You must be logged in to post a comment.
Categories
- BPO (6)
- Business Card Design (2)
- Call Center (3)
- Corporate Identity (2)
- Domain Registration (5)
- Envelop Design (2)
- Graphic Design (3)
- Internet (5)
- KPO (7)
- Letterhead Design (3)
- Logo Design (2)
- Movies (Bollywood) (20)
- Hindi Movie News (9)
- Hindi Movie Reviews (9)
- Hindi Music Review (2)
- News (358)
- PC & Web Security (30)
- SEO (10)
- Sports: Cricket (14)
- IPL T20 (10)
- Team India Cricket (4)
- Wallpapers (4)
- Web Designing (13)
- Web Hosting (10)
- Website Development (2)
- Website Maintenance (2)
- YouTube Videos (31)
Archives
- July 2010 (37)
- June 2010 (41)
- May 2010 (61)
- April 2010 (50)
- March 2010 (55)
- February 2010 (64)
- January 2010 (45)
- November 2009 (16)
- October 2009 (12)
- September 2009 (16)
- August 2009 (20)
- July 2009 (2)
- June 2009 (40)
- May 2009 (10)
- March 2009 (3)
- February 2009 (15)
- January 2009 (15)
- December 2008 (7)
- May 2008 (6)
- April 2008 (4)
Recent Posts
- India Unveils A Portable Computing Device Worth Rs 1600
- Protect Yourself from Scams like Phishing and Vishing to Steal Web Identity
- Microsoft Extends Windows XP Downgrade to 2020
- Walmart Kinect Bundle Worth $258 Now Costs $199
- Google Launches Google Fiber For Communities
- Microsoft Dubs iPhone 4 as Apple Windows Vista
- Youtube and Blu-Ray Going 3D on PS3
- Fujifilm HDs All Its Cameras in India
- Samsung Launches Next Generation Camera NX10 in India
- Sony Launches World Smallest 3D Digital Still Cameras Yet
DESIGN Web Graphic Twitter
- serious about starting your own biz this year? check this out - http://t.co/4wJ7uRve
- serious about starting your own biz this year? check this out - http://t.co/3Qb2m6yo
- are you serious about starting your own business in 2012? you have to check this out - http://t.co/GChcwURp
- serious about starting your own biz this year? check this out - http://t.co/spgDIXYG
- are you serious about starting your own business in 2012? you have to check this out - http://t.co/PQ05Pelt
Popular Terms
3D TV
3G
Apple
Apple Inc
Apple iPad
Apple iPhone
Bluetooth
Computer Games
Cyber Crime
Facebook
Facebook Games
Google
Google Inc
GPRS
Hindi Film Industry
Hindi Movie Reviews
HP
india
Internet
iPad
iPhone
IPL T20
Laptops
LG
Microsoft
Microsoft Inc
Microsoft Windows 7
Mobile Phones
Nokia
Notebooks
Operating System
Samsung
SONY
Sony India
SONY Playstation 3
SONY PS3
Toshiba
Twitter
USB 2.0
Wi-Fi
Windows
Windows 7
Windows 7 OS
Windows OS
YouTube
Calendar
| M | T | W | T | F | S | S |
|---|---|---|---|---|---|---|
| « Jul | ||||||
| 1 | 2 | 3 | 4 | 5 | 6 | |
| 7 | 8 | 9 | 10 | 11 | 12 | 13 |
| 14 | 15 | 16 | 17 | 18 | 19 | 20 |
| 21 | 22 | 23 | 24 | 25 | 26 | 27 |
| 28 | 29 | 30 | 31 | |||
DESIGN Web Graphic RSS
Partner links
Hacker Finds a Way to Exploit PDF Files without a Vulnerability
A security researcher has managed to create a proof-of-concept PDF file that executes an embedded executable without exploiting any security vulnerabilities.
The PDF hack, when combined with clever social engineering techniques, could potentially allow code execution attacks if a user simply opens a rigged PDF file.
Here’s the skinny from researcher Didier Stevens.
I use a launch action triggered by the opening of my PoC PDF. With Adobe Reader, the user gets a warning asking for approval to launch the action, but I can (partially) control the message displayed by the dialog. Foxit Reader displays no warning at all, the action gets executed without user interaction.
Although PDF viewers like Adobe Reader and Foxit Reader doesn’t allow embedded executables (like binaries and scripts) to be extracted and executed, Stevens discovered another way to launch a command (/Launch /Action), and ultimately run an executable he embedded using a special technique.
Stevens said Adobe’s PDF Reader will block the file from automatically opening but he warned that an attacker could use social engineering tricks to get users to allow the file to be opened.
With Foxit Reader, there is no warning whatsoever:
Stevens has not released the proof-of-concept file. The issue has been reported to Adobe’s security response team.
With Adobe Reader, the only thing preventing execution is a warning. Disabling JavaScript will not prevent this (I don’t use JavaScript in my PoC PDF), and patching Adobe Reader isn’t possible (I’m not exploiting a vulnerability, just being creative with the PDF language specs).
Stevens tested his research on Adobe Reader 9.3.1 (Windows XP SP3 and Windows 7).