 bytes
MD5...: 0999aef064dc91d68d48df3d7c1482e4













From: Samuel Berger [mailto:samuelberger19@yahoo.com]
Sent: 2010-05-04 9:46 AM
To: XXXXXXXXXXXXXXXXXXXXX
Subject: Asian Pacific Security stuff if you are interested

Dear Colleague,
Hope this mail finds you well. Attached is my latest paper on military balance in Asia.
The purpose of this essay is to begin redressing the absence of a scholarly debate on today’s military balances. In short, I will 1) analyze certain aspects of the scholarly debate on Cold War balances to identify lessons we might learn for the assessment of Asian-Pacific balances today; 2) identify America’s security interests in the Pacific; and 3) analyze the pasts debates over military balances and assess current U.S. Asian interests to offer ways to think about the balance of power in a region of growing importance.
I am sending it in two versions that are little different in content. Part One has it in Word form, while Part Two has it in PDF form. One reason for this is that the smaller PDF form may be easier to manage. Also, it is easier to markup the PDF with comments.

Best,
Samuel



Headers
Received: (qmail 5604 invoked from network); 4 May 2010 13:46:07 -0000
Received: from web114501.mail.gq1.yahoo.com (HELO web114501.mail.gq1.yahoo.com) (98.136.183.9)
  by XXXXXXXXXXXXXX  SMTP; 4 May 2010 13:46:07 -0000
Received: (qmail 13807 invoked by uid 60001); 4 May 2010 13:46:06 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1272980766; bh=J3HYNvCvCDyPvkGgmftWQ8+zXbK454RBqFWFVNLeREc=; h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type; b=joG8+M0RpG1PiqtkD9078vYk62Fip4emnVHfPGe3yF0VDmLdOVo5pVkBFcvatipshgRZgTtXdwFuwFcPhoTM0OQqfxmxWs7MJ0WCrKLccJ710pmzs9agP15XxmOvugjvke7AuKmPRd6dNYldgNFhwnEhI8wVZD/qT66eL7VbZm4=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
  s=s1024; d=yahoo.com;
  h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type;
  b=1n+A//g4la4ygH85zo+bAofKE8QFyK/8bvJeD2JUxKMQaeAbZ09Lr+Zs80QOOFmYTQP8PPkMSRPQwVfVNGeIDdB1tr2kuUiGAKZ4T14zi7mB2aWN2D3WO85aU779HQ27fkdenU2B71kV8ZkEDgKmEsmGjnd9HDfSyEbOCh9g5cA=;
Message-ID: <418000.60485.qm@web114501.mail.gq1.yahoo.com>
X-YMail-OSG: WFPXxRAVM1k.IwoUJ0A1Rl6ADrcxY3z1LZO4P7F_yPzchs9
 1E3PDb34L
Received: from [66.197.176.8] by web114501.mail.gq1.yahoo.com via HTTP; Tue, 04 May 2010 06:46:05 PDT
X-Mailer: YahooMailClassic/10.1.11 YahooMailWebService/0.8.103.269680
Date: Tue, 4 May 2010 06:46:05 -0700
From: Samuel Berger
Subject: Asian Pacific Security stuff if you are interested
To: XXXXXXXXXXXXXX
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="0-1791380416-1272980765=:60485"

66.197.176.8
Hostname:    swhosting.ie
ISP:    Network Operations Center
Organization:    SOUTHWEST TECHNOLOGIES
Assignment:    Static IP
State/Region:    Pennsylvania
City:    Scranton