DefCon17 Presentation: 0-day, gh0stnet and the inside story of the Adobe JBIG2 vulnerability

DefCon: Matt Richard Malicious Code Researcher, Raytheon
Steven Adair Researcher, Shadowserver

This talk is the story of 0-day PDF attacks, the now famous gh0stnet ring and the disclosure debacle of the Adobe JBIG2 vulnerability in January and February 2009. This is the story of international cyber-espionage using 0-days and the fierce debate over how to defend networks in the face of prolonged periods of exposure to unpatched vulnerabilities.