Click here to join us on IRC (#charas on irc.freenode.net)!
Your session timed out while posting. Please try to re-submit your message.
Uh, it seems no one updated you...Well, let's do it now.Yes, there was a code injection in charas. The code tried to open a malicious PDF document into an invisible 1x1 iframe.Then, by using a known adobe vulnerability, the javascript code tried to use the malicious PDF in order to do... something (i don't know what).Everyone with javascript disabled for PDF reader should be safe (i never understood why in hell PDF docs needed javascript support).However, yesterday we found and removed that code, so now all should be fine.Charas was "exposed" to this from January 7th to yesterday: so, if you do have javascript allowed for Reader and you have an outdated version of Reader itself, a full scan is surely recommended.I'm just sorry i can't tell you more about what that PDF was supposed to do... but considering today's trends, i think to transform your PC into a part of a botnet of something similar
Tell Lucas Irineu to clear his cookies and logon again. And make sure he's clicking on the actual text of the link, not on the general blue area of forum links. It's the only way to preserve session ID for some messed up reason.