lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <6905b1570609131350m744dd2edo49c62b5298e637a4@mail.gmail.com>
Date: Wed, 13 Sep 2006 21:50:13 +0100
From: "pdp (architect)" <pdp.gnucitizen@...glemail.com>
To: "Juha-Matti Laurio" <juha-matti.laurio@...ti.fi>
Cc: full-disclosure@...ts.grok.org.uk, security-basics@...urityfocus.com,
	David Kierznowski <david.kierznowski@...il.com>
Subject: Re: Backdooring PDF Files

I have tested both of the examples and no warning boxes are showing.
It seams that everybody is getting different results. Interesting!

On 9/13/06, Juha-Matti Laurio <juha-matti.laurio@...ti.fi> wrote:
> Proof of Concept for example 1 (backdoored1.pdf) opened with Adobe Reader 7.0.8
> (i.e. no browser plug-in used) issued a Security Warning dialog box:
>
> "The document is trying to conenct to the site:
> http://www.google.com/owned.html
>
> If you trust the site click "Allow", otherwise click "Block"."
>
> Option Remember my action is in use as well.
>
> When clicking "Allow" this Google page was opened in MSIE (in fact FF is my default browser, however).
>
> Am I missing something related to differences between Reader plug-in and Reader application?
>
> - Juha-Matti
>
>
> David Kierznowski <david.kierznowski@...il.com> wrote:
> >
> > Recently, there has been alot of hype involving backdooring various
> > web technologies. pdp (arcitect) has done alot of work centered around
> > this area.
> >
> > I saw Jeremiah Grossman mention PDF's being "BAD", however, I was
> > unable to easily locate any practical reasons as to why. I decided to
> > investigate this a little further.
> >
> > This article discusses two possible backdoor techniques for Adobe
> > Acrabat Reader and Professional. It includes proof of concept code and
> > backdoored PDF documents.
> >
> > The article can be found here:
> > http://michaeldaw.org/
> >
> > _______________________________________________
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> > Hosted and sponsored by Secunia - http://secunia.com/
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>


-- 
pdp (architect)
http://www.gnucitizen.org

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ