TheNewTopical.com - current events, politics, culture, ethics, economics discussion forum  

Go Back   TheNewTopical.com - current events, politics, culture, ethics, economics discussion forum » Main Forum » General & Current Events

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-01-11, 06:09 PM
FredFredson's Avatar
Senior Member
 

Join Date: Dec 2009
Location: North America
Posts: 1,749
Default 27C3: danger lurks in PDF documents

27C3: danger lurks in PDF documents

27C3: danger lurks in PDF documents - The H Security: News and Features

At the 27th Chaos Communication Congress (27C3) in Berlin, security researcher Julia Wolf of US company FireEye pointed out numerous, previously hardly known, security problems in connection with Adobe's PDF standard. For instance, a PDF can reportedly contain a database scanner that becomes active and scans a network when the document is printed on a network printer. Wolf said that the document format is also full of other surprises. For example, it is reportedly possible to write PDFs which display different content in different operating systems, browsers or PDF readers – or even depending on a computer's language settings.

Many businesses and authorities use PDF as their standard file format for maintaining presentation consistency across heterogeneous computer environments. According to Wolf, however, the PDF standard has long had too many functions that can be exploited to launch attacks and wreak other havoc. These functions range from database connections without security features to options that can blindly trigger the execution of arbitrary programs in Acrobat Reader. The researcher said that other risks are generated through the support of inherently insecure script languages such as JavaScript, formats such as XML, RFID tags and digital rights management (DRM) technologies. According to Wolf, Adobe itself calls PDF a "container format" which may indeed hold a variety of things. For example, it is possible to integrate Flash files, which themselves offer many points of attack, as well as audio and video files.

Wolf said that there are generally many places for hiding arbitrary data and code in a PDF. The researcher explained that, for instance, all document and meta data can be read and edited via JavaScript. Even files compressed in formats such as ZIP, which allow further arbitrary objects to be embedded via comments, can reportedly be integrated. Wolf added that it is also possible to generate very small PDF files which only execute JavaScript, and that certain objects can be referenced multiple times to trigger different responses when opening a file.

In the researcher's experience, the security debacle is made worse because most anti-virus programs are incapable of detecting malicious software in PDFs. When running tests with various known exploits, Wolf said that more than half of the 40 scanners she tested didn't respond, even in cases where the corresponding advisories were several months old. When malicious code in JavaScript is compressed, the detection rate is apparently even lower. According to Wolf, Adobe plans to remedy the situation in version 10 of its Reader product by introducing a sandbox which allows code to be executed separately in secure mode. Other security experts recommend using special tools to remove meta data from PDFs or check the file syntax for conformity issues beforehand.

(Stefan Krempl)
__________________
"Patriotism means being loyal to your country all the time and to its government when it deserves it."-- Mark Twain

"Inter arma silent Musae"--when the weapons speak, the muses fall silent.

An't nanum hearm deth, doth hwaet ye willath.

It is forbidden to kill; therefore all murderers are punished
unless they kill in large numbers and to the sound of trumpets. -Voltaire

Economic Left/Right: -3.88
Authoritarian/Libertarian: -4.36
Reply With Quote
  #2 (permalink)  
Old 03-01-11, 12:14 PM
insignificant data point
 

Join Date: Jun 2009
Location: Sydney, Australia
Posts: 3,799
Default

I can't find any independent confirmation of this story. Anyone?
Reply With Quote
  #3 (permalink)  
Old 03-01-11, 01:52 PM
FredFredson's Avatar
Senior Member
 

Join Date: Dec 2009
Location: North America
Posts: 1,749
Default

Well given the nearly monthly disclosure of vulnerabilities in PDF and Adobe reader over the last year this article is no surprise.

Wikipedia has lots on the spec itself: Portable Document Format - Wikipedia, the free encyclopedia

F
__________________
"Patriotism means being loyal to your country all the time and to its government when it deserves it."-- Mark Twain

"Inter arma silent Musae"--when the weapons speak, the muses fall silent.

An't nanum hearm deth, doth hwaet ye willath.

It is forbidden to kill; therefore all murderers are punished
unless they kill in large numbers and to the sound of trumpets. -Voltaire

Economic Left/Right: -3.88
Authoritarian/Libertarian: -4.36
Reply With Quote
Reply


(View-All Members who have read this thread : 3
FredFredson, roadkill, Zichao
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 05:01 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.0