Sat, 16 Sep 2006

Hacker Finds Multiple PDF Backdoors

Wonderful! One less safe format for documents! You'd think Adobe would've learned from the M$ macro virus fiasco of a few years back, but apparently they can't resist adding more and more "features" with bigger and bigger holes.

Eweek.com has a story about a British security researcher figuring out a way to manipulate legitimate features in Adobe PDF files to open backdoors for computer attacks. David Kierznowski, a penetration testing expert specializing in Web application testing, has released proof-of-concept code and two sample PDF files to demonstrate how the Adobe Reader program can be rigged to launch Web-based attacks without any user action. He claims there are least seven different ways to backdoor a PDF.

(link) [Slashdot]

/Technology | 2 writebacks | permanent link


On 9/16/2006 12:30:40
lwood wrote

There's only one answer...


On 9/16/2006 14:57:25
Dave H wrote

Plaintext problems


comment...

 
Notes: If you put a <mailto:> link in the URL field your address will not be mangled: this could be a bad idea as your email address could be easily harvested by bots designed for SPAM. The comments field should now format correctly for line feeds and carriage returns: when you hit the 'Enter' or 'Return' keys in your comment it should break to a new line. The text should wrap cleanly. Please let me know if it doesn't. No HTML tags will pass through - entering links seems to be the main cause of comment SPAM. Also, please be sure that Javascript is enabled in your browser before attempting to post a writeback. Sorry for any inconvenience, but this really helps cut down on the amount of comment SPAM I have to deal with.
 
 Name:
 URL:(optional)
 Title: (optional)
 Comments:  
Save my Name and URL/Email for next time