Hacker Finds Multiple PDF Backdoors

Wonderful! One less safe format for documents! You'd think Adobe would've learned from the M$ macro virus fiasco of a few years back, but apparently they can't resist adding more and more "features" with bigger and bigger holes.

Eweek.com has a story about a British security researcher figuring out a way to manipulate legitimate features in Adobe PDF files to open backdoors for computer attacks. David Kierznowski, a penetration testing expert specializing in Web application testing, has released proof-of-concept code and two sample PDF files to demonstrate how the Adobe Reader program can be rigged to launch Web-based attacks without any user action. He claims there are least seven different ways to backdoor a PDF.

(link) [Slashdot]

07:43 /Technology | 2 comments | permanent link