Results 1 to 6 of 6

Thread: new PDF vulnerability

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Gold Member twinscythe12332's Avatar
    Join Date
    Jan 2007
    Location
    durban
    Posts
    769
    Thanks
    12
    Thanked 110 Times in 84 Posts

    new PDF vulnerability

    pdf insecurity
    This could be fun

  2. #2
    Diamond Member AndyD's Avatar
    Join Date
    Jan 2010
    Location
    Cape Town
    Posts
    4,924
    Thanks
    576
    Thanked 934 Times in 755 Posts
    If you're worried about launch action running executable script from within a pdf there are several options;
    Use an old version of a pdf reader until the exploit is patched. Adobe reader version 5 doesn't support launch action for example, neither do early versions of Foxit (ver 1.3).
    Secondly do what I do and use a sandbox. Here's a free one. You can then right click on any file, including pdf's and select 'run/open sandboxed'.

    This exploit is not really a weakness in the pdf reader (although foxit will execute arbitrary embedded code without a warning window), it's more of a social exploit achieved by manipulating the text in the warning window. Just being aware of the problem should be sufficient to stop you from getting caught by it.

  3. #3
    Gold Member twinscythe12332's Avatar
    Join Date
    Jan 2007
    Location
    durban
    Posts
    769
    Thanks
    12
    Thanked 110 Times in 84 Posts
    yep, pretty much. The real question here would be to ask yourself why you're opening dodgy PDFs in the first place.

  4. #4
    Diamond Member AndyD's Avatar
    Join Date
    Jan 2010
    Location
    Cape Town
    Posts
    4,924
    Thanks
    576
    Thanked 934 Times in 755 Posts
    You have a good point, most of my dodgy stuff is jpeg or mp4 :-)

  5. #5
    Gold Member twinscythe12332's Avatar
    Join Date
    Jan 2007
    Location
    durban
    Posts
    769
    Thanks
    12
    Thanked 110 Times in 84 Posts
    .3gp keep it on the move

  6. #6
    Diamond Member AndyD's Avatar
    Join Date
    Jan 2010
    Location
    Cape Town
    Posts
    4,924
    Thanks
    576
    Thanked 934 Times in 755 Posts
    Quote Originally Posted by twinscythe12332 View Post
    .3gp keep it on the move

Similar Threads

  1. Replies: 0
    Last Post: 09-Jul-08, 08:15 AM
  2. Vulnerability exposed
    By Dave A in forum Technology Forum
    Replies: 3
    Last Post: 05-Jan-07, 11:47 AM

Did you like this article? Share it with your favourite social network.

Did you like this article? Share it with your favourite social network.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •