Can please anyone tell me where to find very specific information about that vulnerability? I'd like to study and recreate one calculator opener as my homework.
i don't understand what just happened. maybe it was just the quality of the viewing process or that i'm just really really stupid. probably the latter.
An error in how Adobe Reader parses PDF files lets hackers make a PDF that can launch a command on the computer of whoever tries to open the file. In this example (poc = proof of concept) Notepad and Calculator is launched, but it might as well be commands to add users to the system, or install a backdoor, etc.
This comment has received too many negative votesshow
Wow, impressive. I wonder if it's actually just Adobe's fault, or a combined adobe/microsoft problem (with an architecture like that, it's usually at least PART MS's fault)
I doubt many *nix users would use adobe's pdf reader. I think its closed-source, and probably pretty poor quality in comparison to an alternative made by a higher quality and quantity of developers.
Let the dumb Windows users suffer in peace, until they learn what a computer is and how to use it.
I guess my question is what this vulnerability exploits. However unlikely, it could possibly simply be something that can be done via almost any platform.
Also, when did this become a "One Family of OS is better than another"? That argument can be taken elsewhere. It's all about preference on the end-user's part.
Actually last time I heard less computers run windows than *nix variants (business servers/terminals). Maybe certain groups of home users like pensioners, rich people/fools who think that spending more money will get them better software, when its the opposite.
Besides, use your head, and you'll know the age of physical media and costly communication is over, copyright and proprietary software have had their day. If it wasnt for them grasping onto the legal system they'd both be extinct. Microsoft are not going to cope if they dont pull out soon.
The video is practically useless to users of pdfs, but it is a perfect way for him to show us his PoCs without actually releasing them.. so Kudos to PdP
@Input006: he wrote in the text editor "this is it!" (The text in the PDF files is: "The following POC can be used for experimental purposes only. GNUCITIZEN disclaims any responsibility for your own actions.")
Hear hear. Either full disclosure, or keep it to yourself and notify the vendor. Anything in between is just advertising to better sell the exploit (if there is one at all) to the blackhats.
Can please anyone tell me where to find very specific information about that vulnerability? I'd like to study and recreate one calculator opener as my homework.
Hy22n 2 years ago
Hello guys, I need to convert a WMF document into PDF format. How do I do it?
ThompsonHilda 2 years ago
YAY ... man i want that pdf / cpp source pleaaaaaaaase it is awesome stuff!
kaiomatico 3 years ago
scemi
SALVATORE1S 3 years ago
kick ass
digerpaji 4 years ago
This comment has received too many negative votes show
stupid
raper5000 4 years ago
i don't understand what just happened. maybe it was just the quality of the viewing process or that i'm just really really stupid. probably the latter.
lampond 4 years ago
An error in how Adobe Reader parses PDF files lets hackers make a PDF that can launch a command on the computer of whoever tries to open the file. In this example (poc = proof of concept) Notepad and Calculator is launched, but it might as well be commands to add users to the system, or install a backdoor, etc.
It is quite serious.
toojuub 4 years ago 8
The programmer in me screams "buffer overrun," the geek in me just says "OH SNAP!!!"
KIFulgore 4 years ago
This comment has received too many negative votes show
Wow, impressive. I wonder if it's actually just Adobe's fault, or a combined adobe/microsoft problem (with an architecture like that, it's usually at least PART MS's fault)
garretttr 4 years ago
This comment has received too many negative votes show
why does this video have 11,594 hits?
krazykizza 4 years ago
slashdot.
sh3l1 4 years ago 5
This comment has received too many negative votes show
Nobody uses Windows any more, who cares.
ephesus 4 years ago
Right. Nobody. Except for the vast majority of desktop PC users.
Anybody know if this exploit effects the adobe reader for Linux or Unix?
Gh0stPreacher 4 years ago 3
only affects adobe's pdf reader apparently
oneofthethree 4 years ago
Right. But does it affect the ones for Unix and Linux?
Gh0stPreacher 4 years ago
I doubt many *nix users would use adobe's pdf reader. I think its closed-source, and probably pretty poor quality in comparison to an alternative made by a higher quality and quantity of developers.
Let the dumb Windows users suffer in peace, until they learn what a computer is and how to use it.
JTickett 4 years ago
I guess my question is what this vulnerability exploits. However unlikely, it could possibly simply be something that can be done via almost any platform.
Also, when did this become a "One Family of OS is better than another"? That argument can be taken elsewhere. It's all about preference on the end-user's part.
Gh0stPreacher 4 years ago
Was just saying its less likely to affect *nix users cos they tend to stay away from the mainstream close-source software solutions.
Most likely a software exploit (Adobe reader) not the PDF format itself. It'd be nice if this PoC explained a bit more.
JTickett 4 years ago
hell yeah!
mushk45 4 years ago
This comment has received too many negative votes show
You're an idiot.
OmnesExeunt 4 years ago
This comment has received too many negative votes show
you're a dumbass. There's probably double the amount of windows users than there are compared to linux and macs combined.
pwner1001 4 years ago
for me xpdf is superior to Adobe reader ;)
mushk45 4 years ago
:D ditto.
I think also Open Office exports PDF format, although I havent tried that so I don't know for sure.
JTickett 4 years ago
Actually last time I heard less computers run windows than *nix variants (business servers/terminals). Maybe certain groups of home users like pensioners, rich people/fools who think that spending more money will get them better software, when its the opposite.
JTickett 4 years ago
Besides, use your head, and you'll know the age of physical media and costly communication is over, copyright and proprietary software have had their day. If it wasnt for them grasping onto the legal system they'd both be extinct. Microsoft are not going to cope if they dont pull out soon.
JTickett 4 years ago
Dude. Please let us know what to disable to avoid this shit until they patch it!
akoropecki 4 years ago
Just don't open PDF files from untrusted sources!
OmnesExeunt 4 years ago
ouch.
imbaczek 4 years ago
nothing
Basically pdfs can launch programs..... which could install things on ur pc such as viruses etc.
tomardern 4 years ago 5
Dang, that's kinda scary.
aercires 4 years ago
This comment has received too many negative votes show
What???????????
Splash1964 4 years ago
The video is practically useless to users of pdfs, but it is a perfect way for him to show us his PoCs without actually releasing them.. so Kudos to PdP
arixshow 4 years ago 3
What did he write in the text editor?
Input006 4 years ago
@Input006: he wrote in the text editor "this is it!" (The text in the PDF files is: "The following POC can be used for experimental purposes only. GNUCITIZEN disclaims any responsibility for your own actions.")
Norbert2 4 years ago 3
This comment has received too many negative votes show
-1 for tim
gikiryu 4 years ago
This comment has received too many negative votes show
and -12 for you!
JTickett 4 years ago
This comment has received too many negative votes show
fuck you with your sad multi-accounts
gikiryu 4 years ago
This comment has received too many negative votes show
I only have 1 account, its just seems people hate you.
JTickett 4 years ago
Not really a fake.
Adpbe said that this vulnerability does exist.
peterchen55 4 years ago 14
Where and when did Adobe say this?
sircutman 4 years ago
That's a good question; so far I've only seen Petko Petkov /claim/ that Adobe has acknowledged the vulnerability.
Norbert2 4 years ago
I thought so. This partial disclosure BS is useless. It serves no purpose to release something like this and the video does not prove anything.
sircutman 4 years ago 4
Hear hear. Either full disclosure, or keep it to yourself and notify the vendor. Anything in between is just advertising to better sell the exploit (if there is one at all) to the blackhats.
catalyst771 4 years ago 5
well... he was able to open a second program by opening a pdf... you can use it to open a exe (virus)...
joseamirandavelez 4 years ago
they did.
frother 4 years ago
Ok... Where??
sircutman 4 years ago
This comment has received too many negative votes show
only a fake
HELLspawnTIM 4 years ago